Communication
VoIP Fraud and Toll Fraud: How to Protect Your Business Phone System
VoIP fraud happens when someone abuses an internet-based phone service, account or feature for unauthorised calls or financial gain. Toll fraud is one of the most common forms: an attacker gains access to a phone system and generates calls to expensive destinations, premium services or numbers connected to the fraud.
The business may not notice until unusual calls appear, staff report strange behaviour or a large carrier invoice arrives. In other cases, the first sign is an account lockout, a sudden spike in call traffic or customers saying they received calls that appeared to come from the business.
Protecting a phone system does not require a business owner to become a telecommunications engineer. It does require clear ownership, sensible calling rules, protected administrator access and monitoring that somebody is responsible for reviewing.
What is VoIP fraud?
Voice over Internet Protocol, or VoIP, carries calls using internet-based networks and services. It gives businesses flexible calling, remote applications, call queues and easier multi-site communication. Those same connections and accounts can be misused when credentials, configuration or provider controls are weak.
VoIP fraud is a broad term that may include:
- unauthorised outbound calls;
- toll fraud to high-cost or international destinations;
- stolen SIP or extension credentials;
- abuse of voicemail forwarding or call-diversion features;
- account takeover;
- caller ID spoofing;
- fraudulent number porting;
- robocalling or spam using compromised services; and
- social engineering aimed at staff or service providers.
Not every unexpected call charge proves that the phone platform was hacked. Misconfiguration, forgotten forwarding rules, compromised devices or misuse by an authorised person may produce similar symptoms. Investigation should follow call records and provider evidence rather than assumptions.
What is toll fraud?
Toll fraud occurs when unauthorised users generate chargeable calls through another person or organisation’s telephone service. The attacker benefits directly or indirectly, while the account holder receives the cost or service disruption.
A common pattern involves repeated calls to international, premium-rate or revenue-sharing numbers. Fraud may be concentrated after hours so that traffic continues for several hours before staff notice. Automated tools can generate large volumes quickly, which is why spending limits and alerts matter.
Toll fraud is not limited to cloud phone systems. Traditional PBXs, voicemail systems, SIP trunks and mobile services can also be abused. The relevant controls depend on the architecture.
How attackers gain access
Weak or reused passwords
An extension, web portal or administrator account protected by a predictable or reused password is easier to compromise. Credentials exposed in another breach may also be tested against phone services.
Exposed management interfaces
Phone-system administration should not be left openly reachable without an approved security design. Attackers scan internet services for known products, default settings and old vulnerabilities.
Unpatched systems
Unsupported or outdated software may contain known weaknesses. Patching needs planning, testing and ownership, especially where an update can affect calling.
Compromised SIP credentials
SIP trunks and endpoints use credentials or trusted connections to register and place calls. If those details are stolen, an attacker may attempt to place calls through the service.
Voicemail and call forwarding
Old voicemail systems and poorly controlled forwarding features have historically been used to route calls or obtain dial tone. Unused remote-access features should be disabled.
Phishing and social engineering
An attacker may persuade an employee or provider to reset access, reveal information or change forwarding. A convincing request can bypass strong technology if identity is not verified.
Compromised remote devices
Softphones, laptops and mobiles used away from the office may store tokens, account details or active sessions. Lost, unmanaged or infected devices can create another route into the service.
Supplier-account compromise
The carrier, reseller, hosted phone provider and internal administrator may each control part of the service. An account compromise at any point can affect numbers, routing or billing.
Common forms of business phone fraud
International revenue-share fraud
Attackers generate traffic to destinations from which they may receive part of the call revenue. Calls can be short and numerous or kept connected for long periods.
Premium-rate fraud
The compromised service is used to call high-cost premium numbers. Blocking unnecessary destinations reduces exposure.
Caller ID spoofing
Scammers may present a caller ID that resembles a real business number. Spoofing does not always mean the business’s phone system was compromised, but it can damage trust and produce complaint calls.
Number-porting fraud
An attacker may try to transfer a business number to another provider by impersonating an authorised contact. Strong account controls and provider verification can reduce the risk.
