EE CLI Spoofing

“After receiving multiple calls from several random numbers I began to suspect my mobile number (CLI) was being used to scam people without my knowledge. Only people that failed to answer the original call would see a missed call and call the number back.”
This can lead to a number of calls with conversations like the following:
Hi, I missed a call from you.
No you didn’t, I have not called your number.
Well I have just called you back from a missed call, so you must have called me!
Nope, someone was attempting to scam you by spoofing my number.
Ok, bye.
If this has happened to you then your mobile number is probably being used to scam people without your knowledge. This could lead to your mobile number being blacklisted and reported as a scam caller.
“EE customer services said there was nothing that could be done and suggested the only fix was to change numbers!” – This kind of response really isn’t the solution!
What they should do is take the details of the calls and investigate how the spoofed CLI numbers are being allowed on their network. Then take action to prevent further CLI spoofing.
A quick search on the internet highlights this is not an isolated incident. Telecoms operators really should be making more of an effort to secure their networks!
I suspect options 2 and 3 below (What Can Mobile Operators Do?) would significantly reduce the problem, however it’s hard to say without seeing the call data.
Understanding CLI Spoofing in Mobile Telecoms: How It Works
In today’s interconnected world, mobile phones are more than just communication devices—they’re gateways to our personal and financial lives. But with convenience comes risk, and one of the sneakiest threats out there is CLI spoofing. If you’ve ever received a call that looked like it was from your bank or a local number, only to realize it was a scam, you might have encountered this tactic. In this blog post, we’ll dive into what CLI spoofing is, why it’s a problem in mobile telecoms, and most importantly, how it technically works—all without getting into the weeds of how anyone could replicate it.
What is CLI Spoofing?
CLI stands for Calling Line Identification, which is essentially the phone number (or caller ID) that pops up on your screen when someone calls you. It’s meant to help you identify who’s on the other end, whether it’s a friend, a business, or an unknown caller. CLI spoofing, also known as Caller ID spoofing, is the deliberate falsification of this information. Fraudsters manipulate the displayed number to disguise their true identity, making the call appear to come from a trusted source like a government agency, your bank, or even a neighbor’s phone.
This isn’t always malicious—there are legitimate uses, such as a doctor calling from their personal mobile but displaying the office number for privacy. However, in the hands of scammers, it’s a powerful tool for voice phishing (vishing), robocalls, and other frauds. It’s particularly prevalent in mobile telecoms because calls traverse complex networks involving multiple carriers, creating vulnerabilities that can be exploited.
The Technical Mechanics: How CLI Spoofing Happens in Mobile Networks
At its core, CLI spoofing exploits the way phone calls are set up and routed through telecom networks. When you make a call, your phone doesn’t just connect directly to the recipient’s device; instead, a series of signaling messages are exchanged between networks to establish the connection. These messages include metadata like the caller’s number (the A-number or originating CLI), which is what gets displayed on the recipient’s phone.
In mobile telecoms, this process often relies on protocols like SS7 (Signaling System No. 7) for traditional circuit-switched networks or SIP (Session Initiation Protocol) for VoIP (Voice over Internet Protocol) calls. SS7 is an old but widely used system that handles call setup, routing, and billing across global telecom infrastructures. VoIP, on the other hand, allows calls to be made over the internet, blending traditional phone systems with digital networks.
Here’s a high-level breakdown of how spoofing occurs:
- Accessing the Network: Spoofers typically gain entry through a carrier or service provider that allows calls to be initiated without strict verification. This could be via VoIP gateways, which convert internet-based calls to traditional phone networks, or even compromised private branch exchanges (PBXs) in businesses. International calls are especially vulnerable because they often pass through multiple intermediaries across borders, where regulations and security vary.
- Manipulating Signaling Data: During call setup, the spoofed CLI is inserted into the signaling messages. For SS7-based calls, fraudsters can alter parameters in the Initial Address Message (IAM), which carries the caller ID info. In VoIP, it’s even simpler: SIP headers can be edited to show a fake number. Since many networks don’t authenticate the CLI at every hop (especially in older systems), the falsified info gets passed along unchallenged.
- Exploiting Lack of Authentication: Telecom networks trust the CLI data received from upstream carriers by default. If a call originates from an unverified source—like a VoIP provider with lax controls or an international route—the spoofed number travels through the system intact. A subtype called GSM spoofing targets mobile-specific protocols, falsifying the source address in the GSM network for SMS or voice calls.
- Delivery to the Recipient: By the time the call reaches your mobile carrier and then your phone, the manipulated CLI is what gets displayed. Your device trusts this info because it’s embedded in the network signaling. Techniques like “neighbour spoofing” make it worse by mimicking numbers similar to yours, increasing the chance you’ll pick up.
In essence, spoofing works because telecom systems were designed decades ago with trust between operators in mind, not the modern reality of digital threats. Advances like STIR/SHAKEN (protocols for verifying caller IDs) are helping in some regions, but global adoption is uneven.
Why Do Fraudsters Use CLI Spoofing?
The goal is deception. By appearing as a local or trusted number, scammers boost answer rates and build false credibility. This paves the way for extracting sensitive info, like bank details or passwords. It’s a key enabler for scams costing billions annually, and mobile users are prime targets due to the portability and constant connectivity of phones.
