Private branch exchange (PBX) phone systems, which are integral to managing and routing calls within organisations, are increasingly being targeted by cyber-criminals due to improper configurations, according to the NCSC.
Poorly configured PBX systems could become accessible to remote attackers through their internet connections, which opens the door to various malicious activities.
One of these is “dial-through fraud,” where threat actors reroute calls to costly overseas numbers or establish premium-rate lines.
Attackers could also compromise the systems remotely and exploit them in denial-of-service (DoS) attacks against other targets.
In response to the emerging threats, the NCSC released new guidance aimed to help organisations, regardless of whether they are managed through cloud-based services or maintained on premises.
A spokesperson of the NCSC’s Economy and Society Team emphasised the importance of implementing robust security measures, starting with the use of strong passwords and multi-factor authentication (MFA) to safeguard administrator accounts. Additionally, she advised organisations to carefully review PBX contracts to ensure they understand their responsibilities and liabilities regarding system security and administration.
Recommended reading
- Cyber Threat Actors are ‘Living Off The Land,’ says NCSC
- NCSC Warns Ransomware Threat to Rise with AI
- What is the Current Data Telling Us About Cyberattacks?
“Your organisation – as the PBX owner – is responsible for the security and administration of your phone system. You should thoroughly examine any PBX contract (or consult with your legal/financial experts if necessary) before signing, to protect yourself from unintended financial consequences,” she said.
“For example, you may decide that you need to limit the types of calls staff make, or restrict the ability to forward calls to an off-premises number. If you’re using a managed service, then attacks as a result of misconfiguration are the responsibility of the provider, something to keep in mind if you’re pressured into taking out insurance to defend against attacks that should be covered by your managed service provider.”





