PBX Toll Fraud: How It Works and How Credit Controls Stop It
Toll fraud is someone using your phone system to place calls you never authorized, usually expensive international ones, and leaving you the bill. Credit and call controls cap that exposure before it grows. ICTPBX limits how many calls a tenant can run at once and warns you when a prepaid balance runs low, so one compromised account can't drain the whole platform.For a multi-tenant PBX software platform, one compromised account should never put the whole system at risk. Per-tenant caps and credit alerts keep a single spike contained and give you time to react. This guide explains how toll fraud actually works, then shows the controls that limit the damage.
What toll fraud actually is
Toll fraud happens when an attacker gets access to an extension or trunk on your PBX and uses it to place calls that earn them money. The classic version is dialing premium-rate or international numbers that the fraudster controls, then collecting a share of the per-minute charge. You don't find out until the calls have already run, often overnight or across a weekend, and the bill can reach thousands before anyone notices.
Any internet-connected phone system is a target, open source or commercial, hosted or on-premise. Attackers scan for SIP endpoints around the clock. The question isn't whether they'll knock, it's how much they can take once they're in. That's why the goal is to cap the blast radius, not just hope the walls hold.
How attackers get into a PBX
Most toll fraud starts with a weak spot in how extensions are secured, not some deep exploit. The usual path looks like this:
- They scan for SIP. Automated tools sweep the internet for systems answering on SIP ports, then flag yours as a live target.
- They guess a password. Extensions with short or default passwords fall to brute-force attempts in minutes. Reused credentials leak the same way.
- They register an extension. Once a password gives, the attacker's software registers as that extension, exactly like a real phone would.
- They place calls fast. With a working registration, they fire off as many simultaneous calls as your system allows, aiming numbers that pay them.
Notice that the money is only made in the last step, and only if your system lets a single account run many calls at once. That's the point where a per-tenant limit changes the math.
The layers that keep toll fraud small
No single setting makes a phone system fraud-proof. You stack a few layers so that if one gives way, the next one still caps the loss. These are the practical ones for a multi-tenant PBX.
Strong, unique extension passwords
This is the front door. Long, random SIP passwords, never reused across extensions, defeat the brute-force step that most attacks depend on. It costs nothing and blocks the common case.Concurrent-call caps per tenant
Even if an account is compromised, a ceiling on simultaneous calls means the attacker can't flood your trunks. ICTPBX lets you set this cap per tenant, so a spike on one account stays that size.Prepaid credit and low-balance alerts
A prepaid balance is a hard financial stop: calls end when the credit does. ICTPBX warns you as a tenant nears its threshold, so a runaway pattern surfaces before it turns into a large bill.Watch your usage
Fraud shows up as an odd spike, calls at 3am, destinations you never dial, volume that doesn't match the tenant. The ICTPBX billing and usage screens put quota and credit in one view so those patterns stand out early.What you get with ICTPBX
ICTPBX bakes the containment layers into the platform, and you set them per tenant rather than one blanket rule for everyone.
Concurrent call caps
Set a ceiling on simultaneous calls per tenant. If credentials leak, an attacker cannot flood your trunks with traffic.Low-credit alerts
Get a warning before a tenant balance hits zero, so service does not stop without notice and runaway usage gets caught.Per-tenant limits
Each tenant carries its own caps and quotas, which keeps one account spike from affecting the rest of the platform.Clear usage view
The billing and usage screens show quota and credit at a glance, so you spot trouble early.Frequently asked questions
It's someone placing calls on your phone system without permission, usually expensive international or premium-rate numbers, so they earn money and you get the bill.
Toll fraud relies on placing many calls fast. A concurrent-call limit caps the damage even if an account is compromised, because the attacker can only run as many calls as your ceiling allows.
No. Fraud targets weak passwords and missing limits, not the license. A well-configured open source PBX with strong credentials and per-tenant caps is as safe as any commercial system.
It triggers as the balance approaches the threshold you set, giving you time to top up or to investigate why usage climbed.
Yes. You define caps and quotas for each tenant separately, so one account never affects the others.
Start with strong, unique SIP passwords on every extension, then set a concurrent-call cap and a prepaid credit limit per tenant. Those three cover the common attack from both ends.
The Billing and Usage pages show current quota use and credit balance for each tenant in one place.