Brand Impersonation Fraud: When Criminals Call as You

It’s 09:10 on a Monday and your customer-care queue is already full of people you never called. The first agent takes a woman who wants to know why “your fraud department” phoned her on Saturday evening and told her to move her savings to a holding account. The third takes a man who read out a one-time code because the caller knew his address and the last four digits of his card. By noon there are sixty tickets, four confirmed losses, and a journalist asking for comment. Nobody in your building dialled any of these people. The number on their screens was yours.

If you run fraud prevention, communications or customer care at a bank, telco, utility or public service, brand impersonation is your problem even though you committed no crime. Your name is the payload. This article looks at how the impersonation works technically, what it actually costs an organization, what today’s defences do and don’t cover, and where verification has to go next.

The caller ID was never yours to begin with

Everything a customer sees when their phone rings is, technically, a claim. The calling number is a field the originating party declares when the call is set up, and on internet telephony, declaring somebody else’s number is a configuration setting, not a hack. Nothing in the default call path checks whether the caller has any right to present your customer-service line. The handset then does the branding work for the attacker: it matches the declared number against the customer’s contacts or a caller-ID database and displays your name, your logo if they have your app installed, sometimes the same entry your genuine texts arrive under.

Text messaging has the same flaw in a sharper form. Alphanumeric sender IDs, the “YourBank” label on an SMS, are chosen by the sender. On many handsets a forged message with your sender ID threads into the same conversation as your genuine messages, directly underneath the real login codes you sent last month. The forgery inherits the accumulated trust of every authentic message above it.

The point for a fraud team: number spoofing business impact starts with the fact that number and name are both attacker-chosen. The customer is not being careless when they believe the screen. The screen is lying with your face.

The bill arrives in three currencies

The first cost is direct losses attributed to your brand. In Belgium, where we’re based, Febelfin reported that criminals stole around €49 million through phishing in 2024, and banks detected, blocked or recovered about 75% of the fraudulent transfers. Behind every one of those cases is a victim who will describe the event as “the bank called me”. Whether liability lands on you or not, attribution does: reimbursement disputes, formal complaints, regulator correspondence, and press coverage that pairs your logo with the word “scam”.

The second cost is operational and shows up in your own queue data. Every impersonation wave produces inbound volume you didn’t plan for: victims, near-victims calling to check whether the call was real, card blocks, dispute files, police report requests. Each contact costs agent minutes; the fraud-ops cases cost hours. Care directors can usually see scam waves in their handle-time dashboards before the fraud team has named them.

The third cost is the slowest and, I’d argue, the largest: the erosion of your outbound channel. Talk to anyone running outbound at a bank and you’ll hear the same thing we hear, which is that customers have stopped answering. Years of “we will never call you about this” messaging, plus lived experience of fake calls, have taught people that a call from their bank is more likely to be a criminal than a banker. So the genuine fraud-alert call goes to voicemail, the arrears call never connects, the care follow-up dies unanswered. You are paying for a channel your own security messaging helped burn down. That is the strategic damage: not one incident, but a permanent tax on every legitimate call you will ever make.

What today’s defences cover, and where they leak

Regulators have not been idle, and the honest picture is progress with structural gaps.

Network-level attestation is the heavyweight approach. The US and Canadian STIR/SHAKEN framework has carriers cryptographically sign calls, and France runs a similar mechanism (the MAN) that has been mandatory for operators since 2024. It helps, and it is also instructive: the FCC is still working to close the non-IP legacy network gap and tighten how attestation levels are assigned, because calls entering through international gateways can carry weak attestation, and a signature proves which operator originated a call, not that the caller had any right to your number. France’s regulator, meanwhile, saw spoofing reports keep climbing after the mechanism went live and opened an investigation into operator compliance. Attestation raises the attacker’s cost. It has not yet made the screen trustworthy.

Belgium chose a blunter instrument: since late 2024, operators must block international calls that present a Belgian number to Belgian recipients, and since 2025 BIPT maintains a Do Not Originate list where organizations can register inbound-only numbers, like fraud helplines, so any call presenting them gets blocked. Germany requires German fixed-line numbers arriving from abroad to be suppressed rather than displayed. These rules genuinely removed easy attack paths. But they are national patches on an international system: fraud reroutes through foreign numbers, mobile-number exemptions and channels the rules don’t touch.

On messaging, sender-ID registration is spreading; Ofcom’s new UK rules require know-your-customer checks on businesses sending branded SMS. Same shape: higher attacker cost, no positive proof for the customer.

And then there’s education. “We will never ask for your PIN” campaigns are necessary, and every organization on this page should run them. But notice their asymmetry: they teach customers what a fake contact looks like, never what a genuine one looks like, because today nothing about a genuine call is provable. Education teaches distrust, not verification. Its logical endpoint is the customer who hangs up on everyone, including you.

What a fraud team can do this quarter

None of this means waiting for the phone system to fix itself. Concrete moves, roughly in order of effort:

  • Inventory every number and sender ID your organization presents outbound, across every department and outsourcer, and eliminate inconsistent or unregistered caller IDs.
  • Register what regulators let you register: Do-Not-Originate listings for inbound-only numbers where available (Belgium has this today), sender-ID protection with your SMS aggregators.
  • Design outbound calls so that refusal is safe: never ask for credentials or payments on a call you initiated, and open every call by inviting the customer to hang up and call back via the number on your website or card.
  • Give care agents a live view of outbound campaigns, so “did you really call me?” gets a factual answer in seconds, plus a script for confirmed victims.
  • Measure impersonation as a KPI: victim reports, verification calls, complaint spikes, outbound answer rates. The channel erosion is invisible until you chart it.
  • Feed every wave to your regulator and carriers; blocking rules improve on reported data.

Verification has to be something you prove

Every measure above shares a ceiling: they make bad calls harder or teach customers to fear them, but none gives the customer positive proof that a good call is good. The web solved the equivalent problem years ago. We stopped telling people to squint at URLs and gave sites certificates; the browser checks the proof, and the burden moved from user vigilance to caller demonstration. Telephony needs its version of that: a directory of verified organizations, and a proof of identity that arrives with the contact and can be checked on the customer’s device, ideally offline, so it works in exactly the moments attackers exploit.

That is what we’re building the organization track of Hongi toward. The consumer app is live today: two paired people each see a rotating codeword, refreshed every 30 seconds and computed offline, so each side can prove itself to the other. The organization layer extends the same mechanism: a verified-organization directory, agent-to-customer verification during a call, and an offline caller-ID layer that shows “Organization X is calling — tap to verify” for registered numbers. I want to be precise about status, because this page is about honesty in a domain full of overclaiming: the portal and API are under construction and the caller-ID layer is in active development. It’s roadmap, not product. If you want to shape it or pilot early, start at our organizations page, and our compliance overview covers how we handle the underlying data.

Your brand is going to be spoofed either way; that part is no longer under your control. What is under your control is whether, when the real you calls, your customer has any way to tell the difference.