Subscribe
  • Home
  • /
  • Telecoms
  • /
  • Euphoria Telecom removes risk of VOIP toll fraud

Euphoria Telecom removes risk of VOIP toll fraud


Cape Town, 26 May 2015

If your phone provider doesn't offer control mechanisms to help prevent fraudulent use of your VOIP account, you may want to look into using a different provider. Local telecoms provider Euphoria Telecom says international hackers are on the prowl, looking to hijack telephone systems and using them to place calls to premium charge-by-the-minute numbers.

Toll fraud is the compromising of a phone system to dial out to premium numbers in other countries at exorbitant rates. There are no laws protecting phone customers from international toll fraud and it is unlikely that insurance companies will cover this.

Euphoria Telecom CTO Conrad De Wet says there are numerous incidents in the industry where businesses are liable for amounts in excess of R50 000 due to toll fraud. "Onsite VOIP-based PBX systems running on unsecure networks are highly vulnerable to toll fraud. The more modern cloud-based VOIP systems can be just as vulnerable if not properly configured and managed by a team of highly skilled technicians with regard to both networks and PBXes."

Typically, a PBX provider would install a VOIP PBX on a company's local network, but would not implement a password policy and even make use of default values under the assumptions that security levels can be reduced because the installation is within the local network, resulting in a lack of proper security.

"A simple, brute force attack can leave the onsite PBX hacked. The PBX provider normally blames the network provider for a lack of network security. In smaller businesses, there is often no network company and the PBX is protected by a basic ADSL router. This is a sure recipe for toll fraud to occur; it's only a matter of time," he warns.

He says a common problem for cloud operators is that VOIP username and passwords are being e-mailed. "E-mail accounts are easily accessible as most of them work on unsecured protocols such as POP and SMTP, which pass usernames and passwords in plain text. These accounts are automatically hacked and searched for VOIP account details and then used in a case of toll fraud. With the correct credentials in hand, there is little administrators can do."

VOIP has all the problems inherent to the Internet, security and identity theft, phishing, viruses and malware. The use of automatic scripts, which attempt to register as a phone or trunk to a company's Internet-facing PBX in order to call premium numbers overseas, is a common form of toll fraud.

Other attacks include hacking voice messaging or voice mail systems for the information they contain, and compromising soft phone services - virtual lines set up for legitimate users - to eavesdrop on phone calls and make unauthorised calls on the compromised line.

"Euphoria solves the problem of eavesdropping by using VPN technology to ensure the calls cannot be accessed by packet sniffing while travelling on the open Internet," he adds.

Euphoria recently applied a major upgrade to its cloud PBX infrastructure to dramatically reduce the risks associated with toll fraud. This is part of the company's consistent development to offer a truly international class, secure and reliable cloud PBX service to South African businesses, a product that is built in South Africa.

Its VOIP-based cloud PBX phone system can be configured to restrict international calls on a granular level. Not only can one restrict specific extensions/users, but also restrict calls to specific countries on a per extension/user basis.

More importantly, one can configure extensions to allow or prohibit international calls. This way, one can allow international calls to those extensions/users that require it, but still block all the high-risk toll fraud countries and secure one's PBX even in the event where a SIP account is compromised.

"Euphoria Telecom also offers blacklist and white list functionality for extensions which can be set up as default or specific lists for specific extensions. We can limit the number of calls per extension/user on multiple levels," he explains.

Euphoria CEO George Golding says it is not uncommon for 100 simultaneous calls to be made in the case of toll fraud from the single compromised extension/user account. "We can set the maximum number of calls on a PBX level, on a local calls per extension level, and most importantly, we can limit the number of simultaneous calls internationally on a per extension level to prevent a large number of international calls being called from one extension in the event of toll fraud."

These newly available features can easily reduce the risk of toll fraud to zero; it provides customers with peace of mind when using Euphoria's cloud PBX services. Euphoria Telecom offers its customers full control over their telephone system; an easy-to-use Web interface allows them to configure the system to their specific requirement.

He says the system automatically monitors extension activity to pick up any out of the ordinary activity and to notify the customer and Euphoria Telecom. "If any suspicious activity is picked up, it will block international calls from the specific user/extension only, not the whole PBX. The customer can simply log-in and unblock the extension if the activity was legitimate, or contact Euphoria in the case of the extension being compromised."

"All of these security additions reduce the risk of bizarre telephone accounts, especially in the case of toll fraud. We want to help protect our customers and reduce the risk of toll fraud and, where possible, remove the risk entirely," he concludes.

For more information, contact Euphoria Telecom on (010) 593-4500 or e-mail sales@euphoria.co.za or visit www.euphoria.co.za.

Share

Euphoria Telecom (www.euphoria.co.za)

Euphoria Telecom is a provider of proprietary cloud PBX communication services for businesses in South Africa. The business was formed in 2010, after years of research and development towards a cloud-based PBX system that could effectively reduce overall costs significantly by doing away with expensive installation, training and support costs.

After three years of impressive growth, Euphoria Telecom offers a complete business communication solution that combines the characteristics of sophisticated PBX and call centre solutions with the ease and cost efficiency of cloud-based technology.

Euphoria Telecom is incorporated in South Africa with the corporate head office situated in Cape Town, South Africa. The company is owned 100% by the current management team, and the business is headed up by George Golding, Conrad De Wet and Rafal Janik.

The business has built up an impressive customer base approaching 1000 business customers.

Editorial contacts

Ivor van Rensburg
IT Public Relations
(082) 652 8050
ivor@itpr.co.za
George Golding
Euphoria Telecoms
(021) 200 0500
sales@euphoria.co.za