HOME

TheInfoList



OR:

Caller ID spoofing is the practice of causing the telephone network to indicate to the receiver of a call that the originator of the call is a station other than the true originating station. This can lead to a
caller ID Caller identification (Caller ID) is a telephone service, available in analog and digital telephone systems, including voice over IP (VoIP), that transmits a caller's telephone number to the called party's telephone equipment when the call i ...
display showing a phone number different from that of the telephone from which the call was placed. The term is commonly used to describe situations in which the motivation is considered malicious by the originator. One effect of the widespread availability of Caller ID spoofing is that, as
AARP AARP (formerly called the American Association of Retired Persons) is an interest group in the United States focusing on issues affecting those over the age of fifty. The organization said it had more than 38 million members in 2018. The magazi ...
published in 2019, "you can no longer trust call ID."


History

Caller ID spoofing has been available for years to people with a specialized digital connection to the telephone company, called an
ISDN Integrated Services Digital Network (ISDN) is a set of communication standards for simultaneous digital transmission of voice, video, data, and other network services over the digitalised circuits of the public switched telephone network. Work ...
PRI circuit. Collection agencies, law-enforcement officials, and private investigators have used the practice, with varying degrees of legality. The first mainstream caller ID spoofing service was launched USA-wide on September 1, 2004 by California-based Star38.com. Founded by Jason Jepson, it was the first service to allow spoofed calls to be placed from a web interface. It stopped offering service in 2005, as a handful of similar sites were launched. In August 2006,
Paris Hilton Paris Whitney Hilton (born February 17, 1981) is an American media personality, businesswoman, socialite, model, and entertainer. Born in New York City, and raised there and in Beverly Hills, California, she is a great-granddaughter of Conrad ...
was accused of using caller ID spoofing to break into a voicemail system that used caller ID for authentication. Caller ID spoofing also has been used in purchase scams on web sites such as Craigslist and eBay. The scamming caller claims to be calling from Canada into the U.S. with a legitimate interest in purchasing advertised items. Often the sellers are asked for personal information such as a copy of a registration title, etc., before the (scammer) purchaser invests the time and effort to come see the for-sale items. In the 2010 election, fake caller IDs of ambulance companies and hospitals were used in Missouri to get potential voters to answer the phone. In 2009, a vindictive Brooklyn wife spoofed the doctor's office of her husband's lover in an attempt to trick the other woman into taking medication which would make her miscarry. Frequently, caller ID spoofing is used for prank calls. In December 2007, a hacker used a caller ID spoofing service and was arrested for sending a
SWAT In the United States, a SWAT team (special weapons and tactics, originally special weapons assault team) is a police tactical unit that uses specialized or military equipment and tactics. Although they were first created in the 1960s to ...
team to a house of an unsuspecting victim. In February 2008, a
Collegeville, Pennsylvania Collegeville is a borough in Montgomery County, Pennsylvania, a suburb outside of Philadelphia on Perkiomen Creek. Collegeville was incorporated in 1896. It is the location of Ursinus College which opened in 1869. The population was 5,089 at ...
, man was arrested for making threatening phone calls to women and having their home numbers appear "on their caller ID to make it look like the call was coming from inside the house." In March 2008, several residents in
Wilmington, Delaware Wilmington (Unami language, Lenape: ''Paxahakink /'' ''Pakehakink)'' is the largest city in the U.S. state of Delaware. The city was built on the site of Fort Christina, the first Swedish colonization of the Americas, Swedish settlement in North ...
, reported receiving telemarketing calls during the early morning hours, when the caller had apparently spoofed the caller ID to evoke
Tommy Tutone Tommy Tutone is an American power pop band, known for its 1981 hit "867-5309/Jenny", which peaked at #4 on the ''Billboard'' Hot 100. Though some people consider the band to be a one-hit wonder, it did reach the Top 40 the year before with "An ...
's 1981 hit " 867-5309/Jenny". By 2014, an increase in illegal telemarketers displaying the victim's own number, either verbatim or with a few digits randomized, was observed as an attempt to evade caller ID-based blacklists. In the Canadian federal election of May 2, 2011, both live calls and
