VoIP hacking on the increase

June 2011 Information Security, Infrastructure

Businesses that implement VoIP (voice over IP) telephony systems on their local or wide area networks must ensure that they have effective protection against the growing incidence of VoIP hacking.

That is according to Graeme Victor, CEO of telecommunications solutions company Du Pont Telecom who says a small Johannesburg company was left with a telephone bill of more than R100 000 recently after criminals hacked into its VoIP telephony system over a weekend.

VoIP is steadily gaining market acceptance as a telephony solution because of its many benefits including the fact that phone calls between two VoIP users on the same system are free. However, IP telephony has already become a popular playground for attackers. As has happened with other emerging technologies, the speed of advances in VoIP technology has typically outpaced the corresponding security requirement.

So far, the emphasis in VoIP security has been to protect the underlying IP network - rather than voice elements - from attacks.

“Businesses spend considerable resources protecting their data networks to prevent loss of data, yet fail to take similarly stringent precautions to protect their voice IP networks despite the fact that an attack could have immediate, potentially crippling financial implications,” he says.

In the United States, a man who operated a low-cost Internet calling company was recently sentenced to 10 years in prison after hacking into 15 unsuspecting companies’ VoIP systems. He illegally routed 100 000 minutes of his customers’ Internet telephone calls through the hacked networks. The fraud cost the victims more than US$1,4 million.

“That hacker got caught but there are people all over the world trying to find ‘free’ channels through which to direct their calls,” Victor says. “Another danger is that hackers use the vulnerabilities of the VoIP system to gain access to the data network. VoIP systems must also be protected against manipulation, tapping and even call hijacking in which the connection is reported as unavailable and the call is rerouted.”

He warns local businesses to beware of implementing VoIP on their networks without proper security controls and says both IP PBXs and IP handsets are vulnerable.

“As VoIP is rolled out to more and more businesses in South Africa, the accessibility and allure of attacking their systems by international hacking syndicates will increase.

“Securing a VoIP infrastructure requires planning, analysis and an in-depth and high level of knowledge about the configuration of the chosen VoIP implementation. It is therefore important for local businesses to choose a VoIP provider who understand all aspects of VoIP security,” Victor concludes.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Hytera supports communication upgrade for Joburg
News & Events Infrastructure Government and Parastatal (Industry)
By equipping Johannesburg’s metro police and emergency services with multimode radios which integrate TETRA and LTE networks, Hytera is bridging coverage gaps and improving response times across the city.

Read more...
Want effective Attack Surface Management? Think like an attacker.
Information Security
Effective ASM requires companies to think like attackers, anticipate risks, and act decisively to reduce exposure by knowing their environment, deploying a structured approach, leveraging capable tools, and addressing both internal and external risks.

Read more...
The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
POPIA non-compliance puts municipalities at risk
Information Security Government and Parastatal (Industry)
Digital responsibility must go beyond POPIA compliance to recognising that privacy and service delivery are fundamentally linked. Despite this, only 51 out of 257 municipalities submitted their mandatory data protection and access to information reports in 2024.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...
Most wanted malware
News & Events Information Security
Check Point Software Technologies unveiled its Global Threat Index for June 2025, highlighting a surge in new and evolving threats. Eight African countries are among the most targeted as malware leaders AsyncRAT and FakeUpdates expand.

Read more...
IoT-driven smart data to stay ahead
IoT & Automation Infrastructure AI & Data Analytics
In a world where uncertainty is constant, the real competitive edge lies in foresight. Businesses that turn real-time data into proactive strategies will not just survive, they will lead.

Read more...
Hydrogen is green but dangerous
Fire & Safety Infrastructure Power Management
Hydrogen infrastructure is developing quickly, but it comes with safety challenges. Hydrogen is flammable, and its small molecular size means it can leak easily. Additionally, fires caused by hydrogen are nearly invisible, making them difficult to detect and respond to.

Read more...
Welcome to the new cyber battleground
Information Security
The Iran-Israel conflict is rapidly redefining modern warfare, pushing the boundaries of cyber capabilities and creating a new, borderless digital battlefield. Fortinet’s CISO, Dr Carl Windsor, offers a critical, in-depth analysis of the escalating tactics and global implications in his latest report.

Read more...
A whole-site solution to crack the data centre market
Fire & Safety Infrastructure Facilities & Building Management
Fire safety consultants and contractors who can offer a comprehensive fire safety solution to the data centre market can establish themselves as a supplier of a key safety features that help guarantee the smooth operation of critical infrastructure.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.