Cisco CDR

CUCM Toll Fraud: What Would Happen If It Hit Your Network Today?

September 22nd, 2025

If you are running Cisco Unified Communications Manager (CUCM), you know how critical it is to your business.  However if toll fraud started happening on your system today, would you know right away? 

If you are running Cisco Unified Communications Manager (CUCM), you know how critical it is to your business. But here’s a question worth asking:

If toll fraud started happening on your system today, would you know right away? Or would you only find out next month when a massive phone bill arrives?

Toll fraud doesn’t happen often, and your CUCM may not be vulnerable. But imagine your security team asks you tomorrow: What safeguards do we have in place to catch this?” Would you have a good answer?

What Toll Fraud Might Look Like in CUCM CDR

  • A call comes into Unity voicemail.
  • That call gets transferred.
  • Suddenly, Unity is dialing out to an international number +74956063601

Until you spot the weird outside number, it looks like a normal CDR. But that number is in Russia and someone has just found a way to make your phone system work against you.

How to Spot It With Sideview

It can be as simple as saving this search in our Cisco CDR Reporting and Analytics App:

initial_type="incoming" finalCalledPartyCountry=* NOT finalCalledPartyCountry="United States"

This says find me any calls whose earliest call leg was an incoming” aka inbound leg, but that also had at least one call leg outbound to some country that’s not the US.

Here’s what the results look like when you run that search and find results. Note we’ve added the optional field finalCalledPartyCountry” and it has the value Russian Federation”. 



Both this finalCalledPartyCountry” field and the initial_​type” field are ones that the Sideview product adds — you won’t find those fields in the raw CDR anywhere. Nonetheless in this product you
can filter, exclude, chart, pivot, and build dashboards around these values just as though they were.

Next if you’d like to get alerted if such a call ever happens again, simply click Save Report”, set scheduling properties so Splunk runs this search every hour or every day and it can email you if it ever finds results.

This Is Just The Beginning

This example above just allows you to pull out one little known-bad” cohort of calls. You can repeat this model for anything you might need. However… you can also take larger strides. 

For larger environments, we can help you define leg types in the app. This gives your team structured insight into all of your Unity call flows, and then the monitoring for bad” flows becomes almost a natural by-product of your dashboards. Leg types are a deeper topic that we’ll save or another day.

Next let’s walk through another search which can identify a spike in international calls.

Building a Dashboard for International Call Spikes

  1. Navigate in the app to Investigate > Calls”
  2. Click Edit fields” on the right.
  3. Type country” in the filter box and select the finalCalledPartyCountry” field. Note that dragging fields on the right-hand side up or down will reorder the columns in your results table.
  4. Click Apply”, you’ll see the country values show up. 
  5. Next, in the large search” textfield manually type
    finalCalledPartyCountry=*
    and hit return.
    This will narrow down the results to only calls that have *some* value for the called party country.
  6. Most of the values shown for country will be normal”, ie if you’re in the US the normal ones are probably United States” and Canada”.
    Click each of these normal” values in the table, and when an action menu comes up, select exclude finalCalledPartyCountry=<value>”



  1. Once you’ve excluded each of the normal” values for country, you should only have a small number of calls left (hopefully).
  2. Next click the Chart” tab.
  3. Note the Split by” field which will be set to none”. Change this none” to finalCalledPartyCountry.
  4. Click Create dashboard panel”, and go through the little wizard process. When you’re done you can have this and other charts on a daily dashboard.
  5. Users clicking on elements in that dashboard every morning, will go right to see full details about these calls in the same investigate calls” page, as a springboard for further investigation.



Now you’ve got a chart that highlights unusual international calls daily. You can even have Splunk email the dashboard as a PDF every morning.

Why This Matters

Toll fraud isn’t just about money. It’s about:

  • Financial risk – large, unexpected charges.
  • Operational riskIT scrambling to investigate.
  • Security risk – attackers proving they can exploit your system.

Many organizations are already using Splunk for security. With the Cisco CDR Reporting and Analytics app, you get continuous monitoring, targeted searches, and dashboards that make suspicious activity easy to spot, before the bill comes!

👉 Contact us today to get a trial license and see how it works in your environment https://​side​viewapps​.com.

Related

The finalMobileCallingPartyNumber field is critical to SNR analysis, but it also illustrates the importance of looking beyond the more familiar fields.

December 30th, 2025

What to do when the RTMT installer just quietly fails on you every time.

September 3rd, 2025

Practical steps to investigate and diagnose audio issues in CUCM, including one-way audio, from sanity checking your ports and configuration, to using Sideview's app as your command center. 

June 19th, 2025

We never require manual migration!  (well... almost never. there are some easy steps you have to do for 7.2)

February 16th, 2024

Download a 60-day free trial & work with your own live data

Start My Free Trial

By submitting this form, I agree to Sideview's Trial Internal Use License Agreement and Privacy Policy.