FCC orders phone companies to block scam text messages
arstechnica.com
arstechnica.com
Anyway, I've had (still have) the same phone number for over 20 years in the EU and have never received a spam call/text. Zero. Nada.
To me, it is baffling how all Americans have put up with this annoyance for decades! Finally, it seems some concrete steps are being taken.
* A scumsucking business decides to hawk some scam. They start by creating an LLC (a limited liability company) devoted to telecommunications, ostensibly to resell telephone service sort of like an MVNO would. This LLC is based in the U.S. They buy a range of phone numbers associated with the LLC.
* The company then coordinates with an out-of-country call center, in places like the Bahamas, India, Pakistan, Mexico, etc. The call center receives and sends calls into the U.S. based on an assigned number from the LLC as a PBX (private branch exchange). As a PBX, these call centers can use a single ANI (automatic number identification) based on a US-based address (usually faked by the so-called telecommunications LLC), and the actual numbers behind it are hidden. PBX software allows you to override the number you see when your phone rings - that's why you get numbers on your phone completely unrelated to the actual call origin.
* The LLC may "sell" some numbers to legitimate businesses so they can claim it's just abuse of their systems.
* As people begin to complain about the scam calls, and the network operators that sell the numbers cut the offending numbers off the network (and this takes weeks at least) the LLC will simply cut off the old number, and issue a new number to the offshore call department.
* Eventually, the network operator will refuse to issue new numbers to the LLC, so the LLC will close up shop. However, the owners usually have a new telecommunications LLC ready to start the process all over again.
* The dirty secret here is that the major network operators (Verizon, ATT, etc) don't really care too much about these scam MVNOs/call centers, because they get paid, and paid well, and get to look like they're doing work to prevent scam calls while making money doing it. When these guys tell you "We can't see where the call is coming from" this is a straight-up lie, as any network operator call center employee can tell you.
However there are other tiers of attestation that are less strong, and because telcos also do a screaming business in bulk transport of other people's calls, these calls still get connected. So for example user C in say, Telenor Pakistan calls user A on AT&T, but the call is carried across the world by some transit carrier, like Lumen or BICS. This happens all the time. Then all that ATT see is that BICS attest that they trust Telenor, but have no control over the source number C.
It gets real murky real fast. On top of all this there are yet more complex cases, like American Express buying a block of phone numbers from one phone company but actually being connected to the global phone network by another. Or wanting to have those domestic numbers route offshore but still appear as US numbers when they call you stateside.
Its a mess, and SS helps as best as it can, but I think the real solution requires a change in how telcos get paid, and route one another's traffic for money, and that is not changing anytime soon.
The frustrating thing is I would bet that the vast, vast majority of people in the US do not want anything except those “type A assertion” calls: calls from trusted users of trusted carriers. And I say this as someone who regularly communicates with friends and business associates overseas but essentially never through the traditional phone network.
It seems like that would also cover the situations some people often mention regarding emergencies, since a hospital, school, or random person on the street won’t be calling through some fly-by-night carrier.
I get some people and businesses have more complex needs, and I’m sure there are a million corner cases. But it feels like if you let people easily opt in to a sensible but restrictive plan, and allowlist trusted carriers in other countries, you’d solve a lot of this problem?
The irony is that the end users have built this by themselves: ignore all calls unless they are from a known contact, at best, diverting the rest to voicemail. Basically each user builds a 1-deep network of trust. Sad that it had to come to this.
There's are argument that says this is all a side effect of a technological innovation: the rise of VoIP/SIP over TDM.
- France has a version of STIR/SHAKEN - Germany's Deutsche Telekom has massive presence via local operating entities in poland, austria, czechia etc etc. So it might be that they can assert tighter knowledge of a caller across countries and carriers because its all really DT. - Similarly Orange/Hutchison in France, Austria, and IIRC north Africa.
Beyond that, i dont know.
At that rate, scamming someone on the phone from a different country is prohibitive. The other option would be to setup shop and purchase numbers from all EU nations, which is also prohibitively expensive and probably not as easy since LLC's aren't really a thing.
