security identity · stub
Responding to a suspected toll fraud incident
Verified 2026-10-01 · 57 sources · tier 1–5
Also known as toll fraud response.
Stub. This topic has 57 sources and no published article. The sources below are everything recorded so far.
So far, no summary has been generated for this topic. The sources below are everything recorded so far.
See also
Builds on
- Toll fraud prevention and voice security — Preventive hardening lives in voice-security-toll-fraud; this topic covers detection containment and evidence once fraud is suspected
Related
- Carrier escalation evidence packages — Carrier escalation packaging is covered there; this topic only records which call-record exports exist and how fast they age out
- Troubleshooting outbound call failures in Webex Calling — Outgoing call permission blocks applied during containment surface to users as outbound call failures
Referenced by
- Troubleshooting number port rejections — Port-out locks and port-out fraud protections (47 CFR 52.37) overlap with fraud response.
Sources
- 1The Communications Fraud Control Association estimated global telecommunications fraud losses at 38.95 billion US dollars in 2023, about 2.5 percent of telecom revenues and 12 percent more than in its 2021 survey.Telecommunications fraud increased 12% in 2023 equating to an estimated $38.95 billion lost to fraud. · Opening paragraphs of the press release · Checked 2026-10-01
- 2CFCA's 2023 survey release lists PBX fraud among the top five fraud methods, which together accounted for 51 percent of reported fraud.Telecommunications fraud increased 12% in 2023 equating to an estimated $38.95 billion lost to fraud. · Top fraud methods paragraph · Checked 2026-10-01
- 3With direct-inward-dial isdn under voice service pots, Cisco Unified CME routes incoming ISDN calls on the called number, and calls with no matching outbound dial-peer are disconnected with cause unassigned-number (1).Cisco Unified Communications Manager Express System Administrator Guide - Toll Fraud Prevention · Direct Inward Dial for Incoming ISDN Calls · Checked 2026-10-01
- 4Calls blocked by the toll-fraud check on Cisco Unified CME can be counted and logged using show voice iec description, voice statistics type iec, voice iec syslog, RADIUS accounting and the cCallHistoryIec SNMP object.Cisco Unified Communications Manager Express System Administrator Guide - Toll Fraud Prevention · Troubleshooting Tips / monitoring the internal error code 1.1.228.3.31.0 · Checked 2026-10-01
- 5Cisco Unified CME extends IP address trusted authentication to the line side (registering endpoints) from release 12.6, whereas trunk-side checking dates from 8.1.Cisco Unified Communications Manager Express System Administrator Guide - Toll Fraud Prevention · IP Address Trusted Authentication (feature information) · Checked 2026-10-01
- 6The dial-peer no-match disconnect-cause command makes Cisco Unified CME disconnect incoming ISDN calls that match no inbound dial-peer instead of falling back to default POTS behaviour.Cisco Unified Communications Manager Express System Administrator Guide - Toll Fraud Prevention · Disconnect ISDN Calls With No Matching Dial-peer · Checked 2026-10-01
- 7Cisco Unified CME blocks two-stage dialing on analog and digital FXO ports with no secondary dialtone under the voice-port, and such calls are disconnected with cause unassigned-number (1) when PLAR is not configured.Cisco Unified Communications Manager Express System Administrator Guide - Toll Fraud Prevention · Block Two-stage Dialing Service on Analog and Digital FXO Ports · Checked 2026-10-01
- 8In Cisco Unified CME 8.1 and later, IP address trusted authentication (ip address trusted authenticate) is enabled by default and checks incoming VoIP calls against the trusted IP address list.Cisco Unified Communications Manager Express System Administrator Guide - Toll Fraud Prevention · IP Address Trusted Authentication · Checked 2026-10-01
- 9On Cisco Unified CME, an incoming VoIP call from an untrusted IP address is disconnected with cause code call-reject (21), and internal error code 1.1.228.3.31.0 (TOLL_FRAUD_CALL_BLOCK) is recorded.Cisco Unified Communications Manager Express System Administrator Guide - Toll Fraud Prevention · IP Address Trusted Authentication; Troubleshooting / monitoring rejected calls · Checked 2026-10-01
