security identity · stub

Responding to a suspected toll fraud incident

Verified 2026-10-01 · 57 sources · tier 1–5

Also known as toll fraud response.

Stub. This topic has 57 sources and no published article. The sources below are everything recorded so far.

So far, no summary has been generated for this topic. The sources below are everything recorded so far.

See also

Builds on

Related

Referenced by

Sources

  1. 1
    The Communications Fraud Control Association estimated global telecommunications fraud losses at 38.95 billion US dollars in 2023, about 2.5 percent of telecom revenues and 12 percent more than in its 2021 survey.
  2. 2
    CFCA's 2023 survey release lists PBX fraud among the top five fraud methods, which together accounted for 51 percent of reported fraud.
  3. 3
    With direct-inward-dial isdn under voice service pots, Cisco Unified CME routes incoming ISDN calls on the called number, and calls with no matching outbound dial-peer are disconnected with cause unassigned-number (1).
    Cisco Unified Communications Manager Express System Administrator Guide - Toll Fraud Prevention · Direct Inward Dial for Incoming ISDN Calls · Checked 2026-10-01
  4. 4
    Calls blocked by the toll-fraud check on Cisco Unified CME can be counted and logged using show voice iec description, voice statistics type iec, voice iec syslog, RADIUS accounting and the cCallHistoryIec SNMP object.
    Cisco Unified Communications Manager Express System Administrator Guide - Toll Fraud Prevention · Troubleshooting Tips / monitoring the internal error code 1.1.228.3.31.0 · Checked 2026-10-01
  5. 5
    Cisco Unified CME extends IP address trusted authentication to the line side (registering endpoints) from release 12.6, whereas trunk-side checking dates from 8.1.
    Cisco Unified Communications Manager Express System Administrator Guide - Toll Fraud Prevention · IP Address Trusted Authentication (feature information) · Checked 2026-10-01
  6. 6
    The dial-peer no-match disconnect-cause command makes Cisco Unified CME disconnect incoming ISDN calls that match no inbound dial-peer instead of falling back to default POTS behaviour.
    Cisco Unified Communications Manager Express System Administrator Guide - Toll Fraud Prevention · Disconnect ISDN Calls With No Matching Dial-peer · Checked 2026-10-01
  7. 7
    Cisco Unified CME blocks two-stage dialing on analog and digital FXO ports with no secondary dialtone under the voice-port, and such calls are disconnected with cause unassigned-number (1) when PLAR is not configured.
    Cisco Unified Communications Manager Express System Administrator Guide - Toll Fraud Prevention · Block Two-stage Dialing Service on Analog and Digital FXO Ports · Checked 2026-10-01
  8. 8
    In Cisco Unified CME 8.1 and later, IP address trusted authentication (ip address trusted authenticate) is enabled by default and checks incoming VoIP calls against the trusted IP address list.
  9. 9
    On Cisco Unified CME, an incoming VoIP call from an untrusted IP address is disconnected with cause code call-reject (21), and internal error code 1.1.228.3.31.0 (TOLL_FRAUD_CALL_BLOCK) is recorded.
    Cisco Unified Communications Manager Express System Administrator Guide - Toll Fraud Prevention · IP Address Trusted Authentication; Troubleshooting / monitoring rejected calls · Checked 2026-10-01
  10. 10
    Cisco advises configuring CUBE to route only known number ranges or SIP URIs, and warns that catch-all destination patterns such as destination-pattern .T increase the likelihood of routing a fraudulent call.
    Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · Call Routing and Toll Fraud > Avoid generic dial-peer routing · Checked 2026-10-01
  11. 11
    The CUBE hardening guide recommends Call Admission Control limits on total calls, CPU, memory and bandwidth so that the device can detect and reject call spikes.
    Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · CUBE Threat Mitigation > Denial of Service (DOS) prevention · Checked 2026-10-01
  12. 12
    Where CUBE uses only SIP over TLS, the hardening guide recommends no transport udp and no transport tcp under sip-ua so the device stops listening for unsecured SIP on port 5060.
    Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · Transport Layer Security (TLS) and Public Key Infrastructure (PKI) > Disable Non-Secure SIP Ports · Checked 2026-10-01
  13. 13
    Cisco's CUBE hardening guide prefers silently discarding calls that fail the trusted-list check, because sending a response tells a scanning attacker that the device is listening for SIP.
    Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · Call Routing and Toll Fraud > Allow Connections from Trusted IPs (no silent-discard untrusted discussion) · Checked 2026-10-01
