NYSE: IDT
facebook
Products

Discover how our products can revolutionize the way you communicate and collaborate.

Voice

Explore our advanced voice solutions designed to optimize your communication workflows.

Diverse range of DID number solutions designed to enhance your communication capabilities.

Experience unparalleled communication efficiency with our advanced SIP Trunking Solutions.

Cutting-edge technology to proactively detect and neutralize spam flags on your DID Numbers.

Messaging

Wherever your audience is, our platform ensures seamless messaging across diverse channels.

Build customer journeys by fostering interactive conversations, all within the framework of your app. 

Connect with your audience in a simple and effective way through our cutting-edge SMS platform. 

BYOC

Harness the power of IDT as your chosen carrier while leveraging your platform’s advanced features and services.

Integrate Twilio with our robust carrier routing platform to achieve unparalleled Voice termination system.

Experience reliable and high-quality communication services while leveraging the advanced capabilities of Genesys. 

Integrate IDT with the collaborative strength of MS Teams, unlocking efficient and feature-rich communication. 

Experience the power of our carrier network seamlessly connected to Plivo through our cutting-edge BYOC solution. 

Tools

Experience the power of our online voice tools, designed to simplify communication management. 

Ensure the authenticity and integrity of outbound calls with our STIR/SHAKEN Verification Check tool. 

User-friendly tool to verify the reputation of your business number, ensuring that it remains trusted. 

Compare and gain insights into outbound call expenses, optimize budget, and make informed decisions. 

Easily estimate and compare the costs associated with different DID numbers providers. 

Compare inbound VoIP rates among top CPaaS providers and optimize your inbound call costs. 

Generate custom SMS templates. 

Learn

Empower yourself with the resources you need to thrive in the dynamic landscape of communication.

Articles covering a wide range of topics.

Get answers to common queries.

Find instructions to make the most of our products.

Discover telecom insights and trends.

Find definitions of popular telecom terms.

Explore how our solutions have helped businesses.

Latest telecom trends, innovations, and market insights.

Company

A global telecom partner built to meet your needs. 

Discover the story behind our commitment to delivering innovative solutions to connect people and businesses worldwide. 

Learn about our robust network infrastructure that spans across the globe, ensuring reliable and secure connectivity. 

Got a question, feedback, or need assistance? Our dedicated team is here to help!

Find partners or sign up for partnership programs.

NYSE: IDT
Learn / Blog

Voice termination: Six VoIP Security Threats

|
|  4 min
Voice termination: Six VoIP Security Threats
In this article

Most businesses adopt VoIP as a means by which to reduce costs and gain additional flexibility. But as the technology becomes more widespread, concerns are sometimes raised as to how secure it is. The threats that affect VoIP are partly those that affect any network-based systems, but there are also some that are unique to voice traffic. Let’s take a look at some of the main threats that target VoIP users. 

Voice termination service theft

Perhaps the most worrying is service theft. This allows the attacker to make calls while passing the cost onto someone else. The most common way of doing this is via credential theft. It’s therefore essential to ensure that employees are alert to the risk of phishing attacks that may seek to obtain their login IDs. 

Attackers can also try to obtain IDs via eavesdropping. This potentially allows not just the ability to make calls, but also to access voicemail or change forwarding options, in addition to allowing the theft of sensitive data. With access to an admin account, a hacker could also be able to change calling plans or add extra call time to a victim’s account. 

Vishing attacks

Vishing is a type of phishing that applies specifically to phone users, not necessarily just VoIP. It is carried out by an attacker calling pretending to be from a trustworthy organisation, such as a bank, in order to try to obtain confidential information such as account access codes. 

These attacks use social engineering techniques to lure the victims into a false sense of security. The attackers make considerable efforts to sound professional and convincing. We all like to think we are too smart to fall for scams like this, but the scammers are clever and will build confidence by quoting details including your name and address which you would expect legitimate callers to have. They will also seek to worry you by talking about suspicious transactions on your account or orders for expensive products that you haven’t made. 

Malware and viruses

Just as with any other service that relies upon information technology, VoIP softphones and software are vulnerable to malware. They can be attacked by malicious code; this can attempt to steal information or simply disrupt the service, making it impossible to make or receive calls. 

Malware has also been used to make certain VoIP systems vulnerable to eavesdropping. Whichever system you use it’s therefore vital that you ensure it’s up to date with the latest patches. 

DDoS attacks

Distributed denial of service (DDoS) attacks are a form of malware aimed at preventing a service from accessing the internet. It does this by denying it access to bandwidth, usually by bombarding the server with more requests than it can handle. On VoIP systems, this can make it difficult to make calls or cause calls to drop out. 

DDoS attacks are not always purely disruptive, They can be used as a cloak for other activity such as stealing information or getting control of system admin features. DDoS attacks are usually launched by networks of compromised machines known as botnets. Increasingly these botnets don’t even need to be PCs but can be made up of poorly secured internet of things devices such as routers or security cameras. Cybercriminals often have botnets available for rent on the dark web, so it can be quick and easy to launch an attack. 

SPIT attacks

Spam over internet telephony (SPIT) is, as its name suggests, the VoIP equivalent of email spam. While it’s relatively rare at the moment, SPIT is likely to become more of a problem as VoIP spreads into the mainstream. 

VoIP is already a valuable tool for unscrupulous telemarketers as it allows them to make calls at minimal cost and to disguise the origin of their calls by spoofing caller display systems. SPIT makes use of the IP address that every VoIP device must have in order to work, to send out voicemail messages. This leads to inboxes being clogged with lots of unwanted messages, making it hard for the user to get at the legitimate contents of their voicemail. 

SPIT can also be used in conjunction with some of the other threats we’ve talked about, to distribute malware or to conduct phishing and vishing attacks by asking for confidential information. 

Tampering with calls

VoIP systems can also fall prey to call tampering. This can be used to disrupt the call by injecting interference and noise. Hackers can also interrupt the delivery of the data packets that make up the call, making the communication intermittent. 

Tampering can be carried out by what is known as a man-in-the-middle attack. This means that the attacker intercepts the call data and diverts the call via their own servers. This allows calls to be hijacked and redirected and hackers to masquerade as a legitimate caller. 

Share this article

Leave a Reply

Your email address will not be published. Required fields are marked *

Tags

Meet our wholesale voice routing

Fulfill all your voice calling needs with our category leading wholesale A-Z Voice Termination.
Try IDT Express for a $25 Credit

Get $25 Free Trial Credit

Get IDT Express articles in your inbox

The best source of information in the telecom industry. Join us.

    Most Popular

    toll-free-forwarding-illustration
    |
    |  7 min
    Introduction to Toll-Free Forwarding In today’s fast-paced business landscape where...
    caller-id-thumbnail
    |
    |  7 min
    Introduction to Caller ID Reputation Caller ID reputation is a...
    sms-data-privacy-under-gdpr
    |
    |  6 min
    The European Union’s General Data Protection Regulation (GDPR) has permanently...