VoIP Providers Under Fire: Attack Patterns and Response Steps
Attackers are sustaining pressure on VoIP infrastructure worldwide, using a combination of familiar methods and a persistent, probing approach that sets this campaign apart. Rather than relying on novel techniques, the attackers are systematically testing defenses and refining their targeting based on what they learn. Cloudflare, which fronts some of the largest voice and video providers, has documented the most common attack patterns and the practical steps organizations should take before and during an incident.
How Attackers Are Breaking In
The bulk of the activity relies on off-the-shelf booter services, but the distinguishing factor is the attacker's persistence and willingness to probe for weaknesses. The vectors in play are varied, often layered to stress different parts of the infrastructure simultaneously:
- TCP floods against stateful firewalls — These are being used in "trial-and-error" attacks. They are largely ineffective against telephony infrastructure itself (which is mostly UDP), but they are very effective at overwhelming stateful firewalls that sit in front of it.
- UDP floods against SIP infrastructure — Generic floods without a well-known fingerprint, aimed at critical VoIP services. To unsophisticated filtering systems, this traffic can look legitimate.
- UDP reflection against SIP or RTP services — These can easily overwhelm Session Border Controllers (SBCs) and other telephony gear, and the attacker appears to have learned enough about the target to hit these services with high precision.
- SIP protocol-specific attacks at the application layer — These are of particular concern because generating application errors costs more in resources than filtering on network devices.
In many cases, these network-layer and transport-layer attacks are combined with HTTP attacks aimed at API gateways and corporate websites, indicating an attempt to disrupt the provider's entire operation, not just voice traffic.
Preparing Before the Attack
There is no substitute for having protections in place before an attack begins. Providers that wait for an incident to trigger a response are at a significant disadvantage. Cloudflare recommends a proactive stance with several concrete steps:
- Deploy an always-on DDoS mitigation service. An always-on network-level solution such as Cloudflare Magic Transit should be in place prior to an attack. Reactive, on-demand SOC-based services require humans to analyze traffic and take too long to respond.
- Enforce a positive security model. Block TCP on IP/port ranges that are not expected to receive TCP, rather than relying on on-premise firewalls that can be overwhelmed. Also block network probing attempts (e.g., ICMP) and other packets not normally expected.
- Build custom mitigation strategies. Work with your DDoS protection vendor to tailor mitigations to your specific workload. Every network is different, and each poses unique challenges when integrating with DDoS mitigation systems.
- Educate employees. Train staff to be on the lookout for ransom demands across all channels — email, support tickets, form submissions, and server access logs. Ensure they know to immediately report any ransom demand to the Security Incident Response team.
When a Ransom Demand Arrives
If an attack is accompanied by a threat or ransom demand, the response should be swift and measured:
- Do not pay the ransom. Paying only encourages the bad actors, and there is no guarantee they won't attack again in the future.
- Notify your DDoS protection provider. Cloudflare can help ensure website and network infrastructure are safeguarded against these attacks.
- Notify local law enforcement. They will likely request a copy of the ransom letter.
Scale and Performance Considerations
Mitigating attacks on VoIP infrastructure requires more than just filtering capacity — it requires that the filtering not degrade call quality. Cloudflare's approach is built on over 100 Tbps of network capacity and an architecture that filters traffic close to the source, with a physical presence in over 250 cities. That proximity is critical for latency, jitter, and call quality. Test results demonstrate a performance improvement of 36% on average across the globe for a real customer network using Cloudflare Magic Transit.



