Traffic Pumping and Access Arbitrage: The Toll-Fraud Playbook

Most toll fraud steals something: a compromised PBX, a hijacked SIP credential, a premium-rate number nobody meant to dial. Traffic pumping steals nothing. It manufactures billable minutes and routes them to whoever collects the termination or access fee. The destination number is often perfectly legitimate. The fraud is the volume, and the money moves through the intercarrier compensation system rather than out of any single victim’s account.
That difference changes how you defend against it. An International Revenue Share Fraud call can be blocked outright the instant it matches a bad destination range. A traffic-pumping campaign can’t, because blocking the destination range would cut off legitimate callers who happen to dial the same rate center. Volume fraud is a velocity problem, and it has to be metered rather than switched off.
In this article, we’ll walk you through what access stimulation and traffic pumping actually are, how the toll-free (8YY) variant inverts the money flow, how access arbitrage chains extract the spread between carriers, and where a Session Border Controller fits with its per-destination velocity caps and percentage-based greylisting. For the wider toll-fraud picture and the five typologies an SBC has to recognise, the companion real-time toll fraud detection guide is the place to start.
What Access Stimulation and Traffic Pumping Actually Are
Access stimulation is a scheme built on the plumbing of intercarrier compensation. When a call crosses from one carrier’s network to another, the terminating carrier collects an access charge for delivering it. Those charges vary widely, and historically some rural rate centers carried far higher rates than urban ones. A carrier serving a high-rate location can strike a deal with a high-volume traffic source, a free conference bridge, a chat line, an adult-services provider, and split the inflated access revenue that the artificial volume generates. The terminating carrier “stimulates” access to its own network, hence the name.
Traffic pumping is the industry’s blunter word for the same practice. The mechanics are simple: drive as many minutes as possible to number ranges that pay well, and share the proceeds back down the chain. The destination is not a premium-rate trap in the IRSF sense; it is an ordinary number in a location whose access economics happen to reward volume. That is precisely why it is hard to police. You cannot blacklist a legitimate rural rate center.
Access stimulation is a US regulatory concern with a long history, and the Federal Communications Commission has repeatedly changed the intercarrier compensation rules to remove the arbitrage incentive, most recently by shifting financial responsibility for the traffic onto the carriers that stimulate it. The regulatory framing matters for compliance teams, but for a network operator the practical problem is unchanged: someone is pushing abnormal volume through your trunks, and it costs you money on every minute that terminates. The FCC’s access arbitrage rules address the settlement side; the SBC addresses the traffic side.
Toll-Free Traffic Pumping (the 8YY Variant)
Toll-free numbers invert the usual money flow. On an ordinary call the caller pays; on a toll-free (8YY) call the called party, the toll-free subscriber, pays for the call to be delivered. That inversion creates its own arbitrage opportunity. If a fraudster can generate large volumes of inbound calls to specific 8YY numbers, the toll-free subscriber foots the bill for termination while the originating and intermediate carriers collect the per-minute charges along the way.
The pumped traffic often looks superficially plausible: short calls, repeated attempts, sometimes machine-generated calls that hang up quickly or sit in an IVR long enough to bill. The 8YY subscriber sees a spike in inbound minutes with no corresponding business activity, and a spike in their toll-free bill. Because the access charges on the 8YY path were historically per-query and per-minute, even calls that never reach a human agent generate revenue for the carriers in the middle.
The FCC’s 8YY access charge reform tackled this by capping and restructuring the per-query and per-minute charges that made toll-free pumping profitable. On the network, the in-flight signal is a concentration of inbound calls to a narrow set of 8YY ranges that does not match the subscriber’s normal pattern, and it is caught the same way as any other volume anomaly: by watching the rate and concentration of calls rather than the content of any single one.
Access Arbitrage Fraud and the Revenue-Share Chain
Access arbitrage is the general form of which traffic pumping is one instance. The principle is a spread: one carrier pays a low rate to hand a call off, another collects a higher rate to terminate it, and someone in between profits from the difference. When that spread is exploited with artificially generated traffic rather than genuine customer demand, it becomes fraud, and the artificial volume is the tell.
A typical arbitrage campaign moves minutes through a chain of intermediaries, each taking a margin. The calls tend to be short and repetitive, often to the same B-number patterns, and frequently spread across many rotating calling numbers (A-numbers) to avoid tripping per-source limits. That rotation is deliberate: it spreads the volume thin enough at the source that a per-caller threshold never fires, while the destination concentration stays high enough to keep the scheme profitable.
