• Holland And Barrett Vitamins Gibraltar Offer

Feb 24 - RGP Issues Private Branch Exchange Fraud Warning

The Royal Gibraltar Police is warning small to medium-sized businesses and anyone operating a PBX (Private Branch Exchange) system of an increased threat of PBX fraud. In this type of crime, fraudsters hack into phone lines and make premium rate calls costing thousands.

PBX systems improve business communications, and the fraud (also known as “Dial-Through”) occurs when cyber criminals take advantage of PBX security flaws for the purposes of making numerous calls to premium rate or overseas numbers.

Although, this type of crime is rare in Gibraltar in recent weeks the RGP says it has seen two confirmed incidents of this nature, with costs to organisations varying in accordance with the time period elapsed between the fraud being committed and its detection.

Information suggests that this type of fraud often can occur when organisations are most vulnerable, such as during the early hours of the morning or during weekends/public holidays, when a business may be closed but their PBX system remains “live.”

Protective Measures

 Ensure you have a strong pin/password for your voicemail system that is changed regularly (at least every months).

 If your voicemail is on its default pin/password, ensure this is changed immediately.

 Ensure that access to your voice mail system from outside lines is DISABLED, but if this is essential, ensure this is available to restricted users who must update passwords/pins regularly.

 Explore whether your network provider can block outbound calls whilst your business is closed.

 Implement a system whereby call logging/reporting options are regularly reviewed, and monitor for any increased or suspect call activity on a regular basis

 Consider asking your provider to place call-barring to international numbers/premium rate numbers if you have no need to make such calls.

 Secure your exchange and communications system with the use of a strong PBX firewall. If you don’t need the function, ensure it is closed down.

 Speak to your service/maintenance provider to ensure threat understanding, and request that any identified security flaws are rectified immediately.



{fcomment}