Phone & Caller ID Spoofing Prevention for Banks: FAQs on STIR/SHAKEN, Deepfakes & FFIEC Compliance

JUMP TO SECTION

    JUMP TO SECTION

    Listen to the Blog
    0:00 0:00

    Share this Article

    Picture of Mukul Vaishnav

    Mukul Vaishnav

    VP- Account Management at Matellio

    Talk to an Engineering Expert

    form insights detail

    Related Blogs

    Phone spoofing prevention (also called caller ID or telephone spoofing prevention) is the combination of network-level call authentication, inbound risk scoring, and voice-identity controls a bank uses to stop falsified caller ID – both when fraudsters spoof a customer’s number to get into the contact center, and when they spoof the bank’s own number to deceive customers. STIR/SHAKEN handles the number; deepfake detection and voice biometrics handle the voice.

    For U.S. commercial banks in the $10B-$100B asset range, the phone line is where trust is highest and controls are weakest. This FAQ answers the questions bank CISOs, fraud leaders, and contact-center owners are actually asking about spoofing prevention in 2026 – what STIR/SHAKEN does and does not do, how AI voice cloning changes the threat, and where NIST and the FFIEC now draw the line.

    Two data points frame the urgency. Phone calls were the second most common contact method for reported fraud in 2024, and victims reached by phone lost the most per person – a median of about $1,500 (FTC Consumer Sentinel Network Data Book 2024). Phishing/spoofing was the single most-reported crime type to the FBI’s Internet Crime Complaint Center, part of a record $16.6 billion in reported losses (FBI IC3 2024).

    Throughout this guide, the reference platform for bringing these controls together is Oracle Communications Converged Application Server (OCCAS) – the carrier-grade application server Matellio uses to orchestrate caller ID authentication, voice biometrics, and deepfake detection above a bank’s existing telephony. Spoofing prevention is not a single product but an orchestration problem, and it sits at the center of a broader contact center fraud prevention program that spans both inbound and outbound calls.

    Frequently asked questions

    1. What is phone spoofing and caller ID spoofing, and why do fraudsters target banks?

    Phone spoofing (caller ID spoofing) is when a caller falsifies the number – and sometimes the name – shown on the recipient’s caller ID to hide their identity or impersonate a trusted organization. Banks are prime targets because a call that appears to come from “your bank” carries instant trust, which fraudsters weaponize to extract credentials, one-time passcodes, and payments.

    Spoofing runs in two directions, and banks must address both: inbound, where a fraudster spoofs a customer’s number to slip past the contact center’s caller-ID trust, and outbound, where a fraudster spoofs the bank’s number to reach customers directly. The phone remained the second most common fraud contact method in 2024, and it produced the highest median loss per victim (FTC, 2024).

    2. What is caller ID spoofing prevention, and how do banks actually stop it?

    Caller ID spoofing prevention is the set of controls that verify whether the number shown on a call is genuine and whether the caller is who they claim to be. For a bank it is layered: network-level call authentication (STIR/SHAKEN), inbound spoof/ANI risk scoring, branded and verified outbound calling, and – for the caller’s identity rather than just the number – passive voice biometrics with deepfake detection.

    No single control is sufficient, because each solves a different part of the problem. STIR/SHAKEN attests to the calling number; ANI/spoof scoring flags suspicious inbound routing; branded calling proves an outbound call is really from the bank; and voice biometrics plus synthetic-speech detection judge whether the human on the line is genuine. The resilient pattern combines them in a risk-based decision.

    3. Can a bank stop its own phone number from being spoofed to customers?

    A bank cannot make spoofing technically impossible, but it can make its legitimate calls verifiable and its impostors detectable. By authenticating outbound calls with STIR/SHAKEN A-level attestation and adding branded caller ID (a verified name, logo, and call reason), a bank gives carriers and customers a cryptographic basis to tell a real bank call from a spoofed one.

