Papers
Topics
Authors
Recent
Search
2000 character limit reached

Robocalls: A Worldwide or US-only Problem? Analyzing Spam and Fraud in International Phone Calls

Published 30 Jun 2026 in cs.CR | (2606.31790v1)

Abstract: Unsolicited automated phone calls (robocalls) are a serious threat: in the US alone, these calls resulted in reported losses of 1.1$ billion during 2025. Phishing and spoofing consistently rank among the most reported crimes within the FBI's Internet Crime Complaint Center, with phone call scams having the highest reported median loss. Combating robocalls is difficult due to many legal and practical constraints: robocalls often encompass multiple legal jurisdictions of different countries/states, the large volume of robocalls, their multilingual nature, the lack of publicly available data, privacy concerns with obtaining data, etc. We present a study of international robocalls, aggregating robocall reports from countries across all inhabited continents and contribute by providing new findings on international robocalls from 65 different countries. We also present the first publicly available multimodal and international robocall dataset: 8.7 million call detail records, 839 robocall transcripts from 28 identified robocall campaign clusters, and 677 robocall recordings. We describe our methodology for collecting robocall data over a 9-month period and provide a detailed analysis comparing robocalls in the US with those in other countries. Our analysis covers several aspects, including uncovering calling patterns, identifying co-targeting attacks, discovering common robocall campaigns, extracting callback numbers, analyzing linguistic differences among robocalls in the same language but different regions, and other insights. Our results indicate that although robocalls are an international problem, the severity of the threat is significantly higher in the US than in other countries. We provide steps for future research and suggest remedies to reduce the effectiveness of robocalls based on our analysis.

Summary

  • The paper presents first comparative empirical evidence showing a stark US-centric intensity in robocall activity with a 19:1 call ratio between US and international targets.
  • It employs a novel dual-mode honeypot infrastructure that collected over 8.7 million call records from 65 countries, enabling detailed analysis of campaign structure and linguistic patterns.
  • Advanced clustering and transcript similarity analyses reveal coordinated scam campaigns and dynamic attacker adaptation, informing technical and policy countermeasures.

Robocalls: Transnational Analysis and Empirical Insights from Multimodal, Multilingual Honeypot Data

Introduction

The paper "Robocalls: A Worldwide or US-only Problem? Analyzing Spam and Fraud in International Phone Calls" (2606.31790) delivers the first comparative empirical study of international versus US robocall activity based on a large-scale, multinational honeypot system. The authors present a new multimodal, multilingual open dataset comprising 8.7 million call detail records (CDRs), 839 manually verified robocall transcripts, and 677 call audio recordings from 65 countries. Leveraging over 100,000 globally distributed phone numbers across a 9-month observation window, the research quantitatively and qualitatively contrasts robocall prevalence, campaign structure, linguistic properties, and operational behavior between US and international targets.

Experimental Infrastructure and Dataset

The methodological core is a dual-mode honeypot architecture. In passive mode, the system records inbound call metadata without answering, minimizing influence on caller behavior and maximizing data on unsolicited interactions. In interfering mode, calls are answered and a multilingual warning about call recording is played, after which calls are recorded for subsequent content analysis. This approach is notable for its scale—over 100k phone numbers, yielding approximately 9.6 million raw calls—and for being the first to systematically deploy such an infrastructure internationally. Figure 1

Figure 1

Figure 2: The two honeypot modes: passive (metadata-only, non-interfering) and interfering (active warning, call recordings).

Ethical and legal considerations directed stringent anonymization of metadata and verification by human annotators of all released recordings and transcripts. Notably, only caller IDs with at least two calls are included in analyses, and singletons are excluded as likely human misdials.

Empirical Characterization of Robocall Volume and Patterns

A key numerical result is the US-centricity of robocall activity:

  • Median US honeypot size: ~11,751 numbers; International: ~101,913.
  • Total calls: 8,314,813 targeting US; 432,538 targeting non-US (ratio ≈ 19:1).
  • Normalized rate: 692.6 calls per available US number; 4.25 per non-US number. Figure 2

    Figure 3: Monthly average robocall volume in the US, peaking at 2.56 billion in 2025, the highest since 2019.

Temporal analysis reveals:

  • Robocalls peak during business hours (US: 61% during M–F 9–5; International: 69.9%).
  • Weekend and nighttime calling is markedly reduced, reflecting attacker optimization for answer rates in local callee time zones. Figure 4

    Figure 1: Temporal density of robocalls by hour and day for US versus international numbers, indicating strong business hours targeting in both.

Call distribution is heavy-tailed:

  • Median caller made 6 calls; top 1% of callers generate 24.4% of all calls (Gini = 0.66 US, 0.53 international). Figure 5

    Figure 6: Call volume per caller ID exhibits a long-tail with a small number of hyperactive sources.

Neighbor spoofing (spoofing caller IDs to match callee regions) is dominant:

  • 89.9% of all calls display a caller country code matching the callee.
  • Cross-border attack patterns, e.g., Nigeria is the top non-domestic source for 35 US states. Figure 7

    Figure 4: Global map of dominant external robocall source countries per target nation.

    Figure 8

    Figure 5: US state view of dominant non-domestic robocall sources, with Nigeria prominent.

