It’s a sad fact of life that when disaster strikes, there are those who will opportunistically attempt to benefit from the chaos and uncertainty it creates. In the 2020 remote work revolution, a wave of hacks has arisen and spiked overall cybercrime statistics — and while leaks of sensitive data make the headlines, VoIP telephone systems have vulnerabilities too.
I spoke to Ian Guest, Marketing Director at Pure IP, about the risks that distributed teams should be aware of.
[caption id="attachment_33195" align="alignright" width="200"]
Ian Guest[/caption]
“As soon as you redirect a call, you have an additional step in the journey to consider, perhaps to somewhere not as secure. Earlier in the year, when quick changes were being made to infrastructures, certain vulnerabilities were opened up unknowingly”, he explained. The very technology which allows us to work from anywhere can bring its own risks, especially when people’s guards are naturally lowered due to their environment, “When you’re working from home, as an individual, the distractions and introduction of new systems and workflows can make you more vulnerable to, for example, clicking on links that would otherwise seem suspicious. ”
Old scams, new attack vectors
Some of the malicious acts Pure IP have tracked this year are quaintly old-fashioned, like DDoS attacks, and the calling of premium rate numbers. If an attacker can compromise the password on a hosted PBX, or find an open VoIP port they can gather information about numbers, lines, and extension, then use this data to route high volumes of calls through your network to premium international numbers, leading to rapid and substantial costs.
“We’re constantly monitoring”, Guest explained, “and we quickly pick up trends, like high call volumes from a specific number to a particular destination, that we can flag as suspicious behaviour to our customers or apply temporary blocks...”
This helps protect Pure IP customers from attacks, which are inevitable, relentless, and easy for any organisation to fall victim to. As always, the human element is the weakest link, in terms of password hygiene and data loss, as well as social engineering, particularly when natural anxieties are exploited, in bogus COVID-19 testing alerts and similar cynical scams.




