Telephone fraud — diffuse actors, predominantly originating abroad per AGCOMmedium
The number on your screen is not who is calling: how spoofing works, and what is holding it back
Telephone spoofing means manipulating the CLI, the caller's identity: the caller makes a number appear on your screen that is not theirs, often the real number of a bank or an institution. Italy's communications regulator AGCOM acted with decision 106/25/CONS, introducing in two phases a block on calls from abroad using falsified Italian numbers: fixed-line numbers from 19 August 2025, mobile from 19 November. Monitoring figures show the measure works and the phenomenon is receding. But the filter covers calls from abroad, not all calls — and the behavioural rule stays exactly what it always was.
The display is an opinion
Almost everyone takes one thing for granted without ever questioning it: that the number showing on the phone when it rings belongs to whoever is calling. It is a reasonable assumption, backed by thirty years of habit, and it is technically false.
The number you see is the CLI — Calling Line Identification — a piece of information that travels alongside the call. It is not proof of identity: it is a field. Spoofing means manipulating that field, so that the caller becomes unrecognisable and cannot be called back. AGCOM describes it exactly that way, and highlights the point that makes the phenomenon so hard to prosecute: it obstructs identification of those responsible for nuisance calls.
The practical consequence is the one people deal with: the number on the screen can be your bank's real number. Not something similar: that one. Which is why the advice "check the number" never worked as well as it seemed to.
What AGCOM did
- Decision 106/25/CONSThe anti-spoofing filter
AGCOM introduces technical measures to block calls from abroad with altered Italian CLI.
- 19 August 2025First phase
The block takes effect for calls with fixed-line CLI.
- 6 November 2025Decision 271/25/CONS
Implementing provisions that broaden and refine the measure.
- 19 November 2025Second phase
The block extends to calls with mobile CLI.
The mechanism is not exotic and uses no artificial intelligence: it is a consistency check. Calls arriving from abroad displaying an Italian number are compared against the actual network origin of the call. If the displayed number is Italian but the call cannot have come from that subscriber, it is blocked before reaching the recipient.
The premise is statistical, and AGCOM states it: calls originating abroad account for by far the predominant share of the phenomenon. On spoofing originating within Italy, the regulator notes that existing numbering rules already allow identifying and pursuing the operators responsible — and that this work becomes easier precisely once the noise from abroad is removed.
The November decision added a detail worth knowing because it shows how granular the intervention is: all mobile numbering types were included, covering satellite services and numbering dedicated to machine-to-machine communication, and a simplified procedure was introduced for pre-emptively blocking calls from mobile operators that do not originate voice calls from abroad.
The figures, which describe a decline
That sequence — 8.82%, then 3.84%, then 1.37% — is the most interesting part of the monitoring, and should be read for what it says: not that fraud is over, but that attempts to route calls into Italy using falsified Italian fixed-line numbers have progressively fallen. When a route closes, the people using it stop trying. It is a rare thing in security to see effectiveness measured this explicitly.
What the filter does not do
Here comes the uncomfortable part, because an article that stopped at the figures would do a disservice.
The filter covers calls from abroad using falsified Italian numbers. It does not cover the whole perimeter of telephone fraud. Outside it sit calls from foreign numbers displayed as such, calls from Italian numbers genuinely assigned to the caller, and — above all — everything that does not travel by voice: text messages.
That is the territory of smishing, on which the Italian Postal Police issues recurring alerts. The pattern law enforcement describes is constant: a message that appears to come from your bank, mentioning unauthorised devices connected to your account or suspicious transactions, inviting you to call a number to block them. Whoever calls finds someone calm, competent and helpful. The fraud is not in the message: it is in the call that follows.
- 01The message creates alarma suspicious login, a payment you do not recognise
- 02The number to call is in the messagethe one element the attacker fully controls
- 03The conversation does the resturgency, apparent competence, a request to confirm something
The rule that always holds
One behavioural rule survives every technical variation, and it is less intuitive than it sounds: do not trust the channel you are in — change it yourself.
If you receive a call or a message asking you to do something urgently — block a transaction, confirm details, move money to a "safe account" — hang up and call back yourself, on the number printed on your card or shown in the official app. Not the number they gave you, and not by returning the last received call. It is the one gesture an attacker cannot fake, because you initiate the call.
And the principle the Postal Police has repeated for years is worth remembering, because it is the part that never changes: no financial institution asks for personal or banking details by text, email or phone. Not even to protect you. Not even if the number on your screen is theirs.
A note on the data: the percentages come from AGCOM's monitoring of the first phase and cover July to September 2025. A complete picture including the block on mobile numbering will come from measurements taken after the second phase entered into force.