Docs Wholesale & Carriers Account Security & Toll-Fraud Protection

Account Security & Toll-Fraud Protection

How 6X monitors your account for compromised-account/toll-fraud activity, what a frozen account means, and how to protect yourself.


6X monitors every wholesale account for signs of a compromised account or unauthorized use — the most common and costly fraud pattern in wholesale telephony and messaging is a hacked account or leaked extension password suddenly placing a burst of international/premium-rate calls or sending a blast of spam SMS, usually overnight, before anyone notices. Voice and SMS are watched — and protected — independently: a fraud signal on one channel never touches the other, so an SMS-related freeze never stops your voice calling, and vice versa.

Voice Toll-Fraud Protection

What we watch for on your outbound calling:

  • Sudden call volume spikes compared to your own normal usage pattern.
  • Off-hours activity — calls placed at times that don't match how your account is normally used.
  • Calls to watchlisted high-risk destinations — certain satellite and premium-rate number ranges associated with revenue-share fraud.

If your account matches one of these patterns, you may receive an email alert. Depending on how the signal is configured, your account may also be automatically frozen (outbound calling paused) as a precaution — you'll always be emailed immediately if this happens, with the specific reason.

SMS Fraud Protection

What we watch for on your SMS sending:

  • Sudden message volume spikes compared to your own normal sending pattern.
  • Off-hours SMS activity — messages sent at times that don't match your account's normal pattern, checked in your own timezone.
  • Messages to watchlisted high-risk destinations — the same premium/high-fraud-risk watchlist used for voice.
  • Broadcast blasts — the exact same message sent to a large number of distinct numbers in a short window, the classic spam/smishing signature.
  • Failure-rate spikes — a sudden jump in messages that fail to send, which can indicate a compromised account being used to probe or spam numbers.

If your account matches one of these patterns, you may receive an email alert. Depending on how the signal is configured, SMS sending only may also be automatically disabled as a precaution — your voice calling is never affected by an SMS-side freeze. You'll always be emailed immediately if this happens, with the specific reason.

Being flagged on either channel does not mean you did anything wrong — it means your account's recent activity matched a pattern we ask you to double-check. Common legitimate causes include genuinely ramping up new traffic, or a real change in your calling/messaging pattern (e.g. a new campaign or destination).

If your account gets frozen or SMS disabled

  1. Check the email alert for the specific reason (volume spike, unusual hours, a specific destination, a broadcast pattern, or a failure-rate spike) and which channel it affected.
  2. If the activity was you and is legitimate, contact support to have your account reviewed and restored.
  3. If the activity was not you, contact support immediately and change your SIP/extension passwords or SMPP credentials — this is the classic sign of a compromised account.

Protecting your account

Most toll fraud and SMS abuse starts with a leaked or weak SIP/extension password or SMPP credential. Use strong, unique passwords for every extension and SMPP account, avoid sharing credentials outside your organization, and contact support if you notice call or SMS activity you don't recognize.

Was this article helpful?