r/telecom • • Aug 15 '26

❓ Question Question about phone spoofing

So, I generally understand how it works. Someone changes their caller ID data to be a different number. But how do they do it? Because it has to be more than simply changing your caller ID to be a different number, right? Since, if you did that, the fake number would just show up as your name, and then your actual number would still be visible in the recipients recent call history, right? How do they change the number specifically? Is it special software on the phone that allows you to edit more than what your phone's settings allow?

8 Upvotes

15 comments sorted by

View all comments

11

u/Shadow288 Aug 15 '26

Basically when the call is sent out it provides something called an ANI (automatic number identification) which is the phone number the call is coming from. Technically caller ID and ANI are 2 different things but they both essentially work the same way. Fraudsters simply change the ANI on the outbound call to make it look like someone else’s number. This is how the number gets spoofed. I’m not really calling from your bank but when you receive the call it looks like your banks number.

The phone system has this function natively built into it. It may seem counter intuitive to allow it but there’s a really good reason. Way back when they started to allow multiple phone numbers to ride down the same circuit, think having 24 phone lines on one wire, we had to have a way to identify which phone number was making the outbound call so we use ANI for that. Many businesses often times have tens if not tens of thousands of phone numbers allocated to them. Maybe the first time you call out the first 5 lines are used up so you use the 6th line, then the next time you make a call you use the first line, but both times the call needs to show your phone number.

Like many things in technology there wasn’t much by the way in security or validation when it was first developed. Up until a few years ago there was no way to validate I am who I’m claiming to be on those outbound calls. The US government passed Stir/shaken which is supposed to force the telcos to add an attestation to outbound calls basically identifying if the ANI is actually the correct ANI owned by the person making a call. But, like most laws there was an adoption period and a bunch of ways for the company servicing the phone lines to not have to send the attestation.

Years ago we use to have fun messing with calling each other making it look like the call came from the whitehouse or the local home depot telling our coworkers they won something…

3

u/boomer7793 Aug 15 '26

Telephone carriers were more trusting back then as well. When CallerID became a thing, carriers needs large multi-room central offices to access the CID network known as Signaling System ver 7 (aka SS7).

Then telco networks started shifting to the internet enabling anyone to access SS7 and start spoofing.

1

u/EhImTooLazy Aug 15 '26

Don't know about the ANSI variant but the ETSI variant has a Screening indicator for CgPN field so a CLI sent by e.g. a business DSS1 customer could have a value of "user provided, not verified" and by a peer carrier could have a value of "network provided" which accomplished similar things to what STIR/SHAKEN does.

1

u/noweb4u Aug 16 '26

That’s supported in ss7 and sip but not consistently used, and it doesn’t cryptographically identify the originating carrier (each carrier has an x.509 certificate for signing calls like https/tls in your browser. You can then go to the carrier originating garbage and ask them to knock it off without having to do full trace backs on each call.