robocall A robocall is a phone call that uses a computerized autodialer to deliver a pre-recorded message, as if from a robot. Robocalls are often associated with political and telemarketing phone campaigns, but can also be used for public service or em ...
s are alleged to have been placed with false caller ID, either to replace the caller's identity with that of a fictitious person ( Pierre Poutine of
Joliette, Quebec Joliette is a city in southwest Quebec, Canada. It is approximately northeast of Montreal, on the L'Assomption River and is the seat of the Regional County Municipality of Joliette. It is considered to be a part of the North Shore of Great ...
) or to disguise calls from an
Ohio Ohio () is a U.S. state, state in the Midwestern United States, Midwestern region of the United States. Of the List of states and territories of the United States, fifty U.S. states, it is the List of U.S. states and territories by area, 34th-l ...
call centre as
Peterborough, Ontario Peterborough ( ) is a city on the Otonabee River in Ontario, Canada, about 125 kilometres (78 miles) northeast of Toronto. According to the 2021 Census, the population of the City of Peterborough was 83,651. The population of the Peterborough ...
, domestic calls. See
Robocall scandal The 2011 Canadian federal election voter suppression scandal (also known as the Robocall scandal, Robogate, or RoboCon) is a political scandal stemming from events during the 2011 Canadian federal election. It involved robocalls and real-person ...
. In June 2012, a search on Google returned nearly 50,000 consumer complaints by individuals receiving multiple continuing spoofed
voice over IP Voice over Internet Protocol (VoIP), also called IP telephony, is a method and group of technologies for the delivery of voice communications and multimedia sessions over Internet Protocol (IP) networks, such as the Internet. The terms Internet t ...
(VoIP) calls on lines leased / originating from "Pacific Telecom Communications Group" located in Los Angeles, CA (in a mailbox store), in apparent violation of FCC rules. Companies such as these lease out thousands of phone numbers to anonymous voice-mail providers who, in combination with dubious companies like "Phone Broadcast Club" (who do the actual spoofing), allow phone spam to become an increasingly widespread and pervasive problem. In 2013, the misleading caller name "Teachers Phone" was reported on a large quantity of robocalls advertising credit card services as a ruse to trick students' families into answering the unwanted calls in the mistaken belief they were from local schools. On January 7, 2013, the Internet Crime Complaint Center issued a scam alert for various telephony denial-of-service attacks by which fraudsters were using spoofed caller ID to impersonate police in an attempt to collect bogus
payday loan A payday loan (also called a payday advance, salary loan, payroll loan, small dollar loan, short term, or cash advance loan) is a short-term unsecured loan, often characterized by high interest rates. The term "payday" in payday loan refers to ...
s, then placing repeated harassing calls to police with the victim's number displayed. While impersonation of police is common, other scams involved impersonating
utility companies A public utility company (usually just utility) is an organization that maintains the infrastructure for a public service (often also providing a service using that infrastructure). Public utilities are subject to forms of public control and ...
to threaten businesses or householders with disconnection as a means to extort money, impersonating
immigration Immigration is the international movement of people to a destination country of which they are not natives or where they do not possess citizenship in order to settle as permanent residents or naturalized citizens. Commuters, tourists, ...
officials or impersonating medical insurers to obtain personal data for use in theft of identity. Bogus caller ID has also been used in grandparent scams, which target the elderly by impersonating family members and requesting
wire transfer Wire transfer, bank transfer, or credit transfer, is a method of electronic funds transfer from one person or entity to another. A wire transfer can be made from one bank account to another bank account, or through a transfer of cash at a cash ...
of money. In 2018, one method of caller ID spoofing was called "neighbor spoofing", using either the same
area code A telephone numbering plan is a type of numbering scheme used in telecommunication to assign telephone numbers to subscriber telephones or other telephony endpoints. Telephone numbers are the addresses of participants in a telephone network, r ...
and
telephone prefix A telephone prefix is the first set of digits after the country, and area codes of a telephone number; in the North American Numbering Plan countries (country code +# ), it is the first three digits of a seven-digit phone number, 3-3-4 scheme. In ...
of the person being called, or the name of a person or business in the area.


