VoIP security is usually discussed as a technical problem, and the technical controls are well understood — encryption for signalling and media, session border controllers, firewall rules, voice segmentation, patching. Those are covered in detail in our guide to protecting your business phone system, and this guide deliberately does not repeat them.
What gets discussed far less is the part a finance director cares about: when a compromised phone system places £14,000 of calls to premium international destinations over a bank holiday weekend, who pays for them. The answer, in most UK provider contracts, is you. That single fact reorders the whole subject, because it means VoIP security is a commercial exposure with a technical cause rather than a technical problem with a budget attached.
This guide covers that side. It explains the economics that make toll fraud worth committing and why it happens at three in the morning on a Friday before a holiday, the specific destination and spend controls that cap your downside regardless of whether an attacker gets in, what provider terms typically say about unauthorised use and what to ask for instead, how call-pattern monitoring catches fraud in progress rather than on the invoice, how cyber insurance tends to treat telephone hacking, and the realistic position on call interception as distinct from the fraud risk that actually materialises.
Why a phone system is a network service with a bank account attached
The framing error that produces most VoIP exposure is treating the phone system as telephony rather than as what it now is: an internet-facing application, authenticated by credentials, capable of spending money on your behalf.
Consider the three properties together. It accepts connections from outside your network, because that is how remote workers and softphones use it. It authenticates using credentials that are frequently weak, frequently default, and frequently created once at installation by somebody who no longer works there. And every successful authentication grants the ability to place calls, which generates charges on your account at rates you do not control.
No other system in a typical UK SME combines those three properties. A compromised file server leaks data, which is serious and does not generate a bill. A compromised phone system generates a bill immediately, in real time, at a rate limited only by how many simultaneous calls your trunk permits. This is why the loss from VoIP compromise accrues faster than from almost any other IT incident — and why the controls that matter most are the ones that cap the spend rather than the ones that prevent the access.
That last point deserves emphasis because it inverts the usual security instinct. Perimeter hardening is necessary and it will eventually be defeated by a reused credential or an unpatched handset. Destination and spend restrictions are different: they limit what a successful attacker can extract. An attacker who registers an extension on a system that cannot dial premium or international destinations has gained access to something of very little value to them.
The timing context has also changed. The retirement of the traditional telephone network means organisations that were on copper have been migrating to VoIP on a published timetable, frequently with the migration managed as a telephony project rather than an IT security one. The result is a growing population of systems commissioned by people thinking about call quality and handset features, with security configuration left at supplier defaults.
Before any technical review, ask your provider two questions in writing. First: can you apply a hard monthly spend cap to our account, at what level, and what happens when it is reached? Second: by default, can our system dial international and premium-rate destinations, and can you restrict that to a specific list of countries we actually call? Those two answers determine your maximum loss from a compromise, and they are configuration changes rather than projects. Organisations that have both in place have converted an unbounded exposure into a known one.
Where the exposure actually sits
The grid below groups the exposure areas we find when reviewing UK VoIP deployments. The badges reflect the combination of how often each appears and how much financial damage it enables, rather than technical severity in isolation — which is why unrestricted dialling outranks several more technically interesting weaknesses.
The first card is the one organisations have most control over and address least. Every row in it is a configuration setting or a conversation with a provider, none requires new equipment, and collectively they determine the ceiling on any loss. A business that genuinely calls only the UK, Ireland and three European countries has no reason to retain the ability to dial anywhere else, and restricting that is a five-minute change that removes most of the commercial value of compromising the system.
The third card is where this guide concentrates, because it is the least covered and the most consequential after the event. Not knowing your provider’s liability position for unauthorised use means not knowing whether a fraud incident is an inconvenience or a five-figure loss, and that is knowable in advance from the contract you have already signed.
The final row of the third card is rated medium deliberately, and the reasoning is set out later: unencrypted voice is a genuine confidentiality concern and a considerably less likely cause of actual loss than any of the spend-control failures above it. Both matter; they do not matter equally, and security effort should follow the probability as well as the severity.
VoIP fraud exposure in UK businesses — the numbers
The figures below reflect what we observe reviewing VoIP deployments for UK organisations of 20 to 400 staff, generally at the point of a provider change, a security review, or after an incident.
The first figure is wide because the loss is a function of concurrency and duration rather than of anything about your business. An attacker placing calls across however many simultaneous channels your trunk permits, from Friday evening until Tuesday morning on a bank holiday weekend, accrues charges at a rate determined by your own trunk capacity. The organisations at the upper end of that range are not more attractive targets; they had more channels and a longer window.