  14. 14
    On Cisco Unified Border Element, the ip address trusted list command under voice service voip defines the IPv4 and IPv6 addresses that are allowed to send inbound calls to the device.
    Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · Call Routing and Toll Fraud > Allow Connections from Trusted IPs · Checked 2026-10-01
  15. 15
    CUBE also builds dynamic trusted-list entries from dial-peer session targets and voice class server-group addresses, and show ip address trusted list displays the resulting list.
    Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices · Call Routing and Toll Fraud > Allow Connections from Trusted IPs · Checked 2026-10-01
  16. 16
    For users who do not need international calling, Cisco recommends Unity Connection restriction tables that block all international numbers, so that a compromised mailbox cannot set up call transfers or fax delivery to an international number.
    Security Guide for Cisco Unity Connection Release 14 - Preventing Toll Fraud · Using Restriction Tables to Help Prevent Toll Fraud (international numbers bullet) · Checked 2026-10-01
  17. 17
    Cisco's Unity Connection security guide advises working with the telecommunications provider to restrict the collect-calling option on incoming phone lines where appropriate.
    Security Guide for Cisco Unity Connection Release 14 - Preventing Toll Fraud · Restricting Collect Calling Options · Checked 2026-10-01
  18. 18
    Cisco Unity Connection 14 ships default restriction tables with basic toll fraud restrictions for a dial plan whose trunk access code is 9, and Cisco says they should be adjusted to the organisation's own dial plan and international prefixes.
    Security Guide for Cisco Unity Connection Release 14 - Preventing Toll Fraud · Using Restriction Tables to Help Prevent Toll Fraud · Checked 2026-10-01
  19. 19
    Cisco recommends that every Unity Connection restriction table block calls to the international operator, for example trunk access code 9 followed by 00.
    Security Guide for Cisco Unity Connection Release 14 - Preventing Toll Fraud · Using Restriction Tables to Help Prevent Toll Fraud (international operator bullet) · Checked 2026-10-01
  20. 20
    When Unity Connection is integrated with two phone systems, its restriction tables must match both trunk access codes, so that blocking 900 under code 9 also means blocking 99900 under code 99.
    Security Guide for Cisco Unity Connection Release 14 - Preventing Toll Fraud · Using Restriction Tables to Help Prevent Toll Fraud (two phone system integrations bullet) · Checked 2026-10-01
  21. 21
    Cisco recommends restricting Unity Connection system transfers to destinations such as lobbies or conference rooms, blocking international operators and long distance numbers.
    Security Guide for Cisco Unity Connection Release 14 - Preventing Toll Fraud · Using Restriction Tables to Help Prevent Toll Fraud (system transfers bullet) · Checked 2026-10-01
  22. 22
    The Cisco Unified CM clusterwide service parameter Block OffNet to OffNet Transfer defaults to False, so external-to-external transfers are allowed until an administrator sets it to True.
    Feature Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1)SU3 - External Call Transfer Restrictions · External Call Transfer Restrictions > Configure the Block OffNet to OffNet Transfer service parameter · Checked 2026-10-01
  23. 23
    A Cisco Unified CM route pattern's Allow Device Override checkbox makes the system use the trunk or gateway call classification instead of the route pattern's own OnNet or OffNet classification.
    Feature Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1)SU3 - External Call Transfer Restrictions · External Call Transfer Restrictions > Configure route pattern call classification · Checked 2026-10-01
  24. 24
    Cisco Unified CM External Call Transfer Restrictions let administrators classify gateways, trunks and route patterns as OnNet or OffNet so that external calls cannot be transferred to external destinations.
  25. 25
    When Block OffNet to OffNet Transfer is True and a user tries to transfer a call over an OffNet gateway or trunk, the phone displays a message that the call cannot be transferred.
    Feature Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1)SU3 - External Call Transfer Restrictions · External Call Transfer Restrictions > Feature interactions / user experience · Checked 2026-10-01
  26. 26
    The FCC's 1992 alert describes attackers using computers to call a PBX and try random authorization codes until one works, and recommends using the maximum code length and changing codes frequently.
  27. 27
    The FCC's 1992 toll fraud consumer alert tells victims to contact their local and long-distance telephone companies immediately, including the carrier's security office, and law enforcement.
