VoIP Security: Prevent Toll Fraud & Call Fraud | TELIN

VoIP Security: How to Protect Your Phone System From Toll Fraud

VoIP phone systems provide businesses with flexibility, scalability, and significant cost advantages, but like any internet-connected service, they must be configured and maintained securely.

One of the most costly VoIP security threats is toll fraud, also known as call fraud or PBX fraud. This occurs when an unauthorized person gains access to a phone system, SIP account, extension, or other calling credentials and uses them to place calls at the account owner's expense.

Fraudulent calling can target many destinations, but attacks commonly involve international, premium-rate, or high-cost destinations, where large volumes of unauthorized calls can generate substantial charges in a short period of time.

The Communications Fraud Control Association (CFCA) estimated global telecommunications fraud losses at $38.95 billion in 2023, with PBX fraud among the major fraud methods identified in its survey.

The good news is that many VoIP fraud incidents can be prevented—or their impact significantly reduced—by applying several layers of security.

What Is VoIP Toll Fraud?

VoIP toll fraud is the unauthorized use of a business phone system or SIP service to make chargeable calls.

An attacker may attempt to compromise:

  • PBX administrator credentials
  • User or extension credentials
  • SIP authentication credentials
  • IP phones or other endpoints
  • Remote access to the PBX
  • Poorly configured outbound calling rules
  • Unrestricted international dialing
  • Outdated or vulnerable PBX software
  • Other systems or accounts connected to the phone environment

Once access is obtained, automated tools can potentially generate large numbers of calls very quickly.

This is why VoIP security should rely on multiple layers of protection rather than a single security setting.

How Can I Protect My VoIP Phone System From Fraud?

1. Secure Your Outbound Calling Rules

Outbound rules determine who can place calls, which numbers they can call, and how those calls are routed.

Avoid overly broad rules that allow every user or extension to dial any destination.

Instead, configure outbound calling rules around actual business requirements.

Where appropriate, restrict calls based on:

    • User or extension
    • Department or extension group
    • Dialed prefix
    • Number length
    • Destination
    • Domestic versus international calling requirements

For example, if only a small group of employees needs international calling, international dialing should not be available to every extension.

For 3CX systems, current outbound rules can use criteria including the calling user or department, dialed-number prefix, and number length.

Best practice: Apply the principle of least privilege. Only give users the calling permissions they actually need.

2. Restrict International Calling to the Countries You Need

One of the simplest ways to reduce exposure to toll fraud is to disable international destinations that your business never calls.

If your organization only calls the United States and Canada, there is generally no business reason to leave every international destination available.

For businesses that require international calling, allow only the countries that are legitimately needed.

For 3CX Systems

3CX includes an Allowed Country Codes security feature that can restrict international destinations.

In 3CX V20, this setting is available through the Advanced system settings.

3CX also recommends configuring destination restrictions at the VoIP provider level where those controls are available, rather than relying exclusively on the PBX.

Important for U.S. and Canadian Businesses

Remember that the North American Numbering Plan (NANP) includes destinations outside the continental United States and Canada that also use the +1 country code.

For this reason, businesses should not assume that every number beginning with +1 represents a standard U.S. or Canadian destination.

Review your outbound rules and destination requirements carefully.

3. Use Strong, Unique Credentials

Weak or reused passwords can create unnecessary exposure.

Use strong, unique credentials for:

    • PBX administrator accounts
    • PBX users
    • SIP authentication
    • IP phone administration
    • Voicemail
    • Remote-access accounts
    • Any connected applications or integrations

Avoid easily guessed passwords such as:

    • Company names
    • Telephone numbers
    • Extension numbers
    • Common words
    • Sequential numbers
    • Reused passwords from other systems

Do not reuse administrative or SIP credentials across multiple systems.

Where possible, use a reputable password manager to generate and securely store unique credentials.

4. Enable MFA, 2FA, or SSO Where Available

A password should not be the only protection for an administrative or user account.

