VoIP & Telephony Penetration Testing
VoIP and telephony penetration testing across Europe: SIP, RTP and PBX attacks tested by hand to stop toll fraud and eavesdropping. Fixed price, free retest.
VoIP telephony penetration testing looks at the phone system most companies forgot was on the network: the SIP trunks, the PBX, the desk phones and the softphones an attacker can use to eavesdrop on calls, hijack extensions, or rack up thousands in fraudulent international traffic overnight. If your business runs on voice, this is a live attack surface, and it is rarely tested until the first fraudulent invoice lands.
What VoIP penetration testing actually covers
A modern phone system is just software and network services, which means it can be attacked like any other application, and it usually has weaker controls because nobody thinks of the phones as computers. Toll fraud alone drains real money from businesses every year, quietly, through compromised PBXs dialling premium-rate and international numbers at 3am. Beyond fraud, an attacker on your voice network can record conversations, spoof internal callers, and knock your phones offline during your busiest hour.
How we test a voice environment
Every engagement is manual, run by an engineer who understands SIP at the packet level, not a tool that fires a few registration probes and calls it a day. Voice testing sits between network and application security, so we work across both. The approach adapts to whether you run an on-premise PBX, a cloud voice service, or a hybrid of the two.
Discovery and enumeration
We map the voice infrastructure: SIP servers, trunks, media gateways, desk phones and softphones, and any management or provisioning interface exposed on the network. Using SIPVicious-style enumeration and manual SIP probing we discover valid extensions, identify the PBX platform and version, and flag services that answer to anyone who asks.
Authentication and fraud testing
Here we attack the parts that cost money. We test SIP registration for weak or default credentials, attempt to register as an existing extension and hijack it, and probe the dial plan for ways to place unauthorised outbound calls. Toll fraud is the headline risk, so we specifically look for routes that let an unauthenticated or low-privilege caller reach international and premium-rate numbers through your trunks.
Media interception and spoofing
Where signalling and media are not encrypted, we demonstrate the impact: capturing RTP streams from a call and reconstructing the audio, spoofing caller ID to impersonate an internal extension, and injecting or tampering with signalling. Seeing a recorded test call played back tends to make the case for SRTP and TLS more effectively than any advice.
Resilience testing and reporting
We assess how the system holds up under registration floods and malformed SIP messages that can crash or overwhelm a PBX and drop live calls. Anything disruptive is agreed and scheduled with you first. You then get the written report within days, with reproduction steps and the exact configuration changes to make, a live walkthrough, and a free retest after you remediate.
Vulnerabilities we routinely find in VoIP systems
Phone systems tend to be set up once, by someone focused on getting calls working, and then left alone for years. That is exactly why the same weaknesses keep appearing.
Weak and default SIP credentials
Extensions protected by short numeric passwords, passwords equal to the extension number, or vendor defaults are trivially brute-forced. Once an attacker registers as a valid extension, they can place calls on your account and impersonate a member of staff.
Toll-fraud exposure in the dial plan
Permissive routing rules let a compromised or unauthenticated endpoint dial out through your trunks to expensive destinations. This is the flaw that produces a five-figure phone bill over a weekend, and it is almost always a configuration issue rather than a software vulnerability, which means it is entirely preventable once you know where it is.
Unencrypted signalling and media
When SIP runs in plain UDP and media in plain RTP, anyone with a foothold on the network can record calls and read call metadata. For any business that discusses money, health or personal data by phone, that is a confidentiality breach waiting to happen. We show whether TLS and SRTP are in force and where they quietly are not.
Registration hijacking and caller-ID spoofing
Weak authentication on SIP registration lets an attacker take over an extension or spoof the caller ID of an internal number, a powerful tool for vishing and social engineering against your own staff or customers. We test how easily an endpoint can claim to be someone it is not.
Exposed and outdated PBX platforms
Management interfaces for Asterisk, FreePBX or 3CX reachable from the internet, running old versions with known vulnerabilities, are a direct path to full control of the phone system. We identify exposed and unpatched platforms and test the admin surface for authentication and injection flaws that would hand over the entire system.
