Spoofing – The new operational risk for banks

BY LAINE CROSBY, editor-in-chief, ABA Risk and Compliance, with contribution from Refine Intelligence CEO and co-founder, URI RIVNER.
Originally published in ABA Risk and Compliance, September/October 2026.

ON A SINGLE DAY IN THE MIDWEST, a small community bank suddenly founditself under siege – not from a cyber breach inside its systems, but from a flood of phone calls outside its walls.

Within roughly 24 hours, fraudsters launched a concentrated spoofing campaign impersonating the bank. Thousands of the bank’s customers received calls that appeared to come directly from the bank’s legitimate phone number. Inside the institution, the impact was immediate. According to Paul Benda, executive vice president for risk, fraud and cybersecurity at the American Bankers Association, the bank was overwhelmed with inbound calls from confused and alarmed

customers. As described on ABA Fraudcast: Who is calling me? (Jan.29, 2026), the bank received approximately 600 phone calls from customers reporting the fake fraud alerts they had just received.

Benda explained that thousands of customers had been targeted in that short window. Customers were being pressured in real time, and some accounts were compromised before the bank could react. The incident was discussed alongside Jonathan Thessin, vice president and senior counsel for regulatory compliance and policy at the American Bankers Association. 

The most troubling detail was not merely the volume; it was the speed. In that compressed 24-hour period, the bank had no single government point of contact to shut down the impersonation campaign as it was unfolding. There was effectively “no one to call” in the moment to stop the spoofed calls before they reached thousands of customers. 

This story underscores a central reality of modern call spoofing: the damage is often done not over months, but over hours. For community and regional banks in particular, the operational and reputational shock can be immediate and severe.

How large-scale spoofing is operationally possible

The mechanics behind modern spoofing campaigns are far less sophisticated – and far more accessible – than many bankers might assume. 

Historically, criminals scaled operations by exploiting gaps within the Voice over Internet Protocol (VoIP) ecosystem. A bad actor could sign up with a provider, begin placing thousands of calls, and gradually increase volume. Unless complaints surfaced and someone investigated, the activity could continue largely undetected. Providers were not listening to call content, and unless behavior was flagged, the infrastructure simply carried the traffic. 

More recently, operators have turned to Subscriber Identity Module (SIM) farms and device farms. These setups involve large numbers of mobile SIM cards or connected devices stitched together to originate calls at scale. When a SIM farm is used, the calls appear to come from different phone numbers, helping them to evade detection. The infrastructure can also be leased, allowing capacity to be distributed and volume to be generated rapidly without relying on a single traditional provider. The result is decentralization, and instead of one large origination point, there may be hundreds of smaller ones. 

Perhaps most concerning, the barrier to entry has dropped even further. It is now possible to start up a “telecom company” using software-as-a-service tools with minimal capital and limited technical depth. With modest monthly fees and little physical infrastructure, an entity can register as a voice service provider and gain access to the broader telephone network. 

That ease of entry intersects with another structural weakness: the Robocall Mitigation Database. Entry into the database is largely a clerical process. Voice service providers are required to submit filings to the Database that describe the actions they are taking to prevent illegal calls from traversing their networks. The effectiveness (or non-effectiveness) of a provider’s robocall mitigation plan is generally evaluated after problems surface – not before. Enforcement follows demonstrated misconduct rather than preventing it upfront. 

The result is a “whack-a-mole” dynamic: shut down one operator, and another can reappear under a new name – often with the same ownership. When call originating infrastructure is inexpensive and regulatory review is largely reactive, incentives favor the rapid reemergence of rogue voice service providers shut down by the government

Spoofing as an operational risk, not just a fraud issue 

Large-scale call spoofing is no longer simply a consumer fraud problem. It has become a meaningful operational risk for banks. 

When a spoofing campaign is underway, the effects are immediate. Call volumes spike as confused customers seek to confirm whether a call came from the bank or an impersonator. Call centers staffed for normal demand quickly become strained. 

Spoofing also creates compliance and complaint-management challenges. When customers believe they have been contacted by their bank – even if the caller is an impersonator – disputes and formal complaints often follow. Institutions must document incidents, assess harm, and manage regulatory expectations while campaigns may still be active. 

Reputational risk compounds the impact. After receiving an illegally spoofed call or text, customers are less likely to trust the bank’s fraud alerts and other time sensitive messages. Spoofing erodes confidence in legitimate outreach and weakens the effectiveness of legitimate fraud alerts. Like cyber incidents and major service outages, large-scale impersonation campaigns disrupt operations, strain resources, and weaken customer confidence – even when internal systems remain intact. 

The operational gap: no “911” for banks during live attacks 

When spoofing campaigns unfold, banks often have no immediate, centralized way to stop them. 

