Home/Services/VoIP & Telephony Penetration Testing
security service

VoIP & Telephony Penetration Testing

VoIP and telephony penetration testing across Europe: SIP, RTP and PBX attacks tested by hand to stop toll fraud and eavesdropping. Fixed price, free retest.

Manual, expert-ledEvidence-based findingsFree remediation retest

VoIP telephony penetration testing looks at the phone system most companies forgot was on the network: the SIP trunks, the PBX, the desk phones and the softphones an attacker can use to eavesdrop on calls, hijack extensions, or rack up thousands in fraudulent international traffic overnight. If your business runs on voice, this is a live attack surface, and it is rarely tested until the first fraudulent invoice lands.

What VoIP penetration testing actually covers

A modern phone system is just software and network services, which means it can be attacked like any other application, and it usually has weaker controls because nobody thinks of the phones as computers. Toll fraud alone drains real money from businesses every year, quietly, through compromised PBXs dialling premium-rate and international numbers at 3am. Beyond fraud, an attacker on your voice network can record conversations, spoof internal callers, and knock your phones offline during your busiest hour.

SIP enumeration and authentication: extension discovery and credential brute-forcing
Toll fraud and call routing: unauthorised dial-out and premium-rate abuse paths
Call interception: RTP capture and eavesdropping where media is not encrypted
Registration hijacking and caller-ID spoofing across SIP endpoints
PBX platform review: Asterisk, FreePBX, 3CX and cloud-hosted configurations
Telephony denial of service: flooding SIP registrations and trunks to drop calls
Encryption and transport: TLS for signalling and SRTP for media, or the lack of it

How we test a voice environment

Every engagement is manual, run by an engineer who understands SIP at the packet level, not a tool that fires a few registration probes and calls it a day. Voice testing sits between network and application security, so we work across both. The approach adapts to whether you run an on-premise PBX, a cloud voice service, or a hybrid of the two.

Discovery and enumeration

We map the voice infrastructure: SIP servers, trunks, media gateways, desk phones and softphones, and any management or provisioning interface exposed on the network. Using SIPVicious-style enumeration and manual SIP probing we discover valid extensions, identify the PBX platform and version, and flag services that answer to anyone who asks.

Authentication and fraud testing

Here we attack the parts that cost money. We test SIP registration for weak or default credentials, attempt to register as an existing extension and hijack it, and probe the dial plan for ways to place unauthorised outbound calls. Toll fraud is the headline risk, so we specifically look for routes that let an unauthenticated or low-privilege caller reach international and premium-rate numbers through your trunks.

Media interception and spoofing

Where signalling and media are not encrypted, we demonstrate the impact: capturing RTP streams from a call and reconstructing the audio, spoofing caller ID to impersonate an internal extension, and injecting or tampering with signalling. Seeing a recorded test call played back tends to make the case for SRTP and TLS more effectively than any advice.

Resilience testing and reporting

We assess how the system holds up under registration floods and malformed SIP messages that can crash or overwhelm a PBX and drop live calls. Anything disruptive is agreed and scheduled with you first. You then get the written report within days, with reproduction steps and the exact configuration changes to make, a live walkthrough, and a free retest after you remediate.

SIP-level
packet-level testing, not surface probes
100%
manual verification, no raw scanner dumps
Free
retest after you remediate

Vulnerabilities we routinely find in VoIP systems

Phone systems tend to be set up once, by someone focused on getting calls working, and then left alone for years. That is exactly why the same weaknesses keep appearing.

Weak and default SIP credentials

Extensions protected by short numeric passwords, passwords equal to the extension number, or vendor defaults are trivially brute-forced. Once an attacker registers as a valid extension, they can place calls on your account and impersonate a member of staff.

Toll-fraud exposure in the dial plan

Permissive routing rules let a compromised or unauthenticated endpoint dial out through your trunks to expensive destinations. This is the flaw that produces a five-figure phone bill over a weekend, and it is almost always a configuration issue rather than a software vulnerability, which means it is entirely preventable once you know where it is.

Unencrypted signalling and media

When SIP runs in plain UDP and media in plain RTP, anyone with a foothold on the network can record calls and read call metadata. For any business that discusses money, health or personal data by phone, that is a confidentiality breach waiting to happen. We show whether TLS and SRTP are in force and where they quietly are not.

Registration hijacking and caller-ID spoofing

Weak authentication on SIP registration lets an attacker take over an extension or spoof the caller ID of an internal number, a powerful tool for vishing and social engineering against your own staff or customers. We test how easily an endpoint can claim to be someone it is not.

Exposed and outdated PBX platforms

Management interfaces for Asterisk, FreePBX or 3CX reachable from the internet, running old versions with known vulnerabilities, are a direct path to full control of the phone system. We identify exposed and unpatched platforms and test the admin surface for authentication and injection flaws that would hand over the entire system.

Voicemail, IVR and provisioning weaknesses

The features around the phones matter too. Voicemail protected by a default or four-digit PIN can be raided for sensitive messages, IVR menus sometimes expose a hidden path to an outside line, and auto-provisioning servers that hand out phone configurations without authentication leak credentials and SIP settings to anyone who asks. We test these secondary surfaces because attackers use them as the quiet way in when the front door is locked.

