Establish the scope
Record suspicious call times, destinations and account identifiers. Determine whether the evidence concerns one extension, a trunk or administrative access. Preserve useful logs before making changes that could destroy the incident trail.
Contain chargeable access
Use the PBX and carrier's supported controls to restrict the affected identity or service. Keep legitimate critical communications available through a documented fallback. Do not rely solely on a handset reset when the secret may have been copied elsewhere.
Investigate the entry path
Review provisioning exposure, reused credentials, remote access and route permissions. Check for unexpected contacts, forwarding and new administrative changes. A rotated secret does not repair a compromised management account or vulnerable host.
Restore with narrower authority
Issue a new unique secret through a trusted provisioning path and review the allowed destinations. Verify the intended device, denied-call behavior and monitoring. If host integrity is uncertain, follow a broader incident-recovery process rather than declaring the system clean from one successful test call.
Sources & applicability
Primary references for the technical details above. Operational examples and planning checklists are VoIP.info editorial guidance.