Resources
3CX Guides
About
Contact
Free Bill AnalysisCall 1300 747 266
Guides

Securing your 3CX system against toll fraud

Practical steps to secure 3CX — strong credentials, IP rules, an SBC and anti-fraud limits — so you don't get a shock bill.

Last reviewed
Installed in days, not weeksSavings identified up to 65%*5.0-star Google ratingGreensborough & NE Melbourne

Toll fraud is the nightmare every phone-system owner hopes happens to someone else: a stranger finds a way into your PBX, dials thousands of premium or international calls overnight, and you discover it when a five-figure bill lands. It is not rare, it is automated, and the scanners that hunt for open 3CX systems never sleep. The good news is that 3CX gives you solid tools to shut the door, and most of the work is one-off setup.

This guide walks through the practical layers that keep your 3CX phone system safe: strong credentials, sensible IP rules, a Session Border Controller where it earns its keep, and the anti-fraud limits that cap your exposure even if something does slip through. None of it is exotic, but the order and the detail matter.

Start with credentials, because that is where most attacks begin

The overwhelming majority of toll-fraud incidents trace back to a weak or guessed extension password, or a management login left on a default. Fix that first.

Use long, random extension authentication credentials.

The SIP password for an extension is not the user's voicemail PIN or their email password. Let 3CX generate strong ones and never reuse them across extensions.

Lock down the Admin Console.

Use a strong administrator password, give technicians their own logins rather than sharing one, and remove accounts for people who have left.

Change default ports where practical.

Leaving SIP and the management interface on well-known ports makes you trivial to find for automated scanners.

Keep 3CX updated.

Security fixes ship in updates. An out-of-date PBX is a known-vulnerability PBX.

If you are still setting up users, our guide on adding and managing extensions in 3CX covers how to provision them cleanly from the start.

Control who can reach the system with IP rules

An attacker can only abuse a port they can reach. The fewer places your PBX is exposed to, the smaller your attack surface.

Restrict management access.

Where you can, limit the Admin Console and remote-access ports to known office IP addresses or a VPN, rather than the whole internet.

Use 3CX's built-in IP blacklist and anti-hacking features.

3CX automatically blocks IPs that fail authentication repeatedly. Make sure these protections are enabled and tuned, not switched off because they were "in the way".

Allow-list known-good networks.

If your SIP trunk provider gives you specific signalling IPs, accept SIP from those and treat everything else with suspicion.

A clean network design here pairs well with sensible inbound and outbound rules so that even legitimate traffic only does what you intend.

Use a Session Border Controller for remote sites and devices

The 3CX Session Border Controller (SBC) is a small piece of software you run at a remote office or behind a difficult network. It tunnels remote IP phones and traffic back to the PBX over a single secure connection, so you do not have to open a spread of SIP ports to the internet for every remote device.

The SBC is worth the effort when you have desk phones at people's homes or branch offices, or networks where direct registration is fragile. It both improves security and tends to clear up the NAT headaches that cause one-way audio. For softphones, the 3CX apps for Windows, Mac, iOS and Android use 3CX's own tunnel and are generally a safer remote-worker option than exposing raw SIP.

Getting an SBC and STUN configuration right across a real-world network is one of those jobs that is genuinely fiddly. If you would rather not learn it the hard way, that is exactly the kind of thing we set up for clients.

Cap your exposure with anti-fraud and call limits

Even with good credentials and tight network rules, you want a ceiling on what any single extension or trunk can cost you. This is where 3CX's anti-fraud and security limits earn their place, and it is the layer most people skip.

1

Block international dialling by default.

Most businesses only call a handful of countries, if any. Use Outbound Rules so that international calls are blocked unless a specific extension genuinely needs them.

2

Restrict premium and unusual destinations.

Block premium-rate numbers and high-risk destinations outright. Fraudsters target obscure international ranges that pay them a kickback per minute.

3

Set the allowed simultaneous outbound and international call limits.

3CX lets you cap how many concurrent calls and international calls are permitted. A sensible cap means a runaway attack hits a wall fast instead of running all night.

4

Limit per-extension call rights.

Give each extension only the dialling rights its role needs. Reception and sales may need outbound; a meeting-room phone almost certainly does not.

It also pays to talk to your SIP trunk provider about spend alerts and limits. A good provider will flag a sudden spike in international minutes rather than quietly billing it. If you are unsure what your current setup actually allows, a free bill review is a quick way to spot exposure and overspend at the same time.

Build a habit, not a one-off

Security is not a single switch. A short routine keeps it honest:

  • Review extension and admin accounts when staff change.
  • Keep 3CX and your IP phone firmware up to date.
  • Check call reports occasionally for after-hours or international activity that does not fit your business.
  • Take regular backups so you can recover quickly. Our guide on backing up and restoring 3CX covers how.

As a local Melbourne telco we look after the 3CX systems we install, including the security setup, on both on-premise and hosted PBX deployments. If you would like a hand locking yours down, call us on 1300 747 266 or get in touch through our contact page.

What we see installing this in Melbourne

The single biggest exposure we find on AU SME sites is a 3CX that was stood up in a hurry years ago and never had its outbound rules tightened. International dialling is wide open on every extension, the simultaneous-call cap is still on the default, and nobody has looked at the call reports since cutover. We usually find this during a bill review, not after an incident, which is the lucky version.

A close second is remote desk phones that were rushed home during 2020 and left registering directly across the NBN with SIP ports open on the office firewall. Swapping those over to the 3CX SBC or the desktop and mobile apps removes the exposed ports and tends to fix the NAT-related audio gremlins at the same time.

Where we add value on installs is the boring discipline: enabling and tuning the IP blacklist properly, locking the Admin Console to office IPs or a VPN, agreeing sensible international and concurrent-call caps with the business owner, and getting the SIP trunk provider to set a monthly spend alert before we hand the system over.

Frequently asked questions

How does toll fraud actually happen on a 3CX system?

Almost always through a weak or default credential. Automated scanners probe internet-facing PBXs, guess extension passwords, register as that extension and then dial expensive international or premium-rate numbers, often overnight or over a weekend. Strong passwords, IP restrictions and outbound-call limits close off the common routes.

Will blocking international calls stop me making legitimate overseas calls?

No, as long as you set it up with intent. The approach is to block international dialling by default and then grant it only to the specific extensions that need it. Staff who never call overseas lose nothing, and the few who do still work normally.

Do I really need a Session Border Controller?

Not every business does. If all your phones sit on one office network, you may not. The SBC becomes valuable when you have remote desk phones, branch offices or awkward networks, because it avoids exposing SIP ports to the internet for each device. For remote staff on the 3CX apps, the built-in tunnel often does the job without an SBC.

What happens if I get hit despite taking precautions?

Anti-fraud limits are what save you here. Concurrent-call and international-call caps mean an attack is stopped after a small number of calls rather than running unchecked. Combined with provider spend alerts and a recent backup, the worst case becomes a contained nuisance rather than a catastrophic bill.

Get a free bill analysis — and stop overpaying

Send us a recent phone or internet bill. We’ll show you exactly where the waste is — our bill reviews have identified savings of up to 65%.

Call 1300 747 266 Free Bill Analysis