VoIP toll fraud is one of the most financially damaging cybersecurity threats facing businesses that run phone systems over IP networks. Unlike most cyberattacks, toll fraud generates charges that appear on the victim's phone bill — sometimes thousands of dollars within a single weekend — before anyone notices something is wrong. The Communications Fraud Control Association (CFCA) 2023 Global Fraud Loss Survey estimated total telecom fraud losses at $38.95 billion globally, with International Revenue Share Fraud (IRSF) alone accounting for an estimated $6.23 billion of that figure.
VoIP systems are specifically attractive to fraud attackers because they are software-accessible over IP networks — the same network that connects to the internet. Unlike old-fashioned telephone hardware locked in a wiring closet, a SIP-based phone system with weak credentials or exposed ports can be compromised from anywhere in the world. This article covers the main attack types, how to identify fraud early, and the specific controls that reduce exposure.
Toll Fraud: Unauthorized use of a telephone system to place calls at the account holder's expense. In VoIP environments, this typically involves compromising SIP credentials, PBX configuration, or voicemail systems to place outbound calls — particularly to high-cost international destinations — that generate charges billed to the business. Businesses are generally responsible for charges generated by compromised systems, even if the calls were placed by unauthorized third parties. Quick detection and immediate provider notification is critical.
How Attackers Exploit Business Phone Systems
Understanding the attack types helps focus your defenses on the actual threat vectors, rather than spending effort on lower-risk areas.
1. International Revenue Share Fraud (IRSF)
IRSF is the highest-volume and highest-cost form of toll fraud. The mechanics work as follows: fraudsters obtain or control premium-rate telephone numbers in high-cost international destinations — often certain Pacific island countries, parts of the Caribbean, or Eastern European destinations where termination costs are high and revenue-share arrangements exist. They then compromise a business phone system and use it to generate a high volume of calls to those numbers. Each minute of call time generates revenue for the fraudster through the revenue-share arrangement.
A compromised system placed on a Friday evening can generate hundreds or thousands of minutes of calls over a weekend before anyone at the business notices. At international premium-rate prices, this can result in bills ranging from hundreds to tens of thousands of dollars depending on how quickly the fraud is detected and stopped.
2. PBX Hacking via Exposed SIP Ports
SIP, the protocol most business VoIP systems use for call signaling, operates by default on UDP port 5060. Any system with a SIP port accessible from the internet is subject to automated scanning and brute-force attempts against SIP credentials. Attackers run scanners that continuously probe IP ranges for exposed SIP ports, identify business PBX systems, and attempt to authenticate using common default credentials or dictionary attacks.
Once a SIP account is compromised, the attacker registers their own device to that account and begins placing calls using the business's SIP trunk — with charges appearing on the business's account. This attack requires no physical access and can originate from anywhere in the world.
3. Voicemail System Exploitation
Older PBX voicemail systems sometimes include features that allow callers to dial out from within a voicemail menu — originally intended for features like reaching a live operator or accessing a directory. Attackers who discover these features can use the business's voicemail system as a gateway for placing outbound calls. Default or weak voicemail PINs make this attack easier. Even modern systems can be vulnerable if DISA (Direct Inward System Access) features are enabled without adequate authentication.
4. Call Forwarding Manipulation
If an attacker gains access to a voicemail account portal, extension management interface, or carrier self-service portal, they can reconfigure call forwarding on a number to redirect calls to a premium-rate number. Every incoming call to that number then generates charges — and potentially revenue — for the attacker. This attack is often social engineering-enabled: the attacker calls support impersonating the account holder and requests a forwarding change.
5. Vishing and Social Engineering
In some fraud scenarios, technical system compromise is not the initial vector — a human is. Attackers call employees impersonating IT staff, phone system administrators, or carrier support, and trick them into making configuration changes (enabling features, resetting credentials, or providing authentication information) that enable subsequent fraud. This vector is particularly effective against employees who are unfamiliar with the phone system's administration.
Warning Signs of Active Toll Fraud
Toll fraud is often detectable before the bill arrives, if someone is watching the right signals. Common indicators of active or recent fraud include:
- Unexplained outbound call volume, particularly during off-hours — evenings, overnight, weekends, or holidays when the office is empty
- High concentration of calls to a specific international prefix or country code that your business does not normally call
- Outbound calls originating from extensions or accounts that are not assigned to active employees
- A sudden spike in concurrent outbound calls well above your typical maximum simultaneous usage
- Unusual call detail records showing calls to unfamiliar destinations at unusual times
Call Detail Records (CDRs) are your most important fraud detection tool. Reviewing CDRs regularly — or configuring automated alerts for anomalous call patterns — allows you to catch fraud within hours rather than at month-end billing.
