Registration for Britannic's Annual Summit is now open!

Register Now!

*Updated 14 September 2026*

Toll fraud is no longer just a legacy phone system problem.

Enterprise voice now spans SIP trunks, cloud communications, Microsoft Teams, contact centres, mobile clients, remote users and traditional PBXs. Every connection, account, routing rule and permission can potentially create another route for unauthorised calling if it is not controlled correctly.

This becomes particularly important as UK organisations continue moving from traditional PSTN services towards IP-based communications ahead of the January 2027 PSTN retirement.

Moving to SIP or cloud calling can provide significantly greater control, resilience and visibility. It does not automatically remove fraud risk.

The security model needs to move with the technology.

The Communications Fraud Control Association reported global telecommunications fraud losses of $41.82 billion in 2025, increasing from $38.95 billion in 2023.

For businesses, the priority should therefore be to prevent fraudulent calls before significant charges can accumulate rather than relying on someone noticing an unusual bill afterwards.

What Is Toll Fraud?

The short answer

Toll fraud is the unauthorised use of an organisation's telecommunications services to generate calls, messages or other chargeable traffic.

Attackers commonly target expensive international, premium-rate or revenue-sharing destinations where repeated traffic can generate financial returns.

Toll fraud is also known as dial-through fraud, PBX fraud or VoIP fraud depending on how the attack is carried out.

The National Cyber Security Centre warns that attackers can exploit poorly configured PBX systems using weaknesses such as default passwords, open SIP ports and inadequate firewall controls. Once access is obtained, expensive destinations can be called hundreds or thousands of times.

The principle now applies more broadly across modern enterprise communications.

An attacker does not necessarily need physical access to a traditional PBX. Compromised user accounts, administrator credentials, SIP services, forwarding rules and cloud communications configurations can all become potential attack routes.

Why Is Toll Fraud Still A Risk With Cloud Communications?

Moving telephony into the cloud changes the threat surface rather than eliminating it.

A traditional PBX attack may focus on exposed ports, voicemail or physical infrastructure. A modern communications attack can also target identities, accounts, permissions, applications and configuration.

Environment Potential Toll Fraud Risk
Traditional PBX Default passwords, remote access, voicemail exploitation and incorrect call barring
IP PBX
Exposed SIP services, weak credentials, insecure firewall rules and unpatched software
SIP trunking Unauthorised traffic, compromised endpoints, routing misuse and excessive call volumes
Cloud UC Account takeover, excessive permissions and configuration changes
Microsoft Teams calling
Compromised identities, calling permissions and Direct Routing configuration
Contact centre Dialler misuse, compromised agent accounts and outbound routing
Hybrid environment
Inconsistent policies between legacy, cloud and SIP systems

The security controls therefore need to follow the complete voice environment rather than being applied to one PBX or platform.

How Does Toll Fraud Happen?

Toll fraud usually involves an attacker finding a way to place calls through an organisation's communications environment without authorisation.

Common routes include:

  • Default or weak administrative passwords
  • Compromised user credentials
  • Exposed SIP ports
  • Incorrectly configured firewalls
  • Unsecured remote access
  • Unpatched PBX or VoIP systems
  • Compromised voicemail accounts
  • Call forwarding or transfer functionality
  • Overly broad international calling permissions
  • Unused extensions or dormant accounts
  • Poorly controlled administrator access
  • Inadequate monitoring of unusual call patterns

The NCSC specifically recommends restricting premium-rate, personal and unnecessary international destinations and considering restrictions on out-of-hours calling.

These controls are important because toll fraud can develop quickly.

A compromised account that can make unrestricted international calls throughout a weekend creates considerably greater exposure than an account limited to the destinations it genuinely needs.

What Are The Warning Signs Of Toll Fraud?

Toll fraud is easier to contain when unusual behaviour can be identified quickly.

Potential warning signs include:

  • Sudden increases in international calls
  • Unexpected premium-rate traffic
  • Large volumes of calls outside normal working hours
  • Repeated short-duration calls
  • Long-duration calls to unusual destinations
  • Unusual call forwarding
  • Calls from dormant extensions or accounts
  • Rapid increases in call spend
  • Unexpected changes to routing or permissions
  • Authentication attempts from unusual locations
  • High volumes of calls to a small number of destinations

The NCSC recommends monitoring call volumes and patterns and retaining appropriate logs to support investigation following a security incident.

Waiting for the monthly telephone bill is no longer an adequate fraud detection strategy.

What Is Britannic's Five-Layer Toll Fraud Prevention Framework?

Britannic recommends approaching enterprise voice fraud through five connected layers.