Account takeover
Access to the provider portal may allow an attacker to add users, change routing, enable destinations or obtain billing information. Administrator accounts deserve stronger protection than ordinary extensions.
Call-forwarding abuse
Unauthorised forwarding can redirect customer calls or create chargeable call paths. Review forwarding rules, especially after staff changes.
Warning signs of VoIP or toll fraud
Fraud is easier to contain when someone knows what a normal call looks like. Warning signs include:
- international calls to unfamiliar destinations;
- high call volume outside trading hours;
- Repeated short calls or unusually long connections;
- a sudden increase in carrier spend;
- extensions registering from unexpected locations;
- new administrator accounts or configuration changes;
- call forwarding that nobody approved;
- failed login or registration spikes;
- users being locked out;
- complaints about calls apparently made from the business; and
- changes to numbers, trunks or routing.
One unusual call may have a legitimate explanation. A pattern requires prompt review.
How to protect a business phone system?
Use strong, unique credentials
Every administrator, provider portal and supported phone account should use a unique password. Avoid default extension passwords and credentials based on the extension number, business name or address.
Use multi-factor authentication where the service supports it, particularly for administration and provider portals.
Restrict outbound destinations
Most businesses do not need every extension to call every destination. Disable premium and high-risk destinations that are not required. Allow international calling only for approved users or countries.
Restrictions should follow business needs. A company with overseas customers may require broader access, but it can still apply user, time or destination controls.
Set spending and call limits
Ask the carrier or provider about credit limits, call-duration limits, concurrent-call limits and thresholds. A limit cannot prevent every incident, but it can reduce the size of an automated fraud event.
Enable billing and traffic alerts
Alerts should cover unusual destinations, after-hours volume, rapid spending and registration anomalies where available. An alert has value only when it reaches somebody who can assess and escalate it.
Protect administrator access
Limit administration to authorised people and networks. Remove old accounts, avoid shared credentials where possible and record changes. Review administrator access after an employee or supplier leaves.
Maintain supported software
Keep the PBX, applications, gateways, handsets and related systems within vendor support. Apply updates through an agreed process and remove obsolete services.
Secure SIP trunks and endpoints
Use the authentication, encryption, trusted-IP and registration controls supported by the provider and platform. The exact configuration depends on the architecture and should be handled by a qualified person.
Disable unused features
Remote access, voicemail dial-out, forwarding, unused extensions, dormant accounts and old integrations increase the number of paths to manage. Turn off what the business does not need.
Segment voice and guest networks
Where appropriate, separate voice devices from guest and general traffic. Segmentation can improve control and troubleshooting, though it needs proper design.
Protect remote workers
Use supported applications, managed devices where appropriate and a clear process for lost equipment. Staff should know how to verify unexpected login or access requests.
Review call records
Call-detail records can show destination, time, extension, duration and cost. Review them regularly, not only after the invoice increases.
Document supplier responsibility
Write down who manages the phone platform, SIP trunk, internet service, numbers, handsets and billing. Include trusted support contacts and escalation paths.
A practical VoIP fraud prevention checklist
| Control | Question for the business |
|---|---|
| Administrator access | Who has it, and is multi-factor authentication available? |
| Passwords | Are all portal, extension and device credentials unique? |
| Destinations | Which international and premium destinations are blocked? |
| Limits | Are spending, duration and concurrent-call limits configured? |
| Alerts | Who receives unusual traffic or billing notifications? |
| Updates | Are the PBX and connected products supported and maintained? |
| Remote users | How are softphones, mobiles and lost devices handled? |
| Forwarding | Who may create or change call forwarding? |
| Records | How often are call and administrator logs reviewed? |
| Suppliers | Who owns response across the carrier, platform and network? |
What to do if you suspect toll fraud
Contact the provider through a trusted channel
Use the carrier or phone provider’s known contact details. Ask it to review current traffic and apply appropriate restrictions. Do not use the contact details supplied in a suspicious email.
Preserve evidence
Keep invoices, alerts, call records, screenshots and a timeline. Avoid deleting accounts or logs before the provider or investigator advises what is needed.
