The attacker uses valid credentials, so nothing in the security layer sees them. What gives it away is the behaviour.
Satellite and premium ranges are reachable by every customer
with no approval. make migrate loads a starting list.
Nothing has fired.
The multiple is against what THAT customer normally does IN THIS HOUR. Call-centre traffic looks like fraud by default — high CPS, sudden volume, odd hours — so their own pattern is the only useful comparison.
No active customers.
An approval list, not a block list. A block list protects you from what you thought of; an approval list protects you from what you did not. This half does not learn and does not wait — it works on day one.
Nobody is approved for any high-cost range.
Baseline window days. Auto-suspend safety valve: at most customer(s) in one pass, above which nobody is suspended at all.
On the command line: make fraud-check,
make fraud-live, make fraud-alerts,
make fraud-approve CUST=1 P=882 BY="name" WHY="reason" DAYS=14.