Layer Key Question Recommended Action
1. Restrict What calls genuinely need to be permitted? Apply destination, user, time and spend restrictions
2. Secure Who can access and change the communications environment? Protect credentials, administrator access, SIP connections and endpoints
3. Detect Can unusual behaviour be identified quickly? Monitor calling patterns, volumes, destinations and thresholds
4. Block Can suspicious traffic be stopped automatically? Apply automated fraud controls, blacklists, whitelists and blocking rules
5. Review Are controls still appropriate as the environment changes? Regularly review users, routing, permissions, integrations and incidents

The sequence is important.

A business should not give every user unrestricted calling access and then rely on monitoring to detect misuse.

The strongest fraud controls reduce what an attacker can do before suspicious activity occurs.

How Can Call Restrictions Reduce Toll Fraud?

One of the simplest ways to reduce toll fraud exposure is to limit calling to what employees actually require.

For example, an organisation operating exclusively in the UK may have no reason for most employees to make calls to international or premium-rate destinations.

Restrictions can be applied according to factors including:

  • Destination
  • Country
  • Number type
  • Individual user
  • Department
  • Location
  • Time of day
  • Call volume
  • Cost
  • Business requirement

Higher-risk capabilities should only be enabled where there is a clear operational need.

The same principle applies to call forwarding and transfers.

The NCSC highlights that off-premise call forwarding can be abused to route calls towards international or premium-rate destinations.

How Can NetX Help Detect And Prevent Toll Fraud?

Britannic's NetX intelligent communications platform provides network-level visibility and control across enterprise voice.

NetX includes automatic toll fraud controls designed to identify suspicious activity and prevent excessive unauthorised calling.

These include:

  • Configurable fraud alerts
  • Automatic blocking thresholds
  • Destination blacklists
  • Destination whitelists
  • Inbound and outbound calling restrictions
  • Reporting and analytics
  • Role-based access controls
  • Visibility of calls and routes
  • Secure call routing
  • TLS signalling and SRTP media encryption

Because the controls sit at the network layer, they can support different communications environments including Microsoft Teams, Zoom, Mitel, Avaya, Cisco and contact centre platforms.

This is particularly valuable in hybrid estates where an organisation may operate several different voice platforms while using NetX as the common SIP and routing layer.

The objective is not simply to send an alert after suspicious traffic has occurred.

Thresholds and automatic controls can help stop abnormal activity before it develops into a much larger financial exposure.

Why Does Role-Based Access Matter For Enterprise Voice Security?

Fraud prevention is not only about controlling calls.

Organisations also need to control who can change the communications environment.

Administrator accounts may be able to alter:

  • Call routing
  • International calling permissions
  • Number destinations
  • Call forwarding
  • User permissions
  • Fraud thresholds
  • Business continuity routes

Giving more users administrative access than necessary increases risk.

Role-Based Access Control helps separate responsibilities so employees only receive the permissions required for their role.

Organisations should also remove dormant accounts promptly and continuously review privileged users.

The NCSC recommends Multi-Factor Authentication for PBX administrative access and continuously monitoring accounts for unused or unauthorised users.

How Should SIP Be Secured Against Toll Fraud?

SIP is a core part of modern enterprise communications, but it needs to be configured securely.

Businesses should consider:

  • Restricting SIP traffic to trusted IP addresses
  • Protecting administrative interfaces
  • Closing unnecessary ports
  • Applying strong authentication
  • Encrypting signalling and media where appropriate
  • Keeping PBX and endpoint software updated
  • Applying appropriate firewall controls
  • Monitoring unusual registration attempts
  • Reviewing external access
  • Segmenting telephony infrastructure where appropriate

The NCSC recommends locking PBX inbound and outbound traffic to trusted IP addresses and using TLS for signalling and SRTP for media streams in cloud and hosted environments.

NetX supports TLS and SRTP to help protect voice traffic while providing network-level fraud monitoring and routing controls.

Does The PSTN Switch-Off Change Toll Fraud Risk?

Yes, although not because digital communications are inherently less secure.

Openreach states that the UK PSTN will be retired in January 2027. Organisations still relying on traditional services therefore need to migrate affected communications onto digital alternatives.

That migration creates an opportunity to review voice security rather than simply recreating the old telephony environment using newer technology.

Businesses should ask:

  • Which numbers are still required?
  • Which users genuinely need external calling?
  • Who needs international calling?
  • Which legacy forwarding rules remain active?
  • Which unused extensions can be removed?
  • Who has administrative access?
  • Are SIP connections restricted?
  • Are fraud thresholds configured?
  • Are call patterns being monitored?
  • What happens when abnormal activity is detected?

