Installation guide

Identifying toll fraud A-2
: Protecting Your Phone System Against Toll Fraud
Wave Global Administrator Guide
Calling random users and telling them they are a representative from the phone company
and need their voice mailbox password to track down a problem with the phone system.
Users should be told to never give out their passwords, and if they have reason to believe
someone else has it, to change it immediately to something secure.
Identifying toll fraud
The following methods will help you tell whether your system has been targeted by toll fraud
hackers:
Check the Call Log in the User/Group Management applet daily for multiple logon
attempts. A failed logon attempt will show as “logon - Abandoned”. A successful
fraudulent logon will typically show many long distance or international calls placed
afterwards from that extension.
Note: You can have Wave automatically hang up on callers and lock out accounts after
multiple failed logon attempts. See “Enforcing strong password security” on page
4-13.
Check your phone bills carefully for international numbers or long distance numbers you
do not recognize.
Watch your Trunk Monitor (available on the Diagnostics tab of the Management
Console) for sudden bursts where every line is busy with people trying to log on.
Release 2.0
September 2010