MapleReceptionist

MapleReceptionist

MapleReceptionist Blog · August 28, 2026

Your Phone System Is a Server, and Someone Is Knocking

Toll fraud is not exotic. It is the ordinary result of an internet-reachable phone system with a weak extension password, and the resulting bill is usually the victim's to pay.

By Joel Gathercole, founder of Joel & Nanz Inc. (incorporated 2018) and MapleReceptionist (launched 2025). Building VoIP systems in Atlantic Canada since 2002.

The 60-second answer

Toll fraud happens when an internet-reachable phone system has weak extension passwords. Attackers place expensive calls overnight and the bill is usually yours. The controls are strong per-extension credentials, international dialling restricted by default, a spend cap at the carrier, and a platform someone actually patches.

The Monday morning problem

The pattern is consistent enough to be predictable. Fraud starts Friday evening and runs through the weekend, because that is when nobody is in the building and nobody reads a call log. By Monday there are thousands of minutes to destinations the business has never called, and a bill that is not in the budget.

What surprises people most is not the loss. It is the answer to who pays.

From your carrier's position, the calls were authorised. They came from your service, using your credentials. That is what "authorised" means to a billing system.

Some carriers will negotiate a portion as a goodwill gesture, especially where their own fraud detection should have caught an obvious pattern. That is a commercial conversation, not an entitlement, and it is a poor plan. The realistic strategy is prevention.

How they actually get in

Not through sophistication. Automated scanners sweep continuously for phone systems reachable from the internet, and once one responds they try common extension numbers — 100, 101, 200, 1001 — against common passwords, including the extension number itself. Federal guidance on credential strength exists precisely because this category of attack works so reliably [2].

Ranked by how often they are the cause:

  1. Weak or default extension passwords. The overwhelming majority. An extension secret equal to the extension number is functionally an open door.
  2. Unpatched software. Known vulnerabilities in unsupported versions, which is why baseline controls name supported software and applied patches explicitly [1].
  3. Voicemail PINs. Default or trivial PINs on boxes that permit outbound dialling or call-back.
  4. Over-permissive dial rules. A system that allows any extension to dial anywhere, which almost none of them need.
  5. Forgotten extensions. Departed staff, test accounts, the extension created for a contractor in 2021 [1].

The six controls that matter

Why hosted changes the shape of the risk

Hosted call control does not make credentials strong for you, and anyone claiming otherwise is selling badly. What it changes is structural.

First, there is no phone system inside your office network. An on-premise PBX that gets compromised sits on the same network as your file server and your accounting machine, which makes it a foothold as well as a billing problem. A hosted platform that is attacked is attacked somewhere else entirely.

Second, patching becomes someone's actual job rather than a task that competes with everything else. The most common security state for a small-business PBX is not "insecure" but "unattended," and unattended is where the two categories converge.

Third, the fraud-relevant defaults are set correctly at build time — international dialling off unless requested, generated credentials, no default PINs — rather than left at whatever the installer used in 2018.

What a compromised system looks like before the bill

Toll fraud is rarely silent. It produces symptoms for hours or days before anyone connects them to a cause, and the symptoms are usually reported as ordinary phone trouble.

Staff say the system feels slow, or that outbound calls fail with an all-circuits-busy message during the day. That is capacity exhaustion: your trunk has a fixed number of concurrent calls, and if a fraudster is consuming most of them, your own people cannot dial out. A business complaining that it cannot make calls is sometimes a business whose lines are fully occupied by someone else.

Other signals worth recognising: extensions registering from unfamiliar networks, a voicemail box that has been accessed at three in the morning, greetings that have been changed without anyone changing them, and a carrier fraud alert that got filed as spam. Any one of these on its own is ambiguous. Two together, over a weekend, is not.

The reason overnight and long-weekend timing dominates is simple arithmetic on the attacker's side. Fraud is profitable in proportion to how long it runs undetected, so it starts when detection is least likely. A business that checks its call log on Tuesday morning after a long weekend is checking at exactly the right moment, and it takes two minutes.

If it is happening right now

  1. Call your carrier and ask them to block international dialling immediately. This is faster and more reliable than anything you can change on the system, and it stops the loss growing while you work.
  2. Change every extension credential and every administrative password.
  3. Preserve the logs before anything is reset. They are the evidence for both the carrier conversation and any report.
  4. Identify what was reached. If voicemail was accessed, this is not only a billing incident — voicemail is personal information you are obliged to safeguard [5], and an assessment against breach-response guidance is the appropriate next step [6].
  5. Report it. Fraudulent use of a telecommunication facility is an offence under the Criminal Code [3], as is fraudulent unauthorized use of a computer system [4]. Reporting rarely recovers money, but it matters for insurance and for the carrier discussion.
  6. Then fix the cause, which is almost always item one on the list above.

