Skip to content

Toll fraud explained: how phone systems become a bill

How toll fraud works at a high level, who pays for it, why provider caps are not enough, and how to reduce the exposure: a defensive overview.

6 min readPublished 14 August 2026By Rocco Clayfield

Toll fraud turns a compromised phone system into call charges the business usually has to pay. This overview explains how it happens at a high level, who bears the cost, and how to reduce the exposure. It is deliberately non-operational.

How toll fraud happens, at a high level

The pattern is consistent: an attacker gains access to a phone system or account, then uses it to place large volumes of expensive calls, often international or premium-rate, frequently out of hours so the activity runs longer before anyone notices.

The access usually comes from familiar weaknesses: an exposed service, a weak or default account, or permissive dialling that was never tightened.

Who pays for it

Under standard telephony contracts, the customer is generally liable for the cost of fraudulent calls. That is why providers sell fraud-protection add-ons: the financial risk sits with the business, not the carrier.

Reducing the exposure

  • Restrict international and premium-rate dialling to accounts that need it.
  • Disable call routes the business never uses.
  • Strengthen authentication and disable dormant accounts.
  • Reduce external exposure of telephony services.
  • Alert on unusual calling patterns so fraud is caught quickly.

Assessing fraud risk

A toll-fraud risk assessment targets these paths directly, demonstrates the exposure in a controlled, non-billable way, and gives you prioritised controls. Any exposure figure it presents is an illustrative scenario, clearly labelled, never a forecast or an observed loss.

Related service

Toll-Fraud Risk Assessment

Find the exposure that lets attackers turn your phone system into call spend.

Related reading

  • Preventing PBX toll fraud: a defensive guide

    A defensive guide to PBX toll fraud for UK organisations: how it happens at a high level, who bears the cost, the controls that stop it, the scale of the problem and why an authorised assessment closes the paths.

  • Caller-ID spoofing and vishing: a defensive guide

    How caller-ID spoofing and voice phishing work, why they matter for organisations with phone systems, and the defensive controls that reduce the risk.

  • Cloud PBX vs on-premises PBX: the security differences

    A practical UK comparison of cloud and on-premises PBX security as the PSTN switch-off drives businesses onto IP telephony, covering exposure, patching, the shared-responsibility model, authentication, and what an authorised assessment covers for each.

  • How a PBX security assessment works, step by step

    A defensible, standards-aligned methodology for an authorised PBX security assessment, from authorisation and discovery through fingerprinting, validation, prioritisation, reporting, remediation and ongoing assurance.

This guide is educational and defensive. Test only systems you own or are explicitly authorised to test. See our responsible-testing policy.

Find out exactly how exposed your phone system is

Request an authorised PBX, VoIP or SIP security assessment. We confirm scope and authorisation first, then show you what is exposed and what to fix.

Testing is only performed against systems you own or are explicitly authorised to test.