Is your business phone a security risk? A 2026 VoIP fraud guide
VoIP toll fraud can run up six figures over a single weekend. Three controls stop almost all of it. Here is how South African businesses lock the back door before the bill arrives.
Can a business VoIP phone really be a security risk?
Yes. If a VoIP system is not properly secured, criminals can hijack it and dial premium-rate or international numbers they own, leaving you with a bill that can reach hundreds of thousands of rands. The good news: three layers of defence, a fraud-monitoring provider, strong PINs and call barring, prevent almost every attack.
What VoIP toll fraud actually is
Toll fraud, also called PBX hacking, is when criminals get into your phone system and use your lines to call premium-rate or international numbers they profit from. You get the bill.
Once inside, attackers place thousands of automated calls to high-rate destinations they own, often over a weekend or public holiday to maximise the damage before anyone notices. It is not rare or hypothetical. The mechanism behind it, international revenue share fraud, accounted for an estimated US$6.23 billion of losses in 2023 alone, part of a US$38.95 billion global telecom-fraud total that grew 12% that year, according to the CFCA. PBX fraud sits among the most-reported methods worldwide.
The reason it is a growing problem in South Africa is simple: remote work and cloud phone systems have widened the attack surface, and businesses that rush to modernise often pick features and price over security, leaving a door open.
How a toll-fraud attack pays the criminal
Security is the new buying criterion
For years VoIP was sold on per-minute rates and call clarity. In 2026, a cheap service with no security is not a bargain; it is a liability waiting to happen.
You would not run your computers without a firewall and antivirus. Your phone system needs the same vigilance, because the cost of one breach dwarfs the monthly saving from the cheapest plan. Treat security protocols as the first thing you check on a provider, not the last.
The three controls that stop almost all of it
Securing a VoIP system is about layered defence, not complexity. These three actions block the overwhelming majority of toll fraud.
Red flags, and the safe action for each
Use this to spot the gaps in your current setup and fix them today.
| Common red flag | Essential safe action |
|---|---|
| Provider offers no security features, only low prices | Choose built-in, automated fraud detection and alerting |
| Default or simple PINs (e.g. 1234) on extensions and voicemail | Enforce strong, unique passwords and PINs for every user |
| Unrestricted international calling for all employees | Bar high-risk and unnecessary destinations by default |
| A surprisingly high bill at month end | Insist on real-time usage monitoring and threshold alerts |
| No plan for who to call during an incident | Set a security protocol; confirm the provider offers 24/7 fraud support |
A cheap VoIP service with no security is not a bargain. It is a liability waiting to happen.
WhichVoIP editorial view
Our verdict
Toll fraud is a real and present risk for South African SMEs, and it is preventable. The businesses that get burned are almost always the ones that bought on price alone and left default PINs and open international dialling in place. You do not need a security team to close those gaps; you need a provider that monitors for fraud and a few deliberate settings.
Compare VoIP providers on security, not just price
Get matched with South African providers that offer real-time fraud detection, call barring and usage alerts as standard.
Frequently asked questions
What is VoIP toll fraud?
How do I protect my business phone from fraud?
Why do toll-fraud attacks happen over weekends?
Is a cheaper VoIP provider less secure?
What should I do if I spot suspicious calls?
Keep reading
Sources: CFCA Global Telecommunications Fraud Loss Survey (2023, US$38.95bn total / US$6.23bn IRSF) and GLF Fraud Report 2024 (industry context); standard VoIP/PBX security practice. Verified 9 June 2026.