The 3CX Phone System is an IP PBX that is safe from call fraud and outside attacks such as brute force attacks, DOS (denial of service), Invite Floods (DOS), Dictionary attacks, and so on, whether installed on-premises or in the cloud.
Although rare, some call fraud cases occur where an admin makes a configuration mistake that leads to call fraud. How can you avoid it? Here are the tips:
What is call fraud?
Simply put, call fraud happens when an unauthorized party makes calls through your PBX. This usually happens at night or when the office is closed, and calls are made in bulk to various international destinations, and then you get a large bill at the end of the month that you have to pay.
Usually an IP PBX server hacker makes calls to premium international numbers. The motivation is indirect financial gain, because they automatically call thousands of numbers from premium services under their control to earn commissions paid per call or per minute.
This is also known as International Revenue Sharing Fraud (IRSF).
Another common way to profit is by reselling stolen credentials on the darknet to anyone who wants cheap phone routes.
The 3CX Phone System has many built-in security features and default settings that prevent such abuse, but administrators sometimes disable the safeguards without understanding the risks that will follow.
There are roughly 5 common mistakes to avoid.
1. Weak credentials
The first mistake is using weak credentials for your extensions. When you create an extension in your phone system, random default credentials are generated at all levels: the SIP Authentication ID, a strong password for SIP, the web client, mobile, a random voice PIN, and so on. You should keep the default random configuration to ensure protection against brute-force attacks.
The 3CX phone system already comes with a warning when an admin gives weak credentials, shown as an exclamation mark as follows:

Never set credentials for a user thinking you will change them later when going to the live environment, because people usually tend to forget this.
2. Allowing Remote Access
The second most common mistake is having the “Disallow use outside lan” option unchecked in each of your extensions’ menus.
This option prevents remote SIP Trunk registration on your extension and is checked by default when creating an extension. You can still use the softphone remotely under this condition without being affected, because the 3CX softphone comes with a tunnel connected directly to the PBX server.
3. Too many countries allowed
When you first install your PBX, a menu will ask which countries are allowed to make incoming and outgoing calls. This list can later be found under security/allowed country codes. Limit it to the countries users typically use. By default the configuration will limit it to only the country where it is installed, for example Indonesia.
4. Lazy outbound rules
In practice, to simplify the “outgoing rules” settings, admins only create a few rules that let anyone make calls. Restricting calls can be done by grouping local, long-distance, and international.
5. In version 16, 3CX introduced two main security features that improve security further. They are:
a. It lets you restrict management console access based on IP. By default all IPs are allowed; when enabled it only allows the local IP subnet and certain Public IPs. This option does not interfere with other web services such as provisioning, the web client, and so on.
To date the Global IP Blacklist server has received 1000+ IP addresses and ranges that have been reported as scanning or fraud. We recommend that you enable this feature




