When people think about cyberattacks, they picture ransomware or stolen passwords on a computer. Phone systems are targets too. Toll fraud happens when an attacker gains access to your phone system or a voicemail box and uses it to place expensive calls, often to premium-rate or international numbers, at your expense. The first sign is frequently a surprise bill, or a carrier call about unusual usage.
Healthcare and senior-living organizations are not immune. Multiple locations, busy front desks and long-lived voicemail boxes provide plenty of openings. Fortunately, a short list of basic steps prevents most incidents.
Voicemail boxes often keep default or simple PINs such as 1234. An attacker who guesses a PIN can enter the box, and on some systems can use call-forwarding or call-out features to dial external numbers.
A phone system or gateway reachable from the internet with weak or default administrator credentials can be taken over. The attacker then routes calls through it, sometimes after hours or on weekends when nobody is watching.
A stolen extension password allows an attacker to register as your device and place calls. Cloud and software-based phones can be affected if account credentials are reused or exposed.
If every extension can dial any international or premium number, a single compromised account can generate huge charges. Lobby phones, unused extensions and fax lines are often forgotten.
Attackers sometimes use menu options, forwarding rules or transfer features to bounce calls out through your lines.
Require PINs of six digits or more, if the system allows it, and block obvious patterns such as repeated or sequential numbers.
Force a change from the default on first use.
Lock the box after a small number of failed attempts.
Remove unused voicemail boxes, including those of former employees.
Disable the ability to call out or transfer to external numbers from voicemail unless it is truly needed.
Review administrator accounts on your phone system, gateways and cloud phone portal. Replace defaults with strong, unique passwords, remove accounts nobody uses, and enable multi-factor authentication where offered.
Apply calling restrictions by extension type. For example:
Lobby, hallway and resident-area phones: local and emergency calls only.
Most staff extensions: domestic calls.
International calling: blocked by default, enabled for specific people who need it.
Premium-rate numbers: blocked entirely.
Ask your carrier or phone provider about blocking international or premium destinations account-wide.
Do not expose the phone system's administration page to the internet. If remote access is needed, use a VPN or other secure method. Make sure the firewall only allows the traffic your phone provider documents, and apply vendor updates and security patches.
Ask your carrier about usage alerts, daily call-cost caps and notifications for unusual traffic. These controls can turn a weekend-long fraud into a few minutes of nuisance.
Look at call detail records monthly, or have your provider do so. Warning signs include after-hours calls, repeated short calls to unusual countries, spikes in volume and calls from extensions that should be idle.
Analog lines for fax machines, elevators or alarms can also be abused. Include them in your inventory and restrict outbound dialing where possible.
If you suspect toll fraud:
Contact your phone provider immediately to block the destinations and suspend affected accounts.
Change administrator and affected user passwords and PINs.
Preserve call records for the carrier's investigation and for your insurer.
Review other systems for signs of broader compromise.
Report the incident to your insurance carrier, since some cyber and telecom coverage applies.
Ask your carrier early about its policy for fraudulent charges, because it varies.
Teach receptionists and nurses not to share voicemail PINs, to report odd call behavior and to flag voicemail messages that ask them to call back unfamiliar numbers.
UnityCare IT helps healthcare and senior-living organizations review phone system configurations, tighten calling permissions and coordinate with carriers. A one-hour review of PINs, calling rules and alerts can head off an expensive surprise.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172