Skip to content
AI Dialer

Glossary · Voice technology

What is Toll fraud?

Reviewed by Sujan ThapaliyaLast updated

Definition

Toll fraud is the unauthorised use of a phone system to place expensive calls, typically to premium-rate international destinations that pay the fraudster a share of the revenue. Attacks usually run overnight and over weekends, and the bill lands on the account owner.
The three STIR/SHAKEN attestation levels, which underpin how toll fraud behaves in practice: A asserts both that the carrier knows the customer and that the customer may use the calling number, B asserts the customer only, and C asserts neither. A shared number pool can reach B at best, which is why number ownership keeps recurring in these definitions.
Attestation is the backdrop to most caller-ID and deliverability terms, toll fraud included.

In practice

How toll fraud actually works

The common entry points are weak SIP credentials, exposed PBX ports, default extension passwords, and poorly secured DISA.

The controls that actually work are spend caps, destination allow-lists, concurrent-call limits, and alerting on unusual patterns, not stronger passwords alone.

The exposure is asymmetric in a way that surprises people: the fraudster earns a share of the premium-rate revenue, so the incentive is volume rather than secrecy, and a compromised extension will place calls continuously until something stops it. Spend caps and concurrency limits matter more than detection, because detection arrives after the bill.

Worked example

The classic pattern is a weekend: a compromised extension places continuous calls to premium-rate international destinations from Friday night, and the bill is the first anyone hears of it on Monday.

Toll fraud: common questions

How does toll fraud actually happen?
An attacker gets into your phone system — a weak SIP password, a default voicemail PIN, an exposed DISA line — and places large volumes of calls to premium-rate destinations they profit from. It typically runs overnight and at weekends.
Who pays for fraudulent calls?
Usually the account holder. The calls were genuinely placed and genuinely carried, and most carrier contracts put that risk on the customer, which is why prevention matters more here than dispute.
How do you prevent toll fraud?
Strong per-device credentials, no default PINs, international destinations disabled unless needed, spend caps and concurrency limits, and alerting on unusual patterns. A prepaid wallet also caps exposure to whatever is in it.

Sources

  1. Combating Spoofed Robocalls with Caller ID AuthenticationFederal Communications CommissionThe STIR/SHAKEN framework, the attestation levels carriers sign calls with, and the mandate requiring providers to authenticate caller ID.
  2. 47 U.S.C. § 227 — Restrictions on the use of telephone equipmentCornell Legal Information InstituteThe Telephone Consumer Protection Act itself — the consent requirements, calling-hours limits, and private right of action.
  3. ITU-T Recommendation E.164 — The international public telecommunication numbering planInternational Telecommunication UnionThe international number format, the 15-digit maximum, and how country codes and national numbers compose.

See toll fraud in the product

A hosted PBX is a business phone system that runs as software in a provider's data centre instead of a box on your premises. Handsets and softphones register to it over the internet, and capacity, extensions and numbers change in configuration rather than by an engineer visit.