The Phone Bill That Arrives on a Monday Morning
It usually happens over a long weekend. A business in Kingston closes on Friday afternoon, and by Monday the SIP trunk has generated thousands of dollars in international calls — to Cuba, West Africa, Eastern Europe, or premium-rate numbers nobody in the company has ever dialled. The business owner opens their phone bill and assumes it's a mistake. It isn't.
This is SIP trunk toll fraud, and it is one of the most common and costly cyber threats facing Jamaican businesses that run VoIP phone systems. Unlike most cyberattacks, it doesn't encrypt your files or steal your data — it just quietly drains your account while everyone is asleep or away for the holiday.
The good news: toll fraud is largely preventable if you know what to look for and how your SIP trunk should be configured.
How Toll Fraud Actually Works
Your SIP trunk is an internet connection that carries voice calls. Like any internet-facing service, it has a port (typically port 5060) that accepts connection attempts. Automated bots run continuously across the internet, scanning for open SIP ports and then trying lists of common usernames and passwords until they find one that works.
Once attackers gain access to your SIP credentials, they don't stop to celebrate — they immediately begin routing calls to international premium-rate numbers that they own or control. Every call that connects earns them a revenue share from the receiving carrier. The calls can stack up fast: fifty concurrent channels running for eight hours generates enormous volumes at international rates.
The attackers are typically not in Jamaica. They are running automated scripts from servers in Eastern Europe, Southeast Asia, or West Africa. They have no specific interest in your business — you are simply an unlocked door in a neighbourhood they sweep every day.
Why Jamaican Businesses Are Frequently Targeted
Jamaica sits at an interesting intersection for toll fraud. The country has strong business ties to the United States, Canada, the United Kingdom, and other Caribbean islands, which means Jamaican SIP trunks legitimately make international calls. Fraudulent international traffic therefore blends in more easily than it might for a business that never dials outside the island.
Several other factors increase exposure:
- Default PBX passwords. Many on-premise IP-PBX systems are installed with default admin credentials and never changed. Attackers know every default password for every common PBX brand.
- Open SIP registration. Some configurations allow any IP address to attempt to register a SIP extension, rather than locking down to known locations.
- No real-time monitoring. Most businesses have no alert in place that fires when call spend crosses an unusual threshold. The fraud runs undetected until the invoice arrives.
- Unmonitored after-hours windows. Attacks are timed to run at 2am on a Saturday precisely because no one is watching.
Warning Signs Your SIP Trunk May Already Be Compromised
If any of the following appear on your phone bill or in your call logs, treat them as urgent red flags:
- Calls to international destinations your business has no relationship with — particularly West African, Eastern European, or Pacific island numbers
- A large number of short-duration calls (under 10 seconds) to the same number or range of numbers — these are often test calls probing for a working route
- High call volumes between midnight and 6am on any day
- Your trunk reported as busy or congested during normal business hours when call volume shouldn't be unusual
- A monthly bill that is significantly higher than the same period last year with no change in your team size or call habits
If your SIP provider cannot give you itemised, real-time call records on demand, that is itself a problem. You should always be able to see exactly what calls are in progress and what has been billed.
5 Controls That Stop Toll Fraud Before It Starts
Toll fraud is a preventable problem. The following five controls, applied together, close the vast majority of attack vectors:
- 1. Use strong, unique SIP credentials. Your SIP username and password should never be a word found in a dictionary and should be at least 16 characters long. Avoid anything that resembles your company name, phone number, or business address.
- 2. Enable IP-based authentication. Restrict SIP registration so that only your specific IP address or address range is permitted to authenticate. If your office has a static IP — which any serious business internet connection should provide — this single control eliminates almost all automated brute-force attacks.
- 3. Apply geo-blocking. If your business only calls Jamaica, the US, Canada, and the UK, block all other international destinations at the SIP trunk level. There is no legitimate reason a call from your number should be terminating in Guinea-Bissau.
- 4. Set a spend cap and alert. Configure a hard limit on daily or monthly call spend that triggers an alert — or better, cuts off new calls — when exceeded. Even a generous cap like five times your average daily spend will catch fraud within hours rather than days.
- 5. Disable international calling on extensions that don't need it. Your receptionist extension may not need to dial internationally. Lock it down. Only the extensions that legitimately make overseas calls should have that permission.
What Your SIP Provider Should Be Doing on Your Behalf
These controls are not solely the customer's responsibility. A licensed SIP trunk provider — one that owns its own network infrastructure rather than reselling capacity from a third party — should have fraud detection built into the platform at the carrier level.
That means real-time traffic analysis that flags abnormal call patterns, the ability to suspend a trunk or destination within minutes of a suspected compromise, and proactive alerts to your account before charges accumulate. It also means being reachable when you need to act fast. A support team that works business hours only and closes on weekends offers no protection during the exact window when toll fraud typically runs.
When evaluating any SIP provider, ask directly: What happens if my account is compromised at 3am on a Sunday? Who calls me, and how fast can the traffic be stopped? If the answer is vague, that provider is not the right partner for a business that takes its phone system seriously.
Review Your SIP Trunk Security With WOCOM
WOCOM is a licensed telecommunications provider in Jamaica — not a reseller. We own the infrastructure your calls run across, which means we can act at the network level, not just at the application layer, when something looks wrong. Our team can review your current SIP trunk configuration, identify open exposure points, and recommend the right combination of IP restrictions, geo-blocks, and spend controls for your specific business.
Whether you are running a single-location business in Montego Bay or managing call traffic across multiple sites in Kingston, the conversation starts the same way: with a clear picture of how your trunk is currently configured and what it would take to harden it.
Contact WOCOM today to schedule a SIP trunk security review. Call us at 876-300-1911, WhatsApp us, or visit wocomja.com to get started. Do not wait for an unexpected bill to find out your trunk was exposed.
Continue exploring
Ready to upgrade your communications?
Talk to our team about the right solution for your business.
Book a Demo Contact SalesEverett Kildare is WOCOM's voice and infrastructure specialist, with more than 25 years of experience designing and running carrier-grade voice, SIP and virtualization infrastructure. Holding a BSc in Information Technology, he has built, secured and migrated phone systems for businesses of every size. Everett writes WOCOM's technical coverage of SIP trunking, cloud PBX, contact centres, business continuity and migration.