Back to Blog
Guide14 min read

Pay-Per-Call Fraud Types Defined: From IVR Gaming to Caller Collusion

8 pay-per-call fraud patterns named and defined. Know what's draining your margins.

A legal intake network operator told me about the call that finally made him build fraud detection. Eleven minutes long. Caller answered every IVR question correctly — yes, I was in an accident, yes it was in the last two years, yes I was injured. Passed to the intake agent. Gave a name, gave a story, sounded legitimate. The law firm paid $180 for the call.

Two days later, same voice, different name, same scenario. Another $180.

It took six calls before someone noticed the pattern. Same voice. Same cadence. Different identities. $1,080 gone. One person. One week.

That wasn't a confused caller who forgot they'd already phoned in.

That was fraud.

Pay-per-call fraud isn't random bad luck. It's organized gaming of payout structures by people who understand exactly how your campaigns work. The patterns have names. And if you're buying or selling calls without knowing what incentivized traffic, IVR gaming, or caller-buyer collusion actually mean, you're flying blind on calls that cost $35 to $600 each. Understanding these fraud types is essential whether you're running pay-per-call campaigns or managing call center operations.

This isn't a detection guide — we've covered that in our fraud detection how-to. This is the glossary. Eight fraud patterns defined clearly so you can spot them, name them, and explain them to your team.

1. Incentivized Callers

The foundational pay-per-call fraud. Someone runs a scheme — "get paid to make phone calls" — and recruits people to dial your tracking numbers. The callers get $5-$15 per call. The schemer collects your $45-$150 payout. Arbitrage.

How it works: A fraudster identifies your tracking numbers (they're public on your landing pages), reverse-engineers your IVR qualification criteria from test calls, and writes a script. "Say you're a homeowner. Say your AC is broken. Stay on for at least 90 seconds." They recruit callers through gig economy sites, Telegram channels, or low-wage labor markets.

What it looks like in your data:

  • Geographic clustering. Calls cluster in zip codes that don't match your target market.
  • Temporal batching. Twenty calls between 2pm and 4pm on the same day, then nothing.
  • Minimal engagement. Callers say exactly enough to pass IVR, then go silent or hang up.
  • Consistent duration. 80%+ of calls end within 5-10 seconds of your billing threshold.

The economics: If your payout is $50 and they're paying callers $8, that's $42 profit per fraudulent call. A hundred calls a week is $4,200 monthly. That's enough to fund a small operation with margin to spare.

Honestly, incentivized traffic is more common than most operators want to believe. I've talked to networks that found 15-20% of their calls from certain publishers were incentivized — and those publishers had been running for months before anyone caught on.

I'll admit it: I missed an incentivized scheme for six weeks once. The numbers looked fine in aggregate. It wasn't until a buyer complained about close rates that I dug in. Embarrassing.

2. Repeat-Number Rings

The same phone number calling your tracking numbers multiple times, hoping each call generates a separate payout.

How it works: A fraudster (or a caller fed by one) dials your tracking numbers across different campaigns. Campaign A's number, Campaign B's number, Campaign C's number. Each campaign thinks it's a unique caller. Three payouts.

What it looks like:

  • Cross-campaign correlation reveals the same originating number hitting multiple tracking numbers in short windows.
  • Duration is suspiciously consistent — the caller knows your thresholds.
  • Call recordings may sound identical (same script, same cadence, same "qualifying" answers).

Why it works: Most operators analyze each campaign in isolation. Fraudsters know this. They rotate through your tracking numbers assuming you're not correlating.

Classic blind spot.

The fix is straightforward but underused: track originating phone numbers across ALL campaigns and flag repeats. A legitimate callback might hit the same number twice in a week. The same number hitting five different tracking numbers in three days? That's a pattern.

We talked about cross-campaign correlation in the fraud detection guide. If you're on VeloCalls, the platform handles this automatically. On Ringba or CallRail, you'll need to build the correlation yourself via exports or webhooks.

3. IVR Gaming

Callers — often incentivized or bots — who learn your IVR qualification logic and answer exactly what's needed to pass, regardless of actual intent.

How it works: Your IVR asks "Are you a homeowner?" The gamer presses 1. It asks "Is your project residential?" They press 1. It asks "Do you need service in the next 30 days?" They press 1. Every answer is designed to pass, not because it's true, but because they know the routing logic.

What it looks like:

  • Perfect IVR completion rates from specific sources — real callers fumble IVR sometimes.
  • Calls that pass IVR but have near-zero engagement with the agent.
  • Post-call disposition codes skew heavily toward "no intent" or "wrong info."

The danger: IVR gaming calls "qualify" by your platform's rules. They hit your duration threshold. They pass your routing logic. You pay out. But the downstream buyer gets garbage. Enough of that and the buyer drops their bid, demands clawbacks, or cuts your source entirely.

I've seen operators get confused here. "But the call met our criteria!" Sure. And your buyer's close rate from that source is 1%. Criteria met, value destroyed.

Here's my take, and I know some people disagree: IVR-only qualification is broken. If you're not layering agent feedback or post-call disposition into your payout logic, you're handing fraudsters the playbook.

