Insights

VoIP toll fraud: how attackers run up phone bills overnight, and how to stop them

An unsecured phone system can cost thousands in a single weekend. These controls keep it locked down.

Telecom

Topic

6 min

Reading time

29 Sept 2026

Published

In this article

  • How attackers get in
  • Lock down accounts
  • Use a session border controller
  • Restrict destinations
  • Monitor and alert
  • Signs your system may already be compromised
  • Remote workers and softphones
  • Working with your carrier
  • Building fraud prevention into everyday IT
  • Get an audit
VoIP toll fraud: how attackers run up phone bills overnight, and how to stop them

Key takeaways

  • Toll fraud usually strikes out of hours, when no one is watching
  • Weak passwords and exposed admin pages are the main way in
  • A session border controller and destination blocking stop most attacks
  • Spend limits and alerts cap the damage if something slips through

Toll fraud happens when attackers break into a phone system and use it to make large numbers of expensive international or premium-rate calls. It usually starts on a Friday evening, so by Monday the bill can be enormous, and the carrier will still expect payment.

How attackers get in

The most common routes are:

  • Weak or default extension passwords
  • Admin web interfaces exposed to the internet
  • Voicemail systems that allow calls back out
  • Unpatched PBX firmware with known vulnerabilities
  • SIP trunks without IP or destination restrictions

Lock down accounts

Use long, random passwords for every extension and admin account, and remove unused extensions. Restrict registrations to known IP ranges where possible.

Use a session border controller

An SBC sits between your PBX and the internet, hiding the PBX, filtering malicious traffic and enforcing call policies for SIP trunks and remote users.

Restrict destinations

Block international and premium destinations you never call, and require a PIN for high-cost countries. Set call-rate and spend limits so any fraud is capped.

Monitor and alert

Fraud alerts for unusual call volumes, destinations or out-of-hours activity let you stop an attack in minutes rather than discovering it on the invoice.

Signs your system may already be compromised

Toll fraud is often discovered only when the bill arrives. Check your call records regularly for these warning signs:

  • Calls to countries you don't do business with
  • Heavy call activity at night or at weekends
  • Many short calls to premium or satellite numbers
  • Unknown extensions or trunks in the configuration
  • Voicemail PINs changed without explanation
  • Sudden jumps in your carrier's usage alerts

Remote workers and softphones

Softphones and remote extensions are convenient, but each one is another door into your system. Route remote users through a VPN or an SBC rather than exposing the PBX directly, use unique credentials per device, and disable accounts as soon as staff leave. Mobile apps should require sign-in, not just a saved password.

Working with your carrier

Your telecom provider can be an important ally. Ask about fraud monitoring on your SIP trunks, credit limits that stop calls when spending exceeds a threshold, and blocking of international or premium destinations at the carrier level. Carrier-level controls act as a final safety net if your own system is compromised. Keep your account contacts up to date so the carrier can reach you quickly if they notice unusual activity, especially outside business hours.

Building fraud prevention into everyday IT

Toll fraud prevention isn't a one-off project. Build it into routine IT processes: remove extensions when staff leave, review admin accounts quarterly, apply firmware updates promptly and check call reports monthly for unusual destinations or volumes. Include the phone system in your regular security audits alongside firewalls and servers. If you use an IT provider or AMC, make sure the phone system is explicitly within scope, because it's often overlooked. These small, regular habits keep the risk low without adding much work, and they protect against a type of attack that can be extremely expensive.

Get an audit

If your phone system hasn't been reviewed recently, a VoIP security audit is quick and inexpensive, especially compared to a single fraud incident.

Frequently asked questions

  • In almost every case the business that owns the phone system is liable, even though the calls were made by criminals. That's why prevention matters so much.

  • Reputable cloud providers include fraud controls by default, but accounts and passwords are still your responsibility. Both can be secured well; both can be exposed if misconfigured.

  • At least once a year, and whenever you change providers, add remote users or open a new site.

  • Yes, and many businesses do. You can then allow specific countries you need, or require a PIN for international dialling.

Get started

Tell us what your business needs.

Free consultation and site survey. A clear, fixed-price proposal within 24 hours.

On site across all seven emirates, from our base in Jumeirah Lakes Towers, Dubai, with remote support for branches across the GCC.

  • Dubai
  • Abu Dhabi
  • Sharjah
  • Ajman
  • Ras Al Khaimah
  • Fujairah
  • Umm Al Quwain