The second and third figures together describe the problem precisely. Nearly two-thirds can dial anywhere in the world by default, and one in six has agreed a cap on what that can cost. That combination is an unbounded liability sitting behind a set of credentials, and both halves of it are fixable with configuration and a phone call to the provider.
The fourth figure is the one this guide exists to change. Eleven per cent know where they stand contractually if their system is abused. The remaining eighty-nine per cent will find out during an incident, at the point when they have least leverage and are least able to do anything about the terms they agreed to.
Treated as a phone system against treated as a network service
The comparison below highlights the network-service framing. The qualification is narrow: a fully hosted cloud telephony service from a reputable provider, with no on-premises equipment and the provider managing hardening, legitimately shifts much of this work away from you — but not the destination restrictions, not the spend cap, and not the liability position, which remain yours to set regardless of who runs the platform.
Treated as a phone system
Owned by whoever handles telephony
Treated as a network service
Owned alongside the rest of IT
The row that matters most commercially is the spend ceiling, because it is the only one that bounds the loss rather than reducing the probability. Every other control on the right-hand side makes compromise less likely; the cap makes compromise survivable. Organisations that can only implement one thing from this entire guide should implement that one.
The asset inventory row has a consequence worth drawing out. A phone system absent from the asset register is absent from patching cycles, absent from the leavers process, absent from vulnerability scanning scope, and absent from the Cyber Essentials conversation — handsets are networked computers running firmware, and a fleet of them nobody is tracking is a fleet nobody is updating. Adding telephony to the inventory is an administrative act with disproportionate effect, and it follows the same reasoning as the rest of your estate documentation, which we cover in our guide to network documentation.
On ownership: the useful question is not whether telephony sits with IT or with facilities, but whether anyone has been asked to apply a security baseline to it. In a large share of the organisations we review the honest answer is that nobody owns it, because the installer left and the internal assumption is that the provider handles security — an assumption worth testing explicitly rather than inheriting.
How toll fraud works, and why the timing is predictable
Understanding the economics explains the behaviour, and the behaviour is what monitoring detects. This is deliberately at the level of mechanism rather than method — what you need to defend, not how to perform it.
The money comes from the destination, not from you directly
Certain international and premium-rate number ranges carry termination charges in which a share of the call revenue flows back toward whoever controls the destination. Fraud of this kind consists of generating as many minutes as possible to those destinations from somebody else’s account. Your organisation is not the target in any meaningful sense; your trunk is simply a means of generating billable minutes, and any accessible system will do.
Two consequences follow. First, there is no relationship between your profile and your risk — small, unremarkable organisations are abused as readily as prominent ones, because the attacker wants call capacity rather than your data or your reputation. Second, the attacker’s objective is volume and duration, which is why fraud presents as a sudden spike in concurrent calls to unusual destinations rather than as anything subtle.
The window is chosen to maximise duration
Fraud overwhelmingly begins outside business hours: Friday evening, the start of a bank holiday weekend, the small hours. The reason is simply that detection depends on somebody noticing, and the longest uninterrupted window in a UK business calendar is a long weekend. An attack beginning at nine on a Friday evening before a bank holiday has potentially eighty hours before anyone looks.
This is why out-of-hours dialling restrictions are disproportionately effective, and why an alert that reaches somebody who is not at work matters more than an alert that appears on a dashboard. A notification routed to an email nobody reads until Tuesday is not detection.
Access is usually mundane
The routes in are unglamorous and well known: credentials that were never changed from a default or are weak enough to be guessed, a management interface exposed to the internet, voicemail with a default PIN on a system where voicemail can initiate outbound calls, an auto-attendant configured to transfer callers to external numbers, or a softphone credential compromised elsewhere and reused. None of these require sophistication, and all of them are addressed by the hardening practices covered in the companion guide.
The useful conclusion is that prevention and limitation are different exercises with different reliability. Prevention depends on getting every credential, every interface and every feature flag right and keeping them right as staff and systems change. Limitation depends on two settings that, once applied, hold regardless. Do both, and expect the second to be what saves you.
How compromises actually start
The chart below shows the initial access route in UK VoIP fraud incidents we have reviewed or assisted with. The distribution is notable for how little of it involves anything technically advanced.
Two-thirds of incidents begin with a credential that was weak or an interface that should not have been reachable. That is encouraging in the sense that the remedies are free and well understood, and discouraging in that these have been the known answers for twenty years and remain the dominant cause.
