Business VoIP Security: How to Protect Your Phone System from Toll Fraud and Eavesdropping
Toll fraud costs businesses over $1 billion annually and VoIP systems are the primary target. Here is how attackers exploit business phone systems — and the specific steps to lock yours down.
How Attackers Exploit Business Phone Systems
VoIP systems use the same network protocols and infrastructure as everything else on your network — and attackers know it. The most common VoIP attack is toll fraud: an attacker gains unauthorized access to your PBX or SIP trunk and makes thousands of dollars of international calls billed to your account over a single weekend. The bill arrives Monday morning. The fraud is often not discovered for days.
SIP protocol scanning is trivially easy — automated tools probe IP ranges for open SIP ports, identify the PBX software version, and attempt default credentials or known exploits. Hosted VoIP systems have reduced this risk by moving the PBX to a managed cloud environment, but they introduce their own risks: web portal credentials, phone provisioning URLs, and extension-level access controls.
Security Controls Every VoIP System Should Have
- Geo-restrictions: block all international dialing unless specific countries are explicitly required for business
- Time-of-day restrictions: disable outbound calling during non-business hours on extensions with no after-hours need
- Concurrent call limits: set a maximum on simultaneous outbound calls per extension to cap fraud exposure
- Strong credentials: every extension, portal, and admin account needs a unique strong password — never use defaults
- SIP TLS and SRTP: encrypt signaling and media to prevent eavesdropping on calls crossing the internet
- Network segmentation: put VoIP devices on a dedicated VLAN with firewall rules limiting which systems can reach them
- Anomaly alerts: configure billing alerts for unusual call volume or cost spikes
- Regular firmware updates: VoIP phones, ATAs, and session border controllers have their own firmware vulnerabilities
- Audit extension list: remove extensions for former employees immediately — each one is a potential attack surface
- Review call logs monthly: patterns of short failed calls to international numbers are a classic fraud indicator
Infinity Network Support Team
Managed IT & Cybersecurity Specialists
Serving small and mid-sized businesses in Miami & South Florida with managed IT support, cybersecurity, and compliance services.
The AI Governance Playbook
How to adopt AI safely in 2026 — free guide for South Florida businesses.
Have Questions? We're Here to Help.
Our team of South Florida IT specialists is ready to answer your questions and help protect your business.