For U.S. commercial banks in the $10B-$100B asset range, the phone line is where trust is highest and controls are weakest. This FAQ answers the questions bank CISOs, fraud leaders, and contact-center owners are actually asking about spoofing prevention in 2026 – what STIR/SHAKEN does and does not do, how AI voice cloning changes the threat, and where NIST and the FFIEC now draw the line.
Two data points frame the urgency. Phone calls were the second most common contact method for reported fraud in 2024, and victims reached by phone lost the most per person – a median of about $1,500 (FTC Consumer Sentinel Network Data Book 2024). Phishing/spoofing was the single most-reported crime type to the FBI’s Internet Crime Complaint Center, part of a record $16.6 billion in reported losses (FBI IC3 2024).
Throughout this guide, the reference platform for bringing these controls together is Oracle Communications Converged Application Server (OCCAS) – the carrier-grade application server Matellio uses to orchestrate caller ID authentication, voice biometrics, and deepfake detection above a bank’s existing telephony. Spoofing prevention is not a single product but an orchestration problem, and it sits at the center of a broader contact center fraud prevention program that spans both inbound and outbound calls.
Frequently asked questions
1. What is phone spoofing and caller ID spoofing, and why do fraudsters target banks?
Phone spoofing (caller ID spoofing) is when a caller falsifies the number – and sometimes the name – shown on the recipient’s caller ID to hide their identity or impersonate a trusted organization. Banks are prime targets because a call that appears to come from “your bank” carries instant trust, which fraudsters weaponize to extract credentials, one-time passcodes, and payments.
Spoofing runs in two directions, and banks must address both: inbound, where a fraudster spoofs a customer’s number to slip past the contact center’s caller-ID trust, and outbound, where a fraudster spoofs the bank’s number to reach customers directly. The phone remained the second most common fraud contact method in 2024, and it produced the highest median loss per victim (FTC, 2024).
2. What is caller ID spoofing prevention, and how do banks actually stop it?
Caller ID spoofing prevention is the set of controls that verify whether the number shown on a call is genuine and whether the caller is who they claim to be. For a bank it is layered: network-level call authentication (STIR/SHAKEN), inbound spoof/ANI risk scoring, branded and verified outbound calling, and – for the caller’s identity rather than just the number – passive voice biometrics with deepfake detection.
No single control is sufficient, because each solves a different part of the problem. STIR/SHAKEN attests to the calling number; ANI/spoof scoring flags suspicious inbound routing; branded calling proves an outbound call is really from the bank; and voice biometrics plus synthetic-speech detection judge whether the human on the line is genuine. The resilient pattern combines them in a risk-based decision.
3. Can a bank stop its own phone number from being spoofed to customers?
A bank cannot make spoofing technically impossible, but it can make its legitimate calls verifiable and its impostors detectable. By authenticating outbound calls with STIR/SHAKEN A-level attestation and adding branded caller ID (a verified name, logo, and call reason), a bank gives carriers and customers a cryptographic basis to tell a real bank call from a spoofed one.
This is why outbound call integrity is a fraud control, not just a marketing one: a fraud-alert call that a customer ignores because it looks like spam can turn into a downstream loss. Verified, branded calls raise answer rates and shrink the window in which a spoofed “bank” call can succeed.
4. What is STIR/SHAKEN and how does it prevent caller ID spoofing?
STIR/SHAKEN (Secure Telephone Identity Revisited / Signature-based Handling of Asserted information using toKENs) is an industry-standard framework that lets the originating carrier digitally “sign” a call’s caller ID and downstream carriers verify that signature across IP networks. The FCC has required voice providers to implement it in the IP portions of their networks since June 30, 2021.
Enabled by the TRACED Act of 2019, STIR/SHAKEN lets the terminating carrier confirm that the caller ID number was legitimately used and label or block calls that fail verification. The critical nuance for a bank: it authenticates the number and the originating carrier – not the human caller’s identity or the content of the call. It is necessary, but not sufficient on its own. (FCC, Combating Spoofed Robocalls with Caller ID Authentication)
5. What are STIR/SHAKEN attestation levels A, B, and C, and why do they matter to a bank?
Attestation is the originating carrier’s statement of how much it knows about the caller’s right to use the number. There are three levels – A (full), B (partial), and C (gateway) – and they directly affect whether your outbound calls display as verified or get flagged as spam.
| Level | What the carrier is attesting | What it means for a bank |
|---|---|---|
| A – Full | The provider authenticated the caller and confirmed they are authorized to use the calling number. | The target for all legitimate bank outbound traffic – earns verified/branded display and avoids spam labeling. |
| B – Partial | The provider authenticated the call origination but cannot confirm the caller’s right to use the number. | Weaker trust signal; calls are more likely to be analytically down-ranked or labeled. |
| C – Gateway | The provider only passed the call onto the network (e.g., an international gateway) with no relationship to the initiator. | Lowest trust; common on unauthenticated or foreign-originated calls – a red flag inbound. |
To get legitimate outbound calls treated as trustworthy, a bank’s traffic should consistently earn A-level attestation – which is why call-branding and verified-calling programs matter operationally, not just cosmetically. (FCC Report and Order FCC 24-120; ATIS standards)
6. Does STIR/SHAKEN stop deepfake voice fraud?
No. STIR/SHAKEN verifies the calling number and the originating carrier – it says nothing about who is actually speaking or whether the voice is real. A fraudster using a legitimately obtained number, or a deepfake voice on an inbound call, passes through STIR/SHAKEN untouched.
