Getty Images

Tip

Voice spoofing: The hidden vulnerabilities in UC platforms

UCaaS platforms are an attractive target to threat actors launching voice spoofing attacks. But there are strategies to keep your organization safe from these costly events.

Unified communications as a service is a tempting target for voice spoofing. These social engineering attacks come from many directions. Many UCaaS platforms let callers join audio sessions without any verification. The spoofed call might appear to come from an employee extension, the company's own help desk, a registered vendor line or a customer's office.

Because these VoIP calls can be made from either a softphone application or a physical hard phone, voice spoofing attacks are undetectable: Caller IDs are metadata fields, not verified as they are on traditional phones tied to a physical line.

How voice spoofing works in UC environments

Voice spoofing, also known as vishing, is a long-game strategy. Once attackers find a potential enterprise target, they carefully comb through databases and other resources to identify senior management and C-suite executives or employees who might have access to critical data.

Attackers then use unregulated Session Initiation Protocol (SIP) trunk services to modify the original header field and place a spoofed call from the purported executive, which remains unverified by the network. From there, they can fetch enterprise directories to display call extensions, employee names, vendor names or even place an "internal call" label on the spoofed call.

Spoofs can take the form of meeting invites or voice messages from key executives. Threat actors gather staff voices from the officials themselves or from their personal social media profiles and use AI voice-cloning apps to tailor specific requests for information or access.

To counter these types of attacks, companies may ask the caller to appear on a video call. But even that tactic isn't foolproof. Attackers can use deepfake AI to appear to be the actual executive. On the call, they can easily confirm specific details, including name, phone number, company ID or any ticket numbers. They curate a fake story around urgent events, such as compliance checks, audits, security breaches or maintenance.

Once attackers obtain multifactor authentication (MFA) codes and credentials, they can gain unauthorized access to classified data, change passwords, deploy ransomware and redirect staff to fake financial harvesting pages.

User policies in UC platforms

To prevent these attacks, define strict protocols for third-party interactions. Vendors and enterprise customers, for example, should be allowed to reset after completing multi-level authentication and authorization.

Define conditional access policies. For example, the UCaaS tool must block external connections based on location, device types and the nature of requests. If basic conditions are not met, external connections are automatically revoked.

Additionally, restrict Teams federation to an allowlist, disable/scope guest access, promote just-in-time privileged access and enable users to revoke instant sessions if they receive URL sharing requests or sense something is wrong. Consider using a configuration analyzer to identify weak security policies.

Mitigation strategies to protect UCaaS environments

Avoid UCaaS-based voice spoofing attacks by implementing safe login verification, phishing-proof MFA and compliant device states for admin, cloud, enterprise and other important accounts.

1. Biometric integration. Integrate iris- and fingerprint-based biometrics with enterprise credentials, which are very hard to breach.

2. Prevent credential sharing. Apply data loss prevention across UCaaS tools and meetings apps. Enterprise filters will block or flag sensitive information from being shared. 

3. Block common channels. Most threat actors focus on gaining remote access over the vendor dashboard. Revoke access for remote monitoring and management tools and data exfiltration services.

4. Implement access control. Audit the number of VPN connections, API OAuth grants and over-privileged applications. Prevent sudden in-meeting changes and redirection to suspicious or brand-new websites. Eliminate call initiation to external numbers, which is another popular UC spoofing attack known as the callback scam. 

5. Shift to pre-agreed verification. Have callers answer live questions and show ID cards in video meetings to verify identities. Meet in person if particularly sensitive topics are being discussed or significant financial transactions are taking place.

6. Continuous reporting. If an enterprise user clicks on report, a dedicated team should respond immediately. Deploy teams to investigate malicious chats and remove them from UCaaS tools for safety.

7. Collaborative effort. Rely on multiple stakeholders, cybersecurity teams and tools, such as extended detection and response and security information and event management, to comb through unified audit log data to determine if spoofing extends beyond UCaaS platforms.

Threat actors use VoIP to mask themselves as they target their victims, and that's a tactic many enterprises don't train their teams to recognize. Regularly schedule vishing simulations and social engineering awareness drills to counter spoofing attacks.

Venus Kohli is an engineer turned technical content writer, having completed a degree in electronics and telecommunication at Mumbai University in 2019. Kohli writes for various tech and media companies on topics related to semiconductors, electronics, networking, programming, quantum physics and more.

Dig Deeper on Communications & Collaboration