- 10Cisco advises configuring CUBE to route only known number ranges or SIP URIs, and warns that catch-all destination patterns such as destination-pattern .T increase the likelihood of routing a fraudulent call.Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · Call Routing and Toll Fraud > Avoid generic dial-peer routing · Checked 2026-10-01
- 11The CUBE hardening guide recommends Call Admission Control limits on total calls, CPU, memory and bandwidth so that the device can detect and reject call spikes.Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · CUBE Threat Mitigation > Denial of Service (DOS) prevention · Checked 2026-10-01
- 12Where CUBE uses only SIP over TLS, the hardening guide recommends no transport udp and no transport tcp under sip-ua so the device stops listening for unsecured SIP on port 5060.Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · Transport Layer Security (TLS) and Public Key Infrastructure (PKI) > Disable Non-Secure SIP Ports · Checked 2026-10-01
- 13Cisco's CUBE hardening guide prefers silently discarding calls that fail the trusted-list check, because sending a response tells a scanning attacker that the device is listening for SIP.Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · Call Routing and Toll Fraud > Allow Connections from Trusted IPs (no silent-discard untrusted discussion) · Checked 2026-10-01
- 14On Cisco Unified Border Element, the ip address trusted list command under voice service voip defines the IPv4 and IPv6 addresses that are allowed to send inbound calls to the device.Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · Call Routing and Toll Fraud > Allow Connections from Trusted IPs · Checked 2026-10-01
- 15CUBE also builds dynamic trusted-list entries from dial-peer session targets and voice class server-group addresses, and show ip address trusted list displays the resulting list.Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · Call Routing and Toll Fraud > Allow Connections from Trusted IPs · Checked 2026-10-01
- 16For users who do not need international calling, Cisco recommends Unity Connection restriction tables that block all international numbers, so that a compromised mailbox cannot set up call transfers or fax delivery to an international number.Security Guide for Cisco Unity Connection Release 14 - Preventing Toll Fraud · Using Restriction Tables to Help Prevent Toll Fraud (international numbers bullet) · Checked 2026-10-01
- 17Cisco's Unity Connection security guide advises working with the telecommunications provider to restrict the collect-calling option on incoming phone lines where appropriate.Security Guide for Cisco Unity Connection Release 14 - Preventing Toll Fraud · Restricting Collect Calling Options · Checked 2026-10-01
- 18Cisco Unity Connection 14 ships default restriction tables with basic toll fraud restrictions for a dial plan whose trunk access code is 9, and Cisco says they should be adjusted to the organisation's own dial plan and international prefixes.Security Guide for Cisco Unity Connection Release 14 - Preventing Toll Fraud · Using Restriction Tables to Help Prevent Toll Fraud · Checked 2026-10-01
- 19Cisco recommends that every Unity Connection restriction table block calls to the international operator, for example trunk access code 9 followed by 00.Security Guide for Cisco Unity Connection Release 14 - Preventing Toll Fraud · Using Restriction Tables to Help Prevent Toll Fraud (international operator bullet) · Checked 2026-10-01
- 20When Unity Connection is integrated with two phone systems, its restriction tables must match both trunk access codes, so that blocking 900 under code 9 also means blocking 99900 under code 99.Security Guide for Cisco Unity Connection Release 14 - Preventing Toll Fraud · Using Restriction Tables to Help Prevent Toll Fraud (two phone system integrations bullet) · Checked 2026-10-01
- 21Cisco recommends restricting Unity Connection system transfers to destinations such as lobbies or conference rooms, blocking international operators and long distance numbers.Security Guide for Cisco Unity Connection Release 14 - Preventing Toll Fraud · Using Restriction Tables to Help Prevent Toll Fraud (system transfers bullet) · Checked 2026-10-01
