Home › VoIP › VoIP Security for SA Businesses: How to Protect Your Phone System from Fraud and Attacks
VoIP VoIP Phones AI Briefed

VoIP Security for SA Businesses: How to Protect Your Phone System from Fraud and Attacks

In this article, we will explore the various vulnerabilities that VoIP systems can face and provide best practices for protecting your business from security threats.

In brief: VoIP phone systems are increasingly targeted by fraudsters and hackers. South African businesses using hosted PBX or SIP trunking need to understand the specific attack types they face and the practical steps to prevent them — before an attack adds thousands of rands to their phone bill.

Why VoIP Security Matters More Than Ever

Voice over IP systems are software applications running on internet-connected servers — and like all internet-facing software, they are subject to attack. The motivation for attackers is typically financial: a compromised VoIP system can be used to make thousands of international calls at the victim’s expense, running up bills of R10,000 to R100,000+ before the fraud is detected.

South African businesses are attractive targets for international toll fraud rings because of SA’s relatively high call rates to certain international destinations and the prevalence of older, inadequately secured PBX systems. Attacks typically happen outside business hours — Friday nights and weekend mornings — when call traffic anomalies are less likely to be noticed quickly.

For telecoms resellers, VoIP security is both a service responsibility and a commercial risk. If a client’s system you installed is compromised and runs up a large fraud bill, the resulting dispute, reputation damage, and potential liability make prevention a strong business interest.

The Most Common VoIP Attack Types

SIP brute force: Attackers scan the internet for systems running SIP services (port 5060) and attempt to authenticate as registered extensions using dictionary attacks. Once they find valid credentials, they register their own device and start making calls. Most vulnerable: systems with weak extension passwords, default credentials, or no fail2ban protection.

Toll fraud / IRSF: International Revenue Share Fraud involves attackers routing calls to premium-rate numbers they control in countries like Somalia, Guinea, or parts of Eastern Europe. Each call generates revenue for the fraudster at the victim’s expense. A successful IRSF attack can generate hundreds of calls per hour to high-cost destinations.

Vishing (VoIP phishing): Attackers use spoofed caller IDs to impersonate banks, SARS, or other authority figures, using the professional appearance of a business number to make scam calls more convincing. Businesses can unknowingly become vectors for vishing if their outbound caller ID is spoofable.

DoS/DDoS against VoIP infrastructure: Flood attacks against SIP servers can knock phone systems offline. For on-premise PBX systems directly exposed to the internet, this is a real risk. Cloud-hosted systems in professional data centres have DDoS mitigation infrastructure that protects individual customers.

Eavesdropping: Unencrypted SIP traffic can be intercepted on untrusted networks. VoIP calls made over public WiFi without SRTP (Secure Real-time Transport Protocol) encryption can theoretically be recorded by a network observer. This is more relevant for mobile softphone users than office deployments on private networks.

Essential VoIP Security Measures for SA Deployments

Strong Authentication

Every SIP extension and trunk must use strong, unique passwords — not the default credentials and not common patterns like “1234” or “extension number + 1234”. Modern VoIP platforms including 3CX and Yeastar P-Series automatically generate strong random passwords for new extensions. Never override these with simple passwords for convenience.

IP Restriction and Geoblocking

Configure your SIP trunk provider and PBX to only accept connections from known IP address ranges where possible. Most SA businesses only make calls to SA numbers or a small set of international destinations. Block all calls to high-risk international destination groups (West African countries, certain Caribbean nations) at the SIP trunk level unless they’re genuinely needed.

Fail2Ban / Intrusion Detection

3CX, Yeastar, and most professional PBX platforms include intrusion detection that automatically blocks IP addresses after a configurable number of failed authentication attempts. Ensure this is enabled and set to appropriate thresholds (e.g., 5 failed attempts = 24-hour block).

Call Cost Limits and Anomaly Alerts

Configure your SIP trunk provider to alert you when spend exceeds a daily or hourly threshold. Euphoria Telecom, Voxtelecom, and other SA providers offer configurable spend limits that cut off calling when a threshold is reached. A R500 daily limit may not suit a high-volume call centre but is appropriate for a 10-person SME that makes only local calls.

Disable International Calling by Default

Most SA SMEs don’t need unrestricted international calling. Configure the PBX to block all international calls by default, with specific international destinations enabled only for extensions that genuinely need them. International calling enabled on all extensions is the single biggest avoidable fraud risk in a VoIP deployment.

SRTP and TLS Encryption

For deployments where call privacy is important — healthcare, legal, financial services — enable SRTP for call media encryption and TLS for SIP signalling encryption. Both are supported by 3CX, Yeastar P-Series, and modern IP phones. This protects against eavesdropping on the call path.

Regular Password Audits

VoIP systems often have extensions that are no longer in use (departed staff, old conference rooms) but whose credentials remain valid. Disable unused extensions, rotate passwords annually, and audit the extension list against current staff. Orphaned extensions with weak passwords are easy targets.

What to Do if You Suspect an Attack

If you see unexplained international calls, very high call volumes outside business hours, or unexpected charges from your SIP trunk provider, act immediately:

  1. Block all international calling immediately at the PBX and SIP trunk level
  2. Change all SIP trunk passwords and extension passwords
  3. Review call logs to identify the compromised extension or access point
  4. Contact your SIP trunk provider — they can often flag fraudulent charges if reported quickly
  5. Notify your client — they may be entitled to file a police report for insurance purposes

What This Means for SA Telecoms Resellers

VoIP security should be part of every installation checklist, not an afterthought. Building a security configuration checklist that you apply to every deployment — strong passwords, geoblocking, spend limits, fail2ban — protects your clients and protects your reputation as a responsible reseller.

Consider including a brief security review in your managed service offerings: quarterly password rotation checks, extension audits, and confirmation that spend alerts are active. Clients who haven’t experienced an attack may not value this proactively, but they’ll appreciate it enormously if it prevents one.

Mechelle Gindra
Mechelle Gindra
Intelligence Team · South Africa

Mechelle Gindra is the managing editor and lead content strategist at Telecoms-Channel, South Africa's dedicated intelligence platform for telecoms resellers, ICT distributors, and channel partners. She oversees the editorial team's AI-assisted content production pipeline, ensuring vendor news, market analysis, and regulatory updates are accurate, timely, and actionable for the SA telecoms channel community. With deep expertise in the South African telecoms reseller ecosystem, Mechelle directs coverage of vendor partner programmes, ICASA regulatory developments, wholesale market dynamics, and channel business strategy. She is responsible for maintaining Telecoms-Channel's editorial standards, fact-checking processes, and corrections policy.