The observed pattern
Automated scanning identifies an exposed registration endpoint or a weak credential, and high-concurrency calls are then placed to premium-rate or high-cost destinations.
Initiation clusters outside working hours and before extended holidays. The variable being exploited is detection latency rather than technical difficulty: an event initiated on a Friday evening runs until Monday.
Recovery is generally discretionary rather than contractual, which makes prevention economically dominant over remediation by a wide margin.
Deny at the boundary
Restrictive destination policy at the connectivity boundary is the single highest-value control. Most organisations dial a small, stable destination set; permitting the complement provides no operational value while carrying the entire exposure.
Premium-rate and satellite ranges warrant explicit exclusion. They are the monetisation path, and legitimate accidental dialling is vanishingly rare.
Remove the credential
For fixed sites, address-based authorisation is structurally stronger than credential-based registration because it removes the secret entirely. There is nothing to extract from a configuration backup, a support ticket or a departing administrator.
Where credentials are unavoidable — soft clients and mobile endpoints — they should be long, unique per device, provisioned automatically rather than transcribed, and rotated on device loss or departure.
Contain, do not alert
An alert is effective only if observed, and the timing of these events is chosen precisely so that it is not.
Thresholds must therefore act: concurrency ceilings, rolling spend limits and destination deviation, each capable of stopping traffic unattended. Set them tightly enough to detect anomaly and accept occasional false positives as the price of a control that works while nobody is watching.