VoIP phone systems provide businesses with flexibility, scalability, and significant cost advantages, but like any internet-connected service, they must be configured and maintained securely.
One of the most costly VoIP security threats is toll fraud, also known as call fraud or PBX fraud. This occurs when an unauthorized person gains access to a phone system, SIP account, extension, or other calling credentials and uses them to place calls at the account owner's expense.
Fraudulent calling can target many destinations, but attacks commonly involve international, premium-rate, or high-cost destinations, where large volumes of unauthorized calls can generate substantial charges in a short period of time.
The Communications Fraud Control Association (CFCA) estimated global telecommunications fraud losses at $38.95 billion in 2023, with PBX fraud among the major fraud methods identified in its survey.
The good news is that many VoIP fraud incidents can be prevented—or their impact significantly reduced—by applying several layers of security.
VoIP toll fraud is the unauthorized use of a business phone system or SIP service to make chargeable calls.
An attacker may attempt to compromise:
Once access is obtained, automated tools can potentially generate large numbers of calls very quickly.
This is why VoIP security should rely on multiple layers of protection rather than a single security setting.
Outbound rules determine who can place calls, which numbers they can call, and how those calls are routed.
Avoid overly broad rules that allow every user or extension to dial any destination.
Instead, configure outbound calling rules around actual business requirements.
Where appropriate, restrict calls based on:
For example, if only a small group of employees needs international calling, international dialing should not be available to every extension.
For 3CX systems, current outbound rules can use criteria including the calling user or department, dialed-number prefix, and number length.
Best practice: Apply the principle of least privilege. Only give users the calling permissions they actually need.
One of the simplest ways to reduce exposure to toll fraud is to disable international destinations that your business never calls.
If your organization only calls the United States and Canada, there is generally no business reason to leave every international destination available.
For businesses that require international calling, allow only the countries that are legitimately needed.
For 3CX Systems
3CX includes an Allowed Country Codes security feature that can restrict international destinations.
In 3CX V20, this setting is available through the Advanced system settings.
3CX also recommends configuring destination restrictions at the VoIP provider level where those controls are available, rather than relying exclusively on the PBX.
Important for U.S. and Canadian Businesses
Remember that the North American Numbering Plan (NANP) includes destinations outside the continental United States and Canada that also use the
+1country code.For this reason, businesses should not assume that every number beginning with
+1represents a standard U.S. or Canadian destination.Review your outbound rules and destination requirements carefully.
Weak or reused passwords can create unnecessary exposure.
Use strong, unique credentials for:
Avoid easily guessed passwords such as:
Do not reuse administrative or SIP credentials across multiple systems.
Where possible, use a reputable password manager to generate and securely store unique credentials.
A password should not be the only protection for an administrative or user account.
Enable multi-factor authentication (MFA) or two-factor authentication (2FA) wherever supported.
For 3CX environments, administrators can also use supported Microsoft 365 or Google SSO configurations and apply the organization's authentication protections. 3CX specifically recommends strong account credentials and supports SSO as part of its PBX security guidance.
This can significantly reduce the risk created by a stolen or compromised password.
Software vulnerabilities are regularly discovered across operating systems, PBX applications, phones, networking equipment, and connected services.
Security patches cannot protect a system if they are never installed.
Maintain supported and current versions of:
3CX emphasizes keeping both the operating system and PBX software current so security fixes can be applied when vulnerabilities are discovered.
For example, 3CX issued security updates during 2026 for V20 deployments and instructed affected self-hosted systems to apply the latest available update.
Do not continue operating an end-of-life PBX version simply because it still works.
3CX Version 18, for example, is now end-of-life and no longer receives the same security and service-maintenance coverage as supported versions.
Modern PBX platforms include security controls designed to detect or limit common attack patterns.
For current 3CX V20 systems, review the security settings available under Admin Console > Advanced, including:
3CX's Anti-Hacking functionality is designed to help protect against common SIP and other attack patterns. Its IP Blacklist can also automatically block IP addresses following repeated failed authentication attempts.
These protections should be reviewed periodically rather than assuming the default configuration is appropriate for every environment.