    Consumer Alert: Telecommunications Toll Fraud (Second in a Series), DA 92-728, 7 FCC Rcd No. 13 · Section on what to do if you are a victim (closing paragraphs) · Checked 2026-10-01
  28. 28
    The FCC's 1992 alert advises businesses to disable unused PBX components, consider disabling the system outside business hours, and ask vendors or carriers for international or country-specific call blocking.
  29. 29
    The FCC's 1992 toll fraud consumer alert sets out no liability rule for PBX owners; the only liability figure it gives is the up-to-$50 calling-card limit under the Truth in Lending Act.
    Consumer Alert: Telecommunications Toll Fraud (Second in a Series), DA 92-728, 7 FCC Rcd No. 13 · Calling card section; whole document reviewed for PBX liability · Checked 2026-10-01
  30. 30
    In a suspected toll fraud incident on Webex Calling or Teams Phone, applying an international and premium block first and analysing records afterwards is sound, because the Teams usage report lags 24 to 48 hours behind and so cannot confirm the fraud quickly.inferred
    Microsoft Teams PSTN usage report · Interpret the report > callout 2 (latency), combined with outbound restriction policy options · Checked 2026-10-01
  31. 31
    A Unity Connection deployment whose dial plan does not use 9 as the trunk access code is not effectively covered by the default restriction tables until they are edited.inferred
    Security Guide for Cisco Unity Connection Release 14 - Preventing Toll Fraud · Using Restriction Tables to Help Prevent Toll Fraud (default tables paragraph) · Checked 2026-10-01
  32. 32
    Because Block OffNet to OffNet Transfer defaults to False, a Unified CM cluster that never changed it allows inbound PSTN callers to be transferred back out to the PSTN, which is a standing exposure to check during a fraud investigation.inferred
    Feature Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1)SU3 - External Call Transfer Restrictions · External Call Transfer Restrictions (service parameter default) · Checked 2026-10-01
  33. 33
    On an IOS voice gateway an untrusted SIP source may either receive a call-reject or get no response at all, depending on release and on whether silent-discard untrusted is active, so a lack of any SIP response from the gateway is not evidence that it is unreachable.inferred
    Cisco IOS Voice Command Reference - S commands - signal through srv version · silent-discard untrusted > Command Default, read with CME guide IP Address Trusted Authentication · Checked 2026-10-01
  34. 34
    A Teams Phone tenant that never assigned a restrictive dial-out policy has international PSTN calling open for every voice-enabled user, so containment on Teams needs an explicit policy grant, whereas Webex Calling locations block international calling unless an administrator opened it.inferred
    Outbound call restrictions - Audio Conferencing & PSTN calls - Microsoft Teams · Introductory paragraph (defaults) · Checked 2026-10-01
  35. 35
    The CUBE command silent-discard untrusted is enabled by default and discards SIP requests from untrusted sources on an incoming SIP trunk.
    Cisco IOS Voice Command Reference - S commands - signal through srv version · silent-discard untrusted > Command Default · Checked 2026-10-01
  36. 36
    silent-discard untrusted is configured in the sip submode of voice service voip.
    Cisco IOS Voice Command Reference - S commands - signal through srv version · silent-discard untrusted > Command Modes · Checked 2026-10-01
  37. 37
    The silent-discard untrusted command was introduced in Cisco IOS 15.3(3)M and Cisco IOS XE 3.10S, and YANG model support for it was added in IOS XE Cupertino 17.7.1a.
    Cisco IOS Voice Command Reference - S commands - signal through srv version · silent-discard untrusted > Command History · Checked 2026-10-01
  38. 38
    By default, Microsoft Teams outbound call controls allow both international and domestic calls, for audio conferencing dial-out as well as end-user PSTN calls.
    Outbound call restrictions - Audio Conferencing & PSTN calls - Microsoft Teams · Introductory paragraph above the controls table · Checked 2026-10-01
  39. 39
    The Teams dial-out policy instances that disable PSTN calling, such as tag:DialoutCPCandPSTNDisabled, still allow emergency calls.
    Outbound call restrictions - Audio Conferencing & PSTN calls - Microsoft Teams · Using PowerShell > policy overview table, PSTNDisabled rows · Checked 2026-10-01
  40. 40
    The Teams End-user PSTN calls control offers International and Domestic (default), Domestic, or None, and the audio conferencing control offers Any destination, the organiser's country or region, Zone A only, or Don't allow.
