VoIP security: how to avoid toll fraud
Toll fraud is not a sophisticated attack: somebody finds an extension with a weak password, registers a device on it and calls expensive destinations for as long as the credit lasts. It nearly always happens at night or over a weekend. Here is how to close the door.
Extension passwords
This is the way in for 90% of cases. Nothing clever is needed: long passwords, different from each other.
- Randomly generated passwords, at least 16 characters, one per extension
- Never use the extension number as the password
- Change the credentials at once when a device is lost or someone leaves
IP authentication
If the PBX or dialer has a fixed address, the password can go away entirely: we accept calls only from that address.
- No password to steal
- An IP address can belong to one account only: no ambiguity
- It has to be updated when the site's connection changes
Close what you do not use
The rule is simple: anything you do not need stays off. Fraud always goes to destinations you never call.
- Enable only the countries you actually call
- Set a daily spending cap for every account
- Set a maximum per-minute rate: it blocks satellite and premium destinations
- Give each account only the simultaneous channels it needs
What to look at every week
Five minutes of checking beats any alarm.
- Calls outside working hours, especially at night and on holidays
- Destinations you have never seen in the report before
- Failed SIP registrations: the platform's firewall blocks whoever gets the credentials wrong, but the attempt tells you somebody is trying
- A balance going down faster than usual, even slightly
Let's talk: the demo is given by a person, not a video
One of our operators walks you through the portal live and answers the questions that matter for your case. If you would rather write, we are on WhatsApp.
Signing up is free and with no commitment: we credit your account with trial credit so you can make your test calls.