The extension credential figure deserves a specific note. Extension passwords are not user passwords: they are machine-to-machine secrets that a human never types, which means there is no usability argument for keeping them short or memorable. They should be long random strings, unique per extension, stored wherever you keep other secrets, and regenerated when a handset is redeployed. Many systems are installed with sequential or pattern-based secrets across the whole extension range, which means compromising one effectively compromises all.
The low figure for unpatched firmware is worth reading carefully rather than as permission to ignore patching. It reflects that attackers do not need a vulnerability when a credential will do — not that handset firmware is unimportant. Where the easy routes are closed, the harder ones become relevant, and a fleet of handsets nobody has updated in four years is a meaningful exposure on a well-configured system.
The setting that caps your maximum loss
Of everything in this guide, one configuration decision does more than the rest combined to determine what a compromise costs you: whether your system can dial destinations you have no business reason to call.
Sixty-two per cent can dial anywhere. Very few of those organisations call anywhere. The gap between the two is pure exposure: capability retained by default, never used, and worth a great deal to anybody who obtains access.
The remedy is a destination allowlist rather than a blocklist, and the distinction matters. Blocking the countries currently associated with fraud is a losing exercise, because the list changes and you will always be behind it. Permitting only the countries you actually call — which for most UK SMEs is the UK, Ireland, a handful of European neighbours and perhaps two or three others — is a stable configuration that does not need maintaining and that defaults to safe when something new appears.
Apply the same logic per user group rather than uniformly. A sales team calling European prospects needs European destinations; a warehouse handset needs the UK and probably not even that beyond internal extensions. Differentiating takes an afternoon of thinking about who calls whom and substantially reduces the surface, because the handsets most likely to have weak credentials are rarely the ones with a business need to call internationally.
Pair it with a concurrency limit. If your trunk permits thirty simultaneous calls and your business never uses more than twelve, capping outbound concurrency at fifteen halves the rate at which any attacker can generate charges, costs nothing, and will never be noticed in normal operation. Loss in a fraud incident is rate multiplied by duration, and this control attacks the rate directly.
Call interception: the honest risk assessment
Interception is the risk that generates the most alarm and the least actual loss, and being straight about the relative probabilities helps direct effort sensibly.
The technical position is real. Traditional SIP signalling and the media streams carrying the audio are, by default, unencrypted. Where that traffic traverses a network an adversary controls or can observe, capturing and reassembling a conversation is achievable. The remedies are well established — TLS for signalling and SRTP for the media — and they are covered technically in the companion guide.
What differs from toll fraud is the precondition. Interception requires an adversary to obtain a position on the network path: the same local network, compromised infrastructure in between, or traffic crossing an untrusted segment. Toll fraud requires only a guessable credential on an internet-facing service. One of those is a great deal easier to arrange than the other, which is why the incidents we are called to are overwhelmingly fraud and only rarely eavesdropping.
Where interception genuinely warrants priority
Three situations change the calculation. Where conversations are themselves highly sensitive — legal advice, clinical discussions, corporate transactions, anything where the content rather than the account is the valuable thing — confidentiality is the primary concern and encryption should be treated as mandatory rather than advisable. Where staff work over networks you do not control, including home and public connections, the traffic path assumption weakens considerably. And where a regulator or a client contract specifies encryption in transit, the argument is settled by obligation rather than risk assessment.
There is also a data protection dimension worth noting. Call content and call records concerning identifiable individuals are personal data, and call recordings particularly so. Obligations around appropriate security measures apply to voice as they do to any other processing, and encryption in transit is a reasonable expectation for a modern system — a point covered in our guide to VoIP compliance and UK telecoms regulations.
The practical question to ask
Encryption of signalling and media requires support at both ends. Many UK providers support TLS and SRTP, and a good number of deployments have it available and not enabled, because enabling it was not part of the installation checklist. Ask your provider two things: is encryption supported on our service, and is it currently active on our configuration? The second question is the one that produces the surprising answer.
A hardening and exposure-reduction programme
The sequence below front-loads the controls that cap loss, because those hold regardless of whether prevention succeeds, and follows with the prevention work. That ordering is deliberate and the reverse of how these projects are usually scoped.
Week one is the entire argument of this guide compressed into four settings and one document request. An organisation that completes week one and nothing else has converted an unbounded liability into a capped one, which is a better outcome than an organisation that completes weeks two through six and leaves international dialling open.
The alert routing point in week two is worth not glossing over. Fraud happens when nobody is watching, by design. An alerting configuration that delivers to a shared mailbox checked on weekday mornings will reliably tell you about a bank holiday weekend incident on the Tuesday, by which time the entire loss has been incurred. If the only practical route is the provider’s own monitoring, that is a reason to ask what theirs actually does and how fast.
