img

Q3 2025 Fraud Report by AB Handshake

#Fraud types#IRSF#Wangiri#Spam#Flash Calls#AIT#P2S

Knowledge base

7 min read
Oct 09, 2025

This read pulls together our quarterly findings, explains what each fraud looks like in practice, shares real-world patterns and anecdotes, and closes with practical detection and mitigation advice driven by AB Handshake’s AI-equipped Fraud Management System. 

Telecom fraud never sleeps. What changes is the how. Q3 2025 is full of surprising events across our customer base, as we observe fraudulent attacks continue trying to break through defenses.

Our Q3 2025 review focuses on the major fraud vectors observed in voice and SMS traffic monitored by the AB Handshake Fraud Management System:

  1. Spam
  2. Wangiri
  3. Flash Calls and the Countries They Terminate To
  4. Flash Calls and the Countries They Originate From
  5. Flash Calls: Local Number Origination and Termination
  6. CLI Spoofing: The Invisible Engine Behind Most Modern Fraud

1. Spam

What It Is

Spam traffic typically includes unsolicited robocalls or autodialed messages, often used for advertising, scamming, or phishing. These calls may not always result in monetary loss, but they disrupt operations and harm user trust.

Q3 Highlights

  • Top receivers of inbound spam: Colombia led with 21.99%, followed by the USA (10.79%) and Mexico (10.43%).

What the Data Tells Us

The USA has historically been a major target for spam traffic, which in part drove the development of the STIR/SHAKEN framework. However, the Q3 data suggests that spam remains a persistent challenge, indicating that STIR/SHAKEN alone is not sufficient to fully prevent these attacks. Interestingly, Colombia accounts for roughly twice the share of observed inbound spam compared with the average US subscriber, highlighting how spam patterns are shifting geographically. This may suggest that while STIR/SHAKEN has helped reduce the impact of spam in some markets, additional strategies and detection measures are still required to address the evolving threat.

2. Wangiri inbound attacks

What It Is

Wangiri fraud works by triggering short one-ring calls or missed calls to users from revenue-share numbers, enticing them to call back. Those who do return these calls do not realize they are calling a revenue-share number from which the fraudster profits. 

Q3 Highlights

  • Top receivers of inbound Wangiri attacks as a percentage of all inbound traffic: The UK leads with 10.41%, followed by Kazakhstan (7.42%).

What the Data Tells Us

Wangiri attempts continue to lure unsuspecting users into calling back revenue-share numbers, generating profit for fraudsters with every returned call. What stands out in the data this quarter is the noticeable absence of certain countries, such as the USA, among the top targets of inbound Wangiri attacks. This may suggest that proactive anti-fraud measures, such as STIR/SHAKEN and ongoing regulatory collaboration, are having a deterrent effect. When countries take visible steps to strengthen their defenses and openly address these scams, it appears that fraudsters may shift their attention elsewhere, avoiding markets that have become too costly or complex to exploit.

3. Flash Calls and the Countries They Terminate To — The Silent, Unmonetized 2FA Loophole

What It Is

Flash calls are often used legitimately for rapid verification (app sign-ins, one-time password delivery). Fraudsters abuse this mechanism to generate silent calls at scale or to farm responses from carriers and APIs.

Q3 Highlights

  • Top destinations for Flash Calls: Mexico leads with an overwhelming 248.8M total attempts, followed by Chile (184.2M) and Peru (147.2M).

What the Data Tells Us

Flash Calls continue to surge, with 248.8 million calls terminated to Mexico this quarter alone. Analysis of our customer networks shows that countries in Central and South America are being targeted most heavily, while much of Europe is experiencing comparatively lower volumes. This pattern highlights a regional concentration of Flash Call activity and underscores the need for targeted fraud detection and mitigation strategies in the hardest-hit markets.

4. Flash Calls and the Countries They Originate From

What It Is

Flash calls are often used legitimately for rapid verification (app sign-ins, one-time password delivery). Fraudsters abuse this mechanism to generate silent calls at scale or to farm responses from carriers and APIs.

Q3 Highlights

  • Top origins of Flash Calls: Mexico leads with an overwhelming 234.3M total attempts, followed by Chile (180.5M) and Peru (146.2M).

What the Data Tells Us

Analysis of Flash Call originations highlights a strong overlap between the top sending and receiving countries, namely Mexico, Chile, and Peru. These countries are not only generating massive volumes of Flash Calls but are also among the primary destinations, indicating a potentially self-contained cycle of fraud.

The scale and persistence of this activity underscore the urgent need for effective mitigation. Fraud continues to grow where preventative measures are absent, and the detection of this traffic by AB Handshake demonstrates that many existing fraud systems are currently unable to identify or block these sophisticated operations effectively. Without targeted intervention, fraudsters continue to view these schemes as highly profitable and low-risk.

