How are the alerts sent?
International Fraud alerts can be sent to us via email from different addresses. Reason being we have different application servers in which Broadsoft users and/or groups exist and each having fraud detection enabled. The email that it is sent from should follow the scheme of internationalfraud@AS[?].voip.evolveip.net.
How are these alerts different?
As stated in the definition of this type of alert, if the block threshold is reached, you will see 1 of 2 messages depending on the alert is for a user or the group indicating the seat or group was intercepted. Intercepted meaning the line will be placed out of service and all outbound and inbound call attempts will fail:
User Intercept Message: THIS USER WILL BE BLOCKED!!!
Group Intercept Message: THIS GROUP WILL BE BLOCKED!!!
By the time you see this message the user seat or group has already been intercepted by the platform, so it stating, “WILL BE” does not mean it did not happen.
Example Email Alert
In this example we see the fraud alert was sent from email address of AS15. In the email body we can see the threshold setting that caused this alert to fire is user call threshold=6. In addition, we can also see the group threshold as group call threshold=25. Next we can set the block thresholds are user block threshold=10 and group block threshold=50. We can see the user placed a total of 35 calls, but only 11 were international. We get the User ID of the seat, all 11 international calls that triggered the alert, and lastly the message, “THIS USER WILL BE BLOCKED.” So due to this user seat having block threshold being 10 and placing 11 consecutive international calls the seat was intercepted.
Step 1: Grab the User IDs/Phone Numbers in question and start gathering the details:
What you need to investigate is the legitimacy of these call attempts. Legitimacy can be determined by confirming but not limited to the following:
Is International Dialing Enabled?
What device was being used to initiate the calls (Ex: UC-One or Desk Phone)?
What IP of the said device is registering from? If placed from a desk phone, confirm if they have an Edgewater present.
There is no Call Forward Always, Remote Office, or Sim Ring sending calls to an International number. Please keep in mind that even if there is a Call Forward Always set in certain cases can be legit if the pinhole is created in Broadsoft Backend.