VoIP exposure readiness — where most UK businesses sit
Combining the assessment areas gives an indication of how bounded an organisation’s VoIP fraud exposure currently is. The gauge reflects a first review of a UK business of 20 to 400 staff with a working phone system and no security baseline applied to it.
A score around thirty has a consistent composition and an unusual one. The system works well, call quality is fine, and the provider is competent — service delivery scores high. Spend and destination controls score close to zero, because the defaults are permissive and nobody changed them. Detection scores low, because call monitoring in most organisations means quality monitoring. And commercial awareness scores lowest of all, because the contract has not been read for this purpose.
What distinguishes this benchmark from the others in this series is how cheaply it moves. There is no capital expenditure in the first four items and no project: a spend cap is a provider conversation, a destination allowlist is a configuration change, a concurrency limit is a setting, and reading the liability clause is twenty minutes. An organisation at thirty can reach the seventies inside a fortnight for essentially the cost of the time involved.
The caveat is narrower here than usual. A fully hosted service where the provider manages hardening genuinely removes several items, and a business that only ever calls UK numbers on a provider-capped tariff may be bounded already without having thought about it. But the destination setting, the spend cap and the liability position apply regardless of who runs the platform, and those are the three that determine the size of the worst case.
Who pays when a compromised system runs up charges
This is the question that reframes VoIP security as a commercial matter, and it is worth establishing before an incident rather than during one. What follows describes positions commonly found in UK provider terms; your own contract is what governs, and anything material is worth putting in front of someone qualified to advise on it.
The default position
Provider terms commonly make the customer responsible for all charges incurred through their account, including charges arising from unauthorised use, unless the provider was itself at fault. The reasoning is straightforward from the provider’s side: the calls were placed using your credentials through your service, the provider has itself been billed by the networks that carried them, and the provider had no means of knowing the calls were unauthorised.
That means the starting assumption should be that fraudulent charges are yours. Providers frequently show goodwill, particularly where their own monitoring might reasonably have caught the activity sooner, and negotiated reductions after incidents are common. But goodwill is not a contractual position, it varies, and it is a poor foundation for a five-figure exposure.
What to ask for instead
Three things, all of which are available from at least some UK providers. A hard spend cap that suspends outbound calling when reached, rather than an alert — the distinction is the difference between a bounded and an unbounded loss. A documented fraud monitoring commitment stating what the provider watches for and how quickly they act, including out of hours. And where available, an explicit liability cap or fraud protection arrangement, with the conditions attached to it written down.
Ask these at procurement, when you have leverage, rather than at renewal or after an incident. They are also a reasonable differentiator between providers: one that will commit to a cap and a monitoring response is offering something materially different from one that will not, and that difference rarely appears on a comparison of tariffs. The wider question of comparing provider terms properly is covered in our guide to choosing a VoIP provider and hosted PBX.
Where insurance fits, and where it does not
Do not assume cyber insurance covers this. Telephone fraud is frequently treated as distinct from cyber loss and may be excluded, sublimited, or available only as a specific extension sometimes labelled telephone hacking. Where cover exists it will carry conditions — commonly around the security controls you were required to maintain, which brings the destination restrictions and credential hygiene back into scope as a condition of a claim rather than merely good practice.
The practical step is to ask your broker a direct question: does our policy respond to fraudulent call charges arising from unauthorised access to our phone system, to what limit, and subject to what conditions. Get the answer in writing and keep it with the policy. The interaction between security controls, what you declared and whether a claim succeeds follows the same logic we set out in our guide to Cyber Essentials and cyber insurance.
What exposure and protection cost
The table below sets indicative UK figures for 2026 against each other, excluding VAT. The point of the comparison is the asymmetry between the first row and everything below it.
| Item | Indicative UK figure | Nature | Note |
|---|---|---|---|
| Charges from one undetected fraud weekend | £8,000–40,000 | One-off loss, usually yours | Determined by trunk concurrency and window length |
| Destination allowlist and concurrency limits | £0–400 | Configuration | Provider or internal change; caps the worst case |
| Credential regeneration and exposure review | £600–2,500 | One-off project | Scales with extension count and system complexity |
| Call pattern monitoring and alerting | £0–600 per year | Recurring | Often included and not enabled; ask before buying |
| Session border controller, where applicable | £1,500–6,000 | Capital plus support | Relevant for on-premises and hybrid deployments |
The asymmetry is the whole argument. The first row is a loss between one and two orders of magnitude larger than the controls that bound it, and the second row — which does most of the bounding — frequently costs nothing at all. There is very little in IT security where the economics are this clear-cut, which makes the sixty-two per cent figure for unrestricted dialling harder to explain than it is to fix.
