Cloud, Services and Security

How Do You Protect the PBX from Hacking?

Toll fraud is the exploitation of an extension or a PBX to place calls at the organization's expense — usually expensive calls abroad, at night and on weekends. Protection is based on strong passwords, access restrictions and monitoring.

Toll fraudSIP hackingDialing fraudIRSFPBX hacking

Reading time: about 8 minutes

What telephony hacking is

The term Toll fraud describes a situation where a stranger uses your phone lines to place calls, and you get the bill. The attacker doesn't want to listen to your calls or steal documents. He wants call minutes.

The most common form is called IRSF (International Revenue Share Fraud). The attackers hold numbers in expensive destinations abroad, where every minute to them earns them money. After taking over an extension, they dial from it to those numbers again and again — sometimes dozens of calls at once. The bill arrives at the organization, and the money goes to the attackers.

This is not only a problem of cloud PBXs. An old office PBX, with a voicemail that allows dialing out or remote access without a good password, was a known target even before the VoIP era. The internet only made the scanning automatic and fast.

How they break in — behind the scenes

  1. Scanning. Automated programs go through addresses on the internet and look for servers that speak SIP.
  2. Password guessing. When a server is found, the program tries thousands of combinations of an extension number and a password: 100 with 1234, 101 with 101, and so on.
  3. Registering. The moment one combination succeeds, the attacker registers as if he were your phone.
  4. Dialing. Usually at night, on Shabbat or on Yom Tov, when no one is watching, long calls to expensive destinations begin.

Other ways in: an IP phone left with the manufacturer's password for its admin interface, an adapter exposed to the internet through the router, a control panel password stolen by a phishing email, or a former employee who still knows the details.

Warning signs

  • Outgoing calls during hours when the office is closed — at night, on Shabbat, on Yom Tov.
  • Destinations abroad that the organization never calls.
  • Many short calls in a row, followed by long calls.
  • Several outgoing calls at the same time from one extension.
  • An extension registered from an unfamiliar device or location.
  • A sudden jump in billing or in the balance.

The simplest tool for spotting all of these is the call history. A one-minute look once a day at the outgoing calls catches most cases long before they turn into a painful bill.

A protection checklist

No single layer solves everything. Good protection is built from several layers, so that even if one fails, the others stop the damage:

  • A strong, random password for every extension — not the extension number, not 1234, not the same password for everyone.
  • Restrict control panel access by IP address — so even someone who obtained a password cannot log in from outside.
  • Restrict destinations — in many systems you can block international and premium-rate numbers for extensions that don't need them.
  • Don't expose equipment to the internet — without needlessly opening ports in the firewall.
  • Change factory passwords on phones and adapters.
  • Remove the extensions of people who left and replace shared passwords.
  • Regular monitoring of the call history.

Common mistakes

"We're small, who would want to break into us?" Attackers don't choose a victim. The programs scan everything, and a five-person office looks to them exactly like a large company. On the contrary — in a small organization fewer people notice.

Writing the password on a note next to the phone or sending it in a WhatsApp group of all the employees. An extension password shouldn't be known to anyone — you enter it once in the device and forget it.

Ignoring an unusual charge. A break-in that lasts a whole weekend costs far more than one caught after an hour. If something looks strange, call the provider right away; don't wait for the next bill.

What to do if you suspect a break-in

  1. Contact the PBX provider right away and ask them to check the outgoing calls.
  2. Change the password of the suspected extension, and if needed, of all extensions.
  3. Change the control panel login password and check which users have access.
  4. Check the equipment in the office: factory passwords, open ports in the router.
  5. Keep monitoring the history in the following days, to make sure the unusual activity has stopped.

A full example: a small office, one weekend

A real estate office with five extensions. On Thursday afternoon the customer's technician sets up a new extension for an employee who starts next week, and picks a password that is easy to remember: the extension number followed by 1234. No one calls over the weekend, so there is no one to notice.

On Friday night an automated program somewhere in the world finds the extension, guesses the password within minutes, and starts dialing: dozens of simultaneous calls to high-rate destinations. Each call lasts for long minutes. By Sunday morning, many hours of calls have piled up.

On Sunday the secretary sees in the call history dozens of outgoing calls to foreign numbers from an extension that hasn't yet been assigned to anyone. That is the moment of discovery. The lesson here is simple: the password was the weak link, and the time that passed until discovery is what determined the size of the damage.

Three layers that stop the damage

Before — passwords that can't be guessed, devices that arrive already configured so no one has to invent a password, and control panel login only from addresses you recognize.

During — a restriction on destinations you have no reason to call, and a limit on the number of simultaneous calls. Even if a stranger managed to get in, he can do very little.

After — monitoring. A call history that someone looks at, an alert on an unusual call, and a short weekly check of outgoing calls. The earlier you discover it, the smaller the bill.