5. Flash Calls: Local Number Origination and Termination

What It Is

This section identifies the top 10 countries where Flash Calls were received using local destination numbers, based on the number of alerted attempts during the quarter. A Flash Call with a local number occurs when a verification call is placed to a number that matches the local numbering format of the receiving country, making it harder to detect as foreign or suspicious. Fraudsters may exploit this method to evade international traffic filters, bypass fraud detection systems, and blend Flash Calls into regular traffic patterns.

Q3 Highlights

  • Top destinations with local numbers: Peru leads with an overwhelming 557K alerted attempts, followed by Mexico (484.8K) and Chile (179.7K).

What the Data Tells Us

Analysis of Q3 data reveals a clear and emerging trend in Flash Call activity involving local numbers, particularly in Peru and Mexico, with similar patterns also appearing in Chile and France. Fraudsters are increasingly reusing successful local-number spoofing strategies across multiple countries, generating Flash Calls that mimic domestic numbering formats to evade detection.

This indicates a replicable methodology, likely orchestrated by the same operators, that is now spreading to additional regions. Early signs suggest that countries such as Brazil, the UK, Bangladesh, the Netherlands, Guatemala, and Italy may also be targeted using the same local-number tactics. While these patterns are still developing, the data highlights the rapid adaptability of fraudsters and the need for proactive detection measures to prevent wider adoption.

6. CLI Spoofing: The Invisible Engine Behind Most Modern Fraud

What It Is

CLI (Calling Line Identification) spoofing is the practice of falsifying the caller ID presented to the recipient of a call. Fraudsters manipulate the calling number to disguise their true identity or origin, making it appear as if a call is coming from a trusted source, a local number, or even a known contact.

Originally used to trick users into answering spam or Wangiri calls, spoofing has now evolved into a much more adaptive and complex fraud vector. It underpins much of today’s call-based fraud ecosystem, silently enabling everything from missed-call scams to large-scale Flash Call operations.

Q3 Highlights

Local-number spoofing has surged, particularly in regions like Peru, Mexico, and Chile, where fraudsters are generating Flash Calls using local-looking CLIs.

Spoofed CLIs are increasingly being used for Wangiri attacks, masking international revenue-share numbers with domestic prefixes to trick subscribers into calling back.

Spam, scam, and robocall campaigns continue to rely on CLI rotation and spoofing to bypass blocking lists and appear more legitimate to users and networks.

What the Data Tells Us

In Q3 2025, we’re seeing a significant shift in how spoofing is being operationalized. Historically, spoofing served as a disguise, but now it’s a weaponized automation tool. Fraudsters are using local-number spoofing to simulate Flash Calls that look entirely domestic, allowing them to blend verification traffic into standard call flows.

This approach is particularly dangerous because it: 

  • bypasses traditional anti-fraud rules that rely on international routing detection 
  • reduces consumer suspicion because the incoming number looks familiar 
  • overwhelms detection systems as millions of micro-duration calls are distributed across legitimate ranges

In several customer networks, AB Handshake detected a repeating pattern where Flash Calls were generated using spoofed local CLIs, often mimicking nearby area codes or mobile prefixes. These were not isolated to one region but were seen across Latin America, Europe, and parts of Asia. The same operators appear to be recycling number pools and techniques from one geography to another, rapidly adapting as detection rules tighten.

The Link to Wangiri and Spam

It’s becoming increasingly evident that the same technical infrastructure used for Wangiri and spam operations is now being repurposed for Flash Call activity. The spoofing logic that once focused on enticing callbacks now focuses on generating trust and avoiding detection. In effect, fraudsters’ intent has evolved, but the underlying toolset (CLI spoofing) remains the same.

Wangiri attacks spoof to entice; flash calls spoof to disappear.

What Success Looks Like and How We Can Get There

Fraudsters have become adept at using spoofing dynamically, manipulating CLI data in real time to imitate local traffic and pass through filters. The traditional reliance on statistical or heuristic detection is no longer sufficient. Only real-time, cryptographically verified call validation can close this loophole.

That’s where AB Handshake’s Call Validation solution becomes critical. By enabling operators to verify every call between networks, confirming that both the A and B parties are legitimate and that the CLI has not been altered, AB Handshake’s system makes CLI spoofing ineffective. When each call is validated through handshake-based cryptographic confirmation, spoofed identities simply fail the validation and are blocked before reaching the subscriber.

As fraudsters continue to innovate, so must we. AB Handshake’s Call Validation solution offers a network-level truth layer that renders spoofing ineffective and restores confidence in caller identity across the telecom ecosystem.