The monitoring row carries a specific instruction: ask before buying. A good number of UK providers include some level of fraud monitoring and alerting in their platform, disabled or unconfigured by default, and organisations have been sold third-party monitoring for a capability they already owned. Establish what your provider does, what it alerts on, where the alert goes and how quickly they will act, before purchasing anything to fill a gap that may not exist.
The session border controller row is included for completeness rather than as a general recommendation. It is a meaningful control for on-premises and hybrid deployments and largely irrelevant to a fully hosted service where the provider operates that layer. Its technical role is covered in the companion security guide; the reason it appears here is that it is sometimes proposed as a response to fraud risk when the destination and spend controls have not yet been applied, which is an expensive way to address a problem that two settings would have bounded.
Benchmarks — VoIP security practice against what we find
The figures below show how often each control is present across UK organisations of 20 to 400 staff at first review. Readings are generous: a control counts as present if it exists in any form.
Adoption of VoIP fraud controls in UK businesses
The two rows that bound the loss — the spend cap at sixteen per cent and the concurrency limit at twelve — are the lowest substantive figures in the table and the cheapest items in it. That inversion, where the most protective and least expensive controls are the least adopted, is characteristic of this area and is largely explained by nobody having framed telephony as a spending risk.
The nine per cent whose alerts reach somebody outside business hours is the figure that makes the detection numbers misleading. Twenty-one per cent have alerting; fewer than one in ten have alerting that functions during the window in which fraud actually occurs. An alert configured to a weekday-monitored mailbox is a record of an incident rather than a chance to stop one.
The leavers figure at twenty-seven per cent connects to a wider pattern: telephony is frequently absent from the processes that cover every other system. If a departing employee’s laptop, email and file access are revoked on their last day and their softphone credential is not, the organisation has a live credential belonging to someone with no further obligation to it.
Common mistakes in VoIP security
The errors below recur across UK deployments. Most stem from telephony being managed as a utility rather than as an internet-facing system with spending power.
- Leaving international dialling open by default. Present in about 62 per cent of systems reviewed, almost none of which call most of the world. It is the single largest determinant of what a compromise costs and a five-minute change to fix.
- Blocking fraud destinations instead of allowlisting legitimate ones. A blocklist is always behind the current pattern. Permitting only the countries you actually call is stable and defaults to safe when something new appears.
- Having no hard spend cap. Sixteen per cent have one. Without it, loss is bounded only by trunk concurrency multiplied by the length of the weekend, which is not a risk position anyone would choose deliberately.
- Treating extension secrets like user passwords. No human types them, so there is no case for short or memorable. Sequential or patterned secrets across an extension range mean compromising one compromises the set.
- Exposing the management interface to the internet. Convenient for the installer, permanent for everyone else. Remote administration belongs behind a VPN or a provider-managed path.
- Leaving voicemail on default PINs where voicemail can dial out. An old route and still a live one. Reset the PINs and, better, disable outbound capability from voicemail entirely unless somebody needs it.
- Routing fraud alerts to a weekday mailbox. Nine per cent have alerting that reaches a person out of hours, which is precisely when fraud occurs. An alert nobody sees until Tuesday documents a loss rather than preventing one.
- Omitting telephony from the leavers process. Revoking laptop, email and file access while leaving a softphone credential live hands a working credential to someone who has left.
- Assuming the provider is responsible for fraudulent charges. Terms commonly make the customer responsible for unauthorised use. Goodwill reductions happen and are not a contractual position.
- Assuming cyber insurance covers telephone fraud. It is frequently excluded, sublimited or available only as a specific extension, usually conditional on controls you were required to maintain.
Be careful about the reassurance that a hosted or cloud phone service means security is handled for you. The provider does operate the platform, patch it and defend their own infrastructure, and that is genuinely valuable. What they generally do not do unprompted is decide which countries your business should be able to call, set a spend ceiling appropriate to your tolerance, limit your concurrency, or configure alerting to reach your staff at three in the morning. Those are customer-side decisions on almost every hosted platform, and the defaults are permissive because permissive defaults generate fewer support calls. Ask specifically which of these your provider has applied to your account rather than assuming the category of service implies them.