The mitigation: Layer post-IVR signals. Transcription analysis catches callers who give monosyllabic answers or repeat IVR prompts verbatim. Sentiment analysis flags calls where the caller sounds robotic or disengaged. AI summaries highlight "caller provided no actual project details." The 4¢/min transcription add-on on VeloCalls pays for itself fast when you're catching IVR gaming.

4. Duration Stuffing

Callers who stay on the line just long enough to hit your billing threshold, then immediately disengage or hang up.

How it works: Your payout threshold is 90 seconds. The caller stays on for 91-95 seconds — enough to qualify — then drops. They might say the minimum words to seem engaged, or just sit silently waiting for the clock.

What it looks like in data:

  • Duration clustering. Pull a histogram of call durations. A spike at threshold + 2-5 seconds is duration stuffing.
  • Natural calls have wide variance — some 2 minutes, some 8 minutes, some 47 seconds that don't qualify. Stuffed calls cluster unnaturally tight.

Why it matters: A 91-second call that qualifies but converts at 0% is worse than a 45-second call that doesn't qualify. You pay for the former. The latter costs you nothing.

Real example pattern: A Medicare broker found that 34% of calls from one publisher ended between 180 and 185 seconds — threshold was 180. That publisher's calls had a 2% close rate vs. 12% industry average. They were sending coached callers who knew exactly how long to stay on the line.

Duration stuffing is often the symptom of incentivized traffic or IVR gaming rather than a standalone fraud type. The caller knows the rules; they're optimizing for payout, not conversion.

Drives me crazy. You build qualification logic to separate good calls from bad, and someone reverse-engineers it in a week.

5. Short-Call Padding

The inverse of duration stuffing. Publishers inflate reported call counts by including calls that never should have been counted — wrong numbers, immediate hang-ups, calls that connected for 3 seconds.

How it works: A publisher sends 500 calls, but 150 of them are sub-10-second connections that never reached a real conversation. If your reporting counts raw connects rather than qualified duration, the publisher looks like they're sending volume. Your CPL looks lower than it really is. And when you audit close rates, the math doesn't add up.

What it looks like:

  • High connect counts but low qualified-call counts.
  • Disproportionate percentage of sub-30-second calls from certain sources.
  • Effective CPL (total spend ÷ actual qualified calls) dramatically higher than reported CPL.

The fix: Define "billable" clearly in your buyer agreements. Most serious operators set duration thresholds at 60-120 seconds. Anything under that doesn't count for volume metrics OR payout. VeloCalls pricing is based on billable minutes, not raw connects—so your costs align with actual value.

6. Caller-Buyer Collusion

The fraud pattern that gets personal. A buyer on your network works WITH callers to inflate billable calls, then splits the payout.

How it works: A buyer sets up their own publisher (or recruits one). The buyer accepts every call from that publisher. The callers are coached to pass qualification. The buyer "buys" the calls, triggers payout to the publisher, and the publisher kicks back a percentage.

What it looks like:

  • A buyer with unusually high acceptance rates from one specific publisher.
  • That publisher's calls converting at near-zero rates downstream (the buyer never intended to work the leads).
  • Payout timing correlates suspiciously with no actual business activity on the buyer's end.

Why it's nasty: This fraud is internal. Someone on your platform is actively working against you. It's not a random bad actor from outside — it's a trusted party exploiting their position.

Detection signals:

  • Cross-reference buyer acceptance rates by publisher. A buyer accepting 99% of calls from Publisher X but 60% from everyone else warrants investigation.
  • Look at downstream conversion. If the buyer's close rate on Publisher X's calls is radically lower than their close rate on other traffic, something's off.
  • Audit payout flows. Collusion sometimes leaves financial fingerprints — payments cycling between related entities.

Strong opinion: most operators don't watch for internal collusion because they trust their buyers. That trust is often misplaced. I've seen collusion from buyers who'd been on platforms for years.

Look, nobody wants to believe their partners are stealing from them. I get it. But if you're not running the cross-checks, you're choosing ignorance over data.

7. Number Spoofing

Callers who manipulate their caller ID to mask their real originating number, evading suppression lists and velocity rules.

How it works: A fraudster uses a VoIP service that lets them set any outbound caller ID. They rotate through spoofed numbers to make each call appear to come from a unique source. Your repeat-number detection sees each call as unique. Your fraud scoring treats them as separate callers.

What it looks like:

  • Caller ID numbers that don't ring back — they're not real assignable numbers.
  • Geographic mismatches — the caller ID area code is Phoenix, but the caller says they're in Miami.
  • Numbers that appear in carrier spam databases or fail carrier validation lookups.

Detection: Twilio's Lookup API and similar services can check number validity and carrier type. Invalid or unassignable numbers flag hard. High rates of unroutable caller IDs from a source is a suppression-worthy signal.

Click fraud detection often correlates here — if you're running paid search to drive calls, ClickzProtect can flag suspicious click patterns that precede suspicious call patterns. Cross-channel fraud correlation catches rings that operate both click farms and call farms.

8. Bot Calling / Auto-Dialer Fraud

Automated systems — not humans — making calls to your tracking numbers.

