Skip to content
Telecommunications

What to Do After a Business Phone System Breach

Marissa Olson
Marissa Olson

Modern business phone systems run over the internet. VoIP and Cloud PBX platforms share the same network infrastructure as your servers, email, and cloud software. That makes them a viable attack target — and one most businesses are not prepared to defend or recover from quickly.

This guide covers every phase of breach response: immediate containment, damage assessment, legal reporting requirements, long-term recovery, and prevention — including industry-specific considerations for healthcare and financial services businesses.

What Is a Business Phone System Breach?

A business phone system breach is any unauthorized access to a VoIP, PBX, or hosted phone platform that results in call interception, fraudulent usage, data theft, or service disruption. Attackers typically exploit weak passwords, unpatched firmware, misconfigured SIP trunks, or compromised user credentials to gain access.

Common attack types include:

  • Toll fraud — attackers use your phone system to place high-volume international calls billed to your account
  • Eavesdropping — call interception via unencrypted SIP traffic
  • Voicemail harvesting — accessing voicemail boxes to retrieve confidential client or employee data
  • Network pivoting — using phone system access as an entry point into your broader IT network
  • Denial of service — flooding your phone system to take it offline

The 2024 AT&T breach, which exposed call and text records of approximately 110 million customers, demonstrated that telecom infrastructure is a high-value target at every scale — from carriers down to individual business phone systems.

What Are the First Steps to Take Immediately After a Phone System Breach?

The first steps are to stop active damage before investigating its full scope. Partial containment enacted immediately produces better outcomes than waiting for a complete picture of the breach.

Take these actions within the first hour:

  • Disable compromised user accounts — suspend any account showing unusual activity
  • Reset all administrative passwords — prioritize SIP trunk credentials, admin portals, and voicemail PINs
  • Block suspicious outbound call destinations — particularly international prefixes your business does not use
  • Restrict or disable international dialing — if your business has no operational need for international calls, turn this off entirely
  • Contact your VoIP or hosted phone provider — they can place call blocks, flag fraudulent traffic, and pull system logs you cannot access directly
  • Isolate affected devices — IP phones or softphone endpoints showing unusual behavior should be disconnected from the network

If toll fraud is actively occurring, time is the primary cost factor. Attackers can generate thousands of dollars in fraudulent call charges within hours by routing calls through premium-rate international numbers.

How Do I Assess the Damage After a Phone System Breach?

After containment, the next step is a structured damage assessment that documents exactly what was accessed, for how long, and what data or services were affected. This documentation is required for insurance claims, regulatory reporting, and legal defense.

Collect the following:

  • Call detail records (CDRs) for the period surrounding the breach — look for unusual call volumes, destinations, or durations
  • System access logs — identify when unauthorized access occurred and which accounts were used
  • Voicemail access logs — determine if voicemail boxes were accessed by unauthorized parties
  • Network traffic logs — check for lateral movement from the phone system into other network segments
  • Billing records — document all fraudulent charges with timestamps

Work with your VoIP provider and IT team simultaneously. Phone system logs and network logs must be cross-referenced to establish a complete timeline.

Document everything in writing. The FTC's data breach response guidance for businesses explicitly states that organizations should secure and preserve all evidence of the breach before beginning remediation steps that could overwrite logs.

What Are the Legal and Regulatory Reporting Requirements After a Phone System Breach?

Reporting requirements depend on your industry, the type of data exposed, and the states where your customers and employees are located. Failing to report within required timeframes carries significant financial penalties.

General requirements:

  • FTC Safeguards Rule — businesses subject to the FTC Act must notify the FTC if a breach affects 500 or more customers in a single event. The FTC requires notification within 30 days of discovery.
  • State breach notification laws — all 50 U.S. states have breach notification laws. California's CCPA, for example, requires notification to affected residents without unreasonable delay, and no later than 45 days after discovery in most cases.

Industry-specific requirements:

  • Healthcare (HIPAA) — if your phone system breach exposed Protected Health Information (PHI) — including voicemails, call records, or any audio containing patient data — the HIPAA Breach Notification Rule applies. Covered entities must notify affected individuals within 60 days of discovery, notify the Secretary of Health and Human Services, and notify local media outlets if the breach affects more than 500 residents of a state or jurisdiction.
  • Financial services (GLBA) — the Gramm-Leach-Bliley Act Safeguards Rule requires financial institutions to notify the FTC within 30 days when a breach involves the information of 500 or more customers. Individual customer notification is also required.
  • Payment card data (PCI DSS) — if call recordings or voicemails captured cardholder data, PCI DSS Requirement 12.10 mandates immediate notification to your acquiring bank and the relevant card brands.

Small and mid-sized businesses frequently underestimate their reporting obligations because they assume breach notification rules apply only to large enterprises. They do not. Regulatory agencies assess penalties based on the nature of the exposed data, not the size of the organization.

How Do I Notify Affected Customers and Employees?

Notification should be factual, timely, and specific about what information was exposed and what actions affected individuals should take. Vague or delayed notification increases regulatory and legal exposure.