Technology and methods

Caller ID is spoofed through a variety of methods and different technology. The most popular ways of spoofing caller ID are through the use of
VoIP Voice over Internet Protocol (VoIP), also called IP telephony, is a method and group of technologies for the delivery of voice communications and multimedia sessions over Internet Protocol (IP) networks, such as the Internet. The terms Internet t ...
or PRI lines.


Voice over IP

In the past, caller ID spoofing required an advanced knowledge of telephony equipment that could be quite expensive. However, with open source software (such as
Asterisk The asterisk ( ), from Late Latin , from Ancient Greek , ''asteriskos'', "little star", is a typographical symbol. It is so called because it resembles a conventional image of a heraldic star. Computer scientists and mathematicians often voc ...
or
FreeSWITCH FreeSWITCH is free and open-source server software for real-time communication applications, including WebRTC, video, and voice over Internet Protocol (VoIP). It runs on Linux, Windows, macOS, and FreeBSD. FreeSWITCH is used to build private bran ...
, and almost any
VoIP Voice over Internet Protocol (VoIP), also called IP telephony, is a method and group of technologies for the delivery of voice communications and multimedia sessions over Internet Protocol (IP) networks, such as the Internet. The terms Internet t ...
company), one can spoof calls with minimal costs and effort. Some VoIP providers allow the user to configure their displayed number as part of the configuration page on the provider's web interface. No additional software is required. If the caller name is sent with the call (instead of being generated from the number by a database lookup at destination) it may be configured as part of the settings on a client-owned analog telephone adapter or SIP phone. The level of flexibility is provider-dependent. A provider which allows users to bring their own device and unbundles service so that direct inward dial numbers may be purchased separately from outbound calling minutes will be more flexible. A carrier which doesn't follow established hardware standards (such as
Skype Skype () is a proprietary telecommunications application operated by Skype Technologies, a division of Microsoft, best known for VoIP-based videotelephony, videoconferencing and voice calls. It also has instant messaging, file transfer, debi ...
) or locks subscribers out of configuration settings on hardware which the subscriber owns outright (such as
Vonage Vonage (, legal name Vonage Holdings Corp.) is an American cloud communications provider operating as a subsidiary of Ericsson. Headquartered in Holmdel Township, New Jersey, the organization was founded in 1998 as ''Min-X'' as a provider of resi ...
) is more restrictive. Providers which market "wholesale VoIP" are typically intended to allow any displayed number to be sent, as resellers will want their end user's numbers to appear. In rare cases, a destination number served by voice-over-IP is reachable directly at a known
SIP address The SIP URI scheme is a Uniform Resource Identifier (URI) scheme for the Session Initiation Protocol (SIP) multimedia communications protocol. A SIP address is a URI that addresses a specific telephone extension on a voice over IP system. Such a ...
(which may be published through ENUM
telephone number mapping Telephone number mapping is a system of unifying the international telephone number system of the public switched telephone network with the Internet addressing and identification name spaces. Internationally, telephone numbers are systematically ...
, a
.tel The domain name .tel is a top-level domain (TLD) in the Domain Name System (DNS) of the Internet. It was approved by ICANN as a sponsored top-level domain, and is operated by Telnic. Telnic announced in January 2011 that over 300,000 domains h ...
DNS record or located using an intermediary such as SIP Broker). Some Google Voice users are directly reachable by SIP, as are all
iNum Initiative The iNum (international number) initiative was a project by Voxbone to create a global dial code for IP communications. Voxbone is a Belgian company specializing in wholesale telephone numbers for VoIP applications. The International Telecommun ...
numbers in country codes +883 5100 and +888. As a
federated VoIP Federated VoIP is a form of packetized voice telephony that uses voice over IP between autonomous domains in the public Internet without the deployment of central virtual exchange points or switching centers for traffic routing. Federated VoIP uses ...
scheme providing a direct Internet connection which does not pass through a signaling gateway to the
public switched telephone network The public switched telephone network (PSTN) provides infrastructure and services for public telecommunication. The PSTN is the aggregate of the world's circuit-switched telephone networks that are operated by national, regional, or local telep ...
, it shares the advantages (nearly free unlimited access worldwide) and disadvantages (ernet applications).


