VoIP and its umbrella technology converged telecommunications is an area of InfoSec which even after 20+ years of deployment still has very little institutional focus.Millions of dollars of fraud are executed globally by highly sophisticated adversaries across a wide range of public, SOHO and carrier level infrastructure. This fraud often goes largely undetected or is written off by the carriers as unrecoverable.In this talk, I will cover some of the standard business models of VoIP hackers, methodologies they use to make sure their tracks are multi-jurisdictional and trans-corporate in such a way that almost guarantees they will be largely left alone. I will also give some practical examples of quick and easy ways to sweep up large collections of unsecured endpoints and show how these can be used to generate stable revenue for criminal groups or unethical individuals.