My guess is the large population of the US + the advantageous legal system for new companies is what makes this a unique issue for Americans.
From what I gathered, it's a lot less of an issue compared to the US, but scam calls & SMS do happen.
My anecdota: I'm French, and receive scam calls from time to time. They are different from the ones you see in the US. Here it's mainly "CPF" scam calls, which is training credits every working person automatically get and they are trying to scam you into paying for a illegitimate training with those (don't ask me for more details, I've not researched it further).
In France, it tends to be less of an issue because the government is at least somewhat invested in fighting such scams, and because the language isn't as universally spoken as English (which is true for most of Europe). You can usually spot a foreigner speaking French miles away, and it's a red flag for any sane person when an incoming call has an accent.
The scams are different in Europe. I’ve had my debit card skimmed twice over the years in Europe and I check the card readers. One scammer took money out of a Philippines ATM. Europe also has a crazy amount of tourist scams I’ve never seen in the State. Fake fights in Rome to draw attention from pickpockets, taxis in Germany taking advantage of me, Gypsies with drugged babies and fake injuries, and various “official” helpers outside airports/train stations.
At least with Disney the workers aren't trying to scam you.
Pretty sure I've seen a local version of that around SF, or at least I used to pre-COVID.
In the last few years I got a new number from Verizon after moving from one state to another, in the hope that it would combat robocalls. Not only did I experience what you did, but received a number previously used by a plumber who apparently had trouble paying his car loan. I was getting frantic calls at all hours from people with plumbing problems, and from Honda threatening to repossess a car. Verizon and other carriers even admit to recycling numbers as soon as 6 months after they were last used. https://community.verizon.com/t5/Windows-Phone/How-Do-I-Chec....
I got calls for literally a decade until they figured out she wasn't going to answer on this number anymore. At first, I would hang up when I heard the robo-voice asking for her, but the calls didn't slow down and eventually stop until I waited on the line for a collections agent to pick up so I could politely tell them to pound sand and stop calling me. Even then it took another few years.
Funnily enough, I recently moved out of the US and ported my number to Google Voice in case I want to come back in the next few years. My phone hardly rings with spam calls now.
This has been standard for decades - it is a holdover from landlines. The companies only own a certain number of phone numbers. (Supposedly, when you change companies, 'ownership' of the number transfers to the new company). They've generally said that in more populous areas (or at least, areas with more phone numbers being actively used) that recycling numbers was the only way without changing the number format again.
I didn't think this was exactly a secret - but I could have learned this working for GTE/Verizon a couple of decades ago.
The scam calls mostly come out of the Philippines, India and Pakistan because they have high familiarity with US culture and millions of people with sufficient English fluency.
Almost none of the EU nations have more than two of these.
It is very easy to understand the problem if you pause and think about it for a short time.
All is explained with a cursory glance at our political system
That explains most of the problems we have, there are really only 2 choices and people are increasingly partisan about them. Although for this specific issue, both parties are equally shitty, but as a US voter I can't signal anything about my displeasure with their telco regulations since it's effectively a binary choice and telco regs are wayyyy down on the platform.
"Before hearing your new important message, wait and listen to these 6 messages that are marked for automatic deletion" Ugh...
All they have to do is reconfigure the voice prompts honestly, but the keep the standard service difficult to encourage and force the extra money out of customers. :(
A handful of scam/spam calls over last few years and precisely 2 SMS.
My parents get some more calls on their landline (~2/month) but I suspect they actually "agreed" to have them from those companies. It went down considerably since the law changed a few years ago to not limit the scope and validity of phone only contracts.
At least in my bubble this is not unusual either. In fact the only people having problems are the few people who moved to the US.
NPA is a number plan area (area code) which is known.
NXX is N=2 to 9, X=0 to 9, is an office code.
XXXX is a station code, where X is 0 to 9.
I get like 60 scam calls for every scam text. Scam texts are mildly inconvenient. Scam calls on the other hand are far worse. I get so many scam calls I don't pick up any phone numbers not on my contact list, and which causes me to miss several important phone calls a year.
