PBX Toll Fraud (PBX Hacking / Toll Fraud)

Also known as: PBX Hacking

PBX toll fraud is a class of attack where an internet-exposed enterprise PBX or IP-PBX (typically via weak SIP registration, DISA misconfiguration or default credentials) is compromised and used to place high volumes of calls to premium-rate or international destinations, generating IRSF revenue for the attacker at the enterprise's expense. Losses are frequently discovered only on the next invoice cycle.

Categories: SignalingThreats and AttacksFraud

PBX Toll Fraud in context

Signaling protocols carry the control-plane messages that set up calls, register subscribers and route SMS. SS7, Diameter, GTP-C and SIP are the four dominant families, and interconnect exposure of any of them is treated by GSMA as top-tier telecom risk.

Telecom threats range from opportunistic SMS phishing and SIM swap to nation-state grade location tracking. The common thread is that most attacks exploit the inherited trust model of legacy signaling protocols.

To place PBX Toll Fraud in the wider telecom-security picture, review GSMA T-ISAC, Anomaly Detection, Artificial Traffic Inflation, Attack Surface Mapping, CLI Spoofing and DDoS — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.