TechNews logo

Voice Mail Hacking

Published Wed, 2006-03-15 21:11

The TELUS Corporate Security Fraud Management Centre detected almost 200 incidents of voice mail hacking in 2005.

After detecting a recent increase in the incidents of voice mail hacking, TELUS is encouraging customers to take several simple precautions to protect themselves from attempts to use this scam to make long distance calls at customers' expense. While businesses are usually the prime target for this type of fraud, residential customers should also take precautions.

The TELUS Corporate Security Fraud Management Centre detected almost 200 incidents of voice mail hacking in 2005 by scanning for sudden abnormal or unusual calling patterns. When voice mail fraud is suspected, TELUS' fraud
analysts contact the affected customer and work with them to shut the fraud down. TELUS estimates the centre saved customers a total of $1.5 million in fraudulent calls due to this scam alone in 2005.

The scam artists most often call a business after-hours and use its automated answering system to troll for vulnerable mailboxes. Experienced fraudsters sometimes recognize the system they are calling by its prompts and
know that system's default passwords, allowing them access to mailboxes with
unchanged passwords. They also try simple passwords such as 1234 and 1111.

Businesses with voice mail systems should take several steps to protect
themselves:

- Ensure employees change manufacturers' default passwords.
- Program voice mail systems to require passwords with at least six
characters.
- Encourage employees not to use easily-guessed passwords such as their
phone numbers, local number, or simple number combinations.
- Never set passwords to a telephone's local number when assigning a
phone to a new employee.
- Program voice mail systems to force users to alter their passwords
every 30 - 90 days.
- Remove unassigned mailboxes.
- Consider whether through-dialing is needed, and if it should be
disabled. Through dialing allows employees to call their mailboxes
from offsite and dial long distance on their work line. If this
feature is used, generate and monitor daily through-dialing reports to
ensure mailboxes are not being hacked.


Post new comment

The content of this field is kept private and will not be shown publicly.