I get plenty of spam SMS, but they're not technically scams. (…unless I suppose if you jokingly consider the GOP a scam…) I wouldn't mind seeing those get cracked down on. (I'm not registered with them, and they continue to spam me about political issues in jurisdictions for which I've not been on the voter roles for over a decade.)
Also, spam SMSs trying to get me to sell my parent's home. (I don't think these are scams, per se, but from what I've read their offers aren't going to be good. Nonetheless, I'm not looking to evict my mother … out of a house I don't own?, of course.)
Finally, my hometown has apparently sold their soul … and somehow my cell phone information? … to a random private company. Instead of publishing WEAs like a normal jurisdiction, I get SMSes that have little to no context, like "take shelter from the storm" while it's completely sunny and the forcast is nothing but sun, and the radar is clear. (It took a while to figure out that they were warnings about a city a few thousand miles away, since, again … 0 context.)
> Recipients of a robocall have the ability to either pick up the phone or not. But on most devices, recipients of a robotext see at least some of an unwanted message immediately
> …unlike robocalls, scam text messages are hard to ignore or hang-up on and are nearly always read by the recipient – often immediately. In addition, robotexts can promote links to phishing websites or websites that can install malware on a consumer’s phone.
And per the article this particular regulation is already in effect for calls:
> The FCC already requires similar blocking of voice calls from these types of numbers.
Recipients of a robotext can choose to delay the moment of interruption. They can wait until a more convenient moment to read a text, and determine whether it was spam or not. Recipients of a robocall have to deal with the interruption immediately. They can potentially delay to voicemail, but that isn't a guarantee.
Because of this, the expectation of robocalls is enough to put the act of answering any unknown caller past the threshold of reasonable effort. Being interrupted by a robocall is likely enough that I don't answer calls from any unsaved numbers; unless I'm expecting an unavoidable call (something employment or healthcare related), in which case I am held captive: forced to answer every spam call the moment it rings.
In that situation, not only must I answer the spam calls, but I must also be prepared each time to answer the important call I am waiting for! This is incredibly stressful, especially since I have ADHD and struggle to prepare for, and to keep myself prepared for, a phone conversation.
Both types of spam are serious problems, but it's robocalls that cause me the most stress and general harm.
In other words, it won't change anything. I still get just as many scam voice calls as I ever have.
Whomever wrote this has never been on-call, never waited to hear back on a job application, never gave their number to a romantic interest nor ran their own business.
Lately all just getting those pointless Amazon scam b.s. texts that I hope the majority of the population know the drill.. .never open just delete.
The scammers I am afraid will start to really use AI ... hack/monitor legions of phones ...spoof your contact list and call you then actually spoof the voice of some of your contacts. For me then I would only use something like a Facebook messenger set up where I only add friends I know already and they pass a series of questions we only know between each other. It's going to get worse .. thinking ahead.
From my own anecdata, I've received about 50/50 texts/calls. I also do not pick up unknown numbers anymore.
I know the current infrastructure can't really deal with that, but it's because the telecoms have no real reason to implement it.
My employer seems to have gotten a lot of sequential phone numbers assigned, so a similar number used to be highly correlated with legitimacy, now it’s a mixed bag.
"I buy junk cars" is pretty easy to filter out. Nowadays they send things like "i/buy/any old/car Yconpro/autos*" (this is a real one I got 9 hours ago). But that's still easier to design a filter for than a phone call which only happens over audio.
I want but cannot find these features:
- Disable/mute notifications for all unsaved (contactless) numbers.
- Block all texts from email addresses. Real people know what is painfully obvious: you can use my email for that!
- Disable/mute notifications for all group texts. People don't expect to get an immediate response from sending a message to a group. You can practically never get multiple people together in person for a conversation without coordinating with each person beforehand.
My work doesn't use my personal phone# - I know this isn't possible for everyone but works for me.
Edit: I just did. Voicemail is an option too.
I've also noticed answering the call makes it much more likely that you will receive more calls in the future. Even though I usually answer the call just to make them waste an hour talking to me as I pretend to be an old man who has trouble installing TeamViewer or finding my credit cards.
