MERCH!
Giant Bomb - a website about video games and the people that make them

Unmasking Caller ID Spoofing: Understanding and Defending Against Fraudulent Calls

by itgametime

Imagine that a call comes through your phone, and the caller ID identifies as being from your credit card provider. When you answer, you’re told that your security password must be reset due to a widespread data breach. The caller then offers to update the security on your account while you are on the call if you provide your username and password. While you may be tempted to act quickly to avo...

No Caption Provided

Imagine that a call comes through your phone, and the caller ID identifies as being from your credit card provider. When you answer, you’re told that your security password must be reset due to a widespread data breach. The caller then offers to update the security on your account while you are on the call if you provide your username and password.

While you may be tempted to act quickly to avoid any unauthorized use of your card, you should be aware that this type of call follows the pattern of a common cyberattack known as caller ID spoofing.

“Caller ID spoofing is a technique used by cybercriminals to falsify a phone number to make their call seem legitimate,” explains Marcelo Barros, Global Markets Leader of Hacker Rangers. “Basically, cybercriminals use the technique to hide the real phone number used to place the call by overlaying it with a legitimate phone number that is identical to that of the institution they’re impersonating.”

Barros is an IT veteran who is passionate about helping individuals and organizations improve their cybersecurity stance. He has assisted clients worldwide with developing and deploying cutting-edge cybersecurity solutions that, among other things, seek to identify and repel caller ID spoofing and other forms of social engineering attacks.

Hacker Rangers is a unique training platform that ensures employees stay up-to-date on the latest cybersecurity threats and the most effective ways to neutralize them. It enhances cybersecurity programs by leveraging the power of gamification to improve an organization’s ability to identify and repel cyber attacks. With Hacker Rangers, an organization’s efforts to improve cyber awareness become fun, engaging, and ultimately more effective.

“Since many people don’t answer calls from unknown numbers, criminals use caller ID spoofing to sidestep that habit and gain greater success connecting with potential victims,” Barros warns. “By using a legitimate number, criminals pose as financial institutions, government agencies, legitimate companies, and even friends or family of the victim.”

The rise of caller ID spoofing

While there are a variety of techniques used to spoof phone numbers, one of the most popular involves using Voice over Internet Protocol (VoIP) technology. VoIP lets users make phone calls over the internet rather than via conventional phone networks. It also allows users to easily manipulate the caller ID data received by the recipient of the call.

“When using VoIP, you can determine and configure the outbound number displayed during calls,” Barros says. “That’s why all the caller sees on their screen is a familiar number, leading them to believe they are getting a call from a known and legitimate person or entity.”

VoIP gives cybercriminals everything they need to develop and deploy an effective scheme. It provides both anonymity and a global reach, allowing calls to be placed from anywhere to anywhere. VoIP is also cheaper than conventional phone service, making it easier to place high volumes of calls.

Thwarting caller ID spoofing

Caller ID spoofing relies on two separate components to succeed. The first is the spoofed number. By hiding behind a legitimate number, those utilizing the scheme hope to get victims to answer the phone.

Once the call is answered, however, the scheme relies on the recipient not realizing they are being scammed. If they quickly acquiesce to providing private information rather than taking steps to confirm the call is legitimate, the attack succeeds. If they are careful and not too quick to trust, the scheme fails.

“When you get a call, and the person on the other side tries everything to persuade you to perform some unusual activity, like providing or confirming certain confidential information, be extra suspicious,” urges Barros. “Never give out personal or financial information over the phone, especially if contact was initiated by someone else. ID numbers, tax numbers, addresses, and passwords are not information that should be given out over the phone, no matter how legitimate the call seems.”

Most institutions — especially financial institutions — regularly warn customers that official representatives will never ask for personal identification numbers, passwords, or social security numbers. They also will not ask you to open a link that they have emailed or texted to you. To ensure you are protected from spoofing schemes, it is best to hang up and contact the institution through their official number.

Today’s technology makes it easier than ever for criminals to craft schemes that have an air of legitimacy. Those who are overly trusting can quickly become the victim of caller ID spoofing or other social engineering schemes. To stay safe, make sure you know how to identify and avoid common schemes.