Unlike physical crimes, where dialing 911 triggers a coordinated response, spoofing attacks offer no comparable emergency pathway. Banks may report incidents to regulators, carriers, or law enforcement, but these processes are largely investigative and reactive. By the time action begins, the damage is often complete. 

In some cases, the Industry Traceback Group – which, as its name suggests, conducts “tracebacks” of calls – can interrupt campaigns when sufficient real-time information is available. By analyzing call authentication data and signatures, active attacks can sometimes be traced back to specific carriers and shut down within hours. However, this capability is not universally deployed. It depends on user coverage, technology partnerships, and available intelligence. Smaller banks and institutions with limited resources may not benefit from early-warning systems. 

As a result, protection is uneven. Some banks can interrupt attacks quickly. Others must endure the full impact before intervention occurs. 

Governance failures and systemic risk in the spoofing ecosystem 

The telecommunications environment enables fraud at low cost and with limited long-term consequences. Infrastructure is inexpensive. Entry is easy. Penalties are difficult to collect, and operators can reappear quickly. Modern calls often pass through multiple carriers – sometimes six to ten networks – before reaching customers. No single entity maintains end-to-end responsibility. 

Tracing responsibility during incidents is time-consuming and requires coordination across providers with limited visibility into the full pathway. This low barrier, low penalty structure weakens deterrence and shifts operational, legal, and reputational risk onto legitimate institutions. 

Uneven defensive capabilities worsen the problem. Larger institutions benefit from advanced tools and partnerships. Smaller banks are more exposed. Resource gaps become security gaps. Governance challenges are compounded by incident response limitations, fragmented data, and limited intelligence sharing. Valuable early-warning indicators remain siloed. In addition, artificial intelligence accelerates these risks by enabling rapid creation of shell companies, documentation, and digital infrastructure. Attribution becomes harder and then enforcement lags further. 

Taken together, these conditions make abusive behavior economically rational and operationally sustainable. Managing spoofing risk therefore requires coordinated controls, formalized response frameworks, stronger third-party oversight, and cross-sector information sharing – particularly to protect smaller institutions.

Spoofing as a customer harm multiplier 

Call spoofing extends beyond immediate fraud losses to create lasting customer harm. 

Repeated impersonation degrades the reliability of bank communications. Over time, customers no longer treat fraud alerts and security warnings as inherently trustworthy. From a compliance perspective, this shift has measurable consequences: increased complaints, more complex dispute resolution, and heightened supervisory attention. 

Spoofing therefore transforms fraud from a transactional loss issue into a broader customer relationship risk, weakening long-term customer engagement. 

From systemic risk to practical response 

The structural weaknesses that enable spoofing – low barriers to entry, fragmented accountability, uneven defenses, and limited real-time response – leave banks managing crises largely on their own. 

To understand how these attacks unfold in practice – and what effective response looks like – this article draws on the experience of Uri Rivner, chief executive officer and co-founder of Refine Intelligence, an AI-driven technology company focused on helping banks resolve fraud and scam alerts more effectively. With more than 25 years in fraud and cyber intelligence, including pioneering work in behavioral biometrics as co-founder of BioCatch, Rivner has advised banks navigating live impersonation and account takeover incidents when response capacity is stretched and decisions must be made in real time. 

“By the time banks realize what’s happening, they’re already in the middle of an avalanche,” Rivner says. “It’s not one alert. It’s hundreds, all at once.” 

His perspective reflects what institutions encounter when spoofing campaigns move from theory to operational reality. 

“The ecosystem makes this easy for criminals and hard for banks,” Rivner says. “Low cost, low friction, and very little real-time accountability.” 

Rivner explains that the most effective entry point for these attacks is now the phone. Criminals spoof bank phone numbers, use AI-generated or coached voices, and reference stolen personal data to appear legitimate. Customers are more likely to trust a call that appears to come from their bank than a suspicious email or text message. Once engaged, victims are directed to fake websites, where credentials are harvested and accounts are taken over. 

In Rivner’s view, the breakdown in trust between banks and customers is compounded by outdated communication practices. He cautions that traditional customer outreach strategies may now be doing more harm than good. 

“The least effective way of engaging customers over fraud today is calling them,” he says. “That’s exactly what criminals are doing.” 

While banks often emphasize customer education, he notes that awareness campaigns have limits. What matters more is consistency. 

“People very quickly understand how their bank actually communicates with them,” Rivner says. “That becomes the signal they trust.” 

When institutions introduce new verification channels or security procedures, he argues, those changes should be clearly communicated through official platforms. At the same time, banks must recognize that system design often matters more than messaging. 

“Customers are more susceptible to manipulation through convincing phone calls than through emails, texts, or other channels,” Rivner adds. 

