Toll Fraud Protection
Somebody gets into your phone system, dials premium-rate and international numbers all weekend, and the call charges are yours. Toll fraud is a billing problem before it is a security one.
Request a quoteThe bill is real, and it is yours
Toll fraud is the unauthorised use of your phone system to make calls somebody else profits from. The way in is almost always credentials rather than anything exotic: a SIP account with a default or guessable password, an extension reachable directly from the internet, a voicemail box whose PIN is still the last four digits of the extension, or a maintenance login the installer set at handover that nobody has touched since. Once an attacker can authenticate, nothing is being broken. Calls are simply placed with your identity, which is why they look legitimate to your phone system, to your carrier, and eventually to your finance team. The exposure has grown as businesses move off ISDN onto IP, because an IP trunk is reachable from anywhere and a copper line was not.
The destinations are not chosen at random. They are chosen because they pay. Premium-rate numbers and certain international ranges share revenue with whoever terminates the call, so an attacker who controls the far end earns on every connected minute. That makes volume the objective, and volume needs a stretch of time without interruption — which is why it starts on a Friday evening, over a bank holiday, or at two in the morning. The system is no weaker at 2am. There is simply nobody in the building to hear thirty simultaneous calls, and a whole weekend before anyone looks.
Then the invoice arrives, and this is the part businesses find hardest to accept. The calls were placed with valid credentials on your account, they were carried, and they were terminated by operators your carrier has already had to pay. Business telecoms contracts generally make the account holder responsible for calls made from the service, whether or not they were authorised — it is usually a clause about unauthorised or fraudulent use, and it is worth reading yours before you need it rather than after. Some providers set their own spend thresholds and will sometimes discuss sharing the loss, but that is discretion rather than entitlement and it is not something to plan around. Prevention is cheaper than the argument, and considerably more reliable.
Detection is a matter of thresholds rather than cleverness, because fraudulent traffic is abnormal in ways you can describe in advance. Spend on an account running past anything that account has ever spent. A call to a country the business has never once dialled. Volume at an hour when the office is empty. Concurrent calls that start together and do not end. Monitoring watches for those and intervenes, and that is what separates an unpleasant bill from a serious one. What it will not do is stop the first calls — there is always a gap between the first fraudulent minute and enough traffic to be recognisable as a pattern. Anyone describing monitoring as prevention is describing barring instead.
The controls that work are unglamorous and mostly cost nothing. Bar the destinations you do not call: most UK businesses never legitimately dial a premium-rate number, a satellite range or the bulk of the international list, and barring those removes the profit motive rather than reporting on it afterwards. Change default and installer passwords, and treat a SIP credential as a password rather than a line in a configuration file. Ask what ceiling your platform can put on call spend — some enforce a hard stop, some only raise an alert, and the difference matters before you rely on it. Monitoring goes on top of that, because barring covers the destinations you predicted and monitoring covers the ones you did not. We would not sell fraud monitoring to a business that has not done the barring first. It is the wrong order, and it is paying somebody to watch a door that could be locked for nothing.
The controls, in the order they matter
Destination barring
Block the ranges you never dial — premium rate, satellite, and the international destinations that carry a revenue share. It costs nothing, takes effect immediately, and removes the profit rather than reporting on it. First thing to do, not last.
Credential hygiene
Default and installer passwords changed, SIP credentials treated as secrets rather than configuration values, voicemail PINs that are not the extension number, and no extension published straight to the internet. Most compromises start at one of those four.
A ceiling on call spend
So the worst case is a figure you chose rather than one you discover on an invoice three weeks later. Worth checking whether your platform enforces a hard stop or only raises an alert — those are not the same protection.
Out-of-hours profiling
Call patterns measured against when your business is genuinely open rather than against a generic baseline. Thirty concurrent calls at 3am on a bank holiday needs no judgement to classify, and it is the signal that catches most incidents early.
Unusual destination alerts
An alert the first time your system dials a country it has never dialled, rather than the first time somebody reads the bill. Cheap to configure, and specific enough that it does not cry wolf.
Voice Safe and VoIP Safe
SCG's fraud protection across voice and VoIP services, part of the Service Assured range, carrying a credit guarantee against fraudulent call charges. Detection limits the damage; the guarantee is what addresses whatever got through.
Who we work with
We are independent of any single network or vendor, so the recommendation follows the requirement.
Telephony platforms
Hosted, on-premise or Microsoft Teams — the right answer depends on the building, not on what we prefer to sell.
Network and vendor names and logos are the trademarks of their respective owners, shown to describe the services SCG Solutions supplies.