    This is why outbound call integrity is a fraud control, not just a marketing one: a fraud-alert call that a customer ignores because it looks like spam can turn into a downstream loss. Verified, branded calls raise answer rates and shrink the window in which a spoofed “bank” call can succeed.

    4. What is STIR/SHAKEN and how does it prevent caller ID spoofing?

    STIR/SHAKEN (Secure Telephone Identity Revisited / Signature-based Handling of Asserted information using toKENs) is an industry-standard framework that lets the originating carrier digitally “sign” a call’s caller ID and downstream carriers verify that signature across IP networks. The FCC has required voice providers to implement it in the IP portions of their networks since June 30, 2021.

    Enabled by the TRACED Act of 2019, STIR/SHAKEN lets the terminating carrier confirm that the caller ID number was legitimately used and label or block calls that fail verification. The critical nuance for a bank: it authenticates the number and the originating carrier – not the human caller’s identity or the content of the call. It is necessary, but not sufficient on its own. (FCC, Combating Spoofed Robocalls with Caller ID Authentication)

    5. What are STIR/SHAKEN attestation levels A, B, and C, and why do they matter to a bank?

    Attestation is the originating carrier’s statement of how much it knows about the caller’s right to use the number. There are three levels – A (full), B (partial), and C (gateway) – and they directly affect whether your outbound calls display as verified or get flagged as spam.

    Level What the carrier is attesting What it means for a bank
    A – Full The provider authenticated the caller and confirmed they are authorized to use the calling number. The target for all legitimate bank outbound traffic – earns verified/branded display and avoids spam labeling.
    B – Partial The provider authenticated the call origination but cannot confirm the caller’s right to use the number. Weaker trust signal; calls are more likely to be analytically down-ranked or labeled.
    C – Gateway The provider only passed the call onto the network (e.g., an international gateway) with no relationship to the initiator. Lowest trust; common on unauthenticated or foreign-originated calls – a red flag inbound.

    To get legitimate outbound calls treated as trustworthy, a bank’s traffic should consistently earn A-level attestation – which is why call-branding and verified-calling programs matter operationally, not just cosmetically. (FCC Report and Order FCC 24-120; ATIS standards)

    6. Does STIR/SHAKEN stop deepfake voice fraud?

    No. STIR/SHAKEN verifies the calling number and the originating carrier – it says nothing about who is actually speaking or whether the voice is real. A fraudster using a legitimately obtained number, or a deepfake voice on an inbound call, passes through STIR/SHAKEN untouched.

    This is the most important misconception for a bank to correct. Number authentication and voice authentication are different layers. Defending against synthetic voice requires passive voice biometrics combined with liveness and dedicated deepfake (synthetic-speech) detection, layered on top of – not replaced by – call authentication.

    Deepfake synthetic-voice detection versus a genuine voiceprint for telephone spoofing prevention in banks

    7. How are deepfakes and AI voice cloning used against bank contact centers?

    Fraudsters use generative-AI voice cloning two ways: to impersonate customers on inbound calls – defeating knowledge-based security questions in the customer’s “own” voice – and to impersonate bank executives or staff in social-engineering and authorized-push-payment scams. The U.S. Treasury’s FinCEN has formally warned banks about this trend.

    In its November 2024 alert (FIN-2024-Alert004), FinCEN reported a rise in suspicious-activity reports describing GenAI deepfake media used to circumvent identity verification and authentication, and recommended multi-factor authentication (including phishing-resistant MFA) and live verification checks as mitigations. Because AI voice cloning is now cheap and fast, any control that relies on a shared secret the caller can simply recite — KBA, PINs – is especially exposed. (FinCEN, 2024)

    8. Are AI-generated voice robocalls illegal?

    Yes, in effect. In a Declaratory Ruling on February 8, 2024, the FCC confirmed that AI-generated and voice-cloned voices are “artificial” under the Telephone Consumer Protection Act (TCPA) – so using them to call consumers without prior express consent is unlawful, and the ruling gave state attorneys general new tools to pursue voice-cloning scams.