- 22The Cisco Unified CM clusterwide service parameter Block OffNet to OffNet Transfer defaults to False, so external-to-external transfers are allowed until an administrator sets it to True.Feature Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1)SU3 - External Call Transfer Restrictions · External Call Transfer Restrictions > Configure the Block OffNet to OffNet Transfer service parameter · Checked 2026-10-01
- 23A Cisco Unified CM route pattern's Allow Device Override checkbox makes the system use the trunk or gateway call classification instead of the route pattern's own OnNet or OffNet classification.Feature Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1)SU3 - External Call Transfer Restrictions · External Call Transfer Restrictions > Configure route pattern call classification · Checked 2026-10-01
- 24Cisco Unified CM External Call Transfer Restrictions let administrators classify gateways, trunks and route patterns as OnNet or OffNet so that external calls cannot be transferred to external destinations.Feature Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1)SU3 - External Call Transfer Restrictions · External Call Transfer Restrictions > Feature overview · Checked 2026-10-01
- 25When Block OffNet to OffNet Transfer is True and a user tries to transfer a call over an OffNet gateway or trunk, the phone displays a message that the call cannot be transferred.Feature Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1)SU3 - External Call Transfer Restrictions · External Call Transfer Restrictions > Feature interactions / user experience · Checked 2026-10-01
- 26The FCC's 1992 alert describes attackers using computers to call a PBX and try random authorization codes until one works, and recommends using the maximum code length and changing codes frequently.Consumer Alert: Telecommunications Toll Fraud (Second in a Series), DA 92-728, 7 FCC Rcd No. 13 · PBX fraud section · Checked 2026-10-01
- 27The FCC's 1992 toll fraud consumer alert tells victims to contact their local and long-distance telephone companies immediately, including the carrier's security office, and law enforcement.Consumer Alert: Telecommunications Toll Fraud (Second in a Series), DA 92-728, 7 FCC Rcd No. 13 · Section on what to do if you are a victim (closing paragraphs) · Checked 2026-10-01
- 28The FCC's 1992 alert advises businesses to disable unused PBX components, consider disabling the system outside business hours, and ask vendors or carriers for international or country-specific call blocking.Consumer Alert: Telecommunications Toll Fraud (Second in a Series), DA 92-728, 7 FCC Rcd No. 13 · Recommendations for businesses list · Checked 2026-10-01
- 29The FCC's 1992 toll fraud consumer alert sets out no liability rule for PBX owners; the only liability figure it gives is the up-to-$50 calling-card limit under the Truth in Lending Act.Consumer Alert: Telecommunications Toll Fraud (Second in a Series), DA 92-728, 7 FCC Rcd No. 13 · Calling card section; whole document reviewed for PBX liability · Checked 2026-10-01
- 30In a suspected toll fraud incident on Webex Calling or Teams Phone, applying an international and premium block first and analysing records afterwards is sound, because the Teams usage report lags 24 to 48 hours behind and so cannot confirm the fraud quickly.inferredMicrosoft Teams PSTN usage report · Interpret the report > callout 2 (latency), combined with outbound restriction policy options · Checked 2026-10-01
- 31A Unity Connection deployment whose dial plan does not use 9 as the trunk access code is not effectively covered by the default restriction tables until they are edited.inferredSecurity Guide for Cisco Unity Connection Release 14 - Preventing Toll Fraud · Using Restriction Tables to Help Prevent Toll Fraud (default tables paragraph) · Checked 2026-10-01
- 32Because Block OffNet to OffNet Transfer defaults to False, a Unified CM cluster that never changed it allows inbound PSTN callers to be transferred back out to the PSTN, which is a standing exposure to check during a fraud investigation.inferredFeature Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1)SU3 - External Call Transfer Restrictions · External Call Transfer Restrictions (service parameter default) · Checked 2026-10-01
