Most small business owners think of their phone system the way they think of a light switch: install it once, and it just works forever. That's exactly the assumption VoIP toll fraud exploits. Unlike ransomware or a phishing email, this attack doesn't need an employee to click, open, or type anything. It targets the phone system itself, quietly, usually overnight or over a holiday weekend when nobody's checking call logs, and by the time anyone notices, the damage is already sitting on next month's carrier invoice. It's one of the least talked-about ways a small business loses real money to a hack, and one of the easiest to prevent once you know where to look.
How VoIP toll fraud actually works
An attacker, or more often an automated scanner working through thousands of businesses at once, looks for a PBX or VoIP admin portal reachable from the open internet, a voicemail box still set to its factory PIN, or remote extensions belonging to an employee who left months ago and was never removed. Once inside, they don't need to steal data or plant malware. They simply place calls, in bulk, to international or premium-rate numbers the attacker controls or profits from through a practice known as international revenue share fraud. Every minute that call runs, the attacker earns a cut of what the carrier bills, and the business footing that bill has no idea it's happening until the invoice lands.
Why this matters for a small business
- The bill can hit five figures in a single weekend. A compromised system running calls unattended for 48-72 hours can generate far more in charges than most owners would guess a phone line could ever cost.
- Carriers don't always reverse the charges. Some will work with a business after a documented fraud incident, but many contracts make the account holder responsible for calls that were technically authenticated with valid credentials, even stolen ones.
- It hides in a system nobody monitors. Firewalls, antivirus, and email filtering all watch computers and inboxes. Almost nobody is watching call logs on the office phone system for a spike at 3 a.m.
- Old accounts are an open door. A departed employee's voicemail box or softphone login is exactly the kind of forgotten access this fraud relies on.
What actually stops it
- Change every default password and PIN on the PBX admin portal, individual phones, and every voicemail box, not just the main system login.
- Block international and premium-rate calling by default, allowing only the specific countries or number ranges the business genuinely needs to call.
- Put the admin portal behind a VPN or firewall rule, not directly reachable from the public internet where scanners can find it.
- Ask the carrier for a spending cap or real-time alert that flags unusual volume or destination the moment it starts, not on next month's bill.
- Disable extensions and remote access immediately at offboarding, the same discipline used for email and file access should apply to the phone system.
Where this fits
- The vishing post, for how attackers abuse the phone from the other direction, calling employees instead of hacking the system itself.
- The password manager post, for closing off the default-credential problem across every system, not just the phone.
- The employee offboarding checklist, for making sure a former employee's extension and voicemail access get cut on day one.
- The managed IT services page and the network design page, for where phone system security fits into a full IT program.
FAQs about VoIP toll fraud
What is VoIP toll fraud?
VoIP toll fraud is when someone breaks into a business's phone system, usually through a weak admin password, a default voicemail PIN, or an internet-exposed PBX, and uses it to place a huge volume of international or premium-rate calls. The attacker profits by controlling the destination number and collecting a cut of what the carrier charges for each minute, leaving the business to pay the bill.
How do hackers get into a business phone system in the first place?
The most common entry points are a PBX or VoIP admin portal left reachable from the open internet with its factory default password never changed, a voicemail box still set to a simple PIN like 0000 or 1234, and remote access or extensions belonging to a former employee that were never disabled after they left. Automated scanners probe for exactly these weaknesses around the clock, so a system doesn't need to be specifically targeted to get hit.
How does a small business stop VoIP toll fraud?
Change every default password on the phone system, require a real PIN of six or more digits on every voicemail box, block international calling by default and allow only the specific countries the business actually calls, and put the admin portal behind a VPN or firewall instead of the open internet. Ask the phone carrier to set a daily spending cap or call-volume alert so a fraud run gets caught in the first hour instead of over a long weekend.
Not sure if your phone system is still using its default password?
30 minutes with a DoD-cleared engineer. We'll check whether your PBX admin portal is exposed, confirm voicemail PINs and international calling are locked down, and make sure former employees' extensions were actually disabled.
Book your free security assessment