Call Spoofing (Calling Line Identification Spoofing)

Also known as: CLI Spoofing, Caller ID Spoofing

Call spoofing is the manipulation of the calling number presented to the called party so that it displays a chosen value instead of the true originator. It is used in vishing, impersonation of banks or public authorities, and to bypass reputation-based filtering. Countermeasures include origin-based CLI validation at interconnect, network-level CLI blocking rules and cryptographic caller authentication such as STIR/SHAKEN.

Categories: Roaming and InterconnectThreats and AttacksFraud

Call Spoofing in context

Roaming and interconnect are where two operators exchange signaling and user-plane traffic. Trust boundaries here are the primary attack surface for location tracking, SMS interception and fraud, which is why GSMA now mandates SEPP with PRINS on 5G interconnect.

Telecom threats range from opportunistic SMS phishing and SIM swap to nation-state grade location tracking. The common thread is that most attacks exploit the inherited trust model of legacy signaling protocols.

To place Call Spoofing in the wider telecom-security picture, review Refile Fraud, Artificial Traffic Inflation, CLI Spoofing, FASG, Flash Call Fraud and ISUP — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.