VoIP.info Guide

Responding to a compromised VoIP extension

Constrain the affected identity and trace its permissions before returning it to service.

Reviewed 2026-09-07Foundational

Establish the scope

Record suspicious call times, destinations and account identifiers. Determine whether the evidence concerns one extension, a trunk or administrative access. Preserve useful logs before making changes that could destroy the incident trail.

Contain chargeable access

Use the PBX and carrier's supported controls to restrict the affected identity or service. Keep legitimate critical communications available through a documented fallback. Do not rely solely on a handset reset when the secret may have been copied elsewhere.

Investigate the entry path

Review provisioning exposure, reused credentials, remote access and route permissions. Check for unexpected contacts, forwarding and new administrative changes. A rotated secret does not repair a compromised management account or vulnerable host.

Restore with narrower authority

Issue a new unique secret through a trusted provisioning path and review the allowed destinations. Verify the intended device, denied-call behavior and monitoring. If host integrity is uncertain, follow a broader incident-recovery process rather than declaring the system clean from one successful test call.

Sources & applicability

Primary references for the technical details above. Operational examples and planning checklists are VoIP.info editorial guidance.