Caller ID Spoofing: What to Do When Scammers Copy Your Business Number

Caller ID Spoofing: What to Do When Scammers Copy Your Business Number
A customer calls back, upset about a conversation your team never had. Another says your number appeared on a threatening call. Yet your phone records show no matching outbound traffic. This pattern can indicate caller ID spoofing: a third party has made a call display your business number even though the call did not originate from your service.
That does not automatically mean your handset, Session Initiation Protocol (SIP) account or phone platform has been hacked. It also does not prove they are safe. The first response must separate copied caller identity from genuine account compromise, because the containment actions are different.
Use this guide to run that check, protect customers and give staff a controlled response. It focuses on defensive action; it does not describe how to falsify caller information.
What caller ID spoofing means for a business
Caller ID is the number—and sometimes the name—presented to the recipient of a call. Spoofing occurs when the displayed information is falsified so that the call appears to come from another person or organisation. A scammer may copy a trusted business number to improve the chance that someone answers or follows an urgent instruction.
The copied number can be yours even when the caller has no access to your devices or accounts. Think of it as someone printing your return address on an envelope: the label creates an appearance, but it does not prove where the item originated.
For a business, the damage is operational as well as technical:
- customers may lose trust in genuine calls;
- staff may receive angry or confused callbacks;
- fraudsters may impersonate finance, support or management teams;
- your service desk can waste time changing endpoints that were never compromised;
- a real account breach may be missed if every report is dismissed as “just spoofing”.
UK networks have introduced measures intended to identify and block more spoofed calls, including calls arriving from abroad that falsely present UK numbers. The UK government describes this network-level work, but no individual business should assume that every falsified call will be stopped. Your practical controls are rapid diagnosis, consistent verification and disciplined management of the identities your own service is allowed to present.
The decisive check: copied display or compromised phone account?
Start with one question: did the suspicious call actually pass through infrastructure or credentials controlled by your organisation?
Your communications provider or administrator should inspect call detail records, billing records, SIP logs, user activity and recent configuration changes. Compare these records with the customer’s evidence using the full destination number, date, time and time zone. A vague report such as “you called yesterday” is not enough to clear or condemn the account.
Signs that point towards external caller ID spoofing
- Multiple recipients report calls, but there are no matching outbound records.
- The scammer’s message or behaviour does not match any internal campaign.
- Staff accounts, devices and call routes show no unexplained activity.
- Charges, destination patterns and login locations remain consistent with normal use.
- The displayed number is correct, but other facts about the caller are generic or wrong.
Signs that demand account-compromise containment
- Outbound calls appear in provider records even though no authorised user placed them.
- Call charges, destinations or traffic spikes are unexplained.
- A SIP credential, extension or administrator account shows an unfamiliar login.
- Forwarding, caller identity, voicemail or routing settings changed unexpectedly.
- A former employee, lost device or unmanaged app may still have active access.
If records show unauthorised traffic, follow an account-breach process immediately: suspend affected credentials or users, preserve logs, rotate secrets through the approved administrator route, check billing exposure and ask the provider to restrict suspicious destinations. The VoIP toll-fraud response guide covers that problem in more depth.
If no matching traffic exists, external spoofing becomes more likely. Keep monitoring while you move into a trust-and-verification response. Do not factory-reset every phone or change the public number on assumption alone.
First hour: stop uncertainty spreading
The first hour is about evidence and message control. Name one incident owner—usually an IT, operations or security lead—and route reports to that person. Reception, support and sales should not run separate investigations or improvise different explanations.
Capture a usable report
Ask each reporting customer for only the evidence needed to investigate, without requesting sensitive information:
- number shown on their screen;
- date, local time and time zone;
- number that received the call;
- what the caller claimed to represent;
- whether the caller requested money, credentials, a one-time code or remote access;
- whether a voicemail or screenshot is available;
- whether the customer acted on the request.
Do not ask customers to forward passwords, bank details or authentication codes. Store screenshots and recordings under the organisation’s normal privacy and retention controls.
Check your own service before reassuring anyone
Review outbound call records for the reported window. Check administrator activity, user logins, recent forwarding changes, newly provisioned devices and unusual billing. If you cannot access authoritative logs, open a high-priority case with the provider and ask it to preserve relevant records.
Create one incident timeline. Record what is known, what is only reported, who owns each check and when the next update is due. The distinction matters: “the displayed number was ours” is evidence; “our phone system was hacked” is still a hypothesis.
Give staff a safe holding line
Use a short script that does not make claims before the evidence is checked:
Thank you for reporting this. We are checking whether the call came through our service or whether our number was copied on the caller display. We will never ask you to disclose a password or one-time security code on an unexpected call. Please end the call and contact us through the number or channel published on our official website.
Tell staff not to call an alleged victim back using contact details supplied during the suspicious interaction. Verification should start from an independently published channel.
First day: align your provider, people and public message
Once the initial evidence is collected, turn the incident into three coordinated workstreams.
Give the provider facts it can investigate
Open one case and include representative timestamps, source and destination numbers, the absence or presence of matching records, affected public numbers and any suspicious account activity. Ask:
- Can you confirm whether the reported calls traversed our account or trunks?
- Are there unauthorised registrations, logins, routes or caller identities?
- Can you preserve the relevant logs and provide a case reference?
- What network or carrier escalation is available for repeated impersonation?
- What controls restrict our authorised outbound caller identities?
- What monitoring can alert us to abnormal traffic from our real account?
Avoid promising customers that the provider can immediately prevent every external network from presenting the number. The provider can investigate your service, help restrict your legitimate outbound identity and escalate network abuse; it may not control every upstream source of a falsified call.
Brief every customer-facing team
Give reception, sales, support, finance and account managers the same facts, script and escalation route. Emphasise the requests that should trigger an independent callback: payment changes, bank details, credentials, one-time codes, remote-access requests and urgent confidentiality demands.
A useful internal rule is: displayed caller ID starts a conversation; it never completes verification for a sensitive action. For higher-risk requests, staff should end the call, locate the trusted number in an approved directory and call back through a separately established route.
Publish only what customers need
If reports are credible and repeated, a short notice on your website or status channel can reduce confusion. Keep it factual and time-stamped:
We are investigating reports that third parties may be displaying our business number on scam calls. Do not share passwords, one-time codes or payment details in response to an unexpected call. End the call and contact us using the details published on this website. If you have received a suspicious call, tell our support team the date, time and number shown.
Do not announce a “data breach” unless evidence supports that conclusion. Do not claim the issue is resolved merely because reports slow down. Your broader customer communication plan should define who approves notices, which channel is authoritative and how updates are withdrawn.

