International Revenue Share Fraud (IRSF)
Summary
The article documents a coordinated IRSF (International Revenue Share Fraud) campaign where a diverse set of organizations, from Citigroup to Build-A-Bear and beyond, unknowingly participated by having their systems call international premium-rate numbers via a compromised SIP server. It explains how the attacks were coordinated, the use of spoofed caller IDs, and how a honeypot API can help organizations quickly check if their networks were involved. The piece also provides actionable steps to detect and mitigate compromised machines and emphasizes daily monitoring.