Phone Fraud Still a Problem For US Businesses

Whatever happened to telecom fraud? Does it stillautomatically prompt and ensure that employees to
exist? Should you as a business owner bechange their passwords every 90 days at minimum.
concerned? Despite huge advances in securityWhen employees leave the company, make sure that
technology and increased telecommunication securityyou delete their unused voicemail boxes as quickly as
protection and customer awareness, phone fraudpossible. Why? The hacker takes control of the voice
continues to be a major concern for all businesses.mail box and records the word "yes." He then places a
Just the thought of the possibility of thousands ofthird party and instructs the outside operator to call the
dollars in losses to a business because of phone fraudnumber of your departed employee's old mailbox. The
is daunting. The fact is that phone fraud still has theoperator says, do you accept third party charges for
potential to put your business out of business and thatMr. Jones' call and the voice mail box answers, "yes"
is a scary proposition. Even with the advent of VOIPas programmed.
technology, the thieves have continued to figure outAnother major threat to companies today is the
how to hack even the most complicated systems andproblem of weak links in personnel, particularly the
companies like yours and mine can still suffer as acompany receptionist. This is sometimes referred to
result.as "social engineering fraud." Employees and your
There are three primary kinds of phone fraud thatreceptionist should be alert for a call that is received
most of us should be concerned with and that will bewhereby an individual may identify him/herself as
addressed in this article. Nuisance fraud (cramming andsomeone working for the phone company who is
slamming), proprietary phone system (PBX and keytesting lines. They might say, "I'm with the phone
system) fraud, voice mail fraud and the newestcompany and I'm running a test on your phone
challenge, VOIP phone system fraud.systems, please transfer me to a particular extension."
Nuisance Fraud: Most of us as business professionalsTransferring a caller to certain digits first accesses an
will at some time or another encounter nuisance fraud,outside phone line "dialing 9" and "dialing the 0"
otherwise known as slamming and cramming.accesses the outside operator who can facilitate a call
Nuisance fraud usually cannot make or break ato anywhere in the world for the crooks. The calls are
business when it strikes, but it can drain revenues if leftthen back billed to your company. Hackers have also
unchecked on the phone bill.been known to use other ploys like finding out who the
Cramming occurs when a third-party provider chargesboard members for large companies and then
for services or fees that the customer has notimpersonating that individual on a call to that company.
authorized. These charges are neither ordered norThe receptionist may not be able to recognize their
desired by your company. These charges can includevoice because typically board members don't interact
products and services such as bogus voice mailwith receptionists as much as employees do.
service charges, operator assisted calls, calling cardHowever, due to a board member's prestige, power or
programs, monthly service fees and credit checkreputation in the company, the receptionists are well
services. Also, bogus yellow pages and white pagesaware of their power, so the caller is able to get
advertising can also mysteriously appear on yourunlimited transferring ability to commit his crimes. The
business phone bills or be billed to you directly.crime usually is not discovered until after the arrival of
Cramming is the addition of charges to a subscriber'sthe phone bill. Warn the receptionist and employees of
telephone bill for services which were neither orderedthis ploy. Numerous companies milked for thousands of
nor desired by the client, or for fees for calls ordollars in overseas calls because of this crime.
services that were not properly disclosed to theIf your business has a toll-free inbound number, be on
consumer. These charges are often assessed byalert! Hackers can call in on the toll free number and
dishonest third-party suppliers of data anduse codes and features to place calls overseas or ring
communication service that phone companies areup service charges on paid calling services.
required, by law, to allow the third-party to place on theAnother thing you should do is restrict some call
bill.forwarding and conferencing features on your
Have you ever looked at your local telephone bill andcompany phone system that might assist hackers in
seen odd charges from "other service providers thatforwarding calls on your dime. Arrange to meet with
you do not recognize?" If you have, chances are veryyour phone system vendor to conduct a vulnerability
good that you've been crammed. For large businesses,analysis ensure that your phone system is secure.
the charges are buried deeply in the bills and areMost of the larger telephone equipment manufacturing
difficult to notice, and can go on for years, month aftervendors, Siemens, Avaya, Nortel and Mitel have
month without being noticed.security bulletins and security support programs to help
How can you get refunds and combat cramming?keep your systems secure and up to date.
