Skip to content

Toll Fraud and Spoofed Calls: Securing Credit Union Phone Lines at the Carrier Level

DigitalWell
DigitalWell
Toll Fraud and Spoofed Calls: Securing Credit Union Phone Lines at the Carrier Level
10:25

Credit unions face two phone threats: toll fraud, where criminals use a hacked phone system to make expensive international calls, and spoofing, where they fake the credit union's number to scam members. Carrier-level controls stop both before the call completes.

TL;DR

  • Toll fraud costs money directly. Spoofing costs member trust, because the scam call appears to come from the credit union.
  • ComReg estimated that scam calls and texts cause over €300 million of harm in Ireland each year, and Irish operators had blocked 100 million scam calls by August 2025.
  • Controls in the carrier's network, such as call pattern monitoring, destination blocking and SBC protection, catch fraud a credit union's own phone system can't see.

What are toll fraud and caller ID spoofing?

Toll fraud is the unauthorised use of an organisation's phone system or SIP trunk to place calls, usually to premium-rate or high-cost international numbers, with the bill landing on the organisation. The criminal earns a share of the termination fees on those numbers. The victim pays the carrier.

 

Caller ID spoofing is the practice of faking the number shown to the person receiving a call. Fraudsters display a trusted number, such as a bank's or credit union's, so the member answers and believes the caller.

 

The two threats hit different people. Toll fraud hits the credit union's accounts. Spoofing hits members, and the credit union gets the phone calls, complaints and reputational damage afterwards.

How does a toll fraud attack on a phone system work?

Toll fraud follows a repeatable pattern, and most of it happens outside office hours. Knowing the sequence shows where each control fits.

 

  1. Scanning. Automated tools search the internet for exposed SIP endpoints, phone system admin portals and voicemail systems.
  2. Access. The attacker guesses or reuses weak passwords on extensions, voicemail PINs or admin accounts, or exploits an unpatched system.
  3. Testing. A few short calls check that the compromised line can reach international numbers.
  4. Pumping. Out of hours, often on a Friday night or bank holiday weekend, the attacker runs many simultaneous calls to high-cost destinations.
  5. Discovery. The organisation finds out when the bill arrives, or when the carrier's monitoring flags the traffic.

 

Step 5 is the one that decides the loss. A phone system with no carrier monitoring can run fraudulent calls for a whole weekend. A carrier watching call patterns in real time can block the traffic within minutes of it starting.

 

Legacy on-premise phone systems are the usual weak point. They often have default passwords, admin portals exposed to the internet, and no security updates once they reach end of support. DigitalWell's article on business voice security covers the phone system side in more depth.

Why does spoofing matter so much to a credit union?

Spoofing matters because a credit union's value to members is trust, and spoofed calls borrow that trust to steal from them. A member who gets a call showing their credit union's number, asking them to "confirm" a card or move money to a "safe account", has little reason to doubt it.

 

The scale in Ireland is large. In its 2023 consultation, ComReg estimated nuisance communications cause over €300 million of harm a year, with 62%, or €187 million, from scam calls. Since April 2024, ComReg has mandated a package of network interventions, and by August 2025 Irish operators had blocked 100 million scam calls, according to ComReg's own figures.

 

Two of those interventions matter directly to credit unions:

 

  • Fixed and mobile CLI call blocking stops calls from abroad that present an Irish number they shouldn't be using.
  • The Do-Not-Originate list lets organisations register numbers that only receive calls, such as a published member helpline. Any outbound call presenting one of those numbers is then blocked as a likely spoof.

 

ComReg's nuisance communications page lists the full set of measures. A credit union's carrier should be able to explain how each one applies to its numbers.

Which controls stop which attack?

Protection sits in two places: the credit union's own phone system and the carrier's network. The table shows which layer catches what.