Some of the spam groups have even blocked my number since I've trolled them so much. But I still get calls from their system, and when I answer it says something like "You have been blocked from contacting this number. Goodbye."
After looking into it a bit more, spam calls seem to be significantly less prevalent in many smaller EU countries that speak their own language when compared to the global average. Probably because it's harder to find scammers speaking the language, or it's less cost-effective to target those demographics.
A lot of reliable research is paywalled, but from what I was able to scrape together, it seems like people in Germany get about 3 times as many spam calls compared to people in Estonia, and people in the US get about 3 times as many spam calls as those in Germany. Those in India get about 3 times more than people in the US, and people in Brazil get about 3 times more spam calls than those in India.
So depending on where you live you may get 81x the amount of scam calls as people in a different region. At least based on quick and unreliable back-of-the-envelope math. Central and Eastern European countries may get 9x fewer spam calls per capita than the US.
It was a non-question, and my answer was still serious. Every topic has a few people jumping in to say "Wow I didn't realize the US sucked at X, we don't have that problem in Y country." Eventually someone else from Y shows up to say "Well, actually, I do, and I live here in Y."
Your observation about English vs non-English is not a bad guess. And with the highest average income in the world, it would make sense to see Americans be targeted more by spammers.
But still, it remains true that plenty of people in both Europe and the US get irritating amounts of spam calls/texts, but some people manage to escape it entirely.
This doesn't reflect my personal experience (anecdata I know) or those of any of the people I know.
I'll think I'll ask around because now I'm curious about the distribution. If a few people here are bombarded with spam calls it would average out the 1-2 a year me and my family/friends get on average on their mobile numbers.
https://www.statista.com/statistics/1045618/spam-calls-per-m... (you'll only be able to view this page once or twice before Statista demands a subscription).
https://www.truecaller.com/blog/insights/top-20-countries-af...
https://blog.hiya.com/what-country-gets-the-most-phone-spam and their report
https://www.hiya.com/state-of-the-call
I also asked GPT to quote some research for me that I fact-checked, and I looked up some news articles about spam calls in different regions. As I said, my estimates are unreliable.
It matched my personal experience which is that of someone who has lived in these smaller EU countries and also in English-speaking regions.
I'll just use push notifications from here on out.
I used to love them and they still might be good for a little personal projects (though your story says otherwise) but I would never pick them to use at scale. At one point they said they needed the /exact/ text of every message we were going to send ahead of time to approve before we sent it... Yeah that doesn't work when you send OTPs (yes, yes, I know, we have to have it as a fallback) or a user-specific/transaction-specific url. So pretty much they only thing you could send is generic marketing trash, cool...
Twilio is forcing Tollfree Number registation and their current timeline is 6 weeks to approve. Well a week or 2 ago they decided that they wanted more data than what was currently submitted. So everyone is currently being denied and having to resubmit their registrations.
10DLC / Local numbers is madness in and of itself too. Forcing businesses to pay quarterly fees so these poor ol' carriers can have more recurring rev.
Someone else who uses my software for SMS to Teletype was just notified by Twilio to register their "marketing campaign". He just uses it as a demo at ham radio conventions.
When there's a ransomware attack or data exfiltration, nobody says, 'where's the FBI?'. We just accept that the Internet is criminal and lawless. Maybe enforcement against crypto fraud was the first step.
https://www.fbi.gov/how-we-can-help-you/safety-resources/sca...
For example, they counter-hacked the Hive ransomware group earlier this year. And gave the decryption keys to the victims.
https://www.justice.gov/opa/pr/us-department-justice-disrupt...
Every IRP (Incident Response Plan) that I have seen had contact information for the local FBI office and typically the names and emails of a couple of agents. While the security folks or leadership had already at least had an intro convo. Now this is typically large companies, mom and pop diner that uses a few work stations would probably call their _IT_ guy who would probably wipe and reinstall.
Multiple tens of TTX (Table Top Exercises) direct and or lead the security team / participants to report to local authorities, typically FBI.
If there is a rash of bank robberies or terrorist activity we expect performance from the FBI. If there is rash of criminal activity on the Internet, we expect the FBI to help out but don't expect actual security.
