Given the above information...if you can figure out exactly when inbound calls began (Activity Log?), and perhaps who this change would benefit, you may be able to narrow it down to a limited group of "suspects"
Take the information @Marari posted and you can check with your provider when calls failed and that will narrow down the time frame. You technically should be able to check the nginx access logs to get an IP address and that would help you track it down.
You can also set the PBX to send an email to the admin when a user (not using the admin account) logs in to the management console. The option is under Settings / Mail / Notifications