Prevention Controls Every Business Should Implement
No single control eliminates toll fraud risk entirely — it is an active adversarial problem, and attackers adapt to new defenses. The goal is defense in depth: multiple overlapping controls that together raise the cost and difficulty of a successful attack to the point where attackers move on to easier targets.
Strong SIP Credentials
SIP account passwords should be long (20+ characters), randomly generated, and not based on any dictionary words, company names, phone numbers, or predictable patterns. Change default credentials immediately upon provisioning any new SIP account. The vast majority of PBX brute-force attacks succeed against weak or default credentials; strong random passwords make brute-force attacks computationally impractical.
IP Allowlisting for SIP Registration
Configure your SIP trunk or PBX to only accept registrations from known IP addresses. If your phone system is hosted in a fixed location (office or data center), only that IP range needs to be allowed to register SIP devices. An attacker with valid credentials from an unexpected IP address will be blocked. For remote workers using softphones, use a VPN to funnel their SIP traffic through a fixed IP, or use a cloud phone platform with built-in authentication that does not rely on IP-based SIP registration.
Restrict International Calling by Default
If your business does not regularly call international destinations, disable international calling on all SIP accounts by default. Whitelist only the specific country codes you actually need. This eliminates the most common IRSF scenario — the attacker cannot place international calls even with valid credentials. This is typically a per-account or account-group setting in your phone system or SIP trunk configuration.
Call Cost Limits and Concurrent Call Caps
Configure hard limits on daily or monthly call spend, and set a cap on simultaneous outbound calls. When the limit is reached, new call attempts are blocked and an alert is triggered. These limits do not prevent an initial fraud event, but they contain the damage: a $500 daily cap means the worst-case loss from a weekend fraud event is bounded, rather than unlimited. Set thresholds below your typical maximum usage so alerts are meaningful rather than noisy.
Disable Unused Features
Features that allow dialing out from within the phone system — DISA (Direct Inward System Access), dial-through voicemail, operator transfer within voicemail — should be disabled unless actively needed. Each of these features was designed for legitimate use but represents a potential bypass path for fraudsters. Review your PBX or cloud platform's feature set and disable anything your organization does not actually use.
Keep Systems Patched and Updated
PBX software vulnerabilities are regularly discovered and patched. On-premise Asterisk, FreeSWITCH, or other open-source PBX deployments that have not been updated in months or years may have known exploitable vulnerabilities. Apply security patches promptly. Cloud-hosted phone systems managed by your provider are typically updated by the provider, but confirm this as part of your service agreement evaluation.
Session Border Controllers (SBCs)
A Session Border Controller is a dedicated hardware or software device that sits at the border between your phone system and the SIP trunk or PSTN connection. SBCs provide signaling protection, rate limiting on call attempts, toll fraud detection logic, and encryption for SIP signaling and media. They are standard infrastructure in carrier and enterprise environments and increasingly available for SMB deployments. SBCs add a layer of fraud detection and access control at the network boundary that complements PBX-level configuration.
Disable SIP ALG on Your Router (Where Applicable)
SIP ALG (Application Layer Gateway) is a feature on many consumer and SMB routers intended to help SIP traffic traverse NAT. In many router implementations, SIP ALG is poorly implemented and causes SIP issues — and in some cases can expose SIP ports in ways that increase attack surface. Unless your specific router implementation of SIP ALG is known to work correctly with your phone system, disabling it is often recommended. Check your router's documentation and test both configurations. For more on SIP and NAT interactions, see what is SIP trunking.
What to Do If You Suspect Active Fraud
If you identify anomalous call activity consistent with toll fraud in progress:
- Contact your SIP trunk provider or phone system provider immediately. They can block outbound calling at the carrier level faster than you can reconfigure your PBX.
- Change all SIP account passwords and voicemail PINs immediately, prioritizing any accounts showing anomalous activity in the CDRs.
- Block international outbound calling at the carrier or PBX level until the vector is identified and closed.
- Review your call detail records to identify the source extension or SIP account used, the destination numbers called, and the time window of activity.
- Document everything — call logs, configuration states, timestamps — in case you need to dispute charges or work with your provider on liability.
Businesses are generally responsible for charges generated by their compromised systems under carrier terms of service. Carriers have varying policies on credit for fraud-related charges — some offer partial credits in fraud scenarios, particularly when the business detected and reported quickly. Review your provider's fraud liability policy as part of your initial vendor evaluation, not after an incident occurs. For broader security considerations in UCaaS and cloud phone environments, see UCaaS security and compliance.