<?xml version="1.0" encoding="UTF-8"?>
<!--Generated by Squarespace Site Server v5.0.0 (http://www.squarespace.com/) on Fri, 05 Dec 2008 08:40:52 GMT--><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><title>Telecom Fraud</title><link>http://www.abilitablog.com/telecom_fraud/</link><description></description><copyright></copyright><language>en-US</language><generator>Squarespace Site Server v5.0.0 (http://www.squarespace.com/)</generator><item><title>Telecom Fraud: It Can Happen To You</title><dc:creator>Abilita Blogsite</dc:creator><pubDate>Fri, 05 Oct 2007 13:50:54 +0000</pubDate><link>http://www.abilitablog.com/telecom_fraud/2007/10/5/telecom-fraud-it-can-happen-to-you.html</link><guid isPermaLink="false">165011:1614737:1295576</guid><description><![CDATA[<em><p><span class="full-image-float-left"><img style="width: 112px; height: 130px" alt="office-pic-1.jpg" src="http://www.abilita.com/dmeades//images/office-pic-1.jpg" /></span></p><p>&nbsp;</p><p style="text-align: left" align="left">&nbsp;</p><p style="text-align: left" align="left"><strong><span class="sizeGreater20">Doug Meades</span></strong><br /><em>Managing Consultant<br />Abilita Telecom Consultants</em><br /><a href="mailto:dmeades@abilita.com">dmeades@abilita.com</a></p><p style="text-align: left" align="left">&nbsp;</p><p style="text-align: left" align="left"><em>It&rsquo;s late evening on a holiday weekend and the security monitoring system at your telecom provider has identified possible telecom fraud activity occurring at your site. This is no amateur operation, professional hackers are passing through your PBX voicemail system and routing international long distance calls on a large scale. In effect they are operating an outbound call centre at your company&rsquo;s expense.</em></p></em><p><em>The above scenario actually happened to one of our clients! Thieves had broken into their PBX and Voice-Mail system and were placing calls as though they originated in the office. As their telecommunications advisor, I was notified immediately by the telecom provider and we were able to take action to shut the intruders out. </em></p><p>Yes, this <strong>can</strong> happen to you and it could be costly but here are some things you can do to protect your business from this type of fraud: <br /></p><p><strong>1. </strong><strong>Know The Exposure<br /></strong></p><p>When hackers break into your phone system you are responsible for the bills resulting from the fraud. Someone is going to pay for those calls and it won&rsquo;t be the telephone company. Understand where you are most vulnerable:<br /></p><p>&middot; <strong>Phone System</strong><br />Intruders seek out passwords, authorization numbers and access codes by hacking into your system, snooping around offices, calling businesses and even rummaging through dumpsters. Compromised numbers are sold or traded in the phone fraud underworld with businesses like yours paying for the calls.</p><p>&middot; <strong>Voice Mail</strong> <br />If your system provides dial-out or dial-through capability you are exposed to fraudulent calls. By transferring out of a system, intruders can place long distance calls. They will also look for default codes on mailboxes so they can change the codes and control the boxes. </p><p>&middot; <strong>Call Forwarding Scam</strong><br />You are requested by someone outside your company to dial a two digit code preceded or followed by the * or # key (such as *72), and then an 800 number. When you dial the number you are not connected to anyone. What has happened is you have actually programmed your phone to forward your calls to a long distance operator. The con artist then calls your number which is forwarded to the long distance operator, calls anywhere they wish and the bill goes back to you.</p><p>&middot; <strong>Remote</strong><strong> Access Port</strong><br />The remote access port is used for administration and support of your PBX. An intruder will often start by trying manufacturers default passwords and if unsuccessful, they use computer-generated passwords until they find a password that works. </p><p>&middot; <strong>Direct Inward System Access (DISA)</strong><br />A DISA permits convenient access to a PBX from a phone outside the business via an 800 number or other special access number. This feature allows your traveling staff to make long distance calls through the PBX and have the call charged to the company. The DISA gives criminals the same opportunity, as well as the chance to set up a call-sell operation at your company&rsquo;s expense. <br /></p><p><strong>2. </strong><strong>Protect Yourself <br /></strong>Telecom fraud continues to increase and the cost of doing nothing is going up. Here are some things you should be doing to protect yourself: </p><p>&middot; Change the security feature settings and passwords on your phone system from the default settings </p><p>&middot; Change passwords on a regular basis and protect these passwords and access codes from unauthorized use</p><p>&middot; Don&rsquo;t publish the remote access phone numbers that connect callers to your voice mail system</p><p>&middot; Program your system to terminate access after the third invalid attempt</p><p>&middot; Remove mailboxes that are no longer in use</p><p>&middot; Immediately deactivate the access codes and voice mail passwords of departing employees</p><p>&middot; Monitor your monthly phone bills</p><p>&middot; Perform regular audits of your telephone environment including privileges and restrictions</p><p>&middot; Physical security &ndash; restrict access to equipment</p><p>&middot; Establish policies and procedures to reduce your risk</p><p>3. <strong>Take Action </strong><br />If you become a victim of telecom fraud:</p><p>&middot; Shut your system down immediately</p><p>&middot; Call your equipment supplier</p><p>&middot; Advise your staff of the situation </p><p>&middot; Call the police and report the incident</p><p>The telephone remains the lifeline of most small business operations today. Arming yourself with knowledge and implementing best practices is your best protection against intrusion to your business. </p><p><strong>Doug Meades</strong> is&nbsp;Managing Consultant at Abilita Telecom Consultants.<br />Doug can be reached at (519) 432-1556 or <a href="mailto:dmeades@abilita.com">dmeades@abilita.com</a>.</p><p><strong>Abilita</strong> is a full service telecom consulting firm helping clients across North America achieve greater cost efficiencies and improved performance for all of their telecommunications needs - voice, data and wireless.</p><div style="text-align: center" align="center"><!--
                  [if !mso]--></div><p><table style="width: 725px" cellspacing="0" cellpadding="0"><tbody><tr><td><div style="text-align: center" align="center"><span class="sizeGreater20"><!--
                  [endif]--></span></div></td></tr></tbody></table></p>]]></description><wfw:commentRss>http://www.abilitablog.com/telecom_fraud/rss-comments-entry-1295576.xml</wfw:commentRss></item></channel></rss>