 

Threat

Where it starts

Carrier-level control

Credit union-side control

Toll fraud via hacked phone system

Weak passwords or exposed admin portals on the PBX

Real-time call pattern monitoring, spend and concurrency limits, automatic blocking

Strong credentials, patched or replaced systems, no internet-exposed admin

Toll fraud via SIP trunk credentials

Stolen or guessed trunk credentials

SBC authentication, IP allow-listing, destination restrictions

Credential rotation, restricted trunk access

International revenue share fraud

Calls pumped to high-cost ranges

Blocking of high-risk destinations and premium ranges by default

Only enable the destinations the credit union needs

Outbound spoofing of the credit union's number

Fraudster's network, anywhere

CLI blocking, Do-Not-Originate list for inbound-only numbers

Register inbound-only numbers; tell members what the credit union will never ask by phone

Denial of service on voice

Floods of calls or SIP traffic

SBC rate limiting and traffic filtering

Capacity planning and failover numbers

 

The right-hand column is the credit union's job. The middle column is the carrier's, and it's the one a phone system alone can't provide, because the traffic has to be seen across the network to be spotted.

What does "carrier-grade" mean for a SIP trunk?

A carrier-grade SIP trunk is a voice connection supplied by a licensed operator that controls the switching, numbering and security of the calls end to end, with the monitoring and redundancy expected of a public telecoms network. The alternative is a reseller passing traffic onto someone else's network, where fraud controls depend on a supplier the credit union never deals with.

 

DigitalWell is a fully licensed telecoms operator in Ireland. Cian Maher, who leads its Intelligent Communications team, describes what that means in practice:

 

"We're an authorised, fully licensed telecoms operator in Ireland. From a voice point of view, we have our own soft switches. We have our own network, our own numbering." Cian Maher, Intelligent Communications, DigitalWell

 

DigitalWell's Intelligent Network combines secure SIP trunking with Ireland, UK & international numbering, SMS, and fraud protection for SIP trunks and session border controllers (SBCs). Because DigitalWell also owns the numbering, it can port a credit union's existing numbers onto its network and manage them as one inventory. The network carries over 100 million minutes of voice traffic, and DigitalWell is ISO 27001 certified.

 

For credit unions, the phone lines are also part of the outsourcing picture. The Credit Unions page covers the documentation pack, incident process and threat-intelligence sharing DigitalWell provides across its credit union customers, so an attack spotted at one can help protect the others.

What should a credit union ask its carrier?

Start with who actually runs the network. If the answer is "we resell another operator's service," ask who monitors the traffic and how quickly they'd act.

 

Then ask what happens at 2am on a Saturday if a line starts calling premium numbers in another country. The answer should name the monitoring, the blocking rule and the alert, and the carrier should act on it immediately.

 

Ask which international destinations are open on your trunks today. Most credit unions never need to call premium ranges or many overseas destinations, so those should be blocked by default.

 

Ask how your inbound-only numbers are protected against spoofing, and whether they're on the Do-Not-Originate list. Ask for the incident notification process in writing, because it feeds your own outsourcing and operational resilience records.

 

Finally, ask what the carrier does if your phone system itself is the weak point. A good carrier will tell you when an old PBX is a risk, and help replace it.

Key Takeaways

  • Toll fraud is a direct financial loss; spoofing is a member-trust problem. Credit unions need controls for both.
  • Carrier-level monitoring and blocking can stop an attack within minutes; without it, the first sign may be the next bill.
  • ComReg's CLI blocking and Do-Not-Originate list give credit unions a way to protect their published numbers from being spoofed.
  • A licensed operator with its own switching and numbering controls the whole call path, which a reseller can't.
  • Legacy on-premise phone systems are the usual way in, so replacing end-of-support kit is part of fraud prevention.

Frequently Asked Questions

Can our phone system's firewall stop toll fraud on its own?

It helps, but it can't see traffic patterns across the network. A carrier monitoring calls in real time can block unusual international traffic even if the phone system itself has been compromised.

What is the Do-Not-Originate list?

It's a ComReg-mandated list of numbers that should never appear as the caller on outbound calls, such as inbound-only helplines. Calls presenting a listed number are blocked as likely spoofs.

Who pays if our lines are used for toll fraud?

Often the customer whose system or credentials were compromised, depending on the carrier's terms, so check your contract. The speed of the carrier's detection and blocking decides how large that bill gets.

Does moving to a cloud phone system remove the risk?

It removes many legacy weaknesses, such as unpatched on-premise hardware, but credentials still need protecting. Carrier-level controls stay essential either way.

Can we keep our existing numbers when moving carrier?

Yes. DigitalWell has its own number ranges and direct porting capability, so existing numbers move onto its SIP network without a gap in service.

 

Want to know which of your lines are exposed? Ask DigitalWell's credit union team for a voice security review covering your trunks, numbers and phone system.

Share this post