We have a customer who's been hit with unauthorized toll charges or fraud. I believe they're getting in via voicemail, and dialing out to the 900 numbers. When this happened a few months ago, they changed all the vpn passwords, we reassigned those physical phones which were associated with the extensions that placed the calls, and changed all of the voicemail pins. But it's happening again, so I believe they must be getting in via voicemail.

900 numbers both 900*, 1900*, 91900* and 9900* are blacklisted in the CoS elements.

How can I know if they're placing the calls via hacking someone's voicemail and getting dial-tone or getting in through the vpn? The extensions that placed the calls have had registrations disabled, so it could possibly be someone spoofing (outpulsing their number) and dialing the 900 numbers.