- Joined
- Mar 25, 2022
- Messages
- 34
- Reaction score
- 8
Good Morning
One of our clients appear to have been hacked overnight .. We got notified by our trunk provider who gave us the times of the hack , when looking at the call logs it appears one extension was used to repeatedly make random calls , most failing but then every so often it looks like an external number has rang another external number. Screenshots of call log and more importantly call report below:


I am just wondering if anyone can shed any light as to what is happening on these calls.
I have regenerated the user extension, changed the phone password and re provisioned and the trunk pwd has been reset, scanned the users machine (it was off overnight so I don't believe it came from there.)
Is there anything else that people can think to do or have I covered bases, is there anything that our provider could maybe look to do to restrict access to that trunk maybe location wise ? ... our management is restricted to our internal IP range through VPN with no other access allowed
Unfortunately our activity logs were only set to low so unable to really get much information in that regards
One of our clients appear to have been hacked overnight .. We got notified by our trunk provider who gave us the times of the hack , when looking at the call logs it appears one extension was used to repeatedly make random calls , most failing but then every so often it looks like an external number has rang another external number. Screenshots of call log and more importantly call report below:


I am just wondering if anyone can shed any light as to what is happening on these calls.
I have regenerated the user extension, changed the phone password and re provisioned and the trunk pwd has been reset, scanned the users machine (it was off overnight so I don't believe it came from there.)
Is there anything else that people can think to do or have I covered bases, is there anything that our provider could maybe look to do to restrict access to that trunk maybe location wise ? ... our management is restricted to our internal IP range through VPN with no other access allowed
Unfortunately our activity logs were only set to low so unable to really get much information in that regards