Campaign Structure and Actor Organization

To detect structural coordination, the authors construct graphs linking caller IDs that target the same honeypot numbers within 24-hour windows and cluster these via weighted Leiden community detection.

  • Group-size distribution is heavy-tailed; most clusters contain few actor IDs, but a small minority are large.
  • Critically, message similarity within clusters (mean cosine similarity 0.728 US, 0.629 international) far exceeds between-cluster similarity (0.516 US, 0.475 international); ratio uplift: 1.41× (US), 1.33× (Intl). Figure 9

    Figure 7: Size distribution of temporal co-targeting caller clusters: most groups are small, with a few large coordinated campaigns.

    Figure 10

    Figure 8: Within-group transcript embeddings exhibit significantly higher semantic similarity than between-group pairs, validating campaign structure inferred from metadata alone.

Call Content and Linguistic Analysis

Silence and Adversarial Adaptation

Analysis of audio recordings and VAD reveals that a substantial fraction of robocalls are "blank" (US: 75.22% silent; Intl: 58.98%), suggesting scout calls or use of Answering Machine Detection (AMD). A switch from passive to interfering honeypot mode—which plays a warning to the caller—produces a pronounced drop in call volume, supporting the hypothesis that attackers dynamically adapt to monitor responses. Figure 6

Figure 9: Daily call volume drops acutely when the honeypot begins answering and warning callers, consistent with AMD-based attacker adaptation.

Figure 11

Figure 10: Call duration distribution with most calls <20s, characteristic of mass scanning and drop-off after preliminary detection.

Figure 12

Figure 11: Proportion of vocal activity: a large fraction of robocalls have minimal or no speech, in line with previous findings.

Linguistic Distribution

  • English dominates both domains (US: 92.35%; Intl: 59.44%), with Spanish and regionally prominent languages (Mandarin, Polish, Hindi) also represented.
  • High-frequency word clouds by language and region display campaign-characteristic terms ("press", "loan", "payment", "credit") but also clear regional variation in phrasing and tactics:
    • US robocalls: More likely to persuade targets to call a given number (33.6% of US transcripts contained a callback number, compared to only 1.8% internationally).
    • International robocalls: Increased use of interactive instructions (e.g., pressing buttons) rather than callback inducement.

(Figure 13) and (Figure 14)

Figure 12: Word clouds and chord diagram illustrating flow of language-to-country in robocall targeting.

Automated and Manual Campaign Discovery

DBSCAN clustering on normalized transcript TF-IDF vectors, followed by manual campaign labeling and LLM categorization, surfaces the most prominent scam archetypes:

  • US: Technology-oriented scams (notably Google business listing impersonations), grants/benefits scams, technical support fraud, and a significant non-malicious segment (legitimate public agency notifications).
  • International: Prevalence of loan/debt/recovery scams, multilingual in execution (English, Hindi, Spanish), and political spam. Figure 15

    Figure 16: Robocall scam category breakdown: US is distinguished by dominance of tech support, business, and some legitimate notifications, while international campaigns skew toward financial/fraud scams.

Theoretical and Practical Implications

Robustness and Attacker Adaptability

The failure of STIR/SHAKEN and related caller authentication frameworks to curtail robocalling, particularly in transnational contexts, is repeatedly underscored. Attackers circumvent regional controls via international routing, multisource spoofing, and adapt dynamically to the presence of detection systems.

Multilinguality and Real-world Impact

The open, multilingual dataset establishes new benchmarks for real-time, multilingual robocall and fraud detection research, particularly for machine learning models robust to adversarial silence, cross-lingual transfer, and spoofed metadata.

Policy and Countermeasure Guidance

Key numerical results: US recipients are an order of magnitude more targeted than international numbers, and a minority of high-volume actors ("supercallers") are responsible for a large portion of activity. This supports interventions that disproportionately burden or block prolific / cross-regional attack infrastructure. Evidence for attacker AMD and campaign-level adaptation suggests that both technical and policy measures should be dynamic and resilient to rapid evolutionary evasion.

Limitations and Future Directions

Main limitations are driven by ethical constraints (e.g., mandatory warning messages in recordings, exclusion of singleton calls to reduce the probability of capturing human misdials) and technical variability (e.g., availability of numbers, treatment of international groups as a single block rather than per-country granularity).

The dataset and codebase provide a foundation for further research, including:

  • Region-specific, language-agnostic detection models.
  • Systematic adversarial studies on attacker adaptation to detection/warning signals.
  • Collaboration with carriers and regulators for fine-grained, real-time threat intelligence fusion.

Conclusion

This study delivers clear empirical evidence that robocalls, while global, are of significantly higher intensity in the US relative to other countries, both in per-number and aggregate terms. The authors expound the structural, temporal, and linguistic features of robocall campaigns, highlighting attacker adaptation strategies in response to detection and deterrence. The release of a large, open, multimodal dataset marks a substantial resource for future robust robocall detection systems, cross-lingual anti-fraud research, and informs evolving regulatory and technical countermeasures addressing the persistent global challenge of fraudulent phone spam.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.

Collections

Sign up for free to add this paper to one or more collections.