Telephony denial of service

SIP services are easy to flood, and a registration or INVITE storm can drop every call in the building. For a contact centre or any business where the phone is the front door, an outage during peak hours is a direct revenue loss, so we assess how resilient the system is and where rate limiting is missing before an attacker tests it for you at the worst possible moment.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

Compliance and standards we align with

Voice carries regulated data more often than people realise, and a telephony test produces evidence that auditors and payment partners accept.

Payment and card data over the phone

If your agents take card payments by phone, the call path is in scope for PCI DSS, and requirement 11.4 calls for regular penetration testing of the connected systems. Where calls are recorded, PCI DSS requires that card data is not stored in recordings, so pause-and-resume and DTMF-masking controls are tested as part of the engagement.

Data protection and confidentiality

Call recordings and voicemail are personal data under GDPR, so we test how they are stored, who can reach them, and whether they cross the network in the clear. The findings support ISO 27001 controls on communications security and access control, and we structure the report so it slots into your audit evidence.

What you get from the engagement

A report your telecoms and IT teams can act on immediately.

  • An executive summary for leadership, your provider and your compliance owner
  • A technical report with each finding scored by CVSS, ranked by fraud and confidentiality impact, and paired with exact reproduction steps
  • Specific remediation: credential policy, dial-plan restrictions, TLS and SRTP, and platform hardening
  • An attestation letter to support PCI DSS 11.4, ISO 27001 or a customer review
  • A live results walkthrough with your voice and network teams
  • A free retest once you have remediated, confirming the fixes hold

Everything is delivered under NDA, and any call data we capture is handled securely and destroyed on request.

Why manual testing beats a scanner here

A scanner can tell you a SIP port is open. It cannot register as an extension, walk your dial plan looking for a route to a premium-rate number in another country, or record a test call and play it back to prove the media is in the clear. Those are the findings that map to actual money and actual privacy breaches, and every one of them needs an engineer who speaks SIP and knows how phone fraud works in practice. We attack your voice system the way a toll-fraud crew or an eavesdropper would, show you the call we placed or captured, and hand you the specific configuration change that shuts it down. On a phone system, an untested assumption is how the surprise bill arrives, or how a confidential call ends up in the wrong hands.

Pricing

Pricing depends on scope: how many SIP endpoints and trunks, whether the PBX and its management are in scope, and whether it is on-premise, cloud or hybrid. Here is the shape of a typical European engagement.

Engagement What’s included Timeline Price
Essential Single PBX or voice service, SIP enumeration and authentication, toll-fraud and dial-plan review, encryption check, report and free retest 4–6 working days from €2,500
Standard Full voice environment: multiple trunks and endpoints, media interception and spoofing testing, PBX platform and management review 6–10 working days €4,000–€8,500
Advanced Large or multi-site telephony, contact-centre platforms, WebRTC, resilience testing and attack-chaining across voice and data networks 10–15 working days €8,500–€18,000
Compliance add-on Mapping and attestation for PCI DSS 11.4, GDPR or ISO 27001, including call-recording controls with any tier from €800
Custom / large estate Several sites or a full multi-region voice estate, scoped after a free call on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call — no hourly surprises, and a retest is included. Get a fixed quote

FAQ

How much does VoIP penetration testing cost?
VoIP telephony penetration testing cost starts from €2,500 for a single PBX or voice service, and scales with the number of trunks and endpoints and whether the platform management and media testing are in scope. You get a fixed price after a free scoping call.
How long does a VoIP penetration test take?
A focused test runs about 4–6 working days plus the report, while a full multi-site voice environment is usually 6–15 days. If we find a live toll-fraud route, you hear about it the same day so you can shut it off immediately.
Do you test for toll fraud specifically?
Yes, and it is usually the highest-value finding. We probe the dial plan and trunk configuration for routes that let an unauthorised or low-privilege endpoint place international and premium-rate calls on your account, which is the fraud that produces surprise five-figure bills.
Can you prove whether our calls can be intercepted?
Where media is unencrypted and we have a network foothold in scope, we capture a test RTP stream and reconstruct the audio to demonstrate the exposure, then show exactly where SRTP and TLS need to be enforced.
Do you work with Asterisk, FreePBX and 3CX?
All of them, plus cloud-hosted and hybrid voice services. We review the platform version and configuration, test the management interface, and identify exposed or outdated systems that give an attacker full control of the phones.
Will testing disrupt our phone calls?
Not without agreement. Enumeration and configuration testing are non-disruptive, and any denial-of-service or flooding checks are scheduled with you and run out of hours. Keeping your phones working is part of the plan, not an afterthought.
Does this cover PCI DSS for phone payments?
Yes. If agents take card details by phone, that call path is in scope for PCI DSS 11.4, and we also test call-recording controls such as pause-and-resume so card data is not captured in recordings, providing the attestation your assessor needs.
Is everything kept confidential?
Every engagement runs under NDA. Any call recordings or data we capture during testing are handled securely, shared only with the people you name, and destroyed on request.

Related services

Who needs this

Businesses running a SIP-based phone system or contact centre, especially those taking card payments by phone or handling sensitive conversations, who want to close off toll fraud, eavesdropping and telephony outages before an attacker finds them first.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "VoIP & Telephony Penetration Testing"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.