Definition
In practice
How toll fraud actually works
The common entry points are weak SIP credentials, exposed PBX ports, default extension passwords, and poorly secured DISA.
The controls that actually work are spend caps, destination allow-lists, concurrent-call limits, and alerting on unusual patterns, not stronger passwords alone.
The exposure is asymmetric in a way that surprises people: the fraudster earns a share of the premium-rate revenue, so the incentive is volume rather than secrecy, and a compromised extension will place calls continuously until something stops it. Spend caps and concurrency limits matter more than detection, because detection arrives after the bill.
Worked example
Toll fraud: common questions
How does toll fraud actually happen?
Who pays for fraudulent calls?
How do you prevent toll fraud?
Sources
- Combating Spoofed Robocalls with Caller ID Authentication — Federal Communications CommissionThe STIR/SHAKEN framework, the attestation levels carriers sign calls with, and the mandate requiring providers to authenticate caller ID.
- 47 U.S.C. § 227 — Restrictions on the use of telephone equipment — Cornell Legal Information InstituteThe Telephone Consumer Protection Act itself — the consent requirements, calling-hours limits, and private right of action.
- ITU-T Recommendation E.164 — The international public telecommunication numbering plan — International Telecommunication UnionThe international number format, the 15-digit maximum, and how country codes and national numbers compose.
See toll fraud in the product
A hosted PBX is a business phone system that runs as software in a provider's data centre instead of a box on your premises. Handsets and softphones register to it over the internet, and capacity, extensions and numbers change in configuration rather than by an engineer visit.