First week: make impersonation harder to exploit
You cannot solve external number spoofing with a handset switch. You can, however, make the copied display less persuasive and make abuse of your real service easier to detect.
Establish callback verification by business process
List the requests that require independent verification. Finance might require callbacks for bank-detail changes; support might prohibit asking for passwords; managers might confirm unusual instructions through a second channel. Put trusted internal and supplier numbers in a controlled directory rather than relying on recent-call lists.
Train staff to explain the rule without blaming the customer: “For this type of request, I will end the call and ring the number held in our approved records.” Test the rule with realistic scenarios and confirm that temporary and remote staff understand it.
Restrict the identities your own users can present
Ask your provider which outbound numbers each user, site or application is authorised to present. Remove old campaign numbers, leavers’ accounts and unnecessary administrative privileges. Investigate whether a user can select an unapproved identity and correct that policy.
For SIP and Voice over Internet Protocol (VoIP) deployments, inventory every credential and endpoint. Disable dormant registrations, avoid shared credentials where individual provisioning is possible, and use long, unique secrets managed through an approved process. Apply rate limits, destination restrictions and alerting where the platform supports them.
If the phone estate includes remote users, use the cloud PBX security checklist for SIP and softphones to review transport security, endpoint updates, lost-device response and least-privilege administration. These controls protect your actual service; they should not be marketed as a guarantee against third parties copying the number elsewhere.
Decide what customers should expect from a genuine call
Write a short, enforceable standard. For example, genuine staff will identify the case reference, will not request full passwords or one-time codes, and will accept an independent callback through the official website number. Avoid publishing a complex “secret phrase” that staff forget or customers can be tricked into revealing.
If you are reviewing the wider calling environment, include identity governance, audit records and offboarding in your business phone-system requirements. A buying checklist cannot stop external spoofing, but it can ensure the service you control produces evidence and limits unauthorised presentation.
Handle the three calls that follow the incident
Different callers need different responses. Treating them all as one technical ticket creates avoidable risk.
A customer says, “Your company just called me”
Thank them, collect the time and displayed number, and explain that the report is being checked. Warn them not to act on requests made in the unexpected call. If they disclosed payment or account information, direct them to the appropriate bank, account-security or fraud-response route without asking them to repeat secrets to your team.
An employee receives a call that appears to come from the boss
Caller ID is not approval. End the call and verify the request through the company directory or an established messaging channel. Payment, payroll, password-reset and data-release requests should follow existing authorisation controls regardless of urgency.
Your team finds real outbound records
Escalate from an impersonation investigation to account containment. Suspend affected access, preserve evidence, involve the provider and follow the organisation’s incident plan. Do not delete users, logs or devices before deciding what evidence must be retained.
For scam-call reports in the UK, use the current government guidance for reporting suspicious calls. If money or information has been lost, follow the linked fraud-reporting and financial-provider steps appropriate to the incident. Keep the provider case reference and evidence timeline available for any report.
Can you stop caller ID spoofing completely?
A business generally cannot guarantee that an external party will never copy its number on another network. Carrier filtering and identity-validation measures can reduce abuse, but controls and coverage vary across routes and providers. Be wary of any endpoint product presented as a universal spoofing cure.
Your organisation can control four important things:
- Whether its own accounts and trunks are compromised.
- Which caller identities legitimate users are authorised to present.
- How quickly abnormal traffic and customer reports are investigated.
- Whether staff and customers verify sensitive requests independently.
These controls reduce both the chance that your real service is abused and the chance that a copied number successfully tricks someone.
Should you change the business number?
Usually not as a first response. A new number can disrupt customers, listings, contracts and marketing, while a fraudster may later copy the replacement. Consider a number change only after provider and risk review identifies a specific reason, not as a reflex to unverified callback reports.
How long should you keep the incident open?
Keep active monitoring for a defined period based on report frequency and business risk. Record new examples consistently, review provider findings and publish a final customer update only when it is useful. Closure should mean that account compromise was addressed or reasonably ruled out, customer guidance remains available and normal monitoring can own future reports.

Prove the service you control
Caller ID spoofing exploits trust in a display. Your strongest response is evidence from your own service plus a verification process that does not depend on that display alone. Check the records, contain genuine compromise, coordinate one clear message and give staff a safe independent-callback rule.
If managed desktop and mobile softphones are part of your environment, run a focused SessionCloud trial with one representative team. Validate authorised outbound identities, managed SIP provisioning, credential handling, locked-device behaviour and rapid user offboarding. The trial will not prevent an external network from copying your number; it will help you prove and govern the endpoints and identities that SessionTalk can control.
A measured response protects customer trust without making false promises. It also leaves you with something valuable after the incident: a clearer record of who can call as your business, how suspicious activity is detected and how every sensitive request is verified.