Your PBX administration interface should not be unnecessarily accessible from anywhere on the internet.
Where practical, restrict administrative access to:
3CX V20 provides Console Restrictions, allowing administrators to restrict access to the management console to specified IP addresses or local subnets.
Limiting access reduces the number of systems that can even attempt to authenticate to the PBX administration interface.
Do not expose SIP endpoints, administrative interfaces, or remote services simply because the option is available.
If a user, phone, or service does not require remote connectivity, disable or restrict it.
Remote-access configurations should follow the PBX vendor's recommended deployment method rather than exposing unnecessary ports or services directly to the internet.
Regular monitoring can help identify fraud before it develops into a significant financial incident.
Look for unusual activity such as:
Administrators should understand what normal calling behavior looks like for their organization so abnormal activity is easier to recognize.
PBX security should not be your only layer of protection.
Your SIP or VoIP provider may offer additional controls such as:
The exact controls available depend on the service and account configuration.
TELIN partners can contact TELIN Support to discuss which account-level protections or calling restrictions may be available for their service.
For a 3CX environment, we recommend reviewing at minimum:
| Security Area | What to Review |
|---|---|
| Outbound Rules | Limit users, departments, prefixes, number lengths, and destinations based on business need |
| Allowed Country Codes | Allow only the countries your organization actually calls |
| IP Blacklist | Review blocked IPs and automatic protection |
| Anti-Hacking | Confirm built-in protections are appropriately configured |
| Automatic Global IP Blacklist | Confirm participation where appropriate |
| Console Restrictions | Restrict administrative access to trusted networks or IPs |
| User Credentials | Use strong, unique credentials |
| MFA / SSO | Enable additional authentication protections |
| Secure SIP | Review secure signaling requirements where applicable |
| PBX Updates | Keep the system on a supported and current release |
| Call Records | Monitor for unusual destinations, times, or call volumes |
3CX refreshed its call-fraud and PBX-security guidance for Version 20 in March 2026 and continues to recommend properly configured systems, current software, and multiple security controls to reduce call-fraud risk.
If you notice calls that you do not recognize or believe your phone system may have been compromised, act immediately.
Do not simply change one password and assume the incident has been resolved. If an attacker gained access through another account, device, configuration, or exposed service, unauthorized activity may continue.
VoIP fraud is unauthorized or deceptive use of a Voice over IP service. It can include compromised SIP credentials, PBX account takeover, unauthorized calling, toll fraud, premium-rate fraud, and other misuse of a business communications system.
VoIP toll fraud occurs when an unauthorized person uses someone else's phone system or calling account to make chargeable calls. These attacks frequently target international, premium-rate, or other high-cost destinations.
Yes. Like other internet-connected systems, a VoIP or PBX environment can be compromised if credentials, software, devices, remote access, or network configurations are inadequately secured.
The goal should be to reduce that risk through layered security rather than relying on one control.
The most important steps include restricting outbound calling, blocking unnecessary international destinations, using strong credentials and MFA, keeping the PBX and devices updated, limiting remote and administrative access, enabling PBX anti-hacking protections, and monitoring call activity.
If your organization does not make international calls, disabling unnecessary international destinations can significantly reduce exposure to international toll fraud.
If international calling is required, allow only the countries and users that legitimately need it.
No.
Strong passwords are important, but VoIP security should also include MFA or SSO where available, restricted administrative access, secure outbound rules, country restrictions, software updates, network security, provider-level controls, and monitoring.
Keep 3CX on a supported version, configure strict outbound rules, review Allowed Country Codes, use strong credentials and additional authentication, review Anti-Hacking and IP Blacklist settings, restrict console access, and regularly review call activity.
Yes. Security controls reduce risk but cannot guarantee that fraud will never occur.
Compromised user accounts, endpoints, connected applications, poor calling permissions, social engineering, or configuration changes can still create exposure. Multiple security layers provide stronger protection.
If you are a TELIN partner and need assistance reviewing your SIP service, outbound calling configuration, or suspicious call activity, contact TELIN Support.
If you believe call fraud is actively occurring, report it as soon as possible so the affected service and available security options can be reviewed.