Contain access
The technical response may include disabling affected extensions, resetting credentials, ending sessions, restricting destinations or blocking registrations. These changes can interrupt legitimate calls, so they should be coordinated.
Review the administrator and forwarding changes
Check recent logins, new accounts, routing and forwarding. Do not assume the only issue is the extension that generated calls.
Contact the insurer and advisers where relevant
If the event has a wider cyber, privacy or financial impact, involve the appropriate insurer, legal adviser or incident specialist.
Report suspected crime
Australian businesses can use official reporting channels such as ReportCyber for cybercrime. Follow the current guidance applicable to the event.
Communicate carefully
Tell affected staff what to do without sharing sensitive configuration widely. If caller ID spoofing is involved, customer communication may be needed even when the phone system was not breached.
Who pays for toll fraud?
Liability depends on the provider’s terms, configuration, notification timing and circumstances. Do not assume the carrier will automatically reverse unauthorised charges.
Ask about fraud treatment before signing a phone agreement. Understand credit limits, alerting, dispute processes and which controls the customer is expected to maintain.
VoIP fraud and remote work
Remote calling introduces more devices, networks and locations. This does not make VoIP unsuitable for remote work, but it increases the importance of supported applications, strong account protection and clear offboarding.
When somebody leaves, remove phone-system access alongside email, applications and other business accounts. Forwarding and voicemail should also be reviewed so customer calls do not continue to an old user or device.
Choosing a phone provider with fraud controls in mind
Ask prospective providers:
- Which fraud alerts and spending controls are available?
- Can international and premium destinations be restricted by user?
- Is multi-factor authentication available for administration?
- How are unusual registrations identified?
- What support path applies to suspected fraud?
- Who manages software updates and configuration?
- What records can the business access?
- How are number-port requests verified?
- What happens after hours?
- Which responsibilities remain with the customer?
Answers should appear in product documentation, service scope or terms, not only a sales conversation.
Protecting the phone system as part of the wider IT environment
The phone system depends on internet connectivity, networks, user accounts and supported devices. It should be managed alongside those services rather than treated as an isolated appliance.
Telco ICT has experience with iPECS and 3CX phone platforms and has been in business for more than 25 years. To compare options for a business phone system, discuss your users, locations, call flows, remote work and current carrier. For ongoing management of the wider technology environment, review managed IT services in Melbourne.
Frequently asked questions
What is VoIP fraud?
VoIP fraud is the unauthorised use or manipulation of an internet-based phone service, account or feature for calls, access or financial gain.
What is toll fraud?
Toll fraud involves unauthorised chargeable calls through another party’s phone service, often to international, premium or revenue-sharing destinations.
How can I tell if our phone system has been compromised?
Look for unusual destinations, after-hours traffic, cost spikes, unknown forwarding, unexpected registrations, account changes and user lockouts.
Can international calls simply be blocked?
Yes, where the service supports it. Businesses that need international calls can restrict access to approved users or destinations.
Does caller ID spoofing mean our system was hacked?
Not necessarily. Scammers may imitate a number without accessing the real phone system. The provider should investigate call records and configuration.
Can multi-factor authentication prevent toll fraud?
It can reduce account-takeover risk for supported portals, but it is one control. Destination restrictions, limits, updates and monitoring are also important.
Will the carrier refund fraudulent calls?
Not automatically. Liability and dispute treatment depend on the terms and circumstances. Review fraud controls and notification requirements in advance.
What should we do first after detecting suspicious calls?
Contact the provider through a trusted channel, preserve records and coordinate restrictions or credential changes without deleting useful evidence.
Is VoIP less secure than a traditional phone system?
Both can be abused. Risk depends on design, configuration, access, maintenance, provider controls and monitoring rather than the technology label alone.
How often should call records be reviewed?
Use alerts for urgent anomalies and a scheduled review suited to call volume and risk. High-volume or international calling may justify more frequent checks.
Table of contents
Related Posts
We’ll handle the tech
so you can get on with
running your business.