Toll fraud happens when an attacker takes control of a phone system or SIP account and uses it to place calls the owner never intended, usually to expensive destinations. For a VoIP provider, a hijacked customer account can generate a large bill very quickly, often overnight or over a weekend.

How accounts get hijacked

Attackers scan the internet for exposed SIP services and try common or weak credentials. Once an extension or trunk registers, they send calls through it. Other routes in include reused or leaked passwords, misconfigured open trunks, and compromised customer devices. The calls often go to destinations that pay revenue share, which links toll fraud to IRSF.

Warning signs in call records

Steps providers can take

How Smart Gravity Shield approaches hijacked accounts

Because each customer is judged against their own history, a hacked account that starts calling a high-risk destination at 3 a.m. stands out even if its total volume is modest. Smart Gravity Shield scores the change, alerts your team and, where you allow it, can rate-limit or block the account. Whitelists protect trusted traffic, and everything is logged in an audit trail.

Common questions

Who pays for toll fraud?

This depends on the contract. Often the account holder is billed, but providers can end up absorbing losses or disputes, especially with wholesale upstream charges.

Can monitoring alone stop toll fraud?

Monitoring shortens the time before action, which limits the loss. Strong credentials, restricted destinations and spend limits reduce the chance of it starting.

This guide is general information, not legal or security advice. Fraud patterns change, and no detection system catches every case.