Voice Fraud & Compliance Wiki

    Fraud Types

    PBX Hacking

    Breaking into a business phone system or SIP trunk — usually through weak credentials or an exposed port — to place fraudulent outbound calls.

    Attackers scan the internet for SIP endpoints on port 5060, then brute-force extension passwords or exploit default credentials and unpatched software. Once inside they place high volumes of international calls, often overnight.

    Warning signs include registration attempts from unfamiliar IP ranges, sudden calls to destinations the customer has never dialed, and a spike in concurrent channels on a single trunk.

    Why it matters to carriers

    Your customer's compromised PBX becomes your fraud problem, because the traffic originates on your switch and appears in your settlement.

    Handling pbx hacking on your own switch

    SipShield scores live SIP traffic with patented AI so the controls behind this term run automatically — and leave the audit trail regulators expect.