    Outbound call restrictions - Audio Conferencing & PSTN calls - Microsoft Teams · Controls table (Control / Description / Control options) · Checked 2026-10-01
  41. 41
    The Teams Direct Routing usage report shows per-call SBC FQDN, final SIP code, final Microsoft subcode and correlation ID, and call types including dr_out_user_transfer and dr_out_user_forwarding.
    Microsoft Teams PSTN usage report · Interpret the report > Direct Routing callout 5 · Checked 2026-10-01
  42. 42
    Teams PSTN usage exports reach back up to one year for Calling Plans and up to 150 days for Direct Routing, subject to country-specific retention rules.
    Microsoft Teams PSTN usage report · Exporting the reports > Exported PSTN usage report; Exported Direct Routing usage report; Data retention table · Checked 2026-10-01
  43. 43
    Granting a Teams dial-out policy with -Global affects only users with no dial-out policy assigned; users who already hold a per-user policy keep it.
    Outbound call restrictions - Audio Conferencing & PSTN calls - Microsoft Teams · Using PowerShell > Set the policy on the tenant level · Checked 2026-10-01
  44. 44
    The Teams OnlineDialOutPolicy cannot be customised; administrators assign one of its predefined instances with Grant-CsDialoutPolicy, per user with -Identity or tenant-wide with -Global.
  45. 45
    In Teams PSTN and Direct Routing reports, the last three or four digits of external numbers are replaced with asterisks for organisations in certain countries such as Germany (3 digits) and France (4 digits).
    Microsoft Teams PSTN usage report · Phone number obfuscation table · Checked 2026-10-01
  46. 46
    For Calling Plans and Operator Connect, the Teams PSTN usage report shows per-call destination dialed, cost, currency, duration, a Domestic/International flag and a call type that distinguishes transfers (user_out_transfer) and forwards (user_out_forwarding) to PSTN.
    Microsoft Teams PSTN usage report · Interpret the report > Calling Plans callout 4 · Checked 2026-10-01
  47. 47
    The Teams PSTN usage report usually reflects a 24 to 48 hour latency from the time of call activity.
    Microsoft Teams PSTN usage report · Interpret the report > Calling Plans callout 2; Direct Routing callout 2 · Checked 2026-10-01
  48. 48
    Organisations on a Telstra calling plan see no call detail records in the Teams PSTN usage report and must get reporting from Telstra.
    Microsoft Teams PSTN usage report · Note under the introduction · Checked 2026-10-01
  49. 49
    Webex Calling can require authorization codes for restricted call types, with up to 1000 authorization codes per location.
    Outgoing call permissions for Webex Calling locations · Authorization codes section · Checked 2026-10-01
  50. 50
    Webex Calling digit patterns can allow or block matching numbers, and digit pattern settings take precedence over permissions by call type.
    Outgoing call permissions for Webex Calling locations · Digit patterns section · Checked 2026-10-01
  51. 51
    In Webex Calling outgoing call permissions, the International call type defaults to Block, with transfers and forwards to it disabled.
    Outgoing call permissions for Webex Calling locations · Call types and default settings table, International row · Checked 2026-10-01
  52. 52
    Webex Calling outgoing call permissions can be set for locations, users, workspaces and virtual lines.
    Outgoing call permissions for Webex Calling locations · Overview / permission entity levels · Checked 2026-10-01
  53. 53
    Webex Calling's Premium Services I and Premium Services II call types default to Block, while national, toll-free, operator assistance, chargeable directory assistance and Special Services I and II default to Allow.
    Outgoing call permissions for Webex Calling locations · Call types and default settings table · Checked 2026-10-01
  54. 54
    A locked Webex Calling voicemail box is recovered by resetting the PIN, which an administrator does in Control Hub under the user's Calling > Voicemail PIN > Reset Voicemail PIN.
  55. 55
    Webex Calling voicemail locks after three incorrect PIN attempts, and Control Hub cannot raise or disable that threshold.
  56. 56
    A new Webex Calling voicemail PIN may not be the reverse of the current PIN or any of the user's last 10 PINs.
    Set or reset your voicemail PIN · PIN requirements list · Checked 2026-10-01
  57. 57
    A Webex Calling user voicemail PIN must be 6 to 30 digits and may not contain repeated patterns, the user's own extension or number, more than three identical consecutive digits, or more than three consecutive ascending or descending digits.
    Set or reset your voicemail PIN · PIN requirements list · Checked 2026-10-01

