A valid account can still be misused
Toll fraud can exploit stolen credentials, permissive routes or exposed applications to place unauthorized chargeable calls. Strong passwords matter, but they do not repair a dialplan that grants outside callers unrestricted outbound access.
Limit the reachable destinations
Assign extensions the calling permissions required for their roles. Review international, premium and forwarding behavior. Test denied destinations as well as allowed ones before activating a trunk, and verify the same restrictions on fallback routes.
Put controls at the carrier too
Arrange spend notifications, destination controls and service limits where the carrier supports them. Confirm who receives alerts outside office hours and how the account can be constrained quickly. A daily review may miss a short expensive incident.
Respond with evidence
If anomalous calling appears, preserve timestamps and call identifiers, constrain affected access and contact the carrier through the established channel. Rotate compromised credentials and investigate the entry point before restoring permissions. Keep incident communication independent of the affected PBX.
Sources & applicability
Primary references for the technical details above. Operational examples and planning checklists are VoIP.info editorial guidance.