That reality raises a pressing question for risk and compliance leaders: 

How should banks respond when spoofing attacks are already underway – and how can they prepare before the next one hits?

What does a spoofing-driven account takeover event look like to a banker? 

For most regional and community banks, these attacks do not begin with a single obvious red flag. They unfold as a rapid accumulation of operational anomalies that, taken together, signal that an institution is under coordinated assault. 

“It rarely looks dramatic at first,” Rivner explains. “It looks like noise – new devices, new payees, small anomalies. Then suddenly it’s everywhere.” 

Early indicators often include: 

  • A sudden increase in transactions to new or unfamiliar beneficiaries 
  • Multiple high-dollar payments that fall outside a customer’s normal pattern 
  • Logins from new or previously unseen devices 
  • Elevated fraud and transaction-monitoring alerts within a short time frame 
  • Unusual account maintenance activity, such as rapid changes to phone numbers, email addresses, or passwords 

Initially, these events may appear unrelated. Operations teams may interpret them as routine fraud spikes, customer behavior changes, or isolated errors. 

Within hours, however, customer-facing signals begin to emerge. 

Banks start receiving calls from customers reporting locked accounts, unauthorized transfers, or missing funds. Branch staff and call centers see a surge in complaints. Fraud queues grow rapidly. In many cases, staff discover that multiple customers were contacted by “the bank” using spoofed phone numbers and convincing scripts. By the time these patterns are fully visible, institutions are often already in crisis mode. 

“Once customer calls start coming in, you’re already behind,” Rivner notes. “That means credentials are compromised and money is probably moving.” 

Alert volumes exceed the bank’s normal review capacity. Manual investigations into alerts move slowly, and customer outreach efforts fail as attackers keep victims’ phone lines engaged or redirect contact information. Bank staff struggle to distinguish legitimate transactions from compromised ones. 

At this stage, the attack resembles an operational flood rather than a traditional fraud incident. Without automated filtering and verification tools, banks are forced into reactive triage – prioritizing cases under extreme time pressure while funds continue to move out of customer accounts. 

“The fact regional banks, community banks and credit unions see a surge in bank impersonation calls isn’t incidental”, Rivner adds. “Criminals know they are less defended targets, and far easier to saturate given their low operational capacity”.

What should banks do proactively – before an attack occurs? 

Rivner emphasizes that many of the most effective controls cannot be deployed during an active incident. Institutions that wait until an attack begins are already behind. 

“You can’t build these controls in the middle of a crisis,” Rivner says. “If you’re trying to stand them up while money is already moving, you’re too late.” 

Preparation must focus on building scalable visibility, verification, and response capabilities in advance. Rivner identifies eight operational priorities that banks should establish before facing a live spoofing incident. 

Align closely with processors and digital banking vendors
Banks should engage regularly with their core processors, online banking providers, and fraud platform partners to understand available controls and response options.
“For most regional banks, your vendors are your first line of defense,” Rivner says. “You need to know exactly what they can see and how fast they can help.”
This includes:

  • Reviewing existing fraud-detection thresholds and escalation paths 
  • Confirming which device, behavioral, and account-monitoring tools are enabled
  • Understanding surge-capacity support during large-scale incidents Establishing clear communication channels with vendor fraud teams

Tighten and refine alerting rules
Institutions should ensure that high-risk behaviors are flagged quickly and consistently. “If everything is an alert, nothing is an alert,” Rivner warns. “You have to design for surge conditions.”
Key indicators include:

  • New payees combined with high-dollar transfers
  • First-time device usage
  • Remote-access or screen-sharing activity
  • Rapid credential changes 
  • Multiple payment attempts in short time frames

Monitor account maintenance activity as a fraud signal
Banks should treat changes to customer contact information and credentials as potential precursors to account takeover. “Attackers almost always change something before they move money,” Rivner says. “Phone numbers, emails, passwords – that’s where the trail starts.”
This includes monitoring for:

  • Phone number changes 
  • Email updates 
  • Password resets 
  • Addition of new authorized users 
  • Changes to notification preferences

Implement behavioral and device-based analytics where feasible
Where supported by vendors, banks should adopt technologies that assess how customers interact with digital platforms.

“Behavioral analytics can tell you when account activity may be carried out by someone other than the legitimate customer, even if the transactions themselves appear normal.,” Rivner explains. “They reveal when someone else is driving the account.”

These tools can identify:

  • Uncharacteristic typing, navigation, or transaction behavior 
  • Indicators of remote-control activity 
  • Deviations from established usage patterns

Build automated, multi-channel customer verification capability
“Banks need automated, effective, digital communication channels where identity is verified by infrastructure not by trust in a phone number or voice ” Rivner stresses.

