Thank you for Subscribing to Telecom Business Review Weekly Brief
Telecom Business Review | Wednesday, April 06, 2022
Toll Fraud, also familiar as VoIP fraud, is when a hacker accesses your phone system to make fraudulent calls from your account, generally to international destinations.
Fremont, CA: The stolen call traffic is usually sold through overseas calling cards or low-cost call tariffs, often funding organized crime and terrorism. They use the latest technology and software to identify insecure systems and find their weak spots.
Regrettably, many businesses only discover that they have fallen victim to toll fraud after the intrusion and the costly telephone bill that comes with it. This is commonly a recipe for unnecessary stress, worry, and unpleasant conversations with your network provider, not to refer the cost.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
How to prevent Toll Fraud
The best prohibition is learning and educating yourself on how toll fraud can happen in the first place. Generally, hackers gain access by finding the following flaws in telephone phone systems:
Password Security
An obvious but critical factor is password security. Telephone system providers tend to offer products that, by default, use easy passwords that are effortlessly guessed. Nevertheless, this is something you can easily combat.
During the telephone system installation, change the password from the default one given to a more secure one. If you have to present your new passwords through a telephone keypad, then guarantee the numeric combination avails of all digits available and avoid easy-to-guess passwords such as:
• Simple patterns.
• Your expansion number
• Dates or Addresses Digit repetition.
• Default passwords
Regular Utilities also suggested that as part of the ongoing maintenance contract of the PBX system, you change your passwords every three months and remember never to give the same password to more than one user.
Auto Attendant
Auto Attendant is a menu-based system often used on incoming calls to direct callers to their destination/ department of choice based on the number of options they enter. This is one of the fiprimary telephone system features to be targeted by attackers.
Intruders will check whether digits can be entered for unannounced/ seemingly unused caller options or if the star key * and hash key # options are designed for system management features. Always, they will look to see if digit ‘9’ allows them access to seize vulnerable trunks and dial through the voicemail onto the PSTN(public telephone network ).
It is suggested that all AA options that don’t have a configured route (particularly digit 9, star key, and hash key) are set to either perform the Auto-Attendant / menu options repeat or drop the call.
Voicemail
Voicemail is very likely to Auto Attendant, and most PBX systems will use the same application as the Auto Attendant system. It is an opinion that most intruders attack PBX systems with the voicemail system.
Intruders accomplish this by firstly calling your number and leaving a message on your voicemail through a particular telephone number. They will then recall into the voicemail to hack your password. Once in the mailbox, the intruder will test the ‘call back’ feature, which commands the PBX to return the call from any messages left.
If it works and the invader receives a call back on their specific number, they will proceed to use the ‘call back’ feature to leave messages from more expensive numbers. Essentially, the intruder is dialling a local number into the voicemail and utilizing your PBX to make calls at an international or premium rate.
Intruders use unused mailboxes, so their activity goes under the radar. Thus, at Standard Utilities, we recommend that you delete any mailboxes for inactive users, delete mailboxes for users that do not use voicemail, remove mailboxes for staff that leave the company and eliminate inactive group mailboxes.
Call Barring or Day and Night Routing
Fixing call barring or Day and Night routing models into your telephone system effectively controls incoming and outgoing calls.
Toll Fraud usually involves attackers pointing a system outside of business hours when intrusion attempts go unnoticed. This allows them to make calls that can be redirected to other numbers at a premium rate.
You can limit your telephone system from dialling costly international numbers or operator services by installing call barring or Day and Night routing patterns. It is also likely to restrict all outgoing calls (except emergency numbers) when the office is closed. We would also suggest you lock down access/admin rights to the system, as it is not unheard of for hackers to have been given access by an internal staff member.
SIP Trunks
With the decline of ISDN lines and technological advances, the adoption of SIP trunks has never been higher. Still, technology that runs over the internet can be vulnerable and open to being attacked.
To help decrease risks, Standard Utilities suggest you avoid using public internet access / wifi on your devices and always try to use a private connection to access your SIP provider. If this is not possible, we recommend that you at least ensure that a reliable firewall is in place only to allow connections from known IP addresses and on specified IP ports.
IP Network
The benefits of using IP telephony outweigh the disadvantages. However, these should never be ignored.
If, for example, you connect to a local or vast area network your provider doesn’t maintain, your telephone system is at risk of intrusion. Standard Utilities would highly recommend that you provide your end users’ IT department with a list of all known IP addresses and ports relating to your telephone system. That way, access can be permitted and restricted accordingly.
If necessary, use IP encryption protocols such as Transport Layer Security (TLS) and Secure Real Time Protocol (SRTP) to ensure all connections and real-time voice traffic.
More in News