This is the most important misconception for a bank to correct. Number authentication and voice authentication are different layers. Defending against synthetic voice requires passive voice biometrics combined with liveness and dedicated deepfake (synthetic-speech) detection, layered on top of – not replaced by – call authentication.

7. How are deepfakes and AI voice cloning used against bank contact centers?
Fraudsters use generative-AI voice cloning two ways: to impersonate customers on inbound calls – defeating knowledge-based security questions in the customer’s “own” voice – and to impersonate bank executives or staff in social-engineering and authorized-push-payment scams. The U.S. Treasury’s FinCEN has formally warned banks about this trend.
In its November 2024 alert (FIN-2024-Alert004), FinCEN reported a rise in suspicious-activity reports describing GenAI deepfake media used to circumvent identity verification and authentication, and recommended multi-factor authentication (including phishing-resistant MFA) and live verification checks as mitigations. Because AI voice cloning is now cheap and fast, any control that relies on a shared secret the caller can simply recite — KBA, PINs – is especially exposed. (FinCEN, 2024)
8. Are AI-generated voice robocalls illegal?
Yes, in effect. In a Declaratory Ruling on February 8, 2024, the FCC confirmed that AI-generated and voice-cloned voices are “artificial” under the Telephone Consumer Protection Act (TCPA) – so using them to call consumers without prior express consent is unlawful, and the ruling gave state attorneys general new tools to pursue voice-cloning scams.
For a bank this cuts two ways. It is a regulatory tailwind against impostors who clone the bank’s or an executive’s voice. It also means the bank’s own use of AI voices – AI voice agents, prerecorded outreach – must meet the TCPA’s consent, caller-identification, and opt-out requirements. (FCC Declaratory Ruling FCC 24-17)
9. How can a bank detect a deepfake or synthetic voice on a call?
Deepfake detection analyzes live call audio for artifacts of synthetic generation – spectral irregularities, unnatural cadence, and replay/playback signatures – and pairs that with liveness detection and a voiceprint comparison. Treated as one signal in a risk-based decision alongside spoof scoring and behavioral analysis, it flags a cloned caller that a security question or PIN never could.
Technically, three things work together: passive voice biometrics builds and matches a voiceprint (“something you are”); a synthetic-speech classifier scores the probability the audio is machine-generated; and liveness confirms a live speaker rather than a recording. FinCEN similarly points banks toward dedicated detection software and metadata analysis, used within a layered program rather than as a single gate.
10. What do the FFIEC and NIST require for phone-channel authentication and spoofing controls?
The FFIEC’s 2021 authentication guidance states that single-factor authentication is inadequate for high-risk users and transactions and directs banks toward layered security and multi-factor authentication, noting that reliable identity verification “generally do[es] not depend solely on knowledge-based questions.” NIST SP 800-63B has withdrawn knowledge-based authentication (security questions) as an acceptable authenticator outright.
Read together, the standards push banks in one direction for the phone channel: retire KBA as a primary control, stop treating any single memorized secret as sufficient for sensitive calls, and move to layered, risk-based authentication in which network-level call authentication and a biometric voice factor do the heavy lifting. Examiners increasingly expect the contact center to meet the same bar as digital banking. (FFIEC 2021 / OCC Bulletin 2021-36; NIST SP 800-63B)
Putting it together: a layered spoofing-prevention program
The through-line across every answer above is that no single control stops spoofing. A resilient bank program layers four things and only escalates to active challenges when risk is elevated:
- Pre-answer risk scoring: validate the calling number against network signaling (ANI/spoof detection) and STIR/SHAKEN verification before routing.
- Passive voice biometrics + deepfake detection: authenticate the caller in the background during natural speech and score the audio for synthetic-voice artifacts.
- Branded, A-attested outbound calling: prove the bank’s own calls are genuine so fraud alerts get answered and impostors are easier to spot.
- Behavioral signals + risk-based step-up: compensate for any one control’s weakness and reserve extra challenges for genuinely high-risk calls – the FFIEC’s layered-security principle.
These layers are most effective when they are orchestrated on a single platform rather than stitched together, which is why the choice of orchestration engine matters as much as the individual controls. It also means spoofing prevention should be designed alongside a bank’s broader call center authentication solutions, so number authentication and caller authentication reinforce each other instead of running as separate projects.
