Home › VoIP › The State of VoIP Security in South Africa: Key Threats and Defences for 2025
VoIP VoIP Phones AI Briefed

The State of VoIP Security in South Africa: Key Threats and Defences for 2025

In this blog post, we will discuss the current state of VoIP phone security in 2023. We will explore the opportunities, risks, and threats associated with using VoIP phones in the telecom industry, and provide tips for improving VoIP phone security.

In brief: VoIP security threats have evolved alongside the platforms themselves. South African businesses running hosted PBX and SIP trunking need to understand the current threat landscape and apply appropriate defences — the attacks that were theoretical in 2020 are now routine and automated in 2025.

Why VoIP Security Is a Growing Challenge

The shift from on-premise ISDN/PSTN telephony to IP-based VoIP has brought significant benefits — lower costs, more flexibility, better features — but also introduced telephone infrastructure to internet-native threats. In 2025, automated scanning tools continuously probe IP address ranges looking for exposed SIP services, and toll fraud attacks can be executed at scale with minimal human involvement.

For South African businesses, the specific risks include toll fraud (calls to premium international destinations), service disruption (DoS attacks on SIP servers), and eavesdropping on unencrypted call traffic. The financial consequences of a successful toll fraud attack — which can generate R50,000–R500,000 in fraudulent call charges over a weekend — are severe enough to threaten business continuity.

Current Threat Landscape: What’s Actually Happening in 2025

SIP Registration Attacks: Automated bots continuously scan port 5060 (the default SIP port) looking for PBX systems. When they find one, they attempt authentication against every extension using common username/password combinations. A 3CX or Yeastar system deployed without intrusion detection and exposed directly on port 5060 will typically see thousands of brute-force attempts per day from global bot networks.

The defence: change the default SIP port (use 5080 or a non-standard port), implement fail2ban with aggressive thresholds (3–5 failures = 24-hour block), and never expose SIP directly without a session border controller or robust firewall rules.

International Revenue Share Fraud (IRSF): Once a fraudster gains access to a SIP account or compromises a PBX, they route calls to premium-rate numbers in countries that pay them a revenue share for each minute completed. Somalia, Guinea, Latvia, Cuba, and specific Caribbean countries are commonly exploited. Automated systems can initiate hundreds of simultaneous calls once access is obtained.

The defence: geoblocking at both the PBX and SIP trunk level. Block all countries you don’t do business with. Most SA businesses only call SA numbers and a handful of international destinations (UK, USA, maybe Germany) — everything else should be blocked by default.

Vishing Campaigns Using Spoofed Caller IDs: Fraudsters use VoIP infrastructure to make calls with spoofed SA business numbers, impersonating banks, SARS, and law enforcement. While this doesn’t directly victimise VoIP system owners (unless their system is compromised), it damages the reputation of the spoofed number and can generate complaints that block the legitimate number on spam lists.

The defence: use only direct SIP trunk providers who implement STIR/SHAKEN or equivalent caller ID verification. Ensure your system doesn’t allow callers to set arbitrary caller IDs on outbound calls without verification.

Denial of Service Against SIP Servers: Direct UDP/SIP flood attacks against exposed PBX infrastructure can overwhelm small to medium servers, causing complete service outages. For on-premise systems, this can be particularly damaging. Cloud-hosted systems in professional data centres benefit from upstream DDoS mitigation.

The defence: for on-premise systems, implement a session border controller (SBC) as the internet-facing edge device, with the PBX on an internal network. SBCs (AudioCodes, Ribbon, Grandstream UCM — which includes basic SBC functions) absorb SIP attacks before they reach the PBX.

Platform-Specific Security in 2025

3CX Security: 3CX V20 includes built-in security features including automatic port blacklisting, intrusion detection, and the option to use SRTP+TLS for encrypted calls. The 3CX Cloud hosting model runs through 3CX’s infrastructure with additional DDoS protection. Key 3CX security configurations to verify: IP blacklisting enabled, extension passwords all auto-generated (not manually set to simple values), and international calling restricted to required destinations only.

Yeastar P-Series Security: Yeastar P-Series includes an auto-defence module that blocks IP addresses after failed authentication attempts. The P-Series also supports SRTP for encrypted call media and TLS for encrypted signalling. Yeastar’s cloud deployment option benefits from Yeastar’s managed infrastructure security.

FreePBX/Asterisk Security: Open-source FreePBX installations require more manual security attention than commercial platforms. Fail2ban configuration, firewall rules, and regular security updates require active management. Commercial FreePBX deployments (Sangoma PBXact) include more managed security features.

Building a VoIP Security Checklist

For resellers deploying VoIP systems, a standard security checklist applied to every installation provides baseline protection:

  1. Change default SIP port from 5060 to a non-standard port (5080–5099 range)
  2. Enable intrusion detection/fail2ban — 3 failures = block for 24 hours
  3. Set strong auto-generated passwords on all extensions — never use extension number, name, or “1234”
  4. Restrict international calling — block all international by default, enable only required destinations
  5. Configure spend alerts on SIP trunk — R200/day limit for most SMEs, higher for call centres
  6. Enable SRTP+TLS where supported and required (healthcare, legal, finance)
  7. Disable extensions of departed staff immediately on employee exit
  8. Place PBX behind SBC or firewall — don’t expose SIP services directly to the internet without protection
  9. Review and test security quarterly — check for failed login attempts in logs, verify spend limits are active

SIP Trunk Provider Security Features

Your SIP trunk provider is a critical line of defence. SA providers like Euphoria Telecom offer spend limits and traffic anomaly alerts. When evaluating SIP trunk providers for clients, include security features in the evaluation:

  • Does the provider offer configurable per-day spend limits?
  • Does the provider offer destination geoblocking at the trunk level?
  • Does the provider have automated toll fraud detection?
  • What is the provider’s response procedure when anomalous traffic is detected?
  • Does the provider offer trunk IP restriction (only accepting calls from known PBX IP addresses)?

What This Means for SA Telecoms Resellers

VoIP security responsibility follows the deployment. If you installed a client’s PBX, you are their first point of contact when something goes wrong — including a toll fraud attack. Making security part of your standard delivery (not an optional extra) protects your clients and protects your reputation.

Consider adding a security audit to your managed service offering: quarterly review of extension credentials, active IPs in blacklists, spend alert configurations, and firmware updates. Clients may not proactively request this, but they will value it retrospectively — especially the ones who haven’t yet experienced an attack. Framing security audits as “insurance against toll fraud” rather than a technical check makes the value proposition easy to communicate.

Mechelle Gindra
Mechelle Gindra
Intelligence Team · South Africa

Mechelle Gindra is the managing editor and lead content strategist at Telecoms-Channel, South Africa's dedicated intelligence platform for telecoms resellers, ICT distributors, and channel partners. She oversees the editorial team's AI-assisted content production pipeline, ensuring vendor news, market analysis, and regulatory updates are accurate, timely, and actionable for the SA telecoms channel community. With deep expertise in the South African telecoms reseller ecosystem, Mechelle directs coverage of vendor partner programmes, ICASA regulatory developments, wholesale market dynamics, and channel business strategy. She is responsible for maintaining Telecoms-Channel's editorial standards, fact-checking processes, and corrections policy.