- 33On an IOS voice gateway an untrusted SIP source may either receive a call-reject or get no response at all, depending on release and on whether silent-discard untrusted is active, so a lack of any SIP response from the gateway is not evidence that it is unreachable.inferredCisco IOS Voice Command Reference - S commands - signal through srv version · silent-discard untrusted > Command Default, read with CME guide IP Address Trusted Authentication · Checked 2026-10-01
- 34A Teams Phone tenant that never assigned a restrictive dial-out policy has international PSTN calling open for every voice-enabled user, so containment on Teams needs an explicit policy grant, whereas Webex Calling locations block international calling unless an administrator opened it.inferredOutbound call restrictions - Audio Conferencing & PSTN calls - Microsoft Teams · Introductory paragraph (defaults) · Checked 2026-10-01
- 35The CUBE command silent-discard untrusted is enabled by default and discards SIP requests from untrusted sources on an incoming SIP trunk.Cisco IOS Voice Command Reference - S commands - signal through srv version · silent-discard untrusted > Command Default · Checked 2026-10-01
- 36silent-discard untrusted is configured in the sip submode of voice service voip.Cisco IOS Voice Command Reference - S commands - signal through srv version · silent-discard untrusted > Command Modes · Checked 2026-10-01
- 37The silent-discard untrusted command was introduced in Cisco IOS 15.3(3)M and Cisco IOS XE 3.10S, and YANG model support for it was added in IOS XE Cupertino 17.7.1a.Cisco IOS Voice Command Reference - S commands - signal through srv version · silent-discard untrusted > Command History · Checked 2026-10-01
- 38By default, Microsoft Teams outbound call controls allow both international and domestic calls, for audio conferencing dial-out as well as end-user PSTN calls.Outbound call restrictions - Audio Conferencing & PSTN calls - Microsoft Teams · Introductory paragraph above the controls table · Checked 2026-10-01
- 39The Teams dial-out policy instances that disable PSTN calling, such as tag:DialoutCPCandPSTNDisabled, still allow emergency calls.Outbound call restrictions - Audio Conferencing & PSTN calls - Microsoft Teams · Using PowerShell > policy overview table, PSTNDisabled rows · Checked 2026-10-01
- 40The Teams End-user PSTN calls control offers International and Domestic (default), Domestic, or None, and the audio conferencing control offers Any destination, the organiser's country or region, Zone A only, or Don't allow.Outbound call restrictions - Audio Conferencing & PSTN calls - Microsoft Teams · Controls table (Control / Description / Control options) · Checked 2026-10-01
- 41The Teams Direct Routing usage report shows per-call SBC FQDN, final SIP code, final Microsoft subcode and correlation ID, and call types including dr_out_user_transfer and dr_out_user_forwarding.Microsoft Teams PSTN usage report · Interpret the report > Direct Routing callout 5 · Checked 2026-10-01
- 42Teams PSTN usage exports reach back up to one year for Calling Plans and up to 150 days for Direct Routing, subject to country-specific retention rules.Microsoft Teams PSTN usage report · Exporting the reports > Exported PSTN usage report; Exported Direct Routing usage report; Data retention table · Checked 2026-10-01
- 43Granting a Teams dial-out policy with -Global affects only users with no dial-out policy assigned; users who already hold a per-user policy keep it.Outbound call restrictions - Audio Conferencing & PSTN calls - Microsoft Teams · Using PowerShell > Set the policy on the tenant level · Checked 2026-10-01
- 44The Teams OnlineDialOutPolicy cannot be customised; administrators assign one of its predefined instances with Grant-CsDialoutPolicy, per user with -Identity or tenant-wide with -Global.Outbound call restrictions - Audio Conferencing & PSTN calls - Microsoft Teams · Using PowerShell · Checked 2026-10-01
- 45In Teams PSTN and Direct Routing reports, the last three or four digits of external numbers are replaced with asterisks for organisations in certain countries such as Germany (3 digits) and France (4 digits).Microsoft Teams PSTN usage report · Phone number obfuscation table · Checked 2026-10-01
- 46For Calling Plans and Operator Connect, the Teams PSTN usage report shows per-call destination dialed, cost, currency, duration, a Domestic/International flag and a call type that distinguishes transfers (user_out_transfer) and forwards (user_out_forwarding) to PSTN.Microsoft Teams PSTN usage report · Interpret the report > Calling Plans callout 4 · Checked 2026-10-01
