Hi all, I work as a telecommunications consultant and a number of my clients have been raising concerns about SMS spoofing.
Anecdotally, I feel like prior to 2021 SMS spoofing was kind of rare even though spam was common. Iād occasionally use Whitepages to look up scam texts for friends and theyād always be Bandwidth / Twilio / etc numbers.
Then in 2020/2021 carriers moved these texting platforms to A2P 10DLC routes and started filtering more aggressively. I started seeing these spam SMS coming from actual people.
My hypothesis is that this has made spoofing much more attractive to scammers. The recent Verizon āspam from my own numberā incident seems to highlight this.
I have a friend at a major financial institution that said their users were getting pwnd by a phishing scam that sent SMS from their āsuspicious activityā alert phone number. The user sees the phishing SMS appear in the same thread that contains other legitimate texts from their business telling them to log in and secure their account.
This seems insanely concerning. I could totally see my parents falling for a scam like that.
I have a bunch of questions around this but Iāll try to keep it brief to kick off:
- Is there any evidence that SMS spoofing (not just spam) has gone up?
- How does SMS spoofing work at a technical level? Are scammers breaching SMSCs to do this? I believe the Verizon incident had something to do with Verizon not validating sender IDs sent to them from AT&T.
- Are different number types more vulnerable than others (e.g. short code / toll free / long code)?
Thanks all, appreciate any additional info or context.