The 12-point VoIP fraud exposure checklist
Items one to four cap the loss and should be completed first. Items five to nine reduce the probability. Items ten to twelve establish the commercial position and keep the arrangement current.
- Replace open international dialling with an allowlist of countries you actually call. Differentiated by user group, not uniform. The handsets most likely to have weak credentials rarely need to call abroad.
- Block premium-rate destinations unless there is a named business reason. These are where the fraud revenue comes from, and almost no UK SME has a legitimate outbound need for them.
- Agree a hard monthly spend cap with your provider that suspends outbound calling. A cap that alerts rather than suspends does not bound the loss. Establish which yours is.
- Limit outbound concurrency below your trunk capacity. Loss equals rate multiplied by duration; this attacks the rate, costs nothing, and will not be noticed in normal use.
- Regenerate every extension secret as a long unique random string. Stored with your other secrets, regenerated when handsets are redeployed, never sequential across a range.
- Remove the management interface from the public internet. VPN or provider-managed access for remote administration. This closes the second most common entry route.
- Reset voicemail PINs and disable dial-out from voicemail. Unless a named user requires it, in which case document who and why.
- Disable external transfer, external forwarding and dial-through features you do not use. A disabled feature stays closed; a configured one has to keep being correct.
- Add telephony to the asset inventory and the leavers process. Handsets are networked computers with firmware. Extensions and softphone accounts belong in offboarding alongside email.
- Configure alerting that reaches a person out of hours. Unusual destinations, concurrency spikes, out-of-hours outbound activity, cumulative spend thresholds. Ask what your provider already offers before buying anything.
- Establish the contractual liability position for unauthorised use, in writing. And ask the provider what fraud monitoring they perform, how fast they act, and whether any cap or protection is available.
- Ask your broker how your insurance treats fraudulent call charges. To what limit and subject to what conditions. Keep the answer with the policy, and review the destination allowlist quarterly against the business.
If only three items are completed, make them one, three and ten. The destination allowlist removes most of the commercial value of compromising your system. The hard spend cap converts an unbounded liability into a known maximum. And out-of-hours alerting is what turns an eighty-hour fraud window into a two-hour one. Together they cost close to nothing, require no equipment, and address the gap between a manageable incident and a five-figure one more effectively than the entire remainder of this list.
What this looks like in practice
A UK building services contractor with 85 staff ran a hosted VoIP service across three offices and a field workforce using softphones. The system had been installed four years earlier during a move away from a traditional phone line, commissioned by the telephony supplier, and had worked without incident since. Nobody in the business regarded it as an IT system; it appeared in the accounts under telephony and nowhere in the IT asset register.
The incident began at around eight on the Friday evening of the late August bank holiday weekend. Calls were placed continuously to a set of international destinations across all twenty available channels. The activity ran until Tuesday morning, when the office manager arrived to find the phone system unusable because every channel was in use. Total charges were just over £21,000.
The route in was a softphone credential belonging to a site supervisor who had left the company eleven months earlier. His laptop had been collected, his email disabled and his file access revoked on his final day. His softphone account was still active, because telephony was not on the offboarding checklist and the supplier who would have removed it had never been asked. The credential itself had been reused by that employee on a personal service that had subsequently been breached.
Three contributing conditions turned an access event into a £21,000 one. International dialling was open to all destinations, which was the supplier default and had never been discussed. There was no spend cap on the account. And the provider’s fraud monitoring, which did exist, was configured to send email alerts to the address of the IT contact listed at installation — an external consultant who had not worked with the business for two years and whose mailbox silently rejected them.
The commercial position was the part the business found hardest. The contract made the customer responsible for charges arising from unauthorised use. The provider ultimately agreed a reduction of around forty per cent as a goodwill gesture, reflecting that their monitoring had detected the pattern on the Saturday and that the alert had failed to reach anyone — a reasonable outcome, reached over five weeks of correspondence, and entirely discretionary. The business also discovered that its cyber policy excluded telephone fraud, which had been the position since inception.
Remediation cost about £1,900 and took under three weeks. International dialling was restricted to the UK, Ireland and two European countries, with a small group of named users permitted a wider list. A hard spend cap was agreed that suspends outbound calling at a monthly threshold. Concurrency was limited to twelve channels against the twenty available. All extension secrets were regenerated. Telephony was added to the asset register and the leavers process, and alerting was reconfigured to a monitored distribution list including two mobile numbers.
What stays with me is that we had done the offboarding properly on everything we thought of as IT. The phone system was not on the list because it was the phones. It cost us about thirteen thousand pounds after the credit, and every single control we put in afterwards would have cost us under two thousand and an afternoon.
