CloudSEK has documented 1,869,521 session initiation protocol (SIP) authentication attempts and 89,465 attempted calls against a controlled internet-facing business telephony honeypot during an 18-day study from May 4 through May 22, 2026. The Bengaluru-based cybersecurity company recorded 15.18 million telemetry events, equivalent to about 3.79 million distinct SIP requests, from 323 source IP addresses. The activity moved in a recognisable sequence from extension enumeration and password spraying to credential replay and suspected international toll fraud, with United Kingdom destinations accounting for more than half of all attempted calls. For businesses, the findings show that exposed phone systems are no longer merely a technical nuisance but a direct route to communications disruption, fraudulent call charges, credential abuse and broader network risk.
Why do CloudSEK’s 1.87 million SIP credential attempts change the risk calculus for business phone systems?
The most important finding is not simply the volume of hostile traffic. It is the degree to which the activity resembled a repeatable industrial process. Attackers first searched for an accessible Session Initiation Protocol service, identified likely telephone extensions, submitted large numbers of password combinations and then tested whether the system could route calls to selected international destinations.
That progression matters because it connects what many organisations treat as harmless internet scanning to a potential financial outcome. An exposed private branch exchange, commonly known as a PBX, is not just another server receiving unwanted traffic. It can provide access to outbound telephone capacity, internal communications and configuration information that may have immediate monetary value.
CloudSEK’s honeypot recorded approximately 9.34 million reconnaissance and enumeration events, representing 61.5% of the real-event population. Attackers submitted 1.85 million unauthenticated registration probes before escalating into credential-bearing requests. The breadth of this activity suggests that systems are being discovered and tested continuously rather than being selected only after a company becomes the subject of a targeted intrusion.
This changes the executive risk calculation. Telephone infrastructure often sits between information technology, telecom procurement, facilities management and external service providers. That fragmented ownership can leave unclear responsibility for password rotation, exposure management, call-spend monitoring and incident response. Cybercriminals tend to appreciate organisational ambiguity. It saves them the trouble of finding a technically sophisticated weakness when a neglected operational system will do.
The financial consequences may also emerge differently from a conventional data breach. A compromised PBX can generate international calling charges quickly, while a company may discover the loss only after receiving an unusual carrier invoice or a telecom expense alert. This makes prevention and real-time cost controls just as important as traditional endpoint detection.

How did attackers move from extension discovery to password spraying and attempted toll fraud?
The observed attack chain began with the predictable structure of business telephone systems. Unlike many enterprise applications, where account names can vary widely, PBX users are frequently represented by short numeric extensions such as 100, 201, 1000 or 2001. Attackers can therefore test the likely account space systematically without needing employee names or email addresses.
CloudSEK recorded attacks against 29,433 distinct numeric extension identities. The most frequently targeted extensions were common three-digit and four-digit combinations, demonstrating that the operators understood how corporate dial plans are typically organised. This was not a broad attempt to log in as administrator or root. It was an effort to find any working telephone extension that could provide access to calling functions.
Once the extensions had been mapped, the attackers submitted 1,869,521 authentication attempts containing full SIP Digest responses. Of these, 1,842,267 were registration attempts and 27,254 were associated with attempted calls. The distinction is operationally important because it shows that the activity was not confined to account discovery. Some traffic had already advanced to the stage of testing call authorisation.
The campaign operated throughout the day, without a meaningful business-hours pattern. Activity peaked on May 11, when the sensor recorded more than 4.15 million telemetry events, but a lower-volume stream persisted outside the peak period. The round-the-clock distribution points to unattended automation rather than operators manually testing individual systems.
The attack software also rotated apparent device identities while preserving underlying behavioural patterns. Requests claimed to originate from FreePBX systems, Cisco devices, Polycom phones, Avaya equipment and other legitimate products. These identifiers can be changed easily, making them poor evidence of the real source. More durable indicators appeared in repeated registration formats, credential-handling behaviour and dial-plan testing routines.
For defenders, this means security monitoring must identify sequences rather than isolated events. A few failed telephone logins may look inconsequential. Thousands of registration probes followed by password attempts, international call requests and repeated prefix changes represent a clear monetisation pipeline.
Why does the recovered password dictionary weaken confidence in complexity-only security policies?
CloudSEK was able to determine the plaintext password used in 96.09% of the captured credential attempts because the honeypot retained the complete authentication material required for analysis. The study produced a recovered dictionary containing 277,632 unique passwords and nearly 1.5 million distinct extension-password combinations.
