The 60-second answer
Toll fraud happens when an internet-reachable phone system has weak extension passwords. Attackers place expensive calls overnight and the bill is usually yours. The controls are strong per-extension credentials, international dialling restricted by default, a spend cap at the carrier, and a platform someone actually patches.
The Monday morning problem
The pattern is consistent enough to be predictable. Fraud starts Friday evening and runs through the weekend, because that is when nobody is in the building and nobody reads a call log. By Monday there are thousands of minutes to destinations the business has never called, and a bill that is not in the budget.
What surprises people most is not the loss. It is the answer to who pays.
From your carrier's position, the calls were authorised. They came from your service, using your credentials. That is what "authorised" means to a billing system.
Some carriers will negotiate a portion as a goodwill gesture, especially where their own fraud detection should have caught an obvious pattern. That is a commercial conversation, not an entitlement, and it is a poor plan. The realistic strategy is prevention.
How they actually get in
Not through sophistication. Automated scanners sweep continuously for phone systems reachable from the internet, and once one responds they try common extension numbers — 100, 101, 200, 1001 — against common passwords, including the extension number itself. Federal guidance on credential strength exists precisely because this category of attack works so reliably [2].
Ranked by how often they are the cause:
- Weak or default extension passwords. The overwhelming majority. An extension secret equal to the extension number is functionally an open door.
- Unpatched software. Known vulnerabilities in unsupported versions, which is why baseline controls name supported software and applied patches explicitly [1].
- Voicemail PINs. Default or trivial PINs on boxes that permit outbound dialling or call-back.
- Over-permissive dial rules. A system that allows any extension to dial anywhere, which almost none of them need.
- Forgotten extensions. Departed staff, test accounts, the extension created for a contractor in 2021 [1].
The six controls that matter
- Restrict international dialling by default. Enable it only for extensions that demonstrably need it, and consider restricting to the specific countries you actually call. This single control caps the loss even if everything else fails, because the destinations that make fraud profitable become unreachable.
- Ask your carrier for a spend cap and fraud alerting. Most will set a daily threshold. It converts an unbounded exposure into a bounded one.
- Strong unique per-extension credentials. Long, random, never equal to the extension number, never shared between staff [2].
- Remove departed staff the day they leave. Extension, voicemail box and any administrative access, on the same checklist as the building key [1].
- Run supported, patched software. If your platform no longer receives updates, that is the finding, and it sets your timeline [1].
- Read the call log occasionally. Once a month, look at what happened between midnight and 6am. It takes two minutes and it is how most fraud is discovered before the bill arrives.
Why hosted changes the shape of the risk
Hosted call control does not make credentials strong for you, and anyone claiming otherwise is selling badly. What it changes is structural.
First, there is no phone system inside your office network. An on-premise PBX that gets compromised sits on the same network as your file server and your accounting machine, which makes it a foothold as well as a billing problem. A hosted platform that is attacked is attacked somewhere else entirely.
Second, patching becomes someone's actual job rather than a task that competes with everything else. The most common security state for a small-business PBX is not "insecure" but "unattended," and unattended is where the two categories converge.
Third, the fraud-relevant defaults are set correctly at build time — international dialling off unless requested, generated credentials, no default PINs — rather than left at whatever the installer used in 2018.
What a compromised system looks like before the bill
Toll fraud is rarely silent. It produces symptoms for hours or days before anyone connects them to a cause, and the symptoms are usually reported as ordinary phone trouble.
Staff say the system feels slow, or that outbound calls fail with an all-circuits-busy message during the day. That is capacity exhaustion: your trunk has a fixed number of concurrent calls, and if a fraudster is consuming most of them, your own people cannot dial out. A business complaining that it cannot make calls is sometimes a business whose lines are fully occupied by someone else.
Other signals worth recognising: extensions registering from unfamiliar networks, a voicemail box that has been accessed at three in the morning, greetings that have been changed without anyone changing them, and a carrier fraud alert that got filed as spam. Any one of these on its own is ambiguous. Two together, over a weekend, is not.
The reason overnight and long-weekend timing dominates is simple arithmetic on the attacker's side. Fraud is profitable in proportion to how long it runs undetected, so it starts when detection is least likely. A business that checks its call log on Tuesday morning after a long weekend is checking at exactly the right moment, and it takes two minutes.
If it is happening right now
- Call your carrier and ask them to block international dialling immediately. This is faster and more reliable than anything you can change on the system, and it stops the loss growing while you work.
- Change every extension credential and every administrative password.
- Preserve the logs before anything is reset. They are the evidence for both the carrier conversation and any report.
- Identify what was reached. If voicemail was accessed, this is not only a billing incident — voicemail is personal information you are obliged to safeguard [5], and an assessment against breach-response guidance is the appropriate next step [6].
- Report it. Fraudulent use of a telecommunication facility is an offence under the Criminal Code [3], as is fraudulent unauthorized use of a computer system [4]. Reporting rarely recovers money, but it matters for insurance and for the carrier discussion.
- Then fix the cause, which is almost always item one on the list above.
The uncomfortable framing
It helps to stop thinking of a PBX as a phone system and start thinking of it as a server that happens to make calls. It runs software with a version number, it holds accounts with passwords, it stores recordings of customers talking about their private business, and in most small offices it is reachable from the internet so that someone can work from home.
Every expectation you would have of a server — patched, inventoried, credentialled, access-controlled — applies to it [1]. The reason toll fraud remains common is that almost nobody applies those expectations to the beige box in the closet.
Bottom line
Restrict international dialling, set a carrier spend cap, use strong unique extension credentials [2], remove departed staff promptly, and run software someone is patching [1]. If it has already happened, block internationally first and assess voicemail exposure as a possible privacy breach rather than a billing dispute [5][6]. The bill is usually yours, which makes prevention the only strategy that pays.