Enable multi-factor authentication (MFA) or two-factor authentication (2FA) wherever supported.

For 3CX environments, administrators can also use supported Microsoft 365 or Google SSO configurations and apply the organization's authentication protections. 3CX specifically recommends strong account credentials and supports SSO as part of its PBX security guidance.

This can significantly reduce the risk created by a stolen or compromised password.

5. Keep Your PBX and Devices Up to Date

Software vulnerabilities are regularly discovered across operating systems, PBX applications, phones, networking equipment, and connected services.

Security patches cannot protect a system if they are never installed.

Maintain supported and current versions of:

    • PBX software
    • Operating systems
    • IP phone firmware
    • Session Border Controllers
    • Firewalls
    • Routers
    • Connected applications
    • Other network devices

3CX emphasizes keeping both the operating system and PBX software current so security fixes can be applied when vulnerabilities are discovered.

For example, 3CX issued security updates during 2026 for V20 deployments and instructed affected self-hosted systems to apply the latest available update.

Do not continue operating an end-of-life PBX version simply because it still works.

3CX Version 18, for example, is now end-of-life and no longer receives the same security and service-maintenance coverage as supported versions.

6. Review Your PBX Anti-Hacking Settings

Modern PBX platforms include security controls designed to detect or limit common attack patterns.

For current 3CX V20 systems, review the security settings available under Admin Console > Advanced, including:

    • IP Blacklist
    • Anti-Hacking
    • Automatic Global IP Blacklist participation
    • Console Restrictions
    • Allowed Country Codes
    • Secure SIP configuration

3CX's Anti-Hacking functionality is designed to help protect against common SIP and other attack patterns. Its IP Blacklist can also automatically block IP addresses following repeated failed authentication attempts.

These protections should be reviewed periodically rather than assuming the default configuration is appropriate for every environment.

7. Restrict Administrative Access

Your PBX administration interface should not be unnecessarily accessible from anywhere on the internet.

Where practical, restrict administrative access to:

    • Approved public IP addresses
    • Trusted internal networks
    • Secure VPN connections
    • Authorized administrators

3CX V20 provides Console Restrictions, allowing administrators to restrict access to the management console to specified IP addresses or local subnets.

Limiting access reduces the number of systems that can even attempt to authenticate to the PBX administration interface.

8. Disable Remote Access That Is Not Required

Do not expose SIP endpoints, administrative interfaces, or remote services simply because the option is available.

If a user, phone, or service does not require remote connectivity, disable or restrict it.

Remote-access configurations should follow the PBX vendor's recommended deployment method rather than exposing unnecessary ports or services directly to the internet.

9. Review Call Records for Unusual Activity

Regular monitoring can help identify fraud before it develops into a significant financial incident.

Look for unusual activity such as:

    • Calls placed outside normal business hours
    • Unexpected international destinations
    • Large increases in outbound call volume
    • Repeated calls to the same destination
    • Unusually long call durations
    • Large numbers of short calls
    • Calls originating from extensions that normally have little activity
    • Calling activity during weekends or holidays when the business is normally closed

Administrators should understand what normal calling behavior looks like for their organization so abnormal activity is easier to recognize.

10. Use Provider-Level Security Controls Where Available

PBX security should not be your only layer of protection.

Your SIP or VoIP provider may offer additional controls such as:

    • International destination restrictions
    • Concurrent call limits
    • Account or spending controls
    • Fraud monitoring
    • Usage alerts
    • Destination blocking

The exact controls available depend on the service and account configuration.

TELIN partners can contact TELIN Support to discuss which account-level protections or calling restrictions may be available for their service.

What 3CX Security Settings Should I Review?

