In short
Common causes include grey routes, SIM farms, SIM boxes, unauthorised SMPP connections, P2P routes carrying commercial traffic, Sender ID manipulation, GT manipulation, traffic misclassification and other forms of routing bypass. Most operators have several running simultaneously, at different scales.
External causes
These are the categories that involve a third party deliberately avoiding the commercial channel:
- Grey routes injecting commercial traffic over P2P-priced interconnects
- SIM boxes and SIM farms terminating A2P as ordinary subscriber traffic
- Unauthorised SMPP connections, often using credentials shared or resold downstream
- Delivery from Global Titles with no A2P agreement, or from spoofed addresses
- SMS home routing bypass, so inbound traffic never reaches the screening point
Internal causes
A significant share of leakage is not fraud at all. Traffic is misclassified because the classifier was never tuned for a new sender category. Registry entries go stale as enterprises change aggregator. Test and staging accounts stay open at production throughput. Volume-based discounts continue after the contractual period.
These are usually easier to fix than bypass and frequently account for more revenue than anyone expects, because nobody is hiding them — nobody is looking.
Finding the proportions
The mix differs by market. Operators with high international A2P exposure tend to leak through interconnect and GT manipulation; operators with large domestic enterprise bases tend to leak through SIM-based termination and misclassification.
Establishing the proportions before choosing controls avoids the common mistake of deploying signaling-layer screening in a market where most leakage is happening over SMPP, or vice versa.