Voicemail, IVR and provisioning weaknesses
The features around the phones matter too. Voicemail protected by a default or four-digit PIN can be raided for sensitive messages, IVR menus sometimes expose a hidden path to an outside line, and auto-provisioning servers that hand out phone configurations without authentication leak credentials and SIP settings to anyone who asks. We test these secondary surfaces because attackers use them as the quiet way in when the front door is locked.
Telephony denial of service
SIP services are easy to flood, and a registration or INVITE storm can drop every call in the building. For a contact centre or any business where the phone is the front door, an outage during peak hours is a direct revenue loss, so we assess how resilient the system is and where rate limiting is missing before an attacker tests it for you at the worst possible moment.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
Compliance and standards we align with
Voice carries regulated data more often than people realise, and a telephony test produces evidence that auditors and payment partners accept.
Payment and card data over the phone
If your agents take card payments by phone, the call path is in scope for PCI DSS, and requirement 11.4 calls for regular penetration testing of the connected systems. Where calls are recorded, PCI DSS requires that card data is not stored in recordings, so pause-and-resume and DTMF-masking controls are tested as part of the engagement.
Data protection and confidentiality
Call recordings and voicemail are personal data under GDPR, so we test how they are stored, who can reach them, and whether they cross the network in the clear. The findings support ISO 27001 controls on communications security and access control, and we structure the report so it slots into your audit evidence.
What you get from the engagement
A report your telecoms and IT teams can act on immediately.
- An executive summary for leadership, your provider and your compliance owner
- A technical report with each finding scored by CVSS, ranked by fraud and confidentiality impact, and paired with exact reproduction steps
- Specific remediation: credential policy, dial-plan restrictions, TLS and SRTP, and platform hardening
- An attestation letter to support PCI DSS 11.4, ISO 27001 or a customer review
- A live results walkthrough with your voice and network teams
- A free retest once you have remediated, confirming the fixes hold
Everything is delivered under NDA, and any call data we capture is handled securely and destroyed on request.
Why manual testing beats a scanner here
A scanner can tell you a SIP port is open. It cannot register as an extension, walk your dial plan looking for a route to a premium-rate number in another country, or record a test call and play it back to prove the media is in the clear. Those are the findings that map to actual money and actual privacy breaches, and every one of them needs an engineer who speaks SIP and knows how phone fraud works in practice. We attack your voice system the way a toll-fraud crew or an eavesdropper would, show you the call we placed or captured, and hand you the specific configuration change that shuts it down. On a phone system, an untested assumption is how the surprise bill arrives, or how a confidential call ends up in the wrong hands.
Pricing
Pricing depends on scope: how many SIP endpoints and trunks, whether the PBX and its management are in scope, and whether it is on-premise, cloud or hybrid. Here is the shape of a typical European engagement.
| Engagement | What’s included | Timeline | Price |
|---|---|---|---|
| Essential | Single PBX or voice service, SIP enumeration and authentication, toll-fraud and dial-plan review, encryption check, report and free retest | 4–6 working days | from €2,500 |
| Standard | Full voice environment: multiple trunks and endpoints, media interception and spoofing testing, PBX platform and management review | 6–10 working days | €4,000–€8,500 |
| Advanced | Large or multi-site telephony, contact-centre platforms, WebRTC, resilience testing and attack-chaining across voice and data networks | 10–15 working days | €8,500–€18,000 |
| Compliance add-on | Mapping and attestation for PCI DSS 11.4, GDPR or ISO 27001, including call-recording controls | with any tier | from €800 |
| Custom / large estate | Several sites or a full multi-region voice estate, scoped after a free call | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call — no hourly surprises, and a retest is included. Get a fixed quote
FAQ
How much does VoIP penetration testing cost?
How long does a VoIP penetration test take?
Do you test for toll fraud specifically?
Can you prove whether our calls can be intercepted?
Do you work with Asterisk, FreePBX and 3CX?
Will testing disrupt our phone calls?
Does this cover PCI DSS for phone payments?
Is everything kept confidential?
Related services
Businesses running a SIP-based phone system or contact centre, especially those taking card payments by phone or handling sensitive conversations, who want to close off toll fraud, eavesdropping and telephony outages before an attacker finds them first.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.