The FBI or DOJ need an electronic infrastructure enforcement division (I despise the sci-fi term 'cyber').
Should it be at the ISP? Should the FBI give every business a black box and say "put this between the internet and your network, we'll monitor and defend against cyber criminals" but if the company did that they would be giving the FBI all of their inbound and outbound traffic.I guess you could use the _nothing to hide_ argument but that's ridiculous.
If we put the onus of security on the FBI/Government that just means a larger government and less rights. Take the PATRIOT Act for example.
You want to try to sell me something? Great, at $10 / minute I'll listen to you.
I wish they'd block the Hilton Hotel roboscam. I get calls from them 3 times a day, all from different phone numbers in the state.
What is it?
I've been getting these for over 5 years now. Sometimes they pretend to be Costco as well. Same voice and inflection, though.
A phone feature I'd love to have is to push a button and an AI chatbot takes over, with a goal to keep the scammer on the line as long as possible. Their whole business model would collapse.
But hopefully these same rules will help block the political scam stuff. Fake announcements, wrong polling place/election time info, libelous stuff not sent by legitimate (registered) organizations, etc.
It’s something.
Hahaha no it doesn't.
Then change phone companies.
When I send a STOP message, I get a message from AT&T stating that the source number is now blocked from sending any more text messages to my phone.
I DO however want to receive notice when my item is out of stock or ready for in-store pickup if I chose that option.
I reply STOP and that always works for each individual campaign organization, but the problem is there are thousands of these orgs.
In the months before voting I'll sometimes get multiple a day. Ugh.
I get this but via email, and they typically say it'll take 2 weeks or more to stop sending me this unsolicited bulk email. This is despite unsubscription being instantaneous.
Just as an aside, since high political office is a fairly direct path to immense wealth, I think these unwanted mails should be explicitly considered unsolicited, bulk commercial email. This is the precise definition of spam and we should treat it as spam and not just think of it as such.
There's no such thing.
The other thing I used to get a lot was political fundraisers or activism and they made a point of calling me by name (not my name, but by some woman's name), and I believe I attempted to STOP those a few times. A related fact may be that I found this woman's name, with my surname, in WhitePages.com under my home address with same phone number. Don't know how she got there, unless I forgot that I was married?
I'll rather everything is delivered and then the spam filtering is done on the provider/device level. These kinds of things are usually implemented with innocuous cover and malicious intent.
Somehow the providers need to get lists of these numbers and it's only going to be as good as the providers' information sources. I suppose a government agency could put someone else's number on a list, but that would be rather obvious.
If we choose not to do that, at some point one of the big tech corporations will manage to get enough of a network going on their own proprietary equivalent service so that everyone else has to join or be left out. And PSTN will die. And we'll have a corporate overlord.
She is an immigrant and her parents cleared out a savings account in the process (the scammer convinced all parties involved my friend would be deported unless…).
IMO, the solution is to have an app that can screen messages based on user-reported spam score.
The reason phone companies shouldn't do it is that it is very unlikely they will do it well. There is still going to be a lot of spam and it is more than likely there is going to be a huge number of false positives that will not be possible to circumvent.
BUT...
My carrier still has an email-to-SMS gateway (like people used to use in the late 90's), and that's how spam gets through.
I tried reporting this and they were incapable of responding to or following up on the problem report, though they did helpfully detail the MMS packet defects to me. Maybe one of their engineers will read this someday.
All companies sending SMS need to be registered. They set a deadline and if they didnt meet the deadline (many didnt including Singapore Airlines), their “caller ID name” became “Likely Scam”.
Legitimate companies got registered very quickly after that.
https://www.channelnewsasia.com/singapore/likely-scam-sms-se...
Lately, I have been getting a dozen or so "We've Locked Your Account" phishing texts per day. I will tend to get them in "bursts," where several come in, within a few minutes.
If companies use it for marketing, they can be shutdown.
The list is easy to get for companies in Belgium. Perhaps it works?
I still get 10 to 20 spam voice calls a day
They don’t show a red pip and don’t make a notification. You can choose in the Messages app whether you do or don’t want to see them.