For a 3CX environment, we recommend reviewing at minimum:

Security AreaWhat to Review
Outbound RulesLimit users, departments, prefixes, number lengths, and destinations based on business need
Allowed Country CodesAllow only the countries your organization actually calls
IP BlacklistReview blocked IPs and automatic protection
Anti-HackingConfirm built-in protections are appropriately configured
Automatic Global IP BlacklistConfirm participation where appropriate
Console RestrictionsRestrict administrative access to trusted networks or IPs
User CredentialsUse strong, unique credentials
MFA / SSOEnable additional authentication protections
Secure SIPReview secure signaling requirements where applicable
PBX UpdatesKeep the system on a supported and current release
Call RecordsMonitor for unusual destinations, times, or call volumes

3CX refreshed its call-fraud and PBX-security guidance for Version 20 in March 2026 and continues to recommend properly configured systems, current software, and multiple security controls to reduce call-fraud risk.

What Should I Do If I Suspect VoIP Toll Fraud?

If you notice calls that you do not recognize or believe your phone system may have been compromised, act immediately.

  1. Contact TELIN Support and report the suspected unauthorized calling.
  2. Restrict or disable outbound calling if unauthorized calls are actively occurring.
  3. Disable or secure affected extensions and accounts.
  4. Reset potentially compromised credentials.
  5. Review recent call records to identify when the activity began and which extensions or destinations were involved.
  6. Review administrator and authentication activity for signs of unauthorized access.
  7. Block unnecessary international destinations.
  8. Verify outbound rules and country restrictions.
  9. Update the PBX and affected devices if they are not current.
  10. Investigate how the compromise occurred before restoring unrestricted calling.

Do not simply change one password and assume the incident has been resolved. If an attacker gained access through another account, device, configuration, or exposed service, unauthorized activity may continue.

Frequently Asked Questions About VoIP Security and Toll Fraud

What is VoIP fraud?

VoIP fraud is unauthorized or deceptive use of a Voice over IP service. It can include compromised SIP credentials, PBX account takeover, unauthorized calling, toll fraud, premium-rate fraud, and other misuse of a business communications system.

What is VoIP toll fraud?

VoIP toll fraud occurs when an unauthorized person uses someone else's phone system or calling account to make chargeable calls. These attacks frequently target international, premium-rate, or other high-cost destinations.

Can a VoIP phone system be hacked?

Yes. Like other internet-connected systems, a VoIP or PBX environment can be compromised if credentials, software, devices, remote access, or network configurations are inadequately secured.

The goal should be to reduce that risk through layered security rather than relying on one control.

How do I prevent VoIP toll fraud?

The most important steps include restricting outbound calling, blocking unnecessary international destinations, using strong credentials and MFA, keeping the PBX and devices updated, limiting remote and administrative access, enabling PBX anti-hacking protections, and monitoring call activity.

Should I block international calling?

If your organization does not make international calls, disabling unnecessary international destinations can significantly reduce exposure to international toll fraud.

If international calling is required, allow only the countries and users that legitimately need it.

Are strong passwords enough to secure a VoIP system?

No.

Strong passwords are important, but VoIP security should also include MFA or SSO where available, restricted administrative access, secure outbound rules, country restrictions, software updates, network security, provider-level controls, and monitoring.

How can I secure a 3CX phone system?

Keep 3CX on a supported version, configure strict outbound rules, review Allowed Country Codes, use strong credentials and additional authentication, review Anti-Hacking and IP Blacklist settings, restrict console access, and regularly review call activity.

Can VoIP fraud happen even if my PBX has security enabled?

Yes. Security controls reduce risk but cannot guarantee that fraud will never occur.

Compromised user accounts, endpoints, connected applications, poor calling permissions, social engineering, or configuration changes can still create exposure. Multiple security layers provide stronger protection.

Need Help Securing Your VoIP System?

If you are a TELIN partner and need assistance reviewing your SIP service, outbound calling configuration, or suspicious call activity, contact TELIN Support.

If you believe call fraud is actively occurring, report it as soon as possible so the affected service and available security options can be reviewed.