Key takeaways
- Toll fraud usually strikes out of hours, when no one is watching
- Weak passwords and exposed admin pages are the main way in
- A session border controller and destination blocking stop most attacks
- Spend limits and alerts cap the damage if something slips through
Toll fraud happens when attackers break into a phone system and use it to make large numbers of expensive international or premium-rate calls. It usually starts on a Friday evening, so by Monday the bill can be enormous, and the carrier will still expect payment.
How attackers get in
The most common routes are:
- Weak or default extension passwords
- Admin web interfaces exposed to the internet
- Voicemail systems that allow calls back out
- Unpatched PBX firmware with known vulnerabilities
- SIP trunks without IP or destination restrictions
Lock down accounts
Use long, random passwords for every extension and admin account, and remove unused extensions. Restrict registrations to known IP ranges where possible.
Use a session border controller
An SBC sits between your PBX and the internet, hiding the PBX, filtering malicious traffic and enforcing call policies for SIP trunks and remote users.
Restrict destinations
Block international and premium destinations you never call, and require a PIN for high-cost countries. Set call-rate and spend limits so any fraud is capped.
Monitor and alert
Fraud alerts for unusual call volumes, destinations or out-of-hours activity let you stop an attack in minutes rather than discovering it on the invoice.
Signs your system may already be compromised
Toll fraud is often discovered only when the bill arrives. Check your call records regularly for these warning signs:
- Calls to countries you don't do business with
- Heavy call activity at night or at weekends
- Many short calls to premium or satellite numbers
- Unknown extensions or trunks in the configuration
- Voicemail PINs changed without explanation
- Sudden jumps in your carrier's usage alerts
Remote workers and softphones
Softphones and remote extensions are convenient, but each one is another door into your system. Route remote users through a VPN or an SBC rather than exposing the PBX directly, use unique credentials per device, and disable accounts as soon as staff leave. Mobile apps should require sign-in, not just a saved password.
Working with your carrier
Your telecom provider can be an important ally. Ask about fraud monitoring on your SIP trunks, credit limits that stop calls when spending exceeds a threshold, and blocking of international or premium destinations at the carrier level. Carrier-level controls act as a final safety net if your own system is compromised. Keep your account contacts up to date so the carrier can reach you quickly if they notice unusual activity, especially outside business hours.
Building fraud prevention into everyday IT
Toll fraud prevention isn't a one-off project. Build it into routine IT processes: remove extensions when staff leave, review admin accounts quarterly, apply firmware updates promptly and check call reports monthly for unusual destinations or volumes. Include the phone system in your regular security audits alongside firewalls and servers. If you use an IT provider or AMC, make sure the phone system is explicitly within scope, because it's often overlooked. These small, regular habits keep the risk low without adding much work, and they protect against a type of attack that can be extremely expensive.
Get an audit
If your phone system hasn't been reviewed recently, a VoIP security audit is quick and inexpensive, especially compared to a single fraud incident.
Frequently asked questions
In almost every case the business that owns the phone system is liable, even though the calls were made by criminals. That's why prevention matters so much.
Reputable cloud providers include fraud controls by default, but accounts and passwords are still your responsibility. Both can be secured well; both can be exposed if misconfigured.
At least once a year, and whenever you change providers, add remote users or open a new site.
Yes, and many businesses do. You can then allow specific countries you need, or require a PIN for international dialling.