    For a bank this cuts two ways. It is a regulatory tailwind against impostors who clone the bank’s or an executive’s voice. It also means the bank’s own use of AI voices – AI voice agents, prerecorded outreach – must meet the TCPA’s consent, caller-identification, and opt-out requirements. (FCC Declaratory Ruling FCC 24-17)

    9. How can a bank detect a deepfake or synthetic voice on a call?

    Deepfake detection analyzes live call audio for artifacts of synthetic generation – spectral irregularities, unnatural cadence, and replay/playback signatures – and pairs that with liveness detection and a voiceprint comparison. Treated as one signal in a risk-based decision alongside spoof scoring and behavioral analysis, it flags a cloned caller that a security question or PIN never could.

    Technically, three things work together: passive voice biometrics builds and matches a voiceprint (“something you are”); a synthetic-speech classifier scores the probability the audio is machine-generated; and liveness confirms a live speaker rather than a recording. FinCEN similarly points banks toward dedicated detection software and metadata analysis, used within a layered program rather than as a single gate.

    10. What do the FFIEC and NIST require for phone-channel authentication and spoofing controls?

    The FFIEC’s 2021 authentication guidance states that single-factor authentication is inadequate for high-risk users and transactions and directs banks toward layered security and multi-factor authentication, noting that reliable identity verification “generally do[es] not depend solely on knowledge-based questions.” NIST SP 800-63B has withdrawn knowledge-based authentication (security questions) as an acceptable authenticator outright.

    Read together, the standards push banks in one direction for the phone channel: retire KBA as a primary control, stop treating any single memorized secret as sufficient for sensitive calls, and move to layered, risk-based authentication in which network-level call authentication and a biometric voice factor do the heavy lifting. Examiners increasingly expect the contact center to meet the same bar as digital banking. (FFIEC 2021 / OCC Bulletin 2021-36; NIST SP 800-63B)

    Putting it together: a layered spoofing-prevention program

    The through-line across every answer above is that no single control stops spoofing. A resilient bank program layers four things and only escalates to active challenges when risk is elevated:

    • Pre-answer risk scoring: validate the calling number against network signaling (ANI/spoof detection) and STIR/SHAKEN verification before routing.
    • Passive voice biometrics + deepfake detection: authenticate the caller in the background during natural speech and score the audio for synthetic-voice artifacts.
    • Branded, A-attested outbound calling: prove the bank’s own calls are genuine so fraud alerts get answered and impostors are easier to spot.
    • Behavioral signals + risk-based step-up: compensate for any one control’s weakness and reserve extra challenges for genuinely high-risk calls – the FFIEC’s layered-security principle.

    These layers are most effective when they are orchestrated on a single platform rather than stitched together, which is why the choice of orchestration engine matters as much as the individual controls. It also means spoofing prevention should be designed alongside a bank’s broader call center authentication solutions, so number authentication and caller authentication reinforce each other instead of running as separate projects.

    Why Oracle OCCAS is the right orchestration platform

    Detecting spoofed and synthetic calls in real time means intercepting and acting on live SIP signaling at the speed of a ringing phone – a job for a telecom-grade application server, not a bolt-on script. Oracle Communications Converged Application Server (OCCAS) is built for exactly this:

    • Carrier-grade SIP application server: OCCAS processes SIP signaling at telecom scale and reliability, so authentication logic runs inline on every call rather than as an afterthought.
    • Standards-based SIP Servlet capabilities: call handling, routing, and authentication orchestration are implemented as portable SIP Servlet applications, making it straightforward to insert STIR/SHAKEN checks, ANI risk scoring, and biometric hooks directly into the call path.
    • High availability: carrier-grade HA with session-state replication keeps authentication running through component failures – essential when the phone channel is a primary fraud and service channel.
    • Horizontal scalability: OCCAS scales out to the call volumes of a $10B-$100B bank without re-architecting the contact center.
    • Oracle SBC integration: tight integration with Oracle Communications Session Border Controller provides the secure SIP border – trunking, topology hiding, and a natural enforcement point for spoof and risk decisions.
    • Enterprise banking fit: a hardened, supportable, standards-based platform aligns with the security, compliance, and reliability expectations of a regulated financial institution.