“Calling customers is manual, slow, and in my experience yields 25% response rates. Banks that have automated customer engagement around fraud can get to an 85% response rate.”

As an example, Rivner points to the emergence of Rich Communication Services (RCS), a messaging standard supported by Google, Apple, and major wireless carriers, as one way banks can move toward authenticated customer outreach with branded texts.

“If the channel itself is trusted, everything downstream gets easier,” he says.
Preparation includes:

  • Enabling branded and verified automated messaging channels that can be scaled up during an attack 
  • Establishing secure web-based confirmation portals 
  • Linking outreach to pre-validated contact records 
  • Supporting outreach to multiple account holders

Establish payment-slowdown and manual-review protocols
Institutions should predefine how high-risk payments will be delayed. “Time is your only real weapon in these attacks,” Rivner notes. “Slowing payments buys you verification.”
This includes:

  • Criteria for triggering manual review 
  • Processes for slowing wires and ACH transactions 
  • Authority levels for temporary holds 
  • Documentation standards for regulatory review

Update customer communication and education strategies
Banks should normalize safer verification channels before incidents occur.
“Customers need to know what real bank communication looks like,” Rivner says.
“Otherwise, criminals define it for them.”
This may include:

  • Explaining how the bank confirms suspicious activity 
  • Clarifying that the bank will not rely on unsolicited phone calls Publishing guidance through online banking portals 
  • Reinforcing reporting channels for suspected impersonation

Stress-test fraud response capacity
Finally, banks should periodically assess whether their fraud operations can withstand coordinated attacks. “Most banks don’t discover their breaking point until they’re already in it,” Rivner says. “Tabletop exercises and simulations are the only way to find it safely.”
This includes:

  • Simulating alert surges 
  • Reviewing staffing and escalation models 
  • Testing vendor response timelines 
  • Evaluating customer outreach throughput 

These exercises help institutions identify operational bottlenecks before criminals exploit them.

Looking forward 

Call spoofing is evolving faster than most institutional response frameworks. As artificial intelligence lowers barriers and accelerates attack cycles, impersonation campaigns will become more targeted, more adaptive, and more difficult to interrupt in real time. 

For banks, this means that spoofing can no longer be managed solely as a fraud or customer-awareness issue. It must be treated as an operational resilience challenge that spans vendor governance, incident response, customer engagement, and executive oversight. 

Institutions that invest early in visibility, verification, and response capacity will be better positioned to contain future campaigns. Those that rely on ad hoc controls and manual intervention will remain vulnerable to rapid escalation. 

In an environment where attacks unfold in hours rather than weeks, preparedness is not a competitive advantage. It is a baseline requirement. 

What the ABA is doing 

Historically, American Bankers Association ‘s (ABA’s) telecom advocacy centered on preserving banks’ ability to reach customers under the TCPA. Today, the emphasis has expanded to include reforms of the telecommunications rules that stop criminals from exploiting those same channels to impersonate banks. 

ABA’s position is that spoofing is no longer solely a fraud issue. It is an infrastructure and governance problem that requires coordinated regulatory, technical, and legislative solutions. Since 2022, ABA has submitted more than a dozen formal letters to the Federal Communications Commission, urging stronger oversight and faster intervention against illegal call activity. Its goal is to make spoofing harder to execute and easier to disrupt. 

Most recently, ABA supported the FCC’s proposals to restrict phone number resale and curb number cycling, two practices that criminals exploit to facilitate large-scale spoofing campaigns.

Regulatory priorities 

ABA has supported several recent and proposed FCC actions, including:

  • Requiring carriers across the call pathway to block calls that are highly likely to be illegal. 
  • Extending call authentication requirements to legacy, non-Internet Protocol networks. 
  • Strengthening rules to ensure originating voice service providers know the entity behind a call and know that the entity has lawful access to the number that will be displayed in the consumer’s caller ID. 

ABA has also pressed for more rigorous and timely enforcement of existing rules. 

Structural and legislative proposals 

ABA also has proposed policy actions that go beyond those currently being considered by the FCC: 

  • Requiring performance bonds for participation in the Robocall Mitigation Database to deter fly-by-night operators. 
  • Banning SIM box infrastructure used for mass call origination. 
  • Creating a national database of ownership of telephone numbers, so that originating providers can verify that a caller has lawful access to the number that will be displayed in the consumer’s caller ID before the call is placed.
  • Establishing a centralized repository of reported spam and scam messages that is accessible to banks and other legitimate brands. 

ABOUT THE AUTHOR 

LAINE CROSBY is editor-in-chief of ABA Risk and Compliance magazine. Reach her at LinkedIn.com/in/lainecrosby/ or rcmageditor@aba.com. 

Republished with permission of the American Bankers Association. Read it on ABA’s site.