This is the 4th and final edition of our blog series. Last time we highlighted our top 4 security tips in Don’t be that guy Vol.3. In this edition, we will see how you can monitor your PBX system closely and also highlight some stats we have gathered from some unfortunate real-world hacking instances.
Email Alerts Keep You Updated

First, there are multiple important email notifications to help with monitoring in 3CX. They allow admins to get alerted when something unexpected happens related to calling or security features. It is good to tick these and ensure that multiple admin email addresses are separated by commas. Email event alerts can be found in “System” > “Alerts”.
The table below gives a brief description of what each event email is reporting against.
| EVENT TITLE | DESCRIPTION |
|---|---|
| Trunk failover or max calls reached | Indicating that the value defined in the Trunk settings in the field “Number of SIM Calls” has been exceeded |
| Trunk error codes detected | Indicating that calls are getting rejected, for example, by the provider |
| License limit reached | Indicating that too many calls were placed simultaneously |
| IP blacklisted | Indicating that an IP has been blocked after repeatedly authenticating with incorrect credentials |
| Anti-hacking rejects requests | Indicating that an IP has been blocked after sending too many requests (flood/DoS) |
| Calls & messages made to blocked countries | Indicating that a user has attempted to call an international number with a country code that was disallowed |
Make Use of The Audit Log
Second, the audit logs that were introduced back in V18 are permanently enabled in V20. They allow you to keep track of each change made on the PBX in the Admin Console by any user with admin rights. Each entry will include a timestamp, username, source IP, and details on the change made with values before/after.
You should periodically review them, looking for unusual actions. You can also export them in CSV format.
Real-World Examples Act as Reminders
Let’s check some real-life statistics for your consideration, from our security team’s review of 255 successful PBX breaches over the course of 4 years (2018-2021). Sounds a lot? On the contrary.
If we consider a base of 350,000 installs active worldwide during that period, 255 (breaches) / 350,000 (installs) *100 = 0.07 % got hacked. This can translate to 1 in every 1400 installations getting breached. Or in other words, we can say that 99.93% of our customers' installations were secure during that period, and we are quite proud of this statistic. Since then, we have hardened the system further and added many more security features.
Successful Hack Cases We Reviewed Arranged by Country
- United States (21%)
- United Kingdom (15%)
- France (13%)
- Germany (8%)
- Belgium (5%)

Total Number of Hack Cases Reviewed per Year

As you can see, unfortunately, it was a rising trend. 2021 saw exponential growth in hacking. The COVID pandemic and other global crises are often good for the hackers. This trend has focused our efforts, and with your help, it’s being driven back!
Concerned? We are Here to Help
If you have experienced call fraud, a PBX security breach, or have any security concerns please reach out by opening a support ticket or reaching out to our Customer Care team. For any data privacy concerns, you can also reach out to [email protected]
What should I do if I receive a security alert from my EDR/Antivirus software?
Please report the issue to your antivirus vendor and share their Antivirus Vendor Report with us once it is available by submitting this contact form and choosing the option Security & Data Protection.
If you have a 3CX Partner, report any security reports/alerts to them immediately.
But please, now you have read our 4-part series with lots of hints and tips… Don’t be “THAT” guy!
See also
Don’t be “THAT” Guy Vol.1: Keep Complex Credentials
Don’t be “THAT” Guy Vol.2: Call Fraud
Don’t be “THAT” Guy Vol.3: Top 4 Security Tips

