· Luke Faragher · Mobile Networks  · 7 min read

Number spoofing explained: why the number on your screen can lie

Caller display can be faked. What number spoofing is, how CLI really works between networks, what Ofcom is doing, and what to do if your number is spoofed.

Caller display can be faked. What number spoofing is, how CLI really works between networks, what Ofcom is doing, and what to do if your number is spoofed.

Number spoofing is when a caller deliberately changes the number displayed on your phone so the call appears to come from someone else. It is possible because caller ID is a label supplied by the caller’s phone company, not something your phone or your network independently verifies, so the number on your screen can be made to say almost anything.

That is the short version. The longer version is worth understanding, because once you know how caller ID actually travels between networks, a lot of scam behaviour suddenly makes sense - and so does the right way to defend yourself.

How caller ID actually works

I have run a mobile network since 2013, so let me explain what happens when your phone rings.

When a call is set up, the originating provider attaches a piece of signalling data called the CLI - calling line identity. That call may then pass through several other networks on its way to yours: a wholesale carrier, an international transit operator, sometimes more than one. Each network in the chain passes the CLI along. When the call finally lands on your network, your provider reads that field and puts it on your screen.

Here is the uncomfortable part: at no point in that journey does anyone cryptographically prove the CLI is genuine. Your network receives an assertion, made by an originating provider it has probably never dealt with directly, relayed through intermediaries. Ofcom’s CLI guidance puts obligations on providers to ensure the numbers they send are valid and dialable, and to block obviously bogus ones. But the system was designed decades ago on the assumption that phone companies would only ever send truthful data. Modern VoIP systems let a caller set the outbound CLI to whatever they type in, and if the provider carrying that traffic does not check it, the lie travels the whole way to your handset looking exactly like the truth.

This is a provider-level choice, and it is worth saying how we handle it at ONSIM: our customers cannot set their own CLI. The only numbers a customer can present are ones we have assigned to them or ones they have ported in and proven ownership of. That is how every provider could work, and if the whole industry did it, spoofing would not exist. The gap between “could” and “does” is the rest of this article.

Legitimate spoofing vs scam spoofing

Changing the presented number is not automatically sinister. It happens legitimately all day, every day:

  • A GP surgery presents the main switchboard number when a doctor calls from a back-office extension, so you can actually call back.
  • A business presents its main 0800 or geographic number on outbound calls from any desk or mobile, so customers see one consistent number. We do this for ONSIM customers ourselves.
  • A call centre working on behalf of a company presents that company’s number rather than its own internal lines.

Under Ofcom’s rules, that is fine as long as the presented number is dialable, identifies the party responsible for the call, and the caller has the right to use it.

Scam spoofing is the same mechanism with none of the legitimacy. Fraudsters present your bank’s real number so the call matches the one on the back of your card. They present ordinary UK mobile numbers, because Ofcom’s research found people are far more likely to answer a UK mobile than an international number - 26% would answer an unknown UK mobile against 9% for an unfamiliar foreign number. And sometimes they present a random member of the public’s number, which is how perfectly innocent people end up receiving furious callbacks about calls they never made. Ofcom’s consumer page on number spoofing scams has more on how these scams play out.

What Ofcom is doing about it

Quite a lot, and the pace has picked up:

  • Blocking invalid numbers. Providers are expected to identify and block calls whose CLI is not a valid, dialable number, and to use the Do Not Originate list - numbers, like banks’ inbound-only lines, that should never appear as a caller ID - under Ofcom’s strengthened CLI guidance.
  • Blocking calls from abroad that fake UK landline numbers. Since January 2025, providers must block international calls that present a UK landline number as the caller ID, outside a short list of legitimate cases. Ofcom said in 2025 that industry measures were already blocking around a million calls a day.
  • Closing the mobile loophole. UK mobile numbers were initially exempt, so that people roaming abroad could still show their own number. Scammers exploited that gap, so in July 2026 Ofcom finalised strengthened guidance: providers should now withhold the caller ID on calls that appear to come from a UK mobile roaming abroad unless they can verify it is genuine.

The honest bit, from someone inside the industry: the reason this is being fixed with blocking rules rather than actual verification is that verification is genuinely hard to retrofit. The United States has STIR/SHAKEN, a system where providers cryptographically sign the caller ID, but it only works across all-IP networks. Ofcom assessed CLI authentication for the UK in 2024 and concluded it cannot work properly until the UK’s remaining legacy networks finish migrating to IP, publishing a roadmap rather than a date. And even then, international gateways remain the weak point: a call handed to a UK network by a foreign transit carrier arrives with whatever CLI it was given several networks ago, signed by nobody. Until originating networks worldwide vouch for their traffic, the display on your screen is an assertion, not a fact.

Is my number being spoofed?

If strangers are ringing or texting you to ask why you called them, your number is probably being used as a spoofed caller ID. Two things to hold on to:

You have not been hacked. A scammer does not need access to your phone, SIM or any account to present your number - they simply typed it into their calling system. There is nothing to secure and nothing they took.

It almost always passes quickly. Scammers rotate through numbers constantly to stay ahead of blocking, and regulator guidance notes they typically stop using any one number within hours or days.

While it lasts: do not get drawn into arguments with angry callbacks, consider a voicemail greeting explaining your number has been spoofed, and let your mobile provider know. If the spoofing is tied to actual fraud - someone impersonating you or scamming people in your name - report it to Report Fraud, which replaced Action Fraud as the national fraud reporting service, on 0300 123 2040 (in Scotland, call Police Scotland on 101).

How to protect yourself from spoofed calls

The defence is simple and it works regardless of how sophisticated the spoofing is: never treat the number on the screen as proof of who is calling.

If a caller claiming to be your bank, HMRC or anyone else asks for money, codes or personal details, hang up. Then call the organisation back on a number you found independently - the one on your card, a statement or the official website - not one the caller gave you. Ofcom recommends waiting a few minutes first, or using a different phone, in case the line has been held open. Forward scam texts to 7726 - our guide to reporting spam texts with 7726 covers exactly how - and see our full guide to stopping spam calls in the UK for blocking tools and services.

Check the number, not just the name

If a number you do not recognise keeps calling, you can look it up free with our UK phone number checker. It will tell you whether the number is validly formatted, what type it is, and where it belongs, and you can browse every dialling code in our UK area codes directory.

One honest caveat, and it is the whole point of this article: a lookup tells you about the number, not the caller. A spoofed call from “your bank’s number” will look up as your bank’s number, because it is - the lie is about who is using it. Treat lookups as one piece of evidence, and treat callback-on-a-number-you-found-yourself as the real security control.


Luke Faragher is the founder of ONSIM, which has run SIM-native business mobile and landline services since 2013. ONSIM is an independent mobile network.

Frequently asked questions

Back to Blog

Related Posts

View All Posts »