Anyone suffered from Toll Fraud? (PBX Hacked)

I’d like to learn from anyone whose PBX was hacked and as a result suffered from toll fraud - or simply got a big $ invoice from their carrier at month end because someone did something bad on your PBX.

I would appreciate if you could post your details

I realize it can take some time to write out the details

If the moderators feel its appropriate (and safe) we would also like to post a top 10 list of how hackers got in.

I got charged for some unauthorized calls, due that I created sip peer account for a demo using weak password and I forgot to delete the acocunt after the demo

Most of the Asterisk hackrs are to weak password or use device name as password and username.

Asterisk provide may good tools we can use to enforce security like

acl configuration

sip permit and deny opton

disallow guest calls

context for guest calls or remote user

also fail2ban do a good job

Also carriers like twilio have a good tool for International Voice Dialing Geographic Permissions

