https://datatracker.ietf.org/wg/stir/documents/its not exactly ELI5.
The CLI (Caller Line ID) field of a "incoming call" message isn't adequately policed. This is sort-of baked into how telephony works. It's stupid, and it should have been thought about more. The CLI field isn't how the call routes, its just how the caller announces who you are. Telephone call routing uses other data fields, its part of SS7 and the other signalling systems the phone network uses. The field which comes up a mobile call, inside "payload" isn't how it routed.
Imagine some company has the indial range 667 2200 to 667 2299.
If you dialled from your assigned handset 667 2241 the CLI can say 667 2200 so it looks like you come from the switch (in this example we assume the company's PBX operator is on 2200, and you publish 2200 as the incoming call number) so people don't learn your office handset: thats why they permitted it.
I have no idea why they allow to to "lie" above your indial group range. But they do.
STIR is how in a VOIP world people are approaching the fix. But really? the FCC and other national regulators have to tell the telco to stomp on the fakeout, when people inject calls into their system.
This has parallels with "envelope sender vs RFC822 header" in email. Or spoofed source if your ISP doesn't do BCP38. Guess what: SPAM is a problem in email (duh) and spoofed source is how DDoS can happen. "telling lies" in end-to-end communications is not helpful.