Step Q · toll fraud

Toll fraud

The attacker uses valid credentials, so nothing in the security layer sees them. What gives it away is the behaviour.

Nothing is gated.

Satellite and premium ranges are reachable by every customer with no approval. make migrate loads a starting list.

Open alerts (0)

Nothing has fired.

Right now, against each customer’s own pattern

The multiple is against what THAT customer normally does IN THIS HOUR. Call-centre traffic looks like fraud by default — high CPS, sudden volume, odd hours — so their own pattern is the only useful comparison.

No active customers.

The hard gate: high-cost destinations

An approval list, not a block list. A block list protects you from what you thought of; an approval list protects you from what you did not. This half does not learn and does not wait — it works on day one.

Who is approved

Nobody is approved for any high-cost range.

Baseline window days. Auto-suspend safety valve: at most customer(s) in one pass, above which nobody is suspended at all.

On the command line: make fraud-check, make fraud-live, make fraud-alerts, make fraud-approve CUST=1 P=882 BY="name" WHY="reason" DAYS=14.