Access arbitrage overlaps with International Revenue Share Fraud but is not the same thing. IRSF drives traffic to premium-rate international ranges owned by a colluding party, and the destination itself is the fraud vector, so blocking it is safe. Access arbitrage is usually domestic, the destination range is often legitimate at normal volumes, and the fraud lives entirely in the rate of calls rather than in any individual call. The response has to reflect that: metering, not blocking. The toll fraud detection guide lays out where each typology sits on that spectrum.
The In-Flight Signals a Volume-Fraud Campaign Leaves
Volume fraud is invisible one call at a time and obvious in aggregate. No single INVITE to a rural rate center or an 8YY number looks wrong. The pattern only appears when you watch the rate and the concentration over a trailing window, which is exactly what an SBC sitting in the signalling path is positioned to do.
Destination concentration is the clearest signal. A sustained, abnormally high share of traffic to a narrow set of B-number prefixes, with no business reason for that concentration, is the defining fingerprint of a pumping campaign. Where per-call fraud scoring asks “is this destination bad?”, volume-fraud detection asks “is this much traffic to this destination normal?”
Velocity covers the short-window rate signals. A sudden climb in calls per second to a destination range, a jump in concurrent calls, or a rate that stays elevated far longer than any legitimate campaign would all point to stimulation. These counters live inside the SBC and are available to the routing chain on every call.
ASR and ACD signatures add confirmation. Toll-free pumping often shows many short answered calls; access arbitrage often shows repetitive short-duration calls across rotating A-numbers. Reading Answer-Seizure Ratio and Average Call Duration together against the trunk’s baseline separates a real traffic surge from a manufactured one.
Source rotation is the countermeasure the fraudster uses against you, and spotting it is itself a signal. When the same B-number concentration is fed by a constantly changing set of A-numbers, that mismatch, high destination concentration but diffuse source, is a pattern legitimate traffic almost never produces.
How an SBC Defends Against Volume Fraud
The governing rule for volume fraud is to throttle before you block. Because the destination range can be legitimate at low volume, a hard block risks cutting off real callers and generating complaints, while the pumper simply shifts to the next range. Rate-limiting starves the campaign of the volume it needs to be profitable without taking the destination offline.
An SBC applies that posture through a handful of composable controls. Per-destination-range velocity caps limit how much traffic can flow to a prefix in a given window. Concurrent-call caps bound how many simultaneous sessions a source or trunk can hold. Anomaly alerts fire when B-prefix concentration crosses a baseline, feeding a human-reviewable queue rather than an automatic action. And ProSBC’s percentage-based greylisting blocks a configurable fraction of calls, so a 90% greylist collapses a campaign’s economics while letting the remaining legitimate traffic through. The SBC Security guide covers dynamic blacklisting and greylisting as part of the broader access-control layer.
On ProSBC these checks run as a before_filter in the Ruby routing chain, before the SBC picks an outbound route, so a throttled call never advances and never bills. The same chain can consult velocity counters, apply greylisting, and query an external scoring service in one pass, with Reason Cause Mapping translating each verdict into a routing action. Wiring those queries and counters into the routing script is the same integration pattern described in the SBC REST API call routing integration guide, and it is the same rate-limiting machinery that defends against SIP-layer denial-of-service floods.
Identity tooling helps at the margins but does not solve volume fraud on its own. A failed STIR/SHAKEN verification sharpens the score on a suspicious call, and a Do-Not-Originate policy stops traffic that claims to come from numbers that never originate calls. But a pumping campaign can run entirely on legitimately attested calls to legitimate destinations. The volume is the fraud, so velocity is the control, and the SBC is the one element in the path that meters it at call setup rather than discovering it four weeks later on the carrier bill.
Meter Volume Fraud at the Call-Setup Edge
ProSBC ships with the per-destination velocity caps, concurrent-call limits, percentage-based greylisting, and Do-Not-Originate module needed to meter access stimulation and traffic pumping in the call-setup window, before any minute terminates. The same Ruby before_filter chain composes those velocity controls with the validated partner integrations, TransNexus ClearIP, SecureLogix, YouMail, JeraSoft, and Neustar, so one routing pass handles volume fraud, identity, and per-call scoring together.
If you want to see how greylisting and velocity caps behave against your own traffic mix, the fastest path is to wire them up on a real trunk in a 30-day evaluation. The ProSBC fraud detection solution page covers the partner integrations and deployment patterns in more detail.
Prefer to evaluate on your own first? Start your 30-day free trial.