Number Spoofing: Why Your Calls and SMS Are No Longer Secure and How Arcep is Reacting
L'équipe Texto SMS Gratuit

L'équipe Texto SMS Gratuit

12 August 2026 · 6 min read

Introduction: The Mirage of Digital Identity

Imagine receiving a call from your bank, your insurance advisor, or even a loved one, with the exact number appearing on your screen. You answer, confident, only to eventually realize you are on the line with a scammer based on the other side of the world. This scenario, once reserved for spy movies, has become a daily reality for millions of people. This is what is known as number spoofing.

Telephone identity, which we consider a unique and reliable identifier, is actually fragile. The protocol used to route calls and SMS was not designed with security as a priority, leaving the door open to simple technical manipulations to mask the sender's real identity. Faced with the explosion of these frauds, Arcep (the Regulatory Authority for Electronic Communications, Posts and Press Distribution) has decided to go on the offensive by opening an investigation targeting all telecom operators.

Close-up of a smartphone displaying a suspicious incoming call

Why does this flaw persist in 2026? How do fraudsters manage to bypass security systems? And above all, what can the regulator do to force operators to secure our communications?

The Technical Mechanism: How Does Spoofing Work?

To understand spoofing, one must understand that the number displayed on your phone is not proof of identity, but a simple "label" transmitted in the call's signaling data.

The SIP Protocol Flaw

Most modern calls transit through the SIP (Session Initiation Protocol), used for Voice over IP (VoIP). The major problem with SIP is that it allows the sender to define the "From" field in the message header themselves.

When a fraudster uses a poorly secured VoIP gateway or specialized software, they can inject any number into this field. The operator's network receives the call and, without thorough verification of the signal's actual origin, simply transmits the requested label to the recipient's phone.

Different Forms of Spoofing

Spoofing is not limited to voice calls. There are three main types of attacks:

  1. Corporate Spoofing: The fraudster imitates the number of an institution (Bank, Tax Office, Health Insurance) to establish immediate trust.
  2. Neighbor Spoofing: The attacker uses a number with the same regional area code as the victim to increase the chances that the call will be answered.
  3. Contact Spoofing: Rarer and more targeted, the fraudster usurps the number of a loved one to request an urgent transfer ("fake son" or "fake boss" scam).

The Arcep Investigation: Operators Facing Their Responsibilities

Since early 2026, Arcep has intensified its surveillance. The open investigation does not target the fraudsters—who are often beyond legal reach—but the operators. The regulator asks a fundamental question: Why do mobile networks allow calls through whose identity is clearly falsified?

Lack of Entry Filtering

Arcep points to the porosity of interconnections. When a call arrives from a foreign operator or a small VoIP provider to a major French network (Orange, SFR, Bouygues, Free), filtering is often insufficient. Operators accept calls by trusting the information transmitted by the originating network, without a cross-validation mechanism.

Financial and Technical Stakes

For operators, implementing strict filtering represents a technical challenge. Verifying the authenticity of every incoming call in real-time could induce connection delays or, worse, block legitimate calls (false positives). Furthermore, the absence of a harmonized global standard makes the fight complex: a French operator cannot easily demand identity guarantees from an operator based in a lax jurisdiction.

Person using a smartphone with a worried expression

What Solutions to Secure Our Communications?

Arcep is pushing operators toward the adoption of certification protocols. The goal is to move from a system of "blind trust" to a system of "verified trust."

The STIR/SHAKEN Standard

Already successfully deployed in North America, the STIR/SHAKEN framework is the preferred technical solution. Here is how it works:

  • STIR (Secure Telephone Identity Revisited): Allows an encrypted digital certificate to be added to the call.
  • SHAKEN (Signature-based Handling of Assertions provided by Tokens): Defines how operators should handle these certificates.

In short, the sender's operator "signs" the call. The recipient's operator verifies the signature. If the signature is missing or invalid, the phone can display a "Potentially Fraudulent Call" notice or block the call.

The Role of Intelligent Filters and AI

In parallel, operators and manufacturers (Apple, Google) are integrating databases of reported numbers. AI now analyzes behavior: a number that makes 10,000 ten-second calls in one hour is almost systematically identified as a spoofing bot and blacklisted.

Practical Guide: How to Protect Yourself from Spoofing?

Until the measures from Arcep and operators are fully effective, vigilance remains your best defense. Spoofing plays on emotion and urgency.

Security Reflexes to Adopt

SituationRecommended Reflex
Bank call asking for a codeHang up immediately. Call your advisor back yourself via the official number.
Urgent SMS from a loved one asking for moneyCall the person on their usual number to verify.
Call from an administration (Taxes, Social Security)Never give banking information over the phone. Administrations communicate primarily via your secure online portals.
Doubt about the interlocutor's identityAsk a personal question that only the real person would know.

Tools to Limit Risks

  • Filtering Apps: Tools like Hiya or Truecaller can help, but be mindful of the privacy of your own contact data.
  • Blocking Unknown Numbers: On Android and iOS, you can configure your phone to send all calls not in your contacts directly to voicemail.
  • Reporting: Use the 33700 platform to report fraudulent SMS. This helps operators identify attack waves in real-time.

Hand holding a smartphone with alert notifications

Conclusion: Toward a Certified Telephone Identity

Number spoofing is the symptom of a network designed for connectivity, but not for security. In 2026, we have reached a breaking point where trust in the displayed number has become a security risk. Arcep's investigation is a strong signal: the responsibility for protection can no longer rest solely on the shoulders of the end user.

The transition toward standards like STIR/SHAKEN and more rigorous filtering at network borders is indispensable. The phone number must become what it should have always been: a reliable proof of identity and not a simple mask used by cybercriminals. In the meantime, remember that in today's digital world, the number displayed is not necessarily the person speaking to you.

#Sécurité#Opérateurs#Arnaque#Mobile#Actualité

Related articles

Send your SMS for free

100% free service, no sign-up and no ads. Send unlimited SMS to France.

Send an SMS
bg wave