Documents

tier 1 standards and regulators

Consumer Alert: Telecommunications Toll Fraud (Second in a Series), DA 92-728, 7 FCC Rcd No. 13

Federal Communications Commission · 1992-06-09 · accessed 2026-10-01

tier 2 current vendor documentation

Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices

Cisco Systems · 2023-04-10 · accessed 2026-09-23

tier 2 current vendor documentation

Cisco IOS Voice Command Reference - S commands - signal through srv version

Cisco Systems · 2026-09-29 · accessed 2026-10-01

tier 2 current vendor documentation

Cisco Unified Communications Manager Express System Administrator Guide - Toll Fraud Prevention

Cisco Systems · 2022-08-15 · accessed 2026-10-01

tier 2 current vendor documentation

Feature Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1)SU3 - External Call Transfer Restrictions

Cisco Systems · 2025-07-31 · accessed 2026-10-01

tier 2 current vendor documentation

Microsoft Teams PSTN usage report

Microsoft · 2026-04-26 · accessed 2026-09-24

tier 2 current vendor documentation

Outbound call restrictions - Audio Conferencing & PSTN calls - Microsoft Teams

Microsoft · 2025-02-18 · accessed 2026-10-01

tier 2 current vendor documentation

Outgoing call permissions for Webex Calling locations

Cisco Systems, Inc. (help.webex.com) · 2025-10-16 · accessed 2026-09-16

tier 2 current vendor documentation

Security Guide for Cisco Unity Connection Release 14 - Preventing Toll Fraud

Cisco Systems · 2025-03-04 · accessed 2026-10-01

tier 2 current vendor documentation

Set or reset your voicemail PIN

Cisco Systems · 2026-01-19 · accessed 2026-09-21

tier 2 current vendor documentation

Unable to Disable WebEx Calling Voicemail Lock Time in Control Hub

Cisco Webex · 2023-11-28 · accessed 2026-09-25

tier 5 independent technical research

Telecommunications fraud increased 12% in 2023 equating to an estimated $38.95 billion lost to fraud.

Communications Fraud Control Association · 2023-11-13 · accessed 2026-10-01

Cite this page

APA

WarmTransfer. (2026, October 1). Responding to a suspected toll fraud incident. WarmTransfer. https://warmtransfer.net/knowledge/toll-fraud-incident-response

BibTeX

@misc{warmtransfer-toll-fraud-incident-response,
  title  = {Responding to a suspected toll fraud incident},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/toll-fraud-incident-response},
  note   = {Verified 2026-10-01}
}