Service providers

Some spoofing services work similarly to a prepaid calling card. Customers pay in advance for a
personal identification number A personal identification number (PIN), or sometimes redundantly a PIN number or PIN code, is a numeric (sometimes alpha-numeric) passcode used in the process of authenticating a user accessing a system. The PIN has been the key to facilitati ...
(PIN). Customers dial the number given to them by the company, their PIN, the destination number and the number they wish to appear as the caller ID. The call is bridged or transferred and arrives with the spoofed number chosen by the caller—thus tricking the called party. Many providers also provide a Web-based interface or a mobile application where a user creates an account, logs in and supplies a source number, destination number, and the bogus caller ID information to be displayed. The server then places a call to each of the two endpoint numbers and bridges the calls together. Some providers offer the ability to record calls, change the voice and send
text messages Text messaging, or texting, is the act of composing and sending electronic messages, typically consisting of alphabetic and numeric characters, between two or more users of mobile devices, desktops/ laptops, or another type of compatible compu ...
.


Orange box

Another method of spoofing is that of emulating the Bell 202 FSK signal. This method, informally called
orange box An orange box is a piece of hardware or software that generates caller ID frequency-shift keying (FSK) signals to spoof caller ID information on the target's caller ID terminal. See also * Blue box A blue box is an electronic device that ...
ing, uses software that generates the audio signal which is then coupled to the telephone line during the call. The object is to deceive the called party into thinking that there is an incoming
call waiting Call waiting is a telephone service where a subscriber can accept a second incoming telephone call by placing an in-progress call on hold—and may also switch between calls. With some providers it can be combined with additional features such a ...
call from the spoofed number, when in fact there is no new incoming call. This technique often also involves an accomplice who may provide a secondary voice to complete the illusion of a call-waiting call. Because the orange box cannot truly spoof an incoming caller ID prior to answering and relies to a certain extent on the guile of the caller, it is considered as much a social engineering technique as a technical hack. Other methods include switch access to the
Signaling System 7 Signalling System No. 7 (SS7) is a set of telephony signaling protocols developed in 1975, which is used to set up and tear down telephone calls in most parts of the world-wide public switched telephone network (PSTN). The protocol also perf ...
network and social engineering telephone company operators, who place calls for you from the desired phone number.


