Voice over Internet Protocol (VoIP), is a technology that allows you to make voice calls using a broadband Internet connection instead of a regular (or analog) phone line. In the current climate particularly those working from home, the use of VoIP calls is on the rise with a 40% increase in some countries. People and Companies are changing the way they buy and utilise phone packages.
VoIP fraud can be defined as the unauthorized use of paid communication services charged to someone who isn’t expecting it, whether that be the service provider or the customer.
So how does the fraud happen? What does a simple attack look like? We’ll break it down for you in three steps inside the motions of a fraudster.
Step 1: The fraudster looks for a vulnerable VoIP device, which is also known as an endpoint (IP phone or switch) to use to send calls. Typically, this is done by scanning the Internet for vulnerable endpoints, which are easiest to access by using the default username and password. And why does that happen? Because many times users don’t change the default user name and password information when they purchase the device. Note to self: Always change the user name and password information when you purchase the device.
Step 2: Now the floodgates are open! The fraudster has breached your device and can begin sending expensive calls through the exposed endpoint. Notice, we said “calls.” It is not solely one call at a time, it could be hundreds of expensive-per-minute international calls running for hours or even days.
Step 3: The fraudster sells the expensive free route at a much lower rate than the industry average. Your hacked VoIP device incurs all the costs for those calls and the fraudster gets all the profits. The easiest way to break it down in everyday scenarios is this: Let’s say you hack into your neighbour’s cable TV service and sell it to renters living in your house. This would be an absolute profit for you. But what if your neighbour finds out what you’ve been doing and he cuts the line? You as the cable-stealing-thief simply tap into another neighbour’s cable service and use that until it’s cut. It is similar with the fraud of the VoIP services. The only difference is the real VoIP fraudsters steal from another country so it is very difficult to find or apprehend them.
In general, fraud isn’t something that we like to think about – but as evidence suggests that the instances of VoIP fraud have begun to rise, it’s more important than ever to make sure that you’re informed, and prepared to avoid the risks.
Fraudulent activities in VoIP are generally linked to a trend in which hackers access paid communication services using unauthorised methods. The access means that the service use is charged to someone, either an end-user or service provider, without their knowledge.
While it might be difficult to prevent VoIP fraud from happening altogether, the right education could help you to reduce your chances of becoming a victim. After all, there’s more to know about fraud than the fact that it could cost your business millions of pounds. For many, education will be the best form of defence against this new business threat.
Source: www.uctoday.com