Industry
Call & Contact Centres
Contact centres run on their phone systems. High call volumes, many extensions and out-of-hours operation make telephony exposure both more likely and more expensive when it is abused.
Why it matters here
The telephony risk in this sector
A contact centre's PBX or VoIP platform is business-critical and constantly in use, which makes both downtime and fraud materially more damaging than in a typical office. Large extension counts, agent turnover and integrations widen the attack surface, and out-of-hours fraud can run for longer before it is noticed.
Scale multiplies exposure
Hundreds of extensions and frequent staff changes leave more accounts to compromise and more permissions to get wrong.
Out-of-hours fraud
Quiet periods are exactly when fraudulent call spend accumulates unnoticed.
Card-by-phone scope
Where agents take card details by phone, the telephony layer falls within PCI DSS scope and needs assessing accordingly.
Uptime is revenue
An exposed, unpatched platform is a single point of failure for the whole operation.
Context
What makes call & contact centres different
Contact-centre estates are the extreme case of the telephony problem. A typical mid-sized centre carries thousands of calls a day across hundreds of concurrent extensions, and the platform is almost never taken offline for maintenance. That combination — high call volume, permanent uptime and many accounts under active change — is exactly what makes both fraud and disruption more damaging here than in a typical office.
Agent turnover is quietly one of the biggest exposures. Every joiner and leaver is an account event on the PBX, and centres running at scale accumulate stale extensions, mailboxes still forwarding to the phones of former staff, and voicemail PINs that were set once and never rotated. Any one of those is a foothold.
Integrations widen the attack surface further. Modern centres are rarely a bare PBX: they wire the call platform into a CRM, a workforce-management tool, a compliance recorder and a queue-analytics dashboard. Each integration is a network path into the phone system, and each one deserves the same scrutiny the CRM or web tier already gets.
Attack scenarios
How this typically goes wrong
Sector-specific scenarios GoldAgent has scoped assessments against. Defensive framing only — nothing here is a how-to.
Weekend toll-fraud burn
The classic contact-centre incident happens on a Friday evening. Attackers who have quietly enumerated extensions and cracked one or more weak SIP registration passwords wait until the operations team goes home. Between then and Monday morning they place large volumes of chargeable calls through premium-rate numbers they control. The centre usually discovers it either when the carrier's fraud alerts fire or, more often, when the bill arrives.
Agent-account harvesting for outbound abuse
Compromised agent extensions are attractive to attackers who want to run vishing campaigns from a trusted business number. Because outbound calls appear to come from the centre's ANI, the target's caller-ID display treats them as legitimate, and any recording, spam or fraud attributed to those calls sits against the centre's reputation, not the attacker's.
Voicemail-to-email hijack
Voicemail systems that forward to email are useful for staff and useful for attackers. If mailboxes are addressable externally, or if PINs can be brute-forced, an attacker can intercept voicemail-based MFA codes, password-reset callbacks or one-time codes used by carriers and payment providers. In a centre where those codes are routine, one compromised voicemail is often enough to escalate elsewhere.
Compliance driver
PCI DSS scope
Where agents take payment card details by phone, the telephony layer is inside PCI DSS scope. That includes the PBX, the SIP trunks that carry the audio, the recorder, any queue or IVR component involved before the payment step, and every network segment those systems sit on. PCI DSS Requirement 11 calls for regular authorised testing of systems in scope, and the QSA will expect telephony to be tested to the same standard as the web tier and databases — not skipped on the assumption that it is “just voice”. GoldAgent's assessments deliver evidence that meets that requirement, so the annual attestation is not held up by a missing piece of scope.
Related services
Explore related assessments
PBX Security Assessment
An authorised, end-to-end assessment of the PBX systems your business runs on.
Read moreToll-Fraud Risk Assessment
Find the exposure that lets attackers turn your phone system into call spend.
Read moreContinuous Assurance
Scheduled, automated reassessment with historical change tracking that keeps your exposure picture current between assessments.
Read more
Find out exactly how exposed your phone system is
Request an authorised PBX, VoIP or SIP security assessment. We confirm scope and authorisation first, then show you what is exposed and what to fix.
Testing is only performed against systems you own or are explicitly authorised to test.