
Most businesses only find out about phone fraud when a bill arrives with figures that don’t add up. Calls to countries no one recognises, charges that run into the thousands, or usage logged at three in the morning when the office was empty. By that point, the damage is already done.
Business phone hacking is a growing problem for UK companies of all sizes, and small businesses are often the least prepared to spot it. Understanding how these attacks work, and why your business might be exposed, is the first step towards protecting yourself from unexpected costs.
Business phone hacking involves criminals gaining unauthorised access to a company’s phone system, then using it to generate calls that cost the business money. It sounds technical, but the mechanics are often surprisingly simple. Attackers scan the internet for phone systems with weak or default passwords, then log in using those same credentials. Once inside, they can route calls, add extensions, or reconfigure settings without anyone noticing straight away.
This is often referred to as PBX fraud, named after the private branch exchange systems many businesses use to manage their calls. Older or poorly configured PBX systems are particularly vulnerable, as they may still be running default settings from installation. Once an attacker has access, the goal is usually to generate as much call traffic as possible before anyone spots the problem.
It’s a common assumption that larger organisations are more attractive targets for cybercrime, given the scale of what they stand to lose. In reality, business phone hacking often targets smaller companies precisely because they’re less likely to have dedicated IT security staff monitoring call activity around the clock. A large enterprise may catch unusual call patterns within hours. A small business might not notice until the monthly bill lands.
This gap in oversight is part of a wider pattern. Telecoms fraud in the UK has grown alongside the shift to cloud based and VoIP phone systems, which offer flexibility but also introduce new points of entry if left unsecured. Many SMEs manage their own phone system with limited technical support, relying on default settings that were never designed to withstand a targeted attack. Attackers know this, and specifically look for smaller, less monitored setups. Phone system hacking thrives on exactly this kind of gap.
The scale of the vulnerability is reflected in recent UK research: 42% of small businesses experienced a cyberattack or breach in the previous 12 months, while 39% of SMEs, equivalent to around two million businesses, had not arranged cybersecurity training for their staff [1]. Although these figures cover cybercrime generally rather than phone hacking alone, they highlight why smaller firms can present attractive opportunities for attackers. Simply put, they may have fewer resources, less specialist oversight and more weaknesses left unaddressed.
Fraudsters use a handful of well-established methods to exploit vulnerable phone systems. Recognising the terminology can help you understand what’s happening if you ever see it on a bill or in a call log:
Each method exploits the same basic weakness: unauthorised access to a system that wasn’t properly secured.
Catching business phone hacking early comes down to knowing what to look for. The clearest signal is usually a business phone bill spike, where charges jump well beyond your typical monthly usage without any obvious explanation. This might show up as a single large charge or a steady accumulation of smaller ones over several days.
The wider scale of telecoms-enabled fraud shows why these warning signs should not be ignored. UK Finance reported that telecoms services enabled 16% of authorised push payment fraud cases in 2024 but accounted for 36% of the money lost, around £160 million [2]. This figure covers telecoms-enabled fraud more broadly, rather than business phone-system hacking specifically, but it demonstrates how telephone services can play a significant role in high-value fraud.
Call logs are worth checking too. Look for calls to unfamiliar international destinations, unusually long call durations, or repeated dialling to the same number in a short space of time. An out-of-hours attack is particularly common, since fraudsters often target systems overnight or at weekends when no one is watching activity in real time.
Any premium rate numbers you don’t recognise, especially clustered together, are also worth investigating straight away. Spotting these patterns quickly can make a significant difference to how much a fraud event ends up costing.
Understanding the warning signs matters but preventing an attack in the first place matters more. Many incidents come down to a handful of common weaknesses that go unnoticed until it’s too late. Default or weak passwords, unused extensions left active, and outdated software are among the most frequent culprits behind phone system vulnerability.
SIP trunking security deserves particular attention, as SIP trunks connect your phone system directly to the wider internet, and if left unprotected, they can become an open door for attackers. Simple steps such as restricting access by IP address, enforcing strong authentication, and keeping systems updated go a long way towards closing these gaps.
The same principles that apply to PBX fraud prevention apply here too, since both hinge on removing the easy entry points that attackers rely on. A regular review of your system’s configuration is one of the simplest ways to stay ahead.
Protecting your business from business phone hacking doesn’t require a complete overhaul of your systems. It starts with visibility and a few consistent habits that catch problems before they escalate:
This is exactly where Town & Country Communications’ fraud monitoring and cost prevention service comes in. Rather than waiting for a bill to reveal a problem, our monitoring flags unusual activity as it happens, giving you the chance to act before costs spiral.
At Town & Country Communications, we’ve spent over 30 years helping businesses across Dorset, Hampshire and Wiltshire keep their phone systems secure and their costs predictable. Our fraud monitoring and cost prevention service is built to catch unusual activity early, so a security gap never turns into a shock invoice.
If you’d like to talk through your current setup, call us on 01202 514444 or get in touch through our contact form. And read more about us to learn what makes us different.
[1] BT, ‘BT Warns UK SMEs Are Primary Targets for Hackers as Only Three in Five Have Had Cyber Security Training’: https://newsroom.bt.com/bt-warns-uk-smes-are-primary-targets-for-hackers-as-only-three-in-five-have-had-cyber-security-training/
[2] Ofcom, ‘Tackling Scam Calls from Abroad’: https://www.ofcom.org.uk/siteassets/resources/documents/consultations/category-1-10-weeks/tackling-scam-calls-from-abroad/consultation—tackling-scam-calls-from-abroad.pdf?v=403699