The Broader Impact and What It Means for You
CLI spoofing erodes trust in telecoms, leading to financial losses for individuals and headaches for operators who face regulatory scrutiny. For users, the best defense is skepticism: Don’t share info over unsolicited calls, use call-blocking apps, and report suspicious activity to your carrier.
As mobile networks evolve toward 5G and beyond, expect more robust protections, but understanding the basics of how spoofing works empowers you to stay one step ahead. Stay vigilant—your caller ID isn’t always what it seems!
What Can Mobile Operators Do?
Mobile operators (MNOs — Mobile Network Operators) have several effective measures available to prevent or significantly reduce CLI spoofing (Caller ID / Calling Line Identification spoofing). While no single solution eliminates it completely — due to the global, interconnected nature of telecom networks and legacy protocols like SS7 — a layered defense approach has proven successful in many markets, often reducing spoofed scam calls by 70–90% or more in pioneering countries (e.g., Finland, Australia, parts of Europe, and others by 2025–2026).
Here are the main strategies mobile operators can (and increasingly do) implement:
1. Implement Caller ID Authentication Frameworks
- STIR/SHAKEN (primarily in North America): This cryptographically signs caller ID information for IP-based calls. By early 2026, Tier-1 U.S. carriers achieved high signing rates (e.g., 85%+ of traffic between major operators signed, with 93% at the highest “A-level” attestation). Mobile operators can extend this to their IP core networks, verify signatures on incoming calls, and block or label unsigned/failed-verification calls. Many providers are required to maintain Robocall Mitigation Plans and update them annually.
- Equivalent or alternative systems globally: In regions without full STIR/SHAKEN adoption, operators use similar in-band or out-of-band verification (e.g., challenge-response mechanisms or proprietary solutions).
2. Block Suspicious International / Inbound Traffic (Especially National CLI from Abroad)
- A very effective real-world tactic is blocking or stripping international calls presenting a national/domestic CLI (e.g., a Finnish number appearing from outside Finland, or a U.S. mobile number from abroad). This directly targets the most common spoofing vector used in scams.
- Pioneers like Finland (Traficom mandate since 2022) and others (Ireland, Belgium, Sweden, India, Egypt, Latvia) have mandated or implemented this, often verifying legitimacy via:
- Home network queries (e.g., number portability + location checks).
- Proxy validation models.
- Result: In Finland, spoofed national numbers were effectively eliminated in practice by late 2023. Similar rapid reductions (70–90%) reported elsewhere.
3. Use Do Not Originate (DNO) Lists and Similar Block/Allow Lists
- Maintain lists of numbers that legitimately never originate calls (e.g., emergency services, government hotlines, banks’ inbound-only lines, tax offices). Any incoming call from these is spoofed → block immediately.
- Combine with blacklists (known fraudulent numbers), whitelists (trusted partners), unallocated number checks, and detection of malformed/invalid CLI formats.
- These are low-effort, high-impact “low-hanging fruit” tools widely recommended by industry bodies.
4. Out-of-Band / Real-Time Validation Solutions
- GSMA Call Check: A GSMA-backed service allowing operators to validate caller details securely between networks (cheap, simple, interoperable across borders).
- Proprietary tools like AB Handshake’s Call Validation (real-time, end-to-end A-number verification), roaming status checks, or test call generators.
- Signaling intelligence platforms (e.g., from Subex, Jtendo, Enea/HardenStance) use machine learning, pattern analysis, and signatures to detect spoofing in real time.
5. Focus on Mobile-Specific Vulnerabilities
- Query outbound mobile roaming traffic — often the “sweet spot” for catching large volumes of spoofed calls, as fraudsters exploit roaming loopholes.
- Validate inbound international calls claiming to be from national mobile numbers via roaming/home network checks.
- Monitor for anomalies like rapid SIM cycling, SIM farms (common in MVNO exploits), or unusual traffic spikes.
6. Industry Collaboration and Regulatory Alignment
- Participate in forums like i3Forum’s “Restore Trust” initiative, One Consortium, GIRAF, GSMA Fraud and Security Group, or CEPT/ECC recommendations.
- Share threat intelligence, DNO lists, and best practices cross-border.
- Comply with (or go beyond) national mandates — many regulators now require blocking spoofed calls within set timelines.
Key Takeaways
- Layered defense wins: Combining 3–5+ of the above (DNO + international CLI blocking + validation + analytics) yields the best results — single measures aren’t enough.
- Mobile is particularly vulnerable due to international roaming and SS7/VoIP gateways, but operators focusing on roaming validation and national CLI checks see the biggest gains.
- Progress is accelerating globally through regulation (e.g., mandates in Europe, India, Australia) and voluntary industry efforts, even if STIR/SHAKEN isn’t universal.
Mobile operators that invest in these protections not only reduce fraud losses and customer complaints but also avoid regulatory penalties and build trust. Many leading MNOs already report blocking millions of spoofed calls monthly through these methods.
If you’re an operator looking to implement any of these, starting with DNO lists and international national-CLI blocking often provides the quickest wins.
