Skip to main content
VoIPMetrics

Security

Toll Fraud

By Myroslav Orshak · operates licensed carrier infrastructure · Updated September 2026

Toll fraud is when someone breaks into your phone system and uses it to place expensive calls — usually international, usually overnight or over a weekend — and the bill lands on you.

How it works

Automated scanners search the internet continuously for phone systems and try common extension numbers against common passwords. When one works, the attacker has valid credentials, and calls placed with valid credentials look entirely legitimate to the phone network.

The money comes from premium-rate destinations. Attackers route call after call to numbers that pay the recipient a share of the connection charge, often in countries with high termination rates, and run many calls simultaneously. Timing is deliberate: the attack starts on a Friday evening, so it has a full weekend to run before anyone looks at a dashboard.

Why it matters

The reason this matters more than most security topics is who pays. The calls were placed with your credentials, so as far as the network is concerned they are your calls, and providers vary enormously in whether they absorb the loss, cap it, or invoice it in full. That makes it a question worth asking before you sign a contract rather than after you receive a bill.

The reassuring part is that stopping it is configuration rather than expertise. Turn international dialing off unless the business genuinely needs it, set a daily spend cap, and give every extension a long random password instead of the extension number. The businesses that get hit are almost never targeted specifically — they are the ones running an extension with a default password that a scanner found within days.

Four settings that stop nearly all of it

Disable international dialing unless required; set a daily or monthly spend cap; use a long random password on every extension, never the extension number; and restrict which addresses may register. Most providers offer all four controls, but not all switch them on by default, so check yours.

Source: Common phone-system hardening practice

Related terms

Frequently asked questions

Who pays for fraudulent calls?

Usually you, which is the part that surprises people. The calls carried valid credentials, so the network treats them as yours. Some providers cap or absorb fraud losses and some do not. Ask what happens in that scenario before signing, because the answer varies widely and is rarely volunteered.

How quickly does it happen?

Fast. Scanners find newly exposed systems within days, and an attack typically runs overnight or across a weekend to maximize the window before anyone notices. That timing is why a spend cap matters more than monitoring — the cap acts while nobody is watching.

How do I know if it is happening?

Look for calls outside business hours, calls to countries you have no reason to call, and many simultaneous calls from one extension. If your provider offers alerts on unusual spend, switch them on — that alert is the cheapest security control available to you.

Does this affect hosted phone systems too?

Yes. A weak extension password is exploitable whether the system runs in your building or in a data center. Hosted providers usually have better detection, but the credentials are still yours to protect and the calls are still billed to your account.