Three simple reasons VoIP abuse will grow

Cisco predicts more hackers will set their sights on Voice over IP. Three reasons why the technology is ripe for abuse

In its recent annual security report, Cisco predicted VOIP abuse as a potential area for cyber crime growth.

"Criminals use brute-force techniques to hack private branch exchange (PBX) systems to place fraudulent, long-distance calls; usually international," the report states. "These incidents, often targeting small or midsize businesses, have resulted in significant financial losses for some companies."

Also see VoIP security: The basics on

One of the most popular scams employed by VOIP-abusing criminals are vhishing schemes, which are telephone-based phishing ploys. The report points to one recent vhishing scam targeting the Federal Deposit Insurance Corporation. Vhishers called U.S. consumers on mobile and land-line phones to inform them they were delinquent in loan payments that had been applied for over the Internet or made through a payday lender. Criminals were able to collect personal information, such as Social Security numbers from victims, according to the report.

"What we've seen in the last couple of years is growing VOIP abuse around getting access to someone else system with baseline security hacks and then either using it for criminal purposes or selling it to other folks as long distance," said Patrick Peterson, Cisco fellow and chief security researcher."Some people have made money that way and some victims received huge telcom bills."

Peterson and Cisco technical manager Randy Birdsall explain why VoIP abuse has been on the upswing in recent years and appears poised for further growth.

It's widely deployed

According to market research firm In-Stat, almost 80 per cent of businesses will use Voice over Internet Protocol by 2013. And VoIP is in most enterprises in some fashion by now, according to Peterson. Whether it's fully deployed or still being tested, it's now pervasive, and therefore a target for criminals.

"Anytime there is a free, anonymous resource, criminals flock to it because that combination of free and anonymity is too good to be true," said Peterson. "What we've seen is an extraordinary increase in the last few years in the number of cracking attempts, and port scans, and attempts to log in with default admin passwords on various VoIP access points."

As VOIP has gained popularity, it's now a worthwhile endeavor from criminals because there is a large pool of potential victims to pull from. Birdsall said the concern among organizations using VoIP has changed, too.

"When I first started talking to companies a few years ago about VOIP security, the comments were 'Well, it's good to know it's available,'" he said. "Now the conversation is, 'We have had this incident happen. Now we want to know everything you can tell us so it doesn't happen again.'"

There are several ways to abuse it

While vhishing and SPIT (spam over internet telephony) get the most attention as VoIP problems, there are many ways criminals can take advantage of a VoIP network. Denial-of-Service attacks using VoIP technology are gaining popularity. In these attacks, criminals make the victims' phones ring constantly or sound busy.

"Organizations are deploying gateways that allow them to do SIP trunking to service providers as a way to save cost on telecom bills," explained Birdsall. "Now they are out on internet with a gateway that has the ability to do SIP trunking, and SIP is an open protocol. There is a lot that is known about that across the entire industry and that is a great thing. But it also allows more people to understand it to the point of manipulating it and using it doing things with it that are malicious."

Some of the other types of exploits Birdsall has seen include criminals routing calls through an organization's SIP trunk under the guise of being a telephony-service provider, therefore selling a service they never had to pay for. Criminals can also route their calls over the unsecured gateway to other sources, therefore bypassing long distance charges and international call charges.

"They can also redirect calls to 900 numbers, or other numbers that allow them to actually make money off of it," said Birdsall.

There is also the potential for hackers to breach your network and steal sensitive data using the gateway.

"One financial institution pulled me in when they noticed traffic coming from their product out to the internet. In that case, they (the criminals) had leveraged the IP-telephony network to gain access to a data path within their corporate enterprise. So the IP-telephony network was a way to get to the data side of things. That's another attack vector people may not have anticipated."

It's not well protected

"In a lot of mid-market organizations, VOIP systems are deployed to save money, but they dont have someone on staff who understands the security implications and knows what to look out for. They are leaving it wide open," said Birdsall.

Read more in Skype security: Is the popular VoIP service safe for business?

A VoIP network often shares the vulnerabilities of the operating system it runs on, yet the organization often fails to protect it with standard firewalls and security software. Many neglect to change the default manufacturer passwords that come with the system.

"Organizations deployed these systems several years ago and then just sort of forgot about security," said Peterson.

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags voiptelecommunicationCisco Systems

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Joan Goodchild

Show Comments

Cool Tech

Bang and Olufsen Beosound Stage - Dolby Atmos Soundbar

Learn more >

Toys for Boys

ASUS ROG, ACRONYM partner for Special Edition Zephyrus G14

Learn more >

Sony WF-1000XM3 Wireless Noise Cancelling Headphones

Learn more >

Nakamichi Delta 100 3-Way Hi Fi Speaker System

Learn more >

Family Friendly

Philips Sonicare Diamond Clean 9000 Toothbrush

Learn more >

Mario Kart Live: Home Circuit for Nintendo Switch

Learn more >

Stocking Stuffer

SunnyBunny Snowflakes 20 LED Solar Powered Fairy String

Learn more >

Teac 7 inch Swivel Screen Portable DVD Player

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Tom Pope

Dynabook Portégé X30L-G

Ultimately this laptop has achieved everything I would hope for in a laptop for work, while fitting that into a form factor and weight that is remarkable.

Tom Sellers


This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang


It really doesn’t get more “gaming laptop” than this.

Jack Jeffries


As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr


The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?