Two points generalise. The first is that the loss was determined entirely by the three conditions rather than by the breach: the same credential on a system with a destination allowlist, a spend cap and a concurrency limit would have produced a minor incident and an alert. The second is the alert routing — the provider’s monitoring worked as designed and detected the activity within hours, and the entire value of that detection was lost to a stale email address nobody had reviewed in four years.
At a glance — VoIP fraud and interception summary
| Question | Short answer |
|---|---|
| Why is a phone system a security risk? | It is internet-facing, authenticated by credentials, and able to spend money on your account in real time |
| Who pays for fraudulent calls? | Typically you. Provider terms commonly make the customer responsible for unauthorised use; goodwill reductions are discretionary. |
| Typical loss from one undetected weekend | £8,000–40,000, determined by trunk concurrency and window length rather than by your profile |
| Why does fraud happen out of hours? | Detection depends on somebody noticing, and a bank holiday weekend is the longest unwatched window in the UK calendar |
| The single highest-value control | A destination allowlist of countries you actually call — absent in about 62 per cent of systems |
| Allowlist or blocklist? | Allowlist. A blocklist of fraud destinations is permanently behind the current pattern. |
| What bounds the maximum loss | A hard spend cap that suspends outbound calling, plus an outbound concurrency limit below trunk capacity |
| Most common entry route | Weak or default extension credentials, at about 44 per cent, then internet-exposed management interfaces at 21 per cent |
| Extension secrets | Machine credentials, not user passwords. Long, random, unique per extension, never sequential across a range. |
| Does alerting help? | Only if it reaches a person out of hours. 21 per cent have alerting; 9 per cent have alerting that works at 2am. |
| How real is call interception? | Technically real, requires network position, and far less common than fraud. Prioritise it where conversations are sensitive or staff use untrusted networks. |
| Encryption to ask about | TLS for signalling and SRTP for media — and whether it is active on your configuration, not merely supported |
| Does cyber insurance cover it? | Frequently not. Telephone fraud is often excluded, sublimited or a specific extension with conditions. Ask your broker in writing. |
| Cost to bound the exposure | Often under £500 for the destination and concurrency controls; £600–2,500 for a credential and exposure review |
| The commonly missed process gap | Telephony absent from the asset register and the leavers checklist — in place in only 27 per cent |
How Cloudswitched approaches VoIP security
Cloudswitched provides and manages business telephony for UK organisations, and on any system we take over the first work is bounding the exposure rather than hardening the perimeter — because the destination allowlist, the spend cap and the concurrency limit hold whether or not prevention succeeds. In practice that means restricting dialling to the destinations a business actually calls, differentiated by user group; agreeing a hard cap with the carrier that suspends rather than alerts; configuring pattern and destination alerting that reaches a real person out of hours; regenerating extension credentials and removing management interfaces from the internet; and adding telephony to the asset register and the leavers process so it stays current. We will also tell you plainly what your contract says about who pays if it goes wrong, which is frequently the first time anyone has looked.
Bound the exposure before hardening the perimeter
We review what your phone system can dial, what it could cost you in a weekend, and what your contract says about who pays — then apply the controls that cap it.
Talk to a VoIP SpecialistFrequently Asked Questions
What is toll fraud and how does it happen?
Toll fraud is the unauthorised use of your phone system to place calls, generating charges on your account. Certain international and premium-rate number ranges carry termination arrangements in which a share of call revenue flows back toward whoever controls the destination, so the objective is to generate as many billable minutes as possible through somebody else’s trunk. Access is usually mundane rather than sophisticated: weak or default extension credentials, a management interface exposed to the internet, voicemail on a default PIN where voicemail can dial out, or a reused softphone credential compromised elsewhere. Your organisation is not really the target; your call capacity is.
Who pays for fraudulent calls on a UK VoIP account?
Typically the customer. Provider terms commonly make you responsible for all charges incurred through your account including unauthorised use, unless the provider was itself at fault — the calls were placed with your credentials, the provider has been billed by the carrying networks, and they had no way of knowing the calls were unauthorised. Goodwill reductions after incidents are common, particularly where the provider’s own monitoring might reasonably have caught it sooner, but they are discretionary and vary. Read your own contract; this is a question worth having answered before an incident rather than during one.
How much can toll fraud cost?
Typically between £8,000 and £40,000 for a single undetected weekend, and the figure is a function of your trunk concurrency multiplied by the length of the window rather than anything about your business. An attacker using every available channel continuously from Friday evening to Tuesday morning on a bank holiday accrues charges at a rate set by your own capacity. That is why organisations at the upper end of the range were not more attractive targets — they simply had more channels and a longer unwatched period.