What happens in the first hour after discovery

  1. Stop the bleeding. Ask the provider to immediately block the suspected extension, or all international dialing, until you understand what happened. A few hours without international calls is better than another night of charges.
  2. Change passwords. First for the extension the calls came from, and if it isn't clear how they got in — for all extensions and for the control panel login.
  3. Check devices. An extension registered from a place you don't recognize is a clear sign. In the control panel you can see, for each extension, which device it is connected from.
  4. Document. Save the call history for the period: this is what you need for an inquiry with the provider and for insurance, if there is any.
  5. Learn. After everything calms down, go over the protection list and mark what is missing. In most cases the weak link was one thing: a password, a permission that was too broad, or no one looking at the history.

Rules of thumb worth knowing

  • Scanning software reaches every address on the internet, usually within hours of the moment it starts answering SIP. There is no "grace period."
  • Guessing a weak password, such as 1234 or the extension number, takes minutes. A random password of 12 characters or more can't be guessed.
  • The typical damage is measured in weekends: when no one is watching, the dialing continues until it is discovered.
  • Limiting concurrent calls is the cheapest brake: if an extension is allowed two simultaneous calls, even unauthorized use is limited to two.

Three real cases, in general terms, and what was learned from them

The adapter left with a default password. An office connected an old fax machine through an adapter, and the installer left the device password as it came from the factory. The adapter itself looks harmless, but it is an extension for all intents and purposes. The lesson: every device connected to the PBX, whether an adapter or a phone in a side room, gets its own password.

The employee who left and took the app with him. A representative left, but his extension stayed active in the app on his personal mobile phone. There was no bad intent, but months later calls were still being made from it at the organization's expense. The lesson: the day someone leaves is also the day to close their extension.

The control panel that was open to the whole world. Logging in to manage the PBX was possible from any address, with a password that also appeared on another site that had leaked. The lesson: restricting login to the office addresses keeps the door closed even when the password is no longer secret.

A five-minute monthly checklist

You don't need a security expert to protect the PBX. A small habit, once a month, for whoever manages the phones in the office is enough:

  1. Open the call log and filter outgoing calls made at night and on weekends. If there are any, find out who dialed.
  2. Look at the list of extensions: is every extension registered from a device you recognize? Is the extension of an employee who left still active?
  3. Check who has access to the control panel, and remove permissions that are no longer needed.
  4. Make sure the number shown as the outgoing caller ID is your number, and not something that was changed.
  5. If you added a device or extension in the past month, make sure its password wasn't chosen by hand.

Five minutes a month, and in most cases there's nothing to find. But the one time there is, it's the difference between a small bill and a bill people talk about for years.

Questions to ask every provider

  • Who generates the extension passwords, and how do they reach the device?
  • Can destinations be restricted for each extension separately?
  • Can login to the control panel be restricted to certain addresses?
  • What happens when unusual activity is detected at night, and who notifies whom?
  • Where can I see all outgoing calls, and how soon do they appear?

A provider who answers these questions with confidence and in detail is one who has already seen cases like these and handled them.

How it works with us at Kesher

Every extension on a Kesher PBX gets a strong password that the system generates by itself. There is no need to come up with a password, and no temptation to pick 1234. The password is entered into the device, and on our phones, which arrive pre-configured, it is already in place.

In the control panel you can see, for each extension, whether it is registered and from which device. If an extension is registered from a place you don't recognize, that's the time to contact us.

Access to the control panel itself can be limited to specific IP addresses, for example only from the office. That way, even a leaked password is not enough to log in from outside and change settings.

The call log shows every call with its route, with search and export, so it is easy to check unusual outgoing calls. And if anything looks strange to you, just call, and a real person will answer.

FAQ

How do you know if the phone system has been accessed without authorization?

Common signs are outgoing calls when the office is closed, calls to foreign destinations that no one normally dials, several simultaneous calls from a single extension, and a sudden jump in charges. Check the call log.

Why does unauthorized use so often happen at night and on Shabbat?

Because no one is watching. Unauthorized use that starts on Friday evening can go on for a whole day before anyone notices it.

Is a cloud phone system more vulnerable than one in the office?

Not necessarily. Both are exposed if the passwords are weak. The advantage of the cloud is that the provider manages the server, creates strong passwords, and can notice unusual activity.

What is the most important thing to do today?

Make sure every extension has a strong, random password, limit access to the control panel, and take a look at the outgoing calls once a day or every other day.

Does insurance cover charges for calls we did not make?

It depends on the policy. Some business cyber policies include this kind of coverage, and most require reasonable protective measures, such as strong passwords and monitoring. Keep the call log and contact your insurance agent early.

What is the difference between misuse of an extension and someone impersonating our number?

Misuse of an extension means getting into your phone system and dialing at your expense. Impersonation means showing your number on other people's screens, without touching your phone system at all. You protect against the first with passwords and restrictions; the second is handled by the rules of the telephone network, which are not in your control.

How often should extension passwords be changed?

A long, random password does not need periodic changes. Change it when there is a reason: an employee left, a device was lost, or there is suspicion of outside access.

Back to the Knowledge Center — all terms

Want to hear how it would work for you?

Tell us how your phones work today — how many calls, who answers, what gets in the way — and we'll get back to you with an organized proposal.

Leave your details and we'll get back to you
077-921-9000