Caller name display

Telephone exchange telephone exchange, telephone switch, or central office is a telecommunications system used in the public switched telephone network (PSTN) or in large enterprises. It interconnects telephone subscriber lines or virtual circuits of digital syste ...
equipment manufacturers vary in their handling of caller name display. Much of the equipment manufactured for
Bell System The Bell System was a system of telecommunication companies, led by the Bell Telephone Company and later by the American Telephone and Telegraph Company (AT&T), that dominated the telephone services industry in North America for over one hundr ...
companies in the
United States The United States of America (U.S.A. or USA), commonly known as the United States (U.S. or US) or America, is a country Continental United States, primarily located in North America. It consists of 50 U.S. state, states, a Washington, D.C., ...
sends only the caller's number to the distant exchange; that switch must then use a database lookup to find the name to display with the calling number.
Canadian Canadians (french: Canadiens) are people identified with the country of Canada. This connection may be residential, legal, historical or cultural. For most Canadians, many (or all) of these connections exist and are collectively the source of ...
landline exchanges often run
Nortel Nortel Networks Corporation (Nortel), formerly Northern Telecom Limited, was a Canadian multinational telecommunications and data networking equipment manufacturer headquartered in Ottawa, Ontario, Canada. It was founded in Montreal, Quebec, ...
equipment which sends the name along with the number. Mobile, CLEC,
Internet The Internet (or internet) is the global system of interconnected computer networks that uses the Internet protocol suite (TCP/IP) to communicate between networks and devices. It is a '' network of networks'' that consists of private, p ...
or
independent Independent or Independents may refer to: Arts, entertainment, and media Artist groups * Independents (artist group), a group of modernist painters based in the New Hope, Pennsylvania, area of the United States during the early 1930s * Independe ...
exchanges also vary in their handling of caller name, depending on the switching equipment manufacturer. Calls between numbers in differing
country code Country codes are short alphabetic or numeric geographical codes (geocodes) developed to represent countries and dependent areas, for use in data processing and communications. Several different systems have been developed to do this. The term ...
s represent a further complication, as caller ID often displays the local portion of the calling number without indicating a country of origin or in a format that can be mistaken for a domestic or invalid number. This results in multiple possible outcomes: * The name provided by the caller (in the analog telephone adapter configuration screen for voice-over-IP users or on the web interface on a spoofing provider) is blindly passed verbatim to the called party and may be spoofed at will * The name is generated from a telephone company database using the spoofed caller ID number. * A destination provider may display no name or just the geographic location of the provided
telephone area code A telephone numbering plan is a type of numbering scheme used in telecommunication to assign telephone numbers to subscriber telephones or other telephony endpoints. Telephone numbers are the addresses of participants in a telephone network, r ...
on caller ID (''e.g.'', "ARIZONA", "CALIFORNIA", "OREGON", or "ONTARIO"). This often occurs where the destination carrier is a low-cost service (such as a VoIP provider) running no database or outdated data in which the number is not found. * If the displayed number is in the recipient's address book, some handsets will display the name from the local address book in place of the transmitted name. Some VoIP providers use
Asterisk (PBX) Asterisk is a software implementation of a private branch exchange (PBX). In conjunction with suitable telephony hardware interfaces and network applications, Asterisk is used to establish and control telephone calls between telecommunication e ...
to provide similar functionality at the server; this may lead to multiple substitutions with priority going to the destination user's own handset as the last link in the CNAM chain.


Legal considerations


Canada

Caller ID spoofing remains legal in Canada, and has recently become so prevalent that the
Canadian Anti-Fraud Centre The Canadian Anti-Fraud Centre (formerly known as PhoneBusters National Call Centre) is Canada's national anti-fraud call centre and central fraud data repository. It was established in January 1993 in North Bay, Ontario, and is jointly operated ...
has "add dan automated message about
he practice He or HE may refer to: Language * He (pronoun), an English pronoun * He (kana), the romanization of the Japanese kana へ * He (letter), the fifth letter of many Semitic alphabets * He (Cyrillic), a letter of the Cyrillic script called ''He'' in ...
to their fraud-reporting hotline". The
CRTC The Canadian Radio-television and Telecommunications Commission (CRTC; french: Conseil de la radiodiffusion et des télécommunications canadiennes, links=) is a public organization in Canada with mandate as a regulatory agency for broadcasti ...
estimates that 40% of the complaints they receive regarding unsolicited calls involve spoofing. The agency advises Canadians to file complaints regarding such calls, provides a list of protection options for dealing with them on its website, and, from July through December 2015, held a public consultation to identify "technical solutions" to address the issue. On January 25, 2018, the CRTC set a target date of March 31, 2019 for the implementation of a CID authentication system. On December 9, 2019, the CRTC extended this date, announcing that they expect STIR/SHAKEN, a CID authentication system, to be implemented by September 30, 2020. On September 15, 2020, the CRTC extended the target date one more time, changing it to June 30, 2021. The CRTC is formally considering making its target date for STIR/SHAKEN mandatory. On December 19, 2018, the CRTC announced that beginning in a year from that date, phone providers must block all calls with caller IDs that do not conform to established numbering plans.