A breach notification should include:

  • A plain-language description of what happened
  • The date the breach occurred and the date it was discovered
  • The specific types of information that were accessed or exposed
  • What the business has done to contain the breach
  • What affected individuals should do to protect themselves
  • A contact point for questions

Do not speculate about the cause or scope in early notifications. Update affected parties if new information emerges. Work with legal counsel before sending notifications when regulatory requirements are involved.

What Are the Financial Impacts of a Phone System Breach on Small and Mid-Sized Businesses?

The direct financial impact on SMBs includes fraudulent call charges, regulatory fines, legal fees, and remediation costs. Indirect costs include lost productivity, damaged client relationships, and increased insurance premiums.

Specific cost categories to anticipate:

  • Toll fraud charges — industry estimates place average toll fraud losses for businesses at thousands to tens of thousands of dollars per incident, depending on how quickly the fraud is detected
  • Regulatory fines — HIPAA penalties range from $100 to $50,000 per violation, with an annual maximum of $1.9 million per violation category
  • Breach notification costs — printing, mailing, and credit monitoring services for affected individuals add up quickly at scale
  • IT forensics and remediation — professional incident response services for SMBs typically range from $5,000 to $50,000 depending on complexity
  • Reputational impact — clients in healthcare, legal, and financial sectors routinely terminate vendor relationships following a confirmed breach

Many SMBs assume their general liability insurance covers phone system fraud. It typically does not. Cyber liability insurance with specific telecom fraud coverage is a separate policy consideration.

How Do I Recover and Rebuild After a Phone System Breach?

Recovery involves three parallel tracks: restoring normal operations, completing regulatory obligations, and implementing security changes that prevent recurrence. Most SMBs focus only on the first track and experience repeat incidents.

Operational recovery:

  • Restore phone services using clean, fully-patched configurations
  • Reissue credentials to all users — do not reactivate compromised accounts with reset passwords; create new accounts entirely
  • Verify call routing, voicemail, and auto-attendant settings have not been altered by the attacker

Regulatory and legal completion:

  • File all required breach notifications within applicable deadlines
  • Retain documentation of the breach timeline, containment actions, and notifications for a minimum of five years (required under several state laws and HIPAA)
  • Respond to any regulatory inquiries with documented evidence of your response process

Security overhaul:

  • Enable end-to-end encryption for SIP traffic using TLS and SRTP protocols
  • Implement multi-factor authentication on all admin portals and user accounts
  • Conduct a full audit of SIP trunk configurations, call routing rules, and international dialing permissions
  • Set real-time alerting thresholds for unusual call volumes or destinations
  • Schedule quarterly security reviews of your phone system configuration

Rebuilding client trust requires consistent communication over time, not a single post-breach email. Businesses that demonstrate specific security improvements — rather than general reassurances — retain more clients following a breach.

How Can I Prevent Future Phone System Breaches?

The most effective prevention measures address the three most common attack vectors: weak credentials, unencrypted traffic, and unrestricted dialing permissions.

Credential security:

  • Enforce strong password policies on all SIP accounts, admin portals, and voicemail boxes — default voicemail PINs (such as 0000 or 1234) are a primary target
  • Require multi-factor authentication for all administrative access
  • Audit user accounts quarterly and remove accounts belonging to former employees immediately upon offboarding

Network and traffic security:

  • Use TLS (Transport Layer Security) to encrypt SIP signaling
  • Use SRTP (Secure Real-Time Transport Protocol) to encrypt call audio
  • Place your phone system on a dedicated VLAN, separate from general business network traffic
  • Configure your session border controller (SBC) to restrict traffic to known IP ranges

Call permission controls:

  • Disable international dialing for all users who do not require it
  • Set per-account and system-wide call spend limits with automatic alerts when thresholds are approached
  • Block premium-rate number ranges at the system level

Ongoing monitoring:

  • Review call detail records weekly for anomalies
  • Work with your VoIP provider to enable real-time fraud detection if available on your platform

Businesses using managed telecom services can offload continuous monitoring and configuration audits to their provider, which reduces the internal IT burden while maintaining consistent security oversight.

What Should SMBs Do Differently Than Large Enterprises After a Phone System Breach?

Small and mid-sized businesses face the same regulatory obligations as large enterprises but have fewer internal resources to manage response, notification, and remediation simultaneously. Prioritization and outside support are critical.

Key differences in SMB breach response:

  • Lean on your VoIP provider first — enterprise IT teams have internal forensics capabilities; SMBs should immediately engage their phone service provider for log access and fraud containment, as this is faster and less expensive than independent forensics
  • Contact your cyber insurance carrier early — many policies include incident response support, legal counsel referrals, and breach notification assistance at no additional cost if you report promptly
  • Document every action taken — regulators assess SMBs on the reasonableness of their response, and written records of each decision and action demonstrate good-faith effort
  • Do not attempt to handle HIPAA or GLBA notification independently — the cost of a compliance attorney for breach notification is significantly lower than the cost of a regulatory fine for improper notification

SMBs are frequently targeted precisely because attackers assume smaller organizations have weaker security and slower detection. A documented incident response plan — even a simple one — substantially reduces both the likelihood and the cost of a breach.

Share this post