Skip to content

Preventing PBX toll fraud: a defensive guide

A defensive guide to PBX toll fraud for UK organisations: how it happens at a high level, who bears the cost, the controls that stop it, the scale of the problem and why an authorised assessment closes the paths.

9 min readPublished 14 August 2026By Rocco Clayfield

Toll fraud is the abuse of a phone system to place calls that generate revenue for the attacker and a bill for the victim. It is quiet, it often runs overnight or across a weekend, and it can accumulate a large cost before anyone notices. This guide explains, at a high level, how toll fraud happens, who ends up paying, and the controls that prevent it. It stays strictly defensive and describes no method an attacker could reuse.

How toll fraud happens, in outline

Toll fraud follows a simple economic logic. An attacker gains the ability to place calls through a system they do not own, and directs those calls to expensive destinations from which they earn a share of the charge. The organisation that owns the system sees the calls on its bill.

The two ingredients are access and permission. Access means a compromised extension, a weakly authenticated endpoint or an exposed service. Permission means a dial-plan generous enough to reach costly international and premium-rate numbers. Remove either ingredient and the fraud becomes far harder to monetise.

Who bears the cost

A common and costly misunderstanding is that the carrier absorbs fraudulent charges. In most UK commercial arrangements the customer is liable for calls placed through their system, including fraudulent ones, because the calls were genuinely carried and terminated.

Carrier fraud caps and alerts are useful, but it helps to be clear about what they do. They react to spend that has already begun, and they limit outbound cost rather than prevent the compromise that caused it. A cap can reduce the size of a bad night; it does not stop an extension being taken over, and it rarely addresses interception or eavesdropping risk.

  • The customer is typically liable for calls placed through their system
  • Carrier caps and alerts trigger after fraud has started, not before
  • Caps limit outbound spend but do not fix the underlying weakness
  • Prevention sits with the controls on the phone system itself

The scale of the problem

Telecom fraud is not a rare misfortune. The Communications Fraud Control Association estimated global telecom fraud losses of around US$38.95bn in 2023, up on the previous year. Toll fraud and related schemes make up a meaningful part of that total, and small and mid-sized organisations are frequently targeted precisely because their phone systems receive less scrutiny than their other IT.

The controls that prevent it

Toll fraud prevention is not exotic. It rests on a handful of well-understood controls that, applied together, remove the easy paths attackers rely on. The theme throughout is least privilege: grant only the calling ability the business genuinely needs.

  • Restrict the dial-plan so international and premium-rate calling is limited to the roles that need it
  • Disable unused routes, trunks and features rather than leaving them dormant
  • Apply out-of-hours and volume limits where the calling pattern allows
  • Enforce strong, unique authentication on extensions and management access, with lockout
  • Alert on spikes in call cost, international traffic or out-of-hours activity so fraud is caught early

No single control is a complete answer. Strong authentication reduces the chance of a foothold; dial-plan restriction limits what a foothold can achieve; alerting shortens the time to notice. Together they turn a potentially large loss into a contained, quickly detected event.

Why the dial-plan comes first

If one control deserves priority, it is the dial-plan. Because toll fraud depends on reaching expensive destinations, a dial-plan that denies those destinations by default caps the damage even when an account is compromised. It is the difference between an incident and a catastrophe.

Most organisations call a predictable range of numbers. Building the dial-plan around that pattern, and requiring a deliberate exception for anything unusual, is both practical and highly effective. It aligns the system's permissions with the business's real needs.

Detection and response

Prevention lowers the odds; detection limits the cost when prevention is imperfect. Because toll fraud runs quietly, the value of monitoring lies in noticing the unusual pattern quickly and having a plan ready to act on it.

  • Review call detail records for unexpected destinations, volumes and timing
  • Alert on sudden increases in international or premium-rate traffic, particularly out of hours
  • Know in advance who can suspend calling or a trunk, and how quickly
  • Keep logs protected so an intruder cannot erase the evidence
  • Rehearse the response so the first real incident is not the first practice

It is worth being honest about the nature of this activity. Reviewing records and responding to alerts are operational tasks the organisation carries out. An assessment confirms the controls are in place; it does not replace day-to-day vigilance.

Why an assessment closes the paths

The controls above only work if they are genuinely implemented, and that is precisely what an authorised toll-fraud risk assessment verifies. Rather than assuming the dial-plan is tight and authentication is strong, it tests the system under a signed scope and reports where the real gaps are.

  • A defined, signed scope naming the systems in bounds and the testing window
  • Review of dial-plan permissions, unused routes and out-of-hours behaviour
  • Assessment of authentication strength and lockout on extensions and management access
  • A view of external exposure that fraud could exploit
  • Findings ranked by severity with remediation, and a retest to confirm each path is closed

Sources

Related service

Toll-Fraud Risk Assessment

Find the exposure that lets attackers turn your phone system into call spend.

Related reading

  • Toll fraud explained: how phone systems become a bill

    How toll fraud works at a high level, who pays for it, why provider caps are not enough, and how to reduce the exposure: a defensive overview.

  • Caller-ID spoofing and vishing: a defensive guide

    How caller-ID spoofing and voice phishing work, why they matter for organisations with phone systems, and the defensive controls that reduce the risk.

  • The complete guide to SIP security

    A defensive guide to SIP security for UK organisations: how the protocol works, why fraud so often starts here, trunk and registration exposure, authentication, transport security, routing and how an authorised SIP audit works.

  • Cloud PBX vs on-premises PBX: the security differences

    A practical UK comparison of cloud and on-premises PBX security as the PSTN switch-off drives businesses onto IP telephony, covering exposure, patching, the shared-responsibility model, authentication, and what an authorised assessment covers for each.

This guide is educational and defensive. Test only systems you own or are explicitly authorised to test. See our responsible-testing policy.

Find out exactly how exposed your phone system is

Request an authorised PBX, VoIP or SIP security assessment. We confirm scope and authorisation first, then show you what is exposed and what to fix.

Testing is only performed against systems you own or are explicitly authorised to test.