India

According to a report from the India Department of Telecommunications, the government of India has taken the following steps against the CLI spoofing service providers: * Websites offering caller ID spoofing services are blocked in India as an immediate measure. * International long-distance operators (ILDOs), national long-distance operators (NLDOs) and access service providers have been alerted to the existence of such spoofing services, and shall collectively be prepared to take action to investigate cases of caller ID spoofing as they are reported. As per DOT, using spoofed call service is illegal as per the Indian Telegraph Act, Sec 25(c). Using such service may lead to a fine, three years' imprisonment or both.


United Kingdom

In the UK, the spoofed number is called the "presentation number". This must be either allocated to the caller, or if allocated to a third party, it is only to be used with the third party's explicit permission. Starting 2016, direct marketing companies are obliged to display their phone numbers. Any offending companies can be fined up to £2 million by
Ofcom The Office of Communications, commonly known as Ofcom, is the government-approved regulatory and competition authority for the broadcasting, telecommunications and postal industries of the United Kingdom. Ofcom has wide-ranging powers acros ...
. In 2021, Huw Saunders, a director at Ofcom, the UK regulator, said the current UK phone network (Public Switched Telephone Network) is being updated to a new system (Voice Over Internet Protocol), which should be in place by 2025. Saunders said, "It's only when the vast majority of people are on the new technology (VOIP) that we can implement a new patch to address this problem f Caller ID spoofing"


United States

Caller ID spoofing is generally legal in the United States unless done "with the intent to defraud, cause harm, or wrongfully obtain anything of value". The relevant federal statute, the Truth in Caller ID Act of 2009, does make exceptions for certain law-enforcement purposes. Callers are also still allowed to preserve their anonymity by choosing to block all outgoing caller ID information on their phone lines. Under the act, which also targets VoIP services, it is illegal "to cause any caller identification service to knowingly transmit misleading or inaccurate caller identification information with the intent to defraud, cause harm, or wrongfully obtain anything of value...." Forfeiture penalties or criminal fines of up to $10,000 per violation (not to exceed $1,000,000) could be imposed. The law maintains an exemption for blocking one's own outgoing caller ID information, and law enforcement isn't affected. ''
The New York Times ''The New York Times'' (''the Times'', ''NYT'', or the Gray Lady) is a daily newspaper based in New York City with a worldwide readership reported in 2020 to comprise a declining 840,000 paid print subscribers, and a growing 6 million paid ...
'' sent the number 111-111-1111 for all calls made from its offices until August 15, 2011. The fake number was intended to prevent the extensions of its reporters appearing in call logs, and thus protect reporters from having to divulge calls made to anonymous sources. The ''Times'' abandoned this practice because of the proposed changes to the caller ID law, and because many companies were blocking calls from the well-known number. Starting in mid-2017, the FCC pushed forward Caller ID certification implemented using a framework known as STIR/SHAKEN. SHAKEN/STIR are acronyms for Signature-based Handling of Asserted Information Using toKENs (SHAKEN) and the Secure Telephone Identity Revisited (STIR) standards. The FCC has mandated that telecom providers implement STIR/SHAKEN-based caller ID attestation in the IP portions of their networks beginning no later than June 30, 2021. On August 1, 2019, the FCC voted to extend the Truth in Caller ID Act to international calls and text messaging. Congress passed the TRACED Act in 2019 which makes Caller ID authentication mandatory.Trump signs the TRACED Act, the first federal anti-robocall law
/ref>


See also

*
Caller ID Caller identification (Caller ID) is a telephone service, available in analog and digital telephone systems, including voice over IP (VoIP), that transmits a caller's telephone number to the called party's telephone equipment when the call i ...
* Truth in Caller ID Act of 2009 *


References


External links

* * * * * {{cite magazine , author=''WIRED'' Staff , title=FCC Probes Caller-ID Fakers , url=https://www.wired.com/news/technology/0,70320-0.html , magazine=
Wired ''Wired'' (stylized as ''WIRED'') is a monthly American magazine, published in print and online editions, that focuses on how emerging technologies affect culture, the economy, and politics. Owned by Condé Nast, it is headquartered in San ...
, department=Science , date=March 2, 2006 Spoofing Confidence tricks Deception Telemarketing