I have a customer that got hit with Toll Fraud recently, but I have not been able to find how it was done. The customer has a Toshiba CIX100 and LVMU voice mail system with PRI and digital phones. It does not have any VoIP devices or even a connection to the Network. They claim during the incident that they observed approximately 4 lines busy with nobody on the phone. They have 7 virtual lines/answer points on the phones, so it points to the vulnerability being in the Voice Mail (4 Ports). I did not find any mailboxes that had the extension changed to an external number or speed dial. I was also not able to find any phones that were forwarded externally.

I am more interested in how it was done, since I know how to fix it. Any help would be appreciated.