The scale of that dictionary is significant, but its composition is more strategically important. The attackers were not relying solely on obvious passwords such as short number sequences or familiar administrator variants. The list contained medium-complexity and high-complexity strings that may have originated from device defaults, previously exposed credentials, customer-specific configurations or wordlists assembled from earlier attacks.
This weakens the assumption that a password is safe merely because it contains uppercase letters, lowercase letters, numbers and symbols. Complexity can reduce the effectiveness of simple guessing, but it offers much less protection when the exact credential has already entered an attacker’s dictionary.
The attack pattern was also broad rather than concentrated around a handful of popular passwords. Even the most frequently tested password appeared only hundreds of times across almost 1.8 million recoverable attempts. That relatively flat distribution indicates that the operators were spreading an extensive dictionary across many extensions, hoping to encounter any reused or default credential.
Businesses should therefore treat uniqueness and exposure history as separate security requirements from complexity. SIP credentials should not be reused across extensions, offices, customer environments or administrative systems. Credentials supplied during installation should be replaced, while secrets associated with former employees, decommissioned phones or migrated systems should be invalidated rather than left dormant.
Managed service providers and telecom integrators face a particularly important challenge. Repeated installation templates can create systemic risk when the same credential patterns are used across multiple customers. One exposed configuration can then help attackers test unrelated organisations that share the same deployment practices.
What does the concentration of United Kingdom call attempts reveal about toll-fraud economics?
Of the 89,465 attempted calls recorded by the honeypot, 47,273 targeted United Kingdom numbers. The activity was concentrated within a relatively small collection of rural and Northern Ireland ranges rather than being distributed evenly across ordinary consumer and business destinations.
The pattern was consistent with International Revenue Share Fraud, a model in which criminals direct compromised telephone systems to numbers that generate termination or revenue-sharing payments. The victim organisation pays the carrier charges, while participants controlling or renting the destination numbers may receive part of the resulting revenue.
Attackers also tested multiple ways of formatting the same telephone number. They alternated between international access prefixes, outbound routing codes, plus signs and unprefixed numbers to determine which version a PBX dial plan would accept. One United Kingdom destination was tested with more than 80 prefix variations.
This is a critical operational detail. A company may believe that international calling is restricted because one obvious format has been blocked, while alternative prefixes remain usable. Effective controls must normalise telephone numbers before applying policy so that the same destination cannot bypass restrictions merely by being written differently.
The activity also demonstrates why authentication controls alone cannot contain the financial risk. Even a successful login should not automatically provide unrestricted international or premium-rate calling. Outbound permissions should reflect the employee’s role, office location and genuine business requirements.
Telecom cost governance becomes part of cybersecurity in this environment. Per-extension limits, trunk-level spending ceilings, destination allowlists and immediate alerts for abnormal call volumes can reduce the loss even when preventive security fails. A chief financial officer may not think of the PBX as a cyber asset, but an unexpectedly creative phone bill has a way of improving cross-functional awareness.
Why are hosting providers and spoofed device identities central to the SIP attack model?
Almost all source-attributed activity came from server-hosting or datacentre infrastructure. CloudSEK calculated that 99.8% of attributed events originated from hosting ranges, while 93.5% of the source IP addresses had already appeared on third-party abuse lists.
The traffic was also highly concentrated. OVH SAS accounted for more than 6.55 million events from 44 addresses, while a single adjacent block of addresses produced over 5.17 million events. Other observed networks included infrastructure operated by Hetzner Online GmbH, Scaleway SAS and IONOS SE.
This does not establish that the hosting companies knowingly supported the activity. Low-cost servers can be rented, compromised, discarded and replaced rapidly, making public cloud and hosting infrastructure attractive to automated attackers. The concentration nevertheless creates an opportunity for enterprises to apply network-level controls when their telephone systems have no legitimate reason to accept registration traffic from arbitrary datacentre ranges.
Geographic and autonomous system filtering should be used carefully because aggressive blocking can disrupt genuine remote workers, carriers and hosted-telephony partners. However, most businesses already know which providers, regions and session border controllers should communicate with their PBX. Restricting the service to those expected peers is substantially safer than exposing port 5060 to the entire internet.
Spoofed device identities reinforce the need for behaviour-based detection. An attacker can claim to be using a Cisco or Avaya phone with little effort. It is harder to conceal repeated extension enumeration, unusual registration contacts, credentials associated with foreign authentication realms and mechanical rotation of international calling prefixes.
The wider lesson extends beyond telephony. Attackers increasingly use inexpensive hosted infrastructure to turn credential testing into a scalable service. Enterprises that rely exclusively on device names, static IP blocklists or one-time password changes will remain behind an operation that can rotate its infrastructure faster than a manual security process can respond.
