Skip to content

What is PBX Hacking?

← General

PBX (Private Branch Exchange) hacking is one of the most common — and costly — telecommunications threats facing businesses. In 2021, US enterprises reported $1.82 billion USD in losses related to telecom fraud, much of it tied to unauthorized PBX access, according to the Communications Fraud Control Association (CFCA).

A PBX is a private telephone system used within an organization to manage internal communications and connect to external phone networks through shared lines. While PBX systems reduce operating costs, they are also a frequent target for hackers who exploit weaknesses to place unauthorized international calls — billing the costs directly to the legitimate PBX owner.

Many businesses are unaware of the threat until they receive a surprise bill.

Attackers typically compromise a PBX by:

  • Guessing or brute-forcing weak voicemail PINs or admin credentials
  • Scanning for open SIP ports and exploiting default configurations
  • Targeting Direct Inward Dialing (DID) numbers to gain access to outbound calling

Once inside, hackers route calls to expensive international destinations. Revenue-sharing arrangements with fraudulent carriers mean the attackers profit from every minute of fraudulent call time.

  • Change default passwords — Replace all default credentials from your service provider. Default passwords are widely published in user manuals and online.
  • Use strong voicemail PINs — Avoid sequences like 1234, 0000, or PINs that match extension numbers. Change PINs regularly.
  • Restrict international dialing — Block outbound international calls at the PBX level unless required, and whitelist only the countries your business legitimately calls.
  • Limit failed login attempts — Configure your system to lock accounts after 3–5 failed password attempts on voicemail and admin interfaces.
  • Avoid publishing a full call directory — A public list of DID numbers gives attackers a map of targets.
  • Use secure VoIP transport — Deploy SIP over TLS (Transport Layer Security) to encrypt call signaling. Consider VPN access for remote SIP clients.
  • Use non-standard SIP ports — Moving away from the default port 5060 reduces exposure to automated port scanners.
  • Disable inactive accounts promptly — When an employee leaves, immediately disable their extension and close their voicemail account.
  • Monitor call detail records (CDRs) — Regularly review CDRs for unusual call patterns, especially after-hours international calls.
  1. Immediately restrict or disable outbound calling on affected extensions.
  2. Change all admin and voicemail credentials.
  3. Contact SIPSTACK Support to review call logs and assist with investigation.
  4. File a report with local law enforcement and your telecom provider.