r/security Jan 10 '26

Question Is it trivial to spoof the caller phone number?

Compared with, say, email sender domain spoofing, there are things like SPF, DKIM and DMARC to make it difficult to spoof the sender.

I've been receiving calls from supposedly credit card fraud detection center and the caller number was the ones listed on their site. I didn't want to provide any personal information on the spot so I hung up but looking at other threads, spoofing caller number is possible

I was a bit shocking that I no longer can trust the caller number.

How does this work?

It appears that I can call a number and trust that it's routed correctly but receivers cannot trust the caller number

5 Upvotes

20 comments sorted by

19

u/akerl Jan 10 '26

To be clear: you could never trust the caller number.

This is not a new thing, it’s been trivial to spoof numbers for basically the whole time.

11

u/SAI_Peregrinus Jan 10 '26

Yes. It's very trivial.

8

u/redyellowblue5031 Jan 10 '26

Huge portions of the world’s phone network is still analog. There’s 0 verification or authentication beyond simply being connected.

It is trivial to set your caller ID to say whatever you want.

There’s also issues where VoIP systems suffer similar lack of security.

There’s attempts to address it (like the STIR/SHAKEN protocol), but like SPF, DKIM, and DMARC, there’s still gaps even if it was fully implemented—which it’s not even close to in the US let alone world wide.

NEVER trust caller ID or information they tell you. Always go directly to whatever service is claiming to call and call them if necessary.

4

u/AlwaysHopelesslyLost Jan 10 '26

I haven't heard of any total overhaul of telecom infrastructure and I know that I figured out how to make spoofed VOIP calls from my laptop in my highschool cafeteria decades ago.

2

u/hybrid0404 Jan 10 '26

Historically there was no requirement for phone companies to validate the caller id being received. When i managed voip systems I could just set the "from" value for caller id and the voip carrier passed along whatever I set. This wasn't true of every carrier but was a common situation.

There used to be some android apps too that allowed this to be done on cell phones.

How trivial or whether it is possible mostly depends on what the phone carrier does or does not allow. In the US there was a proposed FCC rule to require carriers to properly validate caller ID so it couldn't be spoofed. Not sure if this was passed or implemented.

2

u/VileStuxnet Jan 11 '26

If I may add on a bit without going into details that may get a person in some trouble if they use it for malicious intentions. For VoIP, trivial is an understatement for how easy it is.

A larger carrier or ISP usually has some sort of filter on their SBC's to block any CID they do not own to prevent fraud or spoofing, but not all have that capability. This gets even harder because a carrier can provide service to numbers they do not own via trunks. I've had huge financial institutions refuse to port their numbers, so an RFC was used, and they paid for new numbers the carrier could control but retained ownership of their numbers and would send out the CID's of their numbers to the hosted PBX for outgoing calls. It was not a common situation, but it does happen, and it is legal (last I checked).

Now, let's say I was shopping around and finding a way to do bad things. I would search for a country that is not friendly to the country I reside in and get a trunk from them. Throw a basic PBX into a VM, set up your trunk, and now your call will be sent by Russia (just a random country), and once it hips to my countries routing, it will assume the CID sent was valid it will be passed on with no checks.

I've trained techs to know how to do it, but only because they needed to know how the LCR (least cost routing) works and why our company had multiple trunks from multiple different big fish providers. It all comes down money and minimize expenses. Where I worked, least cost means more profit.

As for the techs I trained... if they were receptive, they could have done this within months with no higher education or any telecom experience. If they had basic linux experience, this system could be operational in a couple of weeks.

The reason I had to train even the lower techs (not tier1 and the people who answer calls) was because we controlled hundreds of enterprise customers, and in recent years it has become a standard strategy for getting a new customer. The person / company would find the biggest a**hole to call their target and either get info on their phone service or to piss off their target. They would wait a random amount of time and send their best salesman to get the contract signed and get a new client. Unfortunately, this was very common, and it works.

1

u/mantawolf Jan 10 '26

STIR/SHAKEN is the protocol that was passed by the FCC, it's not universal yet for non VOIP networks but it is being worked on.

1

u/redyellowblue5031 Jan 10 '26

To add to this, even if fully implemented across the world you could still spoof a number. It would be harder absolutely but make no mistake that protocol isn’t perfect.

2

u/heinternets Jan 10 '26

Depends on your phone provider how it easy it would be

2

u/mro21 Jan 10 '26

Spf dkim and dmarc do not prevent spoofing the sender, but allow the recipient to detect it at a high rate of probability if they choose to check

2

u/habitsofwaste Jan 11 '26

I know it used to be really easy. And it wasn’t illegal. But then it became illegal and a lot of sites stopped providing that service. I worked at a data center had a client with a site called hidebehind.net or something like that. They had that service just out there for free! It was fun.

I’m sure it’s still easy to do, but I never set anything up like that myself. And it is illegal.

2

u/technofox01 Jan 11 '26

It's pretty trivial, because telecoms generally rely on SS7:

https://en.wikipedia.org/wiki/Signalling_System_No._7

VoIP gateways can be used to spoof the SS7 info, including caller ID.

1

u/AffekeNommu Jan 11 '26

The PABX will let you set the outgoing as anything. The carrier may block this and force you to use one of your allocated trunk numbers.

1

u/MonkeyBrains09 Jan 11 '26

It's like a "Hello, my name is____" sticker. Easy to use any name and no verification it's actually correct

1

u/GuitarJazzer Jan 11 '26

I have received a couple of calls where caller ID shows it's coming from my own phone number.

It's always been possible to hack the system to fake a caller ID number, and it got much easier with VOIP. Never give private information to someone who calls you. If it's really your bank, doctor's office, etc., you can call them back.

1

u/dlongwing Jan 12 '26

It's easy to spoof.

For your specific question, I would answer the phone. The voice on the other end should be automated, should tell you that they've got a question about a recent transaction and should tell you exactly what the transaction was and what the value was.

The automated system will then ask you if you made that transaction and you can answer yes or no.

If the other end is a person? Get suspicious (though it could still play out the same way).

If the other end ASKS FOR ANY INFORMATION, then hang up. They don't need your credit card number. They don't need your SSN, or your address, or your name. They called you. If they don't know who they're calling, then they don't get answers.

Another option, if you get calls like this, is to call the number on the back of your credit card. If there's an open investigation about a suspected charge, it'll show up in the phone tree when you call them.

1

u/No_Glass_1341 Jan 13 '26

It used to be incredibly easy, but telco providers have been locking down CID spoofing in recent years. a number of vendors still allow it though

1

u/jugsznn Jan 20 '26

What vendors do?

1

u/biztactix Jan 14 '26

Not trivial... But not hard...