TelcoNews UK - Telecommunications news for ICT decision-makers
United Kingdom
Caller ID spoofing warning as phone security evolves

Caller ID spoofing warning as phone security evolves

Wed, 16th Sep 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Snom Technology has warned businesses that caller ID can no longer be treated as proof of identity. The telecoms equipment maker said the issue is becoming more urgent as regulators tighten rules on scam calls.

Caller ID spoofing exploits a basic assumption made by phone users: that a familiar number on a screen identifies the true origin of a call. In practice, the displayed number can be manipulated so a call appears to come from a different source.

According to Snom, the problem has moved beyond a narrow technical concern as European authorities introduce measures to curb manipulated caller IDs. Germany has brought in technical safeguards for overseas calls carrying German caller IDs, while Spain and Italy have expanded similar measures. The UK is also moving to strengthen its approach to scam calls from abroad.

Beyond the network

Snom argued that businesses should not treat spoofing solely as a problem for public telephone networks or as a matter for regulators to resolve. Modern business communications now depend on a wider chain that includes SIP, cloud services, providers, session border controllers, telephone systems, applications and end devices.

As a result, the security question is no longer limited to whether a call can be connected or whether voice quality is acceptable. The more important issue is whether the information exchanged across that chain can be trusted and how that trust is maintained in technical terms.

Caller ID still plays an important operational role for many businesses. Organisations use it to identify customers, prioritise incoming calls, route callers and trigger internal processes. If that information is manipulated, staff can be misled into revealing internal information or mishandling data.

The assessment reflects a broader shift in enterprise telephony, where voice systems are increasingly tied to software platforms and cloud-based services. In that environment, identity and authentication become part of a larger security model rather than a feature confined to the edge of the public network.

PBX role

Snom said the telephone system, or PBX, remains a central link between the network and the device used by the employee. Depending on how it is set up, a PBX can manage call setup and forwarding as well as authentication, authorisation, secure SIP connections, encryption and the configuration of connected devices.

That means providers, session border controllers and PBXs can all help authenticate communication partners and secure connections. Even so, this model is weakened if communications between the PBX and the end device are left unprotected.

Device security

Snom said IP phones should be seen as part of the security framework rather than as passive receivers at the end of the chain. Because they are networked devices with their own software and configuration, they need security mechanisms that cover both communications and device management.

Among the measures highlighted were TLS, SIPS and SRTP, 802.1X, server and telephone authentication, and certificate management. Snom also pointed to regular firmware updates as a way to address known vulnerabilities and keep security settings current.

Provisioning was identified as another area of risk. Businesses need devices to be configured automatically, but in a controlled way and with the correct firmware, Snom said. The company cited its Secure Redirection and Provisioning Service, known as SRAPS, as a cloud-based system for automatic, secure IP telephone management and provisioning.

Snom said the service is designed to ensure that new phones receive the intended firmware and configuration when they are connected to the internet, without on-site intervention. It also stressed that security features are only fully effective when the PBX and end devices are technically compatible and support the same functions.

For that reason, Snom said it works with PBX providers on certifications or deployment guides, depending on the platform involved. The point is that telephony security depends on the interaction of several layers rather than a single control.

Trust question

Snom acknowledged that a secure IP phone cannot stop a number being altered somewhere in the public telephone network. That remains an issue for regulators and operators. But security also depends on how networks, providers, PBXs, session border controllers, applications and end devices work together.

For businesses, the key issue is no longer simply what appears on a phone display, but how far the underlying information can be trusted. As telephony becomes more closely integrated with cloud services, applications and end devices, that question will become more central to business communications security.

Security is no longer a single function, but a characteristic of the entire communication chain.