They can, but you need to know a bit of inside information. It's this sort of stuff that Kevin Mitnick was actually in trouble for. If you know the system, and the IP address of the VOIP gateway a lot of systems will let you connect as if you're within the network providing you have a compatible phone. This is why you should never have your remote user phone interface published anywhere, nothing should forward to it and it should be different to your main external IP address.

