Security, privacy and 9-1-1
How do I protect my phone system from toll fraud?
Toll fraud happens when an outsider gains access to a phone system and uses it to place expensive calls, usually overnight and to international destinations. The main defences are strong, unique SIP passwords on every device and trunk, restricting which destinations each user can dial, and spend alerts that flag unusual usage. These are options you configure with 3CTel during setup and can tighten at any time.
Step by step.
Use strong SIP credentials
Every desk phone, app and SIP trunk registers with its own long, random password. Never reuse one across devices, and never leave a default password in place.
Restrict destinations
Allow international dialling only for the users who need it, and block premium-rate and high-risk destinations for everyone. Restrictions can be set per user or per group.
Set spend alerts
Ask for an alert when calling usage exceeds a threshold you choose, so an overnight spike is noticed within hours rather than on the invoice.
Secure voicemail and portal access
Require PINs on voicemail boxes, disable outbound dialling from voicemail menus, and use strong passwords and two-factor sign-in for administrators.
Keep your own PBX patched
If you use SIP trunking with your own PBX, keep it updated, close unused ports on the firewall, and allow SIP only from the addresses 3CTel provides.
How toll fraud usually happens
Attackers scan the internet for phone systems and try common or leaked passwords. Once one device or trunk registers, they route calls through it to numbers they profit from, often outside business hours so nobody notices until the bill arrives. Voicemail systems with weak PINs are another entry point, because some can be tricked into dialling out.
Hosted systems reduce the exposure because the servers are managed for you, but the credentials on your phones and the permissions on your users are still yours to control.
Signs that something is wrong
- Calls on your log to countries your business never dials, especially at night or on weekends.
- A desk phone that shows as registered from an unexpected location.
- Voicemail greetings or forwarding settings that changed without anyone's knowledge.
- A spend alert triggered when nobody was in the office.
If you suspect fraud, contact support immediately. Credentials for affected devices are reset, outbound calling can be restricted while the cause is found, and the calls are reviewed with you. Restrictions and alerts are options configured with 3CTel; ask your specialist to review yours if it has been a while.
Related questions.
Am I responsible for fraudulent calls?
How fraudulent usage is handled is described in the terms you confirmed before activation. Prevention is far cheaper than dispute, which is why destination restrictions and spend alerts are recommended for every account, not only those that call internationally.
Do apps-only systems get toll fraud?
Less often, because there are no desk phones with configurable SIP credentials, but a stolen app sign-in can still be used to place calls. Strong passwords, disabling departed users promptly, and destination restrictions still apply.
Is SIP trunking riskier than hosted phones?
It shifts responsibility. With your own PBX you manage its security, patches and firewall. 3CTel can restrict the trunk to your PBX's address and apply destination limits, but the PBX itself is yours to protect.
Last updated:
Not a 3CTel customer yet? See your recommended setup in four short steps.
Build My Phone System