The voicemail system is the most common place hackers will use for toll fraud. They may not have set the entire number in the extension field. I would look again for an extension something like 901. The 9 in the extension field will grab an outside line. Also double check your DIDs to make sure that you don't have DISA enabled on a number.

Typically I see hackers getting into the admin mailbox with the default code through the phone rather then using software.

It's good practice to enable destination restrictions for the voicemail extensions . With the IPEdge voicemail system the hackers will login to any user's voicemail box and use the follow-me feature.