
A phone attack can start with a single compromised SIP account. An attacker gains access to outbound calling, routes traffic to expensive international or premium destinations, and the company only notices the problem once the bill spikes. For a call center, there's another scenario: an attack overloads the SIP server, leaving agents unable to receive customer calls.
The scale of the problem goes far beyond isolated attacks. The Communications Fraud Control Association estimated global telecom fraud losses at $38.95 billion for 2023. That's about 2.5% of the sector's worldwide revenue. Compared with the previous study, estimated losses grew by 12%.
For a business, these numbers translate into a very concrete task: access to telephony needs to be protected the same way as a CRM, corporate email, or payment systems.

Virtual PBX and SIP Trunk run over IP networks. Employees don't need to be near a physical PBX to access corporate telephony. That same feature also defines the security model. You need to control accounts, IP addresses, user permissions, routes, and traffic patterns.
CFCA lists PBX Fraud and Account Takeover among the leading telecom fraud methods. Together with Subscription Fraud and Service/Equipment Abuse, the top five categories accounted for 51% of the fraud issues recorded in the 2023 study.
With toll fraud, an attacker gains the ability to place calls through a company's phone system. From there, hundreds or thousands of calls can be launched to expensive destinations.
The problem is easy to miss if a company doesn't monitor the geography and timing of its outbound traffic. For example, a sales team works 9 AM to 6 PM and calls mainly five countries. A sudden 500 calls at 3 AM to a destination the team has never used should trigger a system response before the bill even arrives.
That's why fraud detection needs to work off specific deviations: call time, GEO, call frequency, duration, and sharp changes in traffic volume.
A compromised agent account and a compromised administrator account carry very different levels of risk. An agent typically needs access to calls and their own work data. An administrator can manage users, routes, and other system-level settings.
If every employee gets excessive permissions, compromising a single account opens up far more opportunities for an attack.
That's why access in a corporate PBX should be split by role. A manager works with their own calls, a supervisor gets the tools needed to oversee the team, and changing critical settings stays limited to a small circle of administrators.
In SIP telephony, signaling and voice are transmitted separately, so they use different protection mechanisms. TLS protects SIP signaling, while SRTP encrypts the voice stream.
DID Global supports TLS for SIP signaling and SRTP for voice traffic. At the SIP infrastructure level, geographic restrictions, suspicious-activity monitoring, and secure routing are also applied.

Telephony security is made up of several layers. Encryption doesn't compensate for a weak admin password, and a strong password won't help if a company has left unnecessary access to the SIP server wide open.
That's why configuration should be reviewed as a system, not as a set of individual features.
A SIP connection needs encryption for both signaling and the audio itself. TLS is used to protect SIP's service data, and SRTP protects the voice stream.
If a company handles financial, medical, or other confidential conversations, support for these protocols is worth checking at the stage of choosing a SIP provider.
A password can end up in an attacker's hands through phishing, credential reuse, or a leak from another service. Two-factor authentication adds another check before login.
2FA is most important first for accounts with access to critical settings. In parallel, shared administrative accounts should be eliminated. If five people use the same login, it becomes much harder to determine who changed a configuration and when, after an incident.
If a company only calls ten countries, there's no practical reason to leave every international destination open.
DID Global lets you apply geographic filters and restrict high-risk destinations. This limits the potential scale of toll fraud if credentials are compromised.
It's worth applying the same principle to access itself. If SIP connections should only come from specific IP addresses, a whitelist narrows the number of points from which the system can be reached.
Static configuration isn't enough. You need visibility into what's happening with your telephony after launch.
For a team with a normal load of 2,000 calls a day, a jump to 6,000 warrants a check. The appearance of a new international destination or mass calling during off-hours looks just as suspicious.
DID Global uses SIP traffic monitoring and analyzes atypical calls, sudden spikes, and geographic anomalies. For the client, this makes it possible to react to a changing pattern before anomalous traffic turns into a significant bill.
Telephony risks don't end once a call is over. A call recording can contain a name, phone number, order details, address, financial information, or other personal data. If a company stores thousands of such recordings, they become a separate data asset that access needs to be controlled for.
For companies working with customers in the EU, GDPR requirements come into play here as well.
The European Data Protection Board states directly that, when recording a customer's phone conversations, they must be informed about the purpose of the recording, who receives the recordings, their right to object, and their right to access the recording.
A company also needs to establish a lawful basis for processing personal data and collect only the data needed for the stated purpose.
In practice, this means call recordings shouldn't be kept "just in case." If a company has set a specific retention period, recordings need to be deleted once it expires, in line with internal policy and applicable legal requirements.
The same access rules should extend to backups. If the primary storage is protected by role-based access but a backup containing the same recordings is available to a wider group of employees, data control is effectively bypassed through the backup.

It's better to run this audit before a suspicious bill shows up or lines go down. For a first-pass audit, it's enough to go through the main access points and see which restrictions are already in place.
Check:
whether TLS is used for SIP signaling and SRTP for voice;
whether administrative accounts are protected by 2FA;
how many employees have administrator rights;
whether SIP access is restricted by IP;
whether countries and destinations the company doesn't call are blocked;
whether rate limits are set;
whether sharp changes in call volume are logged;
who has access to call recordings;
how long recordings and backups are retained;
whether there's a response plan for detected fraud.
For example, if 50 agents work in a PBX, not all 50 need administrator access. If a business calls 8 countries, it's worth checking why the system allows dozens of other international destinations. These are exactly the kinds of settings that reduce the number of scenarios an attacker can exploit.
When choosing a provider, it's worth asking for specific answers on encryption, routing, access control, and fraud detection. The phrase "we take security seriously" doesn't explain what happens if hundreds of calls to an atypical international destination start from a single SIP account at 3 AM.
DID Global's SIP Trunk supports TLS and SRTP, secure routing, geographic restrictions, and anomalous traffic monitoring. SIP Trunk also has no fixed limit on the number of channels, so configuration can be built around the company's actual load.
At the same time, part of the responsibility stays with the business. The company decides who gets administrative access, how employees work with their accounts, who can listen to recordings, and what data needs to be retained.
Before connecting or migrating your telephony, share your current PBX configuration, number of users, working GEOs, and call recording requirements with the DID Global team. This makes it possible to define the necessary restrictions, encryption, and routing right away, instead of leaving basic security settings for the "after launch" stage.

A phone attack can start with a single compromised SIP account. An attacker gains access to outbound calling, routes traffic to expensive international or premium destinations, and the company only notices the problem once the bill spikes. For a call center, there's another scenario: an attack overloads the SIP server, leaving agents unable to receive customer calls. The scale of the problem goes...

A company on physical lines pays for more than just call minutes. The bill also includes channel leasing, PBX maintenance, connecting each new workstation, and separate rates for every country of presence. A single PRI channel typically supports 23 voice channels. By market estimates, its monthly cost can run around $300–800 per location, depending on the carrier, region, and contract terms. The...

A digital agency launches advertising for a client in a new GEO, an integrator sets up CRM and telephony, or a consultant helps a company establish a sales team abroad. The same need arises in each scenario: the client requires local phone numbers and call infrastructure. Through the DG Partners affiliate program, an agency can refer the telecom side of the project to DID Global and earn up to 7%...