- 47The Teams PSTN usage report usually reflects a 24 to 48 hour latency from the time of call activity.Microsoft Teams PSTN usage report · Interpret the report > Calling Plans callout 2; Direct Routing callout 2 · Checked 2026-10-01
- 48Organisations on a Telstra calling plan see no call detail records in the Teams PSTN usage report and must get reporting from Telstra.Microsoft Teams PSTN usage report · Note under the introduction · Checked 2026-10-01
- 49Webex Calling can require authorization codes for restricted call types, with up to 1000 authorization codes per location.Outgoing call permissions for Webex Calling locations · Authorization codes section · Checked 2026-10-01
- 50Webex Calling digit patterns can allow or block matching numbers, and digit pattern settings take precedence over permissions by call type.Outgoing call permissions for Webex Calling locations · Digit patterns section · Checked 2026-10-01
- 51In Webex Calling outgoing call permissions, the International call type defaults to Block, with transfers and forwards to it disabled.Outgoing call permissions for Webex Calling locations · Call types and default settings table, International row · Checked 2026-10-01
- 52Webex Calling outgoing call permissions can be set for locations, users, workspaces and virtual lines.Outgoing call permissions for Webex Calling locations · Overview / permission entity levels · Checked 2026-10-01
- 54A locked Webex Calling voicemail box is recovered by resetting the PIN, which an administrator does in Control Hub under the user's Calling > Voicemail PIN > Reset Voicemail PIN.Unable to Disable WebEx Calling Voicemail Lock Time in Control Hub · Resolution · Checked 2026-10-01
- 55Webex Calling voicemail locks after three incorrect PIN attempts, and Control Hub cannot raise or disable that threshold.Unable to Disable WebEx Calling Voicemail Lock Time in Control Hub · Cause · Checked 2026-10-01
- 56A new Webex Calling voicemail PIN may not be the reverse of the current PIN or any of the user's last 10 PINs.Set or reset your voicemail PIN · PIN requirements list · Checked 2026-10-01
- 57A Webex Calling user voicemail PIN must be 6 to 30 digits and may not contain repeated patterns, the user's own extension or number, more than three identical consecutive digits, or more than three consecutive ascending or descending digits.Set or reset your voicemail PIN · PIN requirements list · Checked 2026-10-01
Documents
tier 1 standards and regulators
Consumer Alert: Telecommunications Toll Fraud (Second in a Series), DA 92-728, 7 FCC Rcd No. 13
tier 2 current vendor documentation
Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices
tier 2 current vendor documentation
Cisco IOS Voice Command Reference - S commands - signal through srv version
tier 2 current vendor documentation
Cisco Unified Communications Manager Express System Administrator Guide - Toll Fraud Prevention
tier 2 current vendor documentation
Feature Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1)SU3 - External Call Transfer Restrictions
tier 2 current vendor documentation
Microsoft Teams PSTN usage report
tier 2 current vendor documentation
Outbound call restrictions - Audio Conferencing & PSTN calls - Microsoft Teams
tier 2 current vendor documentation
Outgoing call permissions for Webex Calling locations
tier 2 current vendor documentation
Security Guide for Cisco Unity Connection Release 14 - Preventing Toll Fraud
tier 2 current vendor documentation
Set or reset your voicemail PIN
tier 2 current vendor documentation
Unable to Disable WebEx Calling Voicemail Lock Time in Control Hub
tier 5 independent technical research
Telecommunications fraud increased 12% in 2023 equating to an estimated $38.95 billion lost to fraud.
Cite this page
APA
WarmTransfer. (2026, October 1). Responding to a suspected toll fraud incident. WarmTransfer. https://warmtransfer.net/knowledge/toll-fraud-incident-response
BibTeX
@misc{warmtransfer-toll-fraud-incident-response,
title = {Responding to a suspected toll fraud incident},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/toll-fraud-incident-response},
note = {Verified 2026-10-01}
}