VoIP Security

Is your business phone a security risk? A 2026 VoIP fraud guide

VoIP toll fraud can run up six figures over a single weekend. Three controls stop almost all of it. Here is how South African businesses lock the back door before the bill arrives.

$38.95bnlost to telecom fraud, 2023
Weekendswhen toll fraud usually strikes
3 controlsstop almost all of it
Bar by defaultblock high-risk destinations

The short answer

Can a business VoIP phone really be a security risk?

Yes. If a VoIP system is not properly secured, criminals can hijack it and dial premium-rate or international numbers they own, leaving you with a bill that can reach hundreds of thousands of rands. The good news: three layers of defence, a fraud-monitoring provider, strong PINs and call barring, prevent almost every attack.

0
USD lost to telecom fraud, 2023
0
USD lost to IRSF toll fraud, 2023
0
of operators hit by high IRSF volumes
0
controls that stop most attacks
A South African Business Owner Reviewing An Unexpectedly Large Phone Bill On A Laptop At Night
Toll-fraud attacks are timed for weekends and public holidays, so the damage is done before anyone checks the account.

What VoIP toll fraud actually is

Toll fraud, also called PBX hacking, is when criminals get into your phone system and use your lines to call premium-rate or international numbers they profit from. You get the bill.

Once inside, attackers place thousands of automated calls to high-rate destinations they own, often over a weekend or public holiday to maximise the damage before anyone notices. It is not rare or hypothetical. The mechanism behind it, international revenue share fraud, accounted for an estimated US$6.23 billion of losses in 2023 alone, part of a US$38.95 billion global telecom-fraud total that grew 12% that year, according to the CFCA. PBX fraud sits among the most-reported methods worldwide.

The reason it is a growing problem in South Africa is simple: remote work and cloud phone systems have widened the attack surface, and businesses that rush to modernise often pick features and price over security, leaving a door open.

How a toll-fraud attack pays the criminal

Weak PIN / exposed PBX Lines hijacked, auto-dialled Premium / intl numbers they own You pay the bill

Security is the new buying criterion

For years VoIP was sold on per-minute rates and call clarity. In 2026, a cheap service with no security is not a bargain; it is a liability waiting to happen.

You would not run your computers without a firewall and antivirus. Your phone system needs the same vigilance, because the cost of one breach dwarfs the monthly saving from the cheapest plan. Treat security protocols as the first thing you check on a provider, not the last.

!
The trade-off that bites: the money saved on a no-frills VoIP plan is trivial next to a single weekend of toll fraud. Price the security in, not out.

The three controls that stop almost all of it

Securing a VoIP system is about layered defence, not complexity. These three actions block the overwhelming majority of toll fraud.

Choose a provider with built-in fraud detectionThe single most effective control. Modern systems learn your normal calling patterns and automatically block and alert on a sudden spike to a high-risk destination. Make real-time fraud detection a non-negotiable when you compare providers.
Enforce strong passwords and access controlThe most common entry point is a weak or default PIN on a voicemail box or extension. Never use 1234 or the extension number. Set strong, unique passwords everywhere and restrict admin access to essential staff only. On SIP trunks and self-hosted PBXs, harden the signalling layer too: attackers scan for open SIP ports (5060 for unencrypted SIP, 5061 for SIP over TLS), so use TLS where your provider supports it, enable IP-based authentication and disable any interfaces you do not use.
Configure international and premium-rate call barringMost teams never call high-risk destinations. Bar all international calls by default and whitelist only the countries you actually do business with. Ask your provider to close high-risk prefixes such as +882 and +881 as well, and set per-extension limits on international calls so a single compromised extension cannot run up the whole account. This one change removes a huge slice of the risk.
Bottom line: a fraud-monitoring provider, strong PINs and barring by default turn your phone system from a liability into a secured asset, at no real cost beyond a few configuration changes.

Red flags, and the safe action for each

Use this to spot the gaps in your current setup and fix them today.

Common red flag Essential safe action
Provider offers no security features, only low prices Choose built-in, automated fraud detection and alerting
Default or simple PINs (e.g. 1234) on extensions and voicemail Enforce strong, unique passwords and PINs for every user
Unrestricted international calling for all employees Bar high-risk and unnecessary destinations by default
A surprisingly high bill at month end Insist on real-time usage monitoring and threshold alerts
No plan for who to call during an incident Set a security protocol; confirm the provider offers 24/7 fraud support

A cheap VoIP service with no security is not a bargain. It is a liability waiting to happen.

WhichVoIP editorial view

An It Manager Configuring Call-Barring And Fraud-Detection Settings On A Voip Admin Dashboard
Most of the defence is configuration: fraud detection switched on, strong PINs enforced, and international calling barred by default.

Our verdict

Toll fraud is a real and present risk for South African SMEs, and it is preventable. The businesses that get burned are almost always the ones that bought on price alone and left default PINs and open international dialling in place. You do not need a security team to close those gaps; you need a provider that monitors for fraud and a few deliberate settings.

Our recommendation: make real-time fraud detection a non-negotiable in your provider shortlist, then bar international calling by default and reset every PIN this week. Do it before the next long weekend.

Compare VoIP providers on security, not just price

Get matched with South African providers that offer real-time fraud detection, call barring and usage alerts as standard.

Get VoIP quotes
Read the VoIP guide

Frequently asked questions

What is VoIP toll fraud?
Toll fraud, also called PBX hacking, is when criminals gain unauthorised access to your business phone system and use your lines to make large volumes of calls to premium-rate or international numbers they profit from. The business is left with the bill, which can reach hundreds of thousands of rands.
How do I protect my business phone from fraud?
Three controls stop almost all of it: choose a provider with built-in real-time fraud detection and alerting, enforce strong unique PINs and restrict admin access, and bar international and premium-rate calling by default with a whitelist for countries you actually do business with.
Why do toll-fraud attacks happen over weekends?
Attackers deliberately strike over weekends and public holidays because no one is watching the account, so they can place thousands of automated calls and run up the maximum bill before anyone notices and shuts it down.
Is a cheaper VoIP provider less secure?
Not always, but a provider that competes only on price and offers no fraud detection, monitoring or alerting is a liability. The saving on a no-security plan is trivial next to the cost of a single fraud incident, so treat security features as a core buying criterion.
What should I do if I spot suspicious calls?
Contact your provider immediately to suspend or bar the affected lines, change all relevant PINs and passwords, and review your call logs. Have a security protocol agreed in advance and confirm your provider offers 24/7 support for fraud incidents.

Keep reading

The South African business VoIP guide
Compare VoIP providers and get quotes

Sources: CFCA Global Telecommunications Fraud Loss Survey (2023, US$38.95bn total / US$6.23bn IRSF) and GLF Fraud Report 2024 (industry context); standard VoIP/PBX security practice. Verified 9 June 2026.

Now hiring Hire your AI receptionist