Ghost calls and phantom rings: prove what reached the phone
A phantom ring is a symptom, not proof that an attacker reached the PBX. The phone may have received a direct SIP INVITE, a legitimate PBX call that ended early, a paging or intercom request, or a local notification mistaken for ringing.
Start at the handset
Record the time, displayed caller identity, affected phones and whether answering produces audio. Check the phone’s call log and the PBX call detail record. If the phone logged a call that the PBX never saw, investigate the network path to the handset.
Three useful outcomes
| Capture result | Meaning | Next action |
|---|---|---|
| INVITE arrives directly from an unknown internet address | The handset is reachable outside the intended PBX path | Restrict signalling sources and review exposure |
| INVITE arrives from the PBX | The PBX generated or forwarded the ring | Trace the PBX route, feature and source |
| No SIP arrives during the event | The ring may be local, non-SIP or captured at the wrong point | Check paging, door systems, alerts and switch mirroring |
Do not expose phones as a shortcut
Broad port forwarding to individual handsets makes unsolicited requests easier to deliver and expands the attack surface. Prefer the supported PBX, SBC or secure remote-phone design. Allow only required sources and transports, then monitor rejected attempts without publishing credentials or full packet captures.
Changing the SIP port may reduce background noise but does not replace access control. Likewise, blocking one scanning address treats one source rather than the exposure.
The useful conclusion names the signalling source. “The phone received a direct INVITE from outside the approved PBX path” leads to a network control. “It rang strangely” does not.
Related: VoIP fraud prevention, the security hub and packet captures.
Technical reference
Scheduled for 26 August 2026. Preserve privacy when sharing phone logs and signalling captures.