- Joined
- Aug 15, 2018
- Messages
- 4
- Reaction score
- 2
Recently, our SIP provider notified us of international calls that occurred overnight. We immediately locked down our extensions with stronger passwords and tighter PBX security per 3CX's online documentation.
We now do not see anyone using our extensions, but we do see constant attempts to authenticate from international IPs. I do not believe that anyone has any access to our extensions at this point. But, we are seeing strange issues with our incoming calls now. Sometimes when calls are coming in via our main line and are going to different departments via our IVR, 3CX does not show the actual caller ID information. Instead it shows the name of different employees from within our company, as if they are the ones calling. Also, sometimes, if someone within a department answers a call that has been routed to them, 3CX will show them on the line with two other employees within the company, when they are not, while also being on the line with the actual caller. Sometimes it will even show the recipient as the caller and the callee.
Additionally, it shows this same incorrect information within the 3CX call logs. When I check with our SIP provider, and view our call history, it shows as if our company is calling itself each time, which makes no sense to me. This was never the case before we had been hacked. I'm at a loss for what could be causing this, as little was changed outside of strengthening the extension passwords and changing the failed authentication protection attempts and the blacklist intervals.
We now do not see anyone using our extensions, but we do see constant attempts to authenticate from international IPs. I do not believe that anyone has any access to our extensions at this point. But, we are seeing strange issues with our incoming calls now. Sometimes when calls are coming in via our main line and are going to different departments via our IVR, 3CX does not show the actual caller ID information. Instead it shows the name of different employees from within our company, as if they are the ones calling. Also, sometimes, if someone within a department answers a call that has been routed to them, 3CX will show them on the line with two other employees within the company, when they are not, while also being on the line with the actual caller. Sometimes it will even show the recipient as the caller and the callee.
Additionally, it shows this same incorrect information within the 3CX call logs. When I check with our SIP provider, and view our call history, it shows as if our company is calling itself each time, which makes no sense to me. This was never the case before we had been hacked. I'm at a loss for what could be causing this, as little was changed outside of strengthening the extension passwords and changing the failed authentication protection attempts and the blacklist intervals.