What is the single most effective control?
Replacing open international dialling with an allowlist of the countries you actually call. About 62 per cent of systems we review can dial anywhere in the world, and almost none of those businesses call most of it. Restricting that removes most of the commercial value of compromising your system, takes minutes, and usually costs nothing. Use an allowlist rather than a blocklist, because a list of blocked fraud destinations is permanently behind the current pattern while a list of permitted countries is stable and defaults to safe.
Why does a spend cap matter more than better security?
Because it bounds the loss rather than reducing the probability. Perimeter hardening is necessary and will eventually be defeated by a reused credential, an unpatched handset or a leaver nobody removed. A hard spend cap that suspends outbound calling at a threshold means that when prevention fails, the loss has a known maximum. Only about 16 per cent of UK organisations have one. Check specifically whether yours suspends calling or merely sends an alert, because an alerting cap does not bound anything.
Why does toll fraud happen at weekends and overnight?
Because detection depends on somebody noticing, and the attacker’s return depends on duration. The longest uninterrupted window in a UK business calendar is a bank holiday weekend, so activity beginning on a Friday evening may run for eighty hours before anyone looks. This has two practical implications: out-of-hours restrictions on outbound dialling are disproportionately effective, and alerting only counts if it reaches a person who is not at work. Twenty-one per cent of organisations have alerting; about 9 per cent have alerting that functions at two in the morning.
How should extension credentials be set?
As machine credentials rather than user passwords. No human types an extension secret, so there is no usability case for making it short or memorable: use long random strings, unique per extension, stored wherever you keep other secrets, and regenerated when a handset is redeployed. The specific pattern to avoid is sequential or templated secrets across an extension range, which is a common installation shortcut and means that compromising one extension effectively compromises the whole set.
Is my hosted or cloud phone system already secure?
The provider operates and patches the platform and defends their own infrastructure, which is genuinely valuable. What they generally do not do unprompted is decide which countries your business should be able to call, set a spend ceiling matching your risk tolerance, limit your concurrency, or configure alerting to reach your staff out of hours. Those are customer-side settings on almost every hosted platform, and the defaults are permissive. Ask specifically which have been applied to your account rather than assuming the service category implies them.
How serious is the risk of calls being intercepted?
Technically real and considerably less likely than fraud. Traditional SIP signalling and media streams are unencrypted by default, so an adversary with a position on the network path can capture and reassemble a conversation. The difference is the precondition: interception needs network position — the same local network, compromised infrastructure in between, or an untrusted segment — while fraud needs only a guessable credential on an internet-facing service. Prioritise interception where conversations are themselves sensitive, where staff work over networks you do not control, or where a contract or regulator requires encryption.
What encryption should we be using for voice?
TLS for the signalling and SRTP for the media, which require support at both ends. Many UK providers support both, and a good number of deployments have them available and not enabled because switching them on was not part of the installation checklist. Ask your provider two questions: is encryption supported on our service, and is it currently active on our configuration? The second usually produces the more interesting answer. Treat it as mandatory rather than advisable where call content is sensitive.
Does cyber insurance cover fraudulent call charges?
Frequently not, and this should not be assumed either way. Telephone fraud is often treated as distinct from cyber loss and may be excluded, sublimited, or available only as a specific extension sometimes described as telephone hacking. Where cover exists it will carry conditions, commonly concerning the security controls you were required to maintain — which brings destination restrictions and credential hygiene in as a condition of a claim rather than merely good practice. Ask your broker in writing whether the policy responds, to what limit and subject to what conditions, and keep the answer with the policy.
What should we ask a VoIP provider at procurement?
Four things that rarely appear on a tariff comparison. Can you apply a hard monthly spend cap that suspends outbound calling, and at what level? Can you restrict dialling to a specified list of countries, differentiated by user group? What fraud monitoring do you perform, what does it alert on, where does the alert go and how quickly will you act out of hours? And what does the contract say about charges arising from unauthorised use, including whether any liability cap or fraud protection is available? Ask these while you have leverage; a provider willing to commit to a cap and a monitoring response is offering something materially different from one that will not.
Related reading
More guidance on securing, buying and governing UK business communications and IT:
Know what a bad weekend could cost you
Cloudswitched reviews what your phone system is permitted to dial, what that could cost before anyone notices, and what your contract says about who pays — then applies the destination, spend and alerting controls that cap it.
Talk to a VoIP Specialist