Why Oracle OCCAS is the right orchestration platform
Detecting spoofed and synthetic calls in real time means intercepting and acting on live SIP signaling at the speed of a ringing phone – a job for a telecom-grade application server, not a bolt-on script. Oracle Communications Converged Application Server (OCCAS) is built for exactly this:
- Carrier-grade SIP application server: OCCAS processes SIP signaling at telecom scale and reliability, so authentication logic runs inline on every call rather than as an afterthought.
- Standards-based SIP Servlet capabilities: call handling, routing, and authentication orchestration are implemented as portable SIP Servlet applications, making it straightforward to insert STIR/SHAKEN checks, ANI risk scoring, and biometric hooks directly into the call path.
- High availability: carrier-grade HA with session-state replication keeps authentication running through component failures – essential when the phone channel is a primary fraud and service channel.
- Horizontal scalability: OCCAS scales out to the call volumes of a $10B-$100B bank without re-architecting the contact center.
- Oracle SBC integration: tight integration with Oracle Communications Session Border Controller provides the secure SIP border – trunking, topology hiding, and a natural enforcement point for spoof and risk decisions.
- Enterprise banking fit: a hardened, supportable, standards-based platform aligns with the security, compliance, and reliability expectations of a regulated financial institution.
This is the foundation of Matellio’s voice security for banks offering, because OCCAS deploys as an overlay above existing SIP infrastructure, a bank adds these controls without a rip-and-replace, and can extend the same orchestration during an Amazon Connect or cloud contact-center migration so authentication and platform modernization happen together.
What a protected call flow looks like, end to end
When a call arrives, OCCAS orchestrates a sequence of checks and only routes the call once it has a risk decision. The end-to-end flow for a single inbound call:
- Incoming SIP call – the call reaches the Oracle Session Border Controller and is handed to OCCAS for handling.
- STIR/SHAKEN verification – OCCAS checks the caller ID attestation and verification status to confirm the number was legitimately used.
- ANI / spoof risk scoring – the calling number and network signaling are scored for spoofing indicators before the caller reaches an agent or the IVR.
- Voice biometrics – passive voiceprint matching authenticates the caller during natural speech – the “something you are” factor.
- Deepfake / synthetic-voice detection – the live audio is scored for signs of AI generation, replay, or cloning.
- Risk evaluation – the signals are combined into a single risk decision, with behavioral and device context.
- Routing decision – low-risk calls proceed with minimal friction; elevated-risk calls are challenged, stepped up, or routed to a specialist fraud queue.

The business benefits for a bank
Beyond stopping fraud, a layered voice-security program orchestrated on OCCAS delivers measurable business value across risk, experience, and operations:
- Improved customer trust: branded, verified outbound calls and low-friction inbound authentication make every interaction feel safe and legitimate.
- Reduced fraud losses: catching spoofed and synthetic calls before they reach an agent cuts account-takeover and authorized-payment losses.
- Lower authentication effort: passive voice biometrics removes security-question and PIN interrogation, shortening handle time for legitimate callers.
- Better compliance posture: layered, risk-based authentication maps directly to FFIEC and NIST expectations, easing examinations.
- Enhanced contact center efficiency: fewer failed authentications, escalations, and re-dials mean lower cost per contact and more agent capacity for real service.
Sources
- FCC – Combating Spoofed Robocalls with Caller ID Authentication (STIR/SHAKEN, June 30, 2021 mandate) – https://www.fcc.gov/call-authentication
- FCC – TRACED Act Implementation – https://www.fcc.gov/TRACEDAct
- FCC – Report and Order FCC 24-120 (attestation and third-party signing) – https://docs.fcc.gov/public/attachments/FCC-24-120A1.pdf
- FCC – Declaratory Ruling FCC 24-17: AI-generated voices are “artificial” under the TCPA (Feb 8, 2024) – https://www.fcc.gov/document/fcc-makes-ai-generated-voices-robocalls-illegal
- FinCEN – Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions (FIN-2024-Alert004, Nov 13, 2024) – https://www.fincen.gov/news/news-releases/fincen-issues-alert-fraud-schemes-involving-deepfake-media-targeting-financial
- FTC – Consumer Sentinel Network Data Book 2024 – https://www.ftc.gov/reports/consumer-sentinel-network-data-book-2024
- FBI IC3 2024 Internet Crime Report – https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf
- NIST SP 800-63B, Digital Identity Guidelines – KBA withdrawn as an authenticator – https://pages.nist.gov/800-63-4/sp800-63b.html
- FFIEC – Authentication and Access to Financial Institution Services and Systems (2021) – https://www.ffiec.gov/sites/default/files/media/press-releases/2021/authentication-and-access-to-financial-institution-services-and-systems.pdf
Author Bio

VP- Account Management at Matellio