How it works: A fraudster runs a dialer that calls your numbers, passes IVR via DTMF tones or basic TTS responses, and stays on long enough to bill. No human involvement after setup.

What it looks like:

  • Calls with unnatural audio — synthesized speech, no background noise, perfect timing.
  • AMD (answering machine detection) triggers that don't match a human pickup pattern.
  • Calls that pass IVR perfectly but fail when an agent asks an off-script question.

Why it's less common than you'd think: Most IVRs are simple enough that bots can pass them. But agent handoffs kill bot calls fast — an agent asking "so where exactly is the leak?" gets silence or nonsense. The fraud economics only work if calls never reach an agent, or if your payout triggers purely on duration + IVR completion.

VeloCalls includes AMD (answering machine detection) in the AI Conversation Intelligence layer. It won't catch all bots, but it flags calls where pickup patterns don't match human behavior.

Honorable Mentions

Geographic arbitrage: Callers from low-cost regions (international call centers) calling domestic tracking numbers, pretending to be local. Not technically fraud if the call is legitimate, but often paired with incentivized schemes. Similar geographic masking tactics appear in click fraud operations where bot traffic spoofs locations.

Replay attacks: Recording a legitimate call and replaying the audio to generate duplicate payouts. Rare because most platforms deduplicate on caller ID + timestamp, but it happens on poorly instrumented systems.

Publisher source-washing: A publisher runs incentivized traffic but labels it as organic or Google Ads traffic to pass source-quality filters. The sub-ID lies about origin. Harder to detect without click-call correlation. Tracking pixel-level analytics with tools like JustAnalytics can help correlate traffic sources with call outcomes.

Quick Verdict

If you only internalize one thing from this glossary: fraud patterns compound. Incentivized callers use IVR gaming. IVR gaming leads to duration stuffing. Repeat-number fraud uses number spoofing. The patterns overlap. Catching one reveals others.

The operators who get wrecked treat each fraud type as isolated. The operators who stay clean build scoring models that weight multiple signals together — velocity + duration clustering + geographic anomalies + VoIP status + cross-campaign repeats. Layered detection catches layered fraud.

For the actual detection rules and implementation steps, see our fraud detection how-to. For the broader pay-per-call vocabulary around non-fraud terms, the pay-per-call glossary covers 40 terms from ring trees to DNI.

And if you're running paid search or display to drive calls, correlate your click fraud and call fraud data. Fraud rings often operate both. ClickzProtect catches click fraud patterns; pairing it with call fraud detection closes the loop.

Frequently Asked Questions

What's the difference between incentivized callers and caller-buyer collusion?

Incentivized callers are third parties paid to dial your tracking numbers and fake qualification — they're gaming YOUR system for payout. Caller-buyer collusion is when a buyer on your platform works with callers to inflate billable calls, then splits the payout. The incentivized caller doesn't know or care who the buyer is. The colluding caller is working WITH the buyer against you. Incentivized fraud steals from buyers; collusion steals from publishers and networks.

How do I tell real callbacks from repeat-number fraud?

Real callbacks cluster around legitimate events — a homeowner calls back after getting a quote, or calls again because the call dropped. The time gap is irregular (hours or days), the duration varies naturally, and there's often a buyer or agent on the other end who remembers them. Repeat-number fraud hits the same tracking number pattern repeatedly, often from different tracking numbers in the same campaign, with suspiciously consistent durations. The tell is velocity + rotation — same number hitting multiple tracking numbers in tight windows.

Can IVR gaming actually hurt my campaigns if the calls still qualify?

Yes, because the downstream conversion kills you. An IVR-gamed call might pass your 90-second threshold and qualify for payout, but if the caller has zero intent, your buyer closes nothing. Enough of that and the buyer cuts their bid, demands clawbacks, or leaves your platform. You paid out for the call. You lost the buyer relationship. IVR gaming isn't victimless just because the call "technically qualified."

Is all VoIP traffic fraud?

Not even close. Legitimate callers use Google Voice, business VoIP systems, and softphones. But VoIP numbers are cheaper to provision and discard, so fraud rings favor them. The play isn't blocking VoIP entirely — it's layering VoIP status into your fraud scoring model alongside velocity, duration patterns, and geographic signals. High-VoIP traffic sources warrant extra scrutiny, not automatic rejection.


Try VeloCalls for Your Vertical

AI calling + pay-per-call platform built for HVAC, plumbing, roofing, PI lawyers, Medicare brokers, and insurance. Smart routing, real-time bidding, visual IVR builder, AI conversation intelligence. Per-minute pricing — Managed starts at 4¢/min, BYOC at 2¢/min, both drop as you scale.

See pricing → · Book a demo

pay-per-call-fraudcall-fraud-typesincentivized-callersivr-fraudcaller-collusionbuildinpublicsaasstudioaiworkforcebuildwithclaude
Share

Ready to try VeloCalls?

Set up intelligent call tracking and routing in minutes. No credit card required.

Get Started Free

Stay Updated

Get the latest articles and industry insights delivered to your inbox.

No spam. Unsubscribe anytime.

Related Articles