First, call your local phone provider and ask them toVOIP fraud: The third and final telecom voice fraud
reverse the charges to the offending party. In mostconcern to be discussed is the latest threat to
cases, they will. If they do not cooperate, contact thecompanies and that is VOIP fraud. Voice over IP fraud
FCC, your better state attorney general and the FTCis still in its infancy but becoming more prevalent. Again,
to lodge a complaint. However, first let the crammeras previously mentioned in the earlier section regarding
know that you would like give them the opportunity tophone system fraud, one of the best ways to prevent
refund your money.this kind of fraud is to change the system passwords
Slamming can occur when there is an unauthorizedin your VOIP phone system.
switch or change of a carrier providing local, local toll orThere is starting to be increased attention surrounding
long distance service. Slamming is frustrating becauserecent attacks on VOIP systems but actual cases of
dishonest phone companies are able easily to changedocumented fraud are now just starting to become a
or "pic" your long distance service to their plans, oftenproblem. In 2007, two men were arrested because
at a much higher rate than your preferred or selectedthey routed calls through unprotected network ports at
carrier had provided. Even after you discover theother companies to route calls onto providers. Over
fraud, there is still the headache of switching all of yourthree weeks, the two routed half a million phone calls
lines back to the long distance provider you shouldto a VOIP provider. Federal investigators believe the
have and getting the fraudulent service to issue you atwo made as much as $1m from the scam.
refund. How do you prevent it? Ask the carrier to putNevertheless, actual cases of VOIP fraud on these
a "pic freeze" on your phone lines. Insist on a corporatesystems are still somewhat rare, however, there is a
password for access on your all of your local, cellularlot of potential for harm as vulnerabilities and holes in
and long distance phone accounts and restrict allsecurity are becoming more prevalent and more easily
access to those accounts to two key people in yourexploitable by resourceful hackers.
company.VOIP hackers can exploit system passwords to gain
Phone system and voice mail fraud: These kinds ofaccess to company VOIP voice systems and have
frauds continue to be problematic for many companiesand can potentially steal millions of minutes of long
and will continue to persist as long as companies havedistance service. How? Hackers read up on VOIP
PBX and Key type phone systems in place and longvendor security bulletins and gather public information
distance calls cost money and hackers can easily gainon company IP addresses that are posted on the
access. Proactive prevention of this type of fraud isinternet, which allows them to hack into client systems.
much easier than correcting it once it's occurred andThey devise and use customized software code to
let's face it, like most criminals, hackers are lazy anddecipher access codes and access exposed data
they'll leave your company alone and go someplaceports and data gateways and computer systems.
else if your system has the necessary safeguards inHackers can find it easy to use default or poorly
place. First, make sure that your phone systemchosen passwords.
manufacturer provided master default passwords forTo counteract these attacks on your company and
your phone and voicemail systems are changed atkeep updated with the latest security technology and
your location. Hackers know these passwords andVOIP fraud prevention advice, consult with your VOIP
can easily hack your system if they can get access. Inequipment vendors and ask specific questions on how
fact, many of these phone system master passwordsto best protect your systems. If you have a large
(i.e.: Avaya, Siemens, Nortel, Mitel, Cisco) are posted onVOIP system, it may make sense for you to have a
the internet, available to anyone. A password changeprofessional conduct a security audit on your system.
can be done by placing a call to the company thatIP business consumers and IT managers need to use
maintains services your phone systems.the latest encryption techniques for their network
Also, make sure that your remote access to youaccess and train and monitor their employees on
phone systems are secure. This can often be done byeffective safeguarding of their company data and IP
using security encryption technology for remotesystem information.
access to your system. Next, make sure that yourThe best way to determine if a telecom fraud is being
employees do not use easy passwords like "1111" tocommitted on an organization is to do an extensive
access their voice mail boxes. These can be easilytelecommunications audit and complete phone system
hacked. Also, set your voice mail system toreview.