Skip to main content
Serving businesses nationwide
Cannon VoIP Contact Us
Back to Learning Center
Learn · VoIP Security

VoIP Security: Encryption, Toll Fraud, and How Phone Systems Get Abused

Phone systems are computers now, and they get attacked like computers. The real threats, ranked, and what actually defends against them.

When phones became software, they inherited software's threat model. The good news: the defenses are mature and mostly someone else's full-time job on a hosted system. The bad news: the attacks are automated, constant, and aimed disproportionately at small businesses, because that is where unwatched phone systems live. Understanding the handful of real threats beats vague worry.

Toll fraud: the one that costs actual money

The dominant VoIP crime is boring and lucrative: attackers obtain calling access, by guessing SIP passwords, exploiting exposed PBXs, or compromising voicemail-based dial-through, then pump thousands of calls to premium international numbers they profit from, usually overnight on a weekend. Victims discover it as a five-figure phone bill. Defenses are equally unglamorous: strong unique SIP credentials, international calling disabled by default and enabled per-destination on request, rate limiting and anomaly alerts on calling patterns, and a provider whose fraud monitoring notices 400 calls to unusual destinations at 3 AM before Monday. Ask any prospective provider what happens in exactly that scenario; the quality of the answer tells you plenty.

What encryption actually covers

Two layers matter. TLS encrypts signaling, who is calling whom, registrations, credentials, so they cannot be read or tampered with in transit. SRTP encrypts the audio itself, closing the classic eavesdropping hole where anyone on the network path could reconstruct calls from raw packets. Together they make interception impractical in transit. What encryption does not cover: the endpoints, a compromised laptop hears the call regardless, and recordings at rest, which are governed by the provider's storage security and your own retention choices.

The human-layer attacks

  • Vishing (voice phishing): attackers call staff impersonating banks, vendors, or IT, increasingly with AI voices. Defense is procedure, not technology: callbacks to known numbers for any request involving money or credentials.
  • Caller ID spoofing against you: your number displayed on scam calls you never made; the response playbook is in its own guide.
  • Voicemail PIN attacks: default and trivial PINs let attackers harvest messages or exploit dial-through features. Enforce real PINs and disable features nobody uses.
  • Admin account takeover: the portal that controls routing is the crown jewel; unique passwords and two-factor where offered, always.

A hardening checklist for the office side

Most residual risk on a hosted system lives in the customer's own network and habits: change every default password (phones ship with admin interfaces too), keep phone firmware updated via the provider's provisioning, disable SIP ALG and unnecessary port forwarding on the router (also a reliability fix), put phones on their own VLAN in bigger offices, and audit quarterly: active extensions vs actual employees, forwarding targets, international permissions, who has portal access. Departed-employee extensions that still forward somewhere are both a security hole and a running joke in this industry.

Priority order for a small business: strong unique passwords everywhere, international dialing locked down by default, and a provider with real-time fraud monitoring. Those three cover the losses that actually happen.

Still have a question?

Real people answer our phones. Ask anything about business phone systems, no pitch attached.

Ask a human

Keep exploring

LEARN

Someone is spoofing my number

LEARN

One-way audio and router problems

RELATED

Security and compliance in practice