What should chief information security officers change in PBX controls and telecom governance?
The strongest defensive measure is to stop exposing SIP registration directly to the open internet. Access should be restricted to trusted carrier addresses, known office networks, virtual private networks or session border controllers that can enforce authentication, rate limits and traffic inspection.
Rate limiting and temporary account lockouts can reduce high-volume password spraying, but these controls must be calibrated so that attackers cannot use them to deny service to legitimate extensions. Monitoring should consider attempts across the entire system because password spraying often keeps the number of failures against each individual account deliberately low.
Outbound dial plans should deny international, premium-rate and unnecessary destinations by default. Organisations with legitimate overseas calling requirements can use approved destination lists or require explicit authorisation for higher-risk ranges. Dial-plan rules should account for alternate prefixes and normalise destination numbers before evaluating them.
Unique, high-entropy credentials remain necessary, but they should be combined with checks against breach-derived and attacker-observed dictionaries. Password rotation is particularly important after telecom migrations, acquisitions, office closures and changes in managed service providers, when old credentials can persist unnoticed.
Businesses should also introduce financial containment. Real-time call-spend alerts, per-user limits, trunk-level ceilings and automatic suspension of anomalous traffic can prevent a successful compromise from becoming an open-ended liability. Carrier contracts and incident procedures should establish who can block routes outside normal working hours.
Responsibility must be assigned clearly. Security teams should own exposure and monitoring standards, telecom teams should control dial plans and carrier relationships, procurement should impose requirements on external providers, and finance should receive alerts when call costs depart from established patterns. A control owned by everyone is usually a control operated by no one.
How should executives interpret the study’s single-honeypot scope without underestimating the threat?
The findings came from one controlled internet-facing SIP service observed for 18 days. The honeypot rejected every credential and did not complete any calls, meaning the study measured hostile attempts rather than confirmed compromises or actual financial losses.
The 15.18 million headline figure also represents telemetry events rather than 15.18 million independent attacks. A single SIP request can produce several records, including the inbound packet, parsed request, server response and authentication data. The more comparable measure is approximately 3.79 million distinct SIP requests.
Those limitations should prevent overstatement, but they do not make the findings trivial. A single inert service attracted more than 1.8 million credential attempts from hundreds of addresses without advertising valuable data or belonging to a prominent enterprise. That demonstrates the level of ambient pressure facing any similarly exposed system.
The dataset also captured multiple stages of the same commercial attack model. Extension discovery, broad password dictionaries, credentials apparently harvested from other environments, international call attempts and dial-plan probing all appeared within the observation window. The combination provides stronger evidence of organised fraud activity than raw scanning volume alone.
Executives should therefore read the report as a warning about exposure, not as an estimate of the number of successfully breached companies. The precise global scale cannot be calculated from one honeypot, but the operating model is clear enough to justify immediate review of externally accessible telephony systems.
The broader strategic issue is that business communications infrastructure is converging with cloud computing while often retaining older assumptions about trust and network boundaries. As telephone services become software-managed and internet-connected, they inherit the same credential, configuration and automation risks affecting other enterprise platforms. Organisations must secure them accordingly rather than treating the PBX as an appliance that quietly lives in a cupboard until the bill arrives.
Key takeaways from CloudSEK’s SIP credential attack and toll-fraud findings for business leaders
- CloudSEK recorded 1,869,521 authentication attempts, showing that exposed business phone systems are being tested at industrial scale.
- The attack chain progressed from extension enumeration to credential spraying, replayed authentication material and attempted financial exploitation.
- The 15.18 million telemetry events represented approximately 3.79 million distinct SIP requests, an important distinction when assessing campaign scale.
- A recovered dictionary of 277,632 passwords shows that complexity alone cannot protect credentials that are reused, exposed or based on vendor defaults.
- United Kingdom destinations attracted 47,273 attempted calls, making them the dominant target in activity consistent with international revenue-share fraud.
- Prefix rotation demonstrates that attackers actively test alternative dialling formats to bypass weak outbound calling restrictions.
- Almost all attributed traffic came from hosting infrastructure, giving enterprises an opportunity to use trusted-peer, network and geography-based controls.
- Device names such as Cisco, Avaya, Polycom and FreePBX were easily spoofed, making behavioural detection more reliable than user-agent identification.
- Restricting public SIP access, enforcing unique secrets and locking down international calling should be treated as immediate operational priorities.
- Telecom spending limits and real-time alerts can contain losses even when preventive authentication controls are defeated.
Discover more from Business-News-Today.com
Subscribe to get the latest posts sent to your email.