VoIP.info Guide

Detect suspicious calls before the next bill

Build actionable call alerts from destinations, timing, concurrency and provider evidence.

Reviewed 2026-09-07Operational guidance; Asterisk 22 / FreePBX 17 where applicableIntermediateDocumentation based · not lab tested

Baseline the business, not a universal threshold

Record normal calling hours, destination groups, trunk concurrency and expected high-volume workflows. A seasonal sales campaign may be legitimate; one quiet extension calling an unusual destination overnight may need immediate attention. Neither duration nor geography alone proves fraud.

Use a small set of understandable alerts with an owner and response window. Combine unusual destination, increased attempts, cost exposure and account history. The goal is a decision someone can act on, not a dashboard full of red counters.

Join PBX and provider evidence

PBX call-detail records may split transfers or forwarded calls into several legs. Correlate them with channel events and provider records before treating each row as one customer conversation. Clock synchronization and a documented timezone make this much easier. Failed attempts can matter even when they produce no billable duration.

Monitor the path that creates the charge: a compromised forwarding destination or integration can generate outbound calls without a new desk-phone registration. Track changes to permissions and forwarding rules near the suspicious activity.

Make containment predictable

Define who can restrict a trunk, disable a credential and contact the provider. Preserve the relevant evidence with limited access before routine rotation removes it. Avoid broad public sharing of numbers, credentials or recordings. Follow the incident procedure and retain a path for legitimate urgent calls.

Afterward, confirm the exposed credential or route has been corrected and review why the alert did or did not fire. Test the alert process with approved synthetic records or a controlled permitted scenario. Do not generate chargeable suspicious traffic merely to make an alarm go off.

Sources & applicability

Primary references for the technical details above. Operational examples and planning checklists are VoIP.info editorial guidance.

Examples require adaptation to your topology. No live PBX or hardware testing is claimed.