Egidio
Report · 2026

How a phone number can lie

A call that shows your bank's number isn't necessarily your bank. Spoofing — faking the displayed caller ID — is an old technique, still used at massive scale, that recent protocols are only beginning to counter.

Protect my phone with Egidio Free for calls · 100% on your phone · no account needed

A mechanism distinct from a voice deepfake

This report covers spoofing the displayed number, not cloning a voice with artificial intelligence — a separate topic, covered in the report on generative AI & voice deepfakes. Number spoofing means falsifying the caller ID that shows up on the recipient's screen, by exploiting legacy telephony protocols designed at a time when this kind of verification wasn't a security concern.

"Neighbor spoofing"

The most common technique documented by the US regulator (FCC) displays a number sharing your local area code, to appear familiar and increase the odds you'll pick up — even if the caller has absolutely no connection to your region. The same logic applies to directly spoofing the number of a business or agency you already know. In the United States, the law allows fines of up to $10,000 per violation for this kind of malicious spoofing.

Source: Federal Communications Commission (FCC), "Caller ID Spoofing."

The technical response: STIR/SHAKEN

To address this problem, a call-authentication protocol — STIR/SHAKEN — was deployed to let carriers verify that a calling number is legitimate before passing it along. Adoption is progressing, but remains uneven:

44%
Share of registered phone carriers with full STIR/SHAKEN deployment in the United States, as of September 2025.
FCC, data as of 09/28/2025.
17.5%
Share of traffic signed and verified between small carriers in 2025 — well below the rate among large carriers, creating an uneven verification chain.
TNS, 2026 Robocall Investigation Report.

In other words: the technical verification exists, but as long as it isn't universal across every carrier in a call chain, a spoofed number can still reach its final recipient without being flagged as suspicious.

Spoofing

Falsifying the displayed identifier on a call or text, to pose as a trusted number.

Neighbor spoofing

A spoofing variant using a number that shares your local area code to appear familiar.

STIR/SHAKEN

A technical protocol letting carriers verify and sign the authenticity of a calling number throughout the call chain.

🔒 As long as network-side verification stays incomplete, device-side protection keeps its full value: recognizing a suspicious call pattern even when the displayed number looks familiar. See how Medusa works.

Frequently asked questions

Isn't number spoofing the same thing as a voice deepfake?

No. Spoofing falsifies the number that displays on your screen — a technique that's existed for a long time. A voice deepfake clones a voice using AI. The two can be combined, but they're two distinct mechanisms.

What is "neighbor spoofing"?

A technique that displays a number sharing your local area code, to appear familiar and increase the odds you'll pick up — even if the caller has no connection at all to your region.

Does STIR/SHAKEN fully protect against spoofing?

Not yet completely. This call-authentication protocol is widely deployed among major US carriers, but adoption remains partial among smaller carriers, which leaves gaps in the chain.

Other markets we cover

Regulators outside the US are building their own answers to spoofed caller IDs — different tools, same goal.

🇦🇺Australia — gateway blocking plus fines up to AUD $50 million

Australia blocks international calls that spoof Australian caller IDs at the gateway, and its Scams Prevention Framework Act, in force since February 2025, allows penalties of up to AUD $50 million per contravention for regulated sectors, including telcos, that fail to act on scam traffic. Regulator ACMA has already issued seven-figure infringement notices to carriers over related identity-check failures.

ACMA, "Combating phone scams" & enforcement reports, 2025–2026.

🇬🇧United Kingdom — mandatory blocking of spoofed UK numbers from abroad

Since 29 January 2025, updated Ofcom guidance requires UK telecoms providers to block international calls that falsely display a UK number, and Ofcom can fine providers up to £2,000,000 for persistent misuse of caller ID. A July 2025 consultation proposes going further: withholding the caller ID entirely on calls claiming to be a UK mobile roaming abroad unless it can be verified.

Ofcom, CLI Guidance update, January 2025; consultation, July 2025.

🇨🇦Canada — STIR/SHAKEN mandatory since 2021, still incomplete

Canada's regulator CRTC required all telecom providers to implement the STIR/SHAKEN call-authentication framework by 30 November 2021, with compliance reports due to the CRTC every six months since. The framework only authenticates calls carried over IP-voice networks, so calls routed through older infrastructure can still arrive with an unverified — and potentially spoofed — caller ID.

CRTC, STIR/SHAKEN implementation directives, 2021–2025.

🇮🇳India — a verified caller name replacing the number itself

Rather than only authenticating numbers, India's TRAI approved Calling Name Presentation (CNAP) in October 2025, matching incoming calls against telecom operators' KYC-verified customer databases so a verified name — not just a number — displays on the screen. Rollout to 4G and 5G users nationwide is targeted for March 2026, starting with trial regions including Haryana and Himachal Pradesh.

TRAI, CNAP approval, October 2025; rollout coverage, Mondaq, 2026.

Go further

Cite this page Egidio — The Threat Laboratory, "Caller ID spoofing: how a phone number can lie", egidio.app/en/laboratoire/caller-id-spoofing/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.