Toll Fraud Protection — Common Questions
Who pays for fraudulent calls — us or the carrier?
You do, in almost every case. The calls were placed with valid credentials on your account, they were carried across the network, and they were terminated by operators your carrier has already had to pay. Business telecoms contracts generally make the account holder responsible for calls made from the service, whether or not those calls were authorised, and the clause is usually the one about unauthorised or fraudulent use. Read yours before you need it. Some providers set their own spend thresholds and will sometimes discuss sharing the loss, but that is discretion rather than a right and it is not something to build a plan around.
How do they get into the phone system in the first place?
Credentials, nearly always, rather than anything sophisticated. The common routes are a SIP account with a default or guessable password, an extension reachable directly from the internet, a voicemail box whose PIN is still the last four digits of the extension, and a maintenance login set by the installer at handover that nobody has changed since. Once an attacker can authenticate, nothing is being broken. Calls are simply placed with your identity, which is exactly why they look legitimate all the way through to the invoice.
Why does it always happen at night or over a weekend?
Because volume is the point and interruption is the risk. The money is made per minute on premium-rate and revenue-share international destinations, so an attacker wants as many concurrent calls as possible running for as long as possible. A Friday evening before a bank holiday buys three days before anybody is in the building to hear the phone system running flat out. It is a scheduling decision rather than a technical one. The system is no weaker at 2am, it is just unobserved.
We are on cloud telephony rather than an on-premise PBX. Are we still exposed?
Yes, though the failure mode moves. There is no PBX in your building to compromise, so the exposure shifts to credentials and to the management portal: a user password reused elsewhere and turning up in a breach, an administrator account without multi-factor authentication, or a softphone configuration sitting in a shared folder. Hosted platforms generally have better default protections and better central visibility than an ageing on-premise system, and that genuinely helps. It does not change the underlying position, which is that an attacker holding a valid login is placing calls you will be billed for.
Should we just bar all international calling?
Not entirely, unless you genuinely never call abroad. The useful version is an allow list rather than a blanket block: permit the handful of countries you actually deal with and bar the rest, which keeps the business working and still removes most of the revenue-share destinations. Premium-rate and satellite ranges are the easier decision — very few UK businesses have a legitimate reason to dial either, and those can usually go without an argument.
What are Voice Safe and VoIP Safe?
They are the fraud protection in SCG's Service Assured range — Voice Safe on voice services, VoIP Safe applying the same cover to VoIP. Some of the group's material writes it as Voicesafe; it is the same product. What distinguishes it from monitoring on its own is a credit guarantee against fraudulent call charges, and the terms of that guarantee are the part worth reading rather than assuming. Whether it is worth buying depends on your call profile and on how much the barring has already ruled out, and we would tell you if the answer were no.
What is the single cheapest thing we can do this week?
Ask for the list of destinations your system is currently permitted to dial, then bar every one you have never used. Most businesses have never legitimately called a premium-rate number, a satellite range or the bulk of the international list, and barring them costs nothing, takes minutes, and removes the profit motive rather than merely watching for it. Change the installer and default passwords in the same sitting. That combination closes the routes behind the large majority of incidents, and it does it before you have spent anything on monitoring.
More Telephony Solutions
- Evonex Hosted Telephony
- Microsoft Teams Calling with Fuse 2
- Microsoft Teams Calling Costs: Direct Routing vs an Operator Licence
- SIP Trunking
- On-Premise Telephony & NEC Phone Systems
- SIP Trunking vs Cloud Telephony
- Gamma Horizon Hosted Telephony
- Evonex vs Gamma Horizon
- The Big Switch Off — PSTN & ISDN
- Switching Business Telecoms Provider
- Business Telecoms Contract Renewal: What to Check Before You Sign Again
- Bundling Phone, Mobile and Internet: Is One Supplier Actually Cheaper?
- Contact Centre Solutions
- Call Recording for Business
- Number Porting: Keeping Your Number When You Change Supplier
- Out-of-Hours and On-Call Call Routing
- Hunt Groups and Call Queues
- Auto Attendant and IVR Menus
- Phone Systems Across Multiple Sites
- Alarm, Lift and Emergency Lines After the Switch Off
- Call Analytics and Reporting
- Seasonal Capacity: Paying for Your Peak Only in the Peak
- What a Business Phone System Actually Costs
Where we cover toll fraud protection
We deliver this across the UK. These 8 are where a director is actually based — each page names who you would be dealing with, and what the local economy is made of.
Worried about what your system would allow?
We will look at what your phone system can currently dial, what barring is in place and whether anything is watching the spend — and tell you where the exposure is before it is tested.