A PSTN migration should therefore include a fraud and security review alongside number porting and connectivity planning.

What Is The Difference Between Toll Fraud And Caller ID Spoofing?

Toll fraud and spoofing are related communications security issues, but they are not the same.

Toll Fraud Called ID Spoofing
Uses communications services without authorisation Falsifies the number or identity displayed to the recipient
Often generates direct financial charges
Often supports impersonation or scams
Usually targets the organisation's calling environment Often targets trust in an organisation's identity
Requires controls around access, routing and spend Requires stronger call authentication and identity controls

This distinction is increasingly relevant because enterprise voice security is now about protecting both who can use the network and whether recipients can trust the identity displayed on a call.

Ofcom strengthened its guidance in July 2026 on calls originating overseas that imitate UK mobile numbers, building on previous measures targeting spoofed UK landline numbers.

Britannic's Branded Calls proposition also addresses the customer trust side of enterprise voice by helping organisations authenticate and identify legitimate outbound calls.

How Can Managed Services Strengthen Fraud Prevention?

Fraud controls can become ineffective if they are configured once and then forgotten.

Businesses change.

New locations open, employees leave, platforms are migrated, international operations expand and new contact centre applications are introduced.

Fraud prevention therefore needs ongoing governance.

Britannic's Intelligent Managed Services combine monitoring, maintenance, analytics, risk management and continuous optimisation across communications environments.

That can help organisations identify changes in call behaviour, maintain appropriate policies and review communications architecture as business requirements change.

The principle is simple.

Voice security should be actively managed rather than configured once at deployment.

What Should Businesses Include In A Toll Fraud Review?

A toll fraud assessment should look across technology, people, permissions and processes.

Toll Fraud Prevention Checklist

  • Identify every PBX, SIP trunk and cloud calling platform
  • Document all inbound and outbound voice routes
  • Review international calling permissions
  • Block unnecessary premium-rate destinations
  • Review call forwarding and transfer permissions
  • Remove dormant users, extensions and voicemail accounts
  • Change default passwords
  • Protect administrator accounts with stronger authentication
  • Restrict administrative privileges
  • Review remote access
  • Restrict SIP connections to trusted sources
  • Close unnecessary network ports
  • Apply appropriate firewall controls
  • Keep PBX and endpoint software patched
  • Enable TLS and SRTP where appropriate
  • Establish normal calling patterns
  • Configure call volume thresholds
  • Configure spend or destination limits
  • Set alerts for unusual out-of-hours activity
  • Use blacklists and whitelists where appropriate
  • Review call reports regularly
  • Keep logs for incident investigation
  • Test fraud alerts and blocking rules
  • Document responsibility for responding to fraud alerts
  • Review supplier responsibilities and contractual terms
  • Repeat the assessment after significant system changes

The NCSC also recommends clarifying responsibility for fraud within managed service contracts. Businesses should understand who is responsible if a configuration weakness is exploited and what protections their communications provider will apply.

What Should Businesses Do If Toll Fraud Is Detected?

Speed is critical once suspicious activity is identified.

Businesses should have a documented process that enables teams to:

  1. Block the affected route, account or destination
  2. Disable compromised credentials
  3. Stop unnecessary international or premium-rate calling
  4. Preserve call and authentication logs
  5. Identify when the suspicious activity began
  6. Review routing and configuration changes
  7. Determine which accounts or systems were compromised
  8. Contact the communications provider
  9. Reset affected credentials
  10. Review similar accounts and routes
  11. Document the financial and operational impact
  12. Update controls before restoring normal access

The incident should also trigger a wider review.

Stopping one fraudulent route without understanding how it was compromised can leave the same weakness available elsewhere.

How Can Businesses Build More Secure Enterprise Communications?

Toll fraud prevention should be designed into enterprise communications rather than treated as an additional feature.

Modern voice environments connect people, platforms, carriers, contact centres and cloud applications through increasingly flexible routing.

That flexibility creates significant operational value.

It also means businesses need clear controls over who can make calls, where traffic can go, who can change the environment and what happens when unusual behaviour appears.

Britannic recommends combining five principles.

Restrict what is unnecessary. Secure what is required. Detect what is unusual. Block what is suspicious. Review continuously.

NetX provides a common network layer for applying routing, visibility, resilience and fraud controls across different communications platforms, while Britannic's managed services can support ongoing governance and optimisation.

Organisations reviewing SIP, cloud communications or PSTN migration can book a complimentary meeting with Britannic to assess current voice routing, fraud controls and areas of unnecessary exposure.