The uncomfortable framing

It helps to stop thinking of a PBX as a phone system and start thinking of it as a server that happens to make calls. It runs software with a version number, it holds accounts with passwords, it stores recordings of customers talking about their private business, and in most small offices it is reachable from the internet so that someone can work from home.

Every expectation you would have of a server — patched, inventoried, credentialled, access-controlled — applies to it [1]. The reason toll fraud remains common is that almost nobody applies those expectations to the beige box in the closet.

Bottom line

Restrict international dialling, set a carrier spend cap, use strong unique extension credentials [2], remove departed staff promptly, and run software someone is patching [1]. If it has already happened, block internationally first and assess voicemail exposure as a possible privacy breach rather than a billing dispute [5][6]. The bill is usually yours, which makes prevention the only strategy that pays.

Frequently asked questions

What is toll fraud?

Someone gains access to your phone system and uses it to place calls at your expense, typically overnight or over a long weekend to international destinations that generate revenue for the fraudster. The calls are legitimate as far as your carrier is concerned, because they originated from your system with your credentials.

Who pays the bill?

Usually you. The calls were placed using your service and your authentication, so from the carrier’s position they were authorised. Some carriers will negotiate on a portion as a goodwill matter, particularly where fraud detection should have flagged the pattern, but there is no general entitlement to relief. This is why prevention matters more than recourse.

How do attackers get in?

Overwhelmingly through weak or default extension passwords on an internet-reachable system. Automated scanners sweep for phone systems continuously, then try common extension numbers against common passwords. Secondary routes are unpatched software with known vulnerabilities, and voicemail boxes with default PINs that permit outbound dialling.

Is a hosted PBX safer than one in my office?

Generally yes, for two structural reasons. There is no phone system inside your network to expose, so a compromise cannot pivot into your file server. And the platform is patched and monitored by someone whose job that is, rather than by whoever has time. It is not automatic safety — credentials still matter — but it removes the most common failure.

What are the warning signs?

Calls in your logs at times nobody works, destinations you have no business relationship with, a sudden rise in concurrent calls, staff reporting the system is slow or busy, or a carrier fraud alert. Most toll fraud runs overnight Friday to Monday precisely because nobody is watching.

What should I do first if I suspect it?

Contact your carrier immediately and ask them to block international dialling — that stops the bleeding faster than anything you can do on the system. Then change extension credentials, review who has administrative access, and preserve the logs. If voicemail may have been accessed, assess it as a potential privacy breach rather than only a billing problem.

Sources cited in this article

  1. 1. Canadian Centre for Cyber Security — Baseline cyber security controls for small and medium organizationsFederal baseline controls on patching, supported software, account management and device inventory — the controls an unmaintained PBX fails.
    https://www.cyber.gc.ca/en/guidance/baseline-cyber-security-controls-small-and-medium-organizations
  2. 2. Canadian Centre for Cyber Security — Best practices for passphrases and passwords (ITSAP.30.032)Federal guidance on credential strength, directly applicable to SIP extension secrets and voicemail PINs.
    https://www.cyber.gc.ca/en/guidance/best-practices-passphrases-and-passwords-itsap30032
  3. 3. Criminal Code (R.S.C., 1985, c. C-46), section 326 — theft of telecommunication serviceMakes fraudulent abstraction or use of a telecommunication facility or service an offence — the provision toll fraud falls under.
    https://laws-lois.justice.gc.ca/eng/acts/C-46/section-326.html
  4. 4. Criminal Code (R.S.C., 1985, c. C-46), section 342.1 — unauthorized use of a computerCovers fraudulent unauthorized use of a computer system, which is what a PBX is when someone registers to it without permission.
    https://laws-lois.justice.gc.ca/eng/acts/C-46/section-342.1.html
  5. 5. PIPEDA, Schedule 1 — Principle 7 (Safeguards)Requires safeguards appropriate to the sensitivity of personal information, including voicemail held on a phone system.
    https://laws-lois.justice.gc.ca/eng/acts/P-8.6/page-7.html
  6. 6. Office of the Privacy Commissioner of Canada — Responding to a privacy breach at your businessOPC guidance on assessing and reporting breaches, applicable if voicemail or call records are accessed.
    https://www.priv.gc.ca/en/privacy-topics/business-privacy/safeguards-and-breaches/privacy-breaches/respond-to-a-privacy-breach-at-your-business/gd_pb_201810/

All sources verified 2026-08-28. If a link has changed or you would like to suggest a correction, email support@mapleworksuite.com.

A maintained platform is a security control.

See hosted PBX pricing

Bilingual EN/FR. PIPEDA + PHIPA compliant. From $25 CAD/month. Month-to-month, no contract on Solo, Starter and Business tiers.

MapleReceptionist launched 2025 in Moncton, NB by Joel & Nanz Inc. (founded 2018).