    This is the foundation of Matellio’s voice security for banks offering, because OCCAS deploys as an overlay above existing SIP infrastructure, a bank adds these controls without a rip-and-replace, and can extend the same orchestration during an Amazon Connect or cloud contact-center migration so authentication and platform modernization happen together.

    What a protected call flow looks like, end to end

    When a call arrives, OCCAS orchestrates a sequence of checks and only routes the call once it has a risk decision. The end-to-end flow for a single inbound call:

    1. Incoming SIP call – the call reaches the Oracle Session Border Controller and is handed to OCCAS for handling.
    2. STIR/SHAKEN verification – OCCAS checks the caller ID attestation and verification status to confirm the number was legitimately used.
    3. ANI / spoof risk scoring – the calling number and network signaling are scored for spoofing indicators before the caller reaches an agent or the IVR.
    4. Voice biometrics – passive voiceprint matching authenticates the caller during natural speech – the “something you are” factor.
    5. Deepfake / synthetic-voice detection – the live audio is scored for signs of AI generation, replay, or cloning.
    6. Risk evaluation – the signals are combined into a single risk decision, with behavioral and device context.
    7. Routing decision – low-risk calls proceed with minimal friction; elevated-risk calls are challenged, stepped up, or routed to a specialist fraud queue.

    End-to-end bank call flow on Oracle OCCAS: STIR/SHAKEN verification, ANI risk scoring, voice biometrics, deepfake detection, and routing for phone spoofing prevention

    The business benefits for a bank

    Beyond stopping fraud, a layered voice-security program orchestrated on OCCAS delivers measurable business value across risk, experience, and operations:

    • Improved customer trust: branded, verified outbound calls and low-friction inbound authentication make every interaction feel safe and legitimate.
    • Reduced fraud losses: catching spoofed and synthetic calls before they reach an agent cuts account-takeover and authorized-payment losses.
    • Lower authentication effort: passive voice biometrics removes security-question and PIN interrogation, shortening handle time for legitimate callers.
    • Better compliance posture: layered, risk-based authentication maps directly to FFIEC and NIST expectations, easing examinations.
    • Enhanced contact center efficiency: fewer failed authentications, escalations, and re-dials mean lower cost per contact and more agent capacity for real service.

    Schedule a bank voice-security assessment for caller ID and phone spoofing prevention

    Sources

    Author Bio

    Mukul Vaishnav

    Mukul Vaishnav
    VP- Account Management at Matellio
    Mukul is Vice President – Account Management, specializing in Oracle Communications (OCCAS), SIP-based application development, enterprise telecom solutions, and AI-driven digital transformation. He is focused on enabling organizations to build scalable, carrier-grade communication platforms and accelerate business transformation through innovative, enterprise-ready technology solutions.

    Related Topics

    Recent Blogs

    Voice analytics for call centers turning every recorded call into insight for banks and credit unions
    Every call a bank or credit union answers contains information nobody is using: how the member or customer actually felt, whether the agent followed the required disclosure script, whether the call pattern looks like the start of a fraud attempt. Voice analytics for call centers is the discipline of extracting that information automatically, at the scale a manual review team never could. A voice analytics call center deployment does not just record calls - it turns every one of them into a data point a QA lead, compliance officer, or fraud analyst can act on.
    Voice biometrics solution for credit unions buyer guide: what to look for before you buy
    Choosing a voice biometrics solution for credit unions is not the same buying decision a large national bank makes. Credit unions run leaner teams, often share infrastructure through a core processor or CUSO, and answer to the same federal examiners on a smaller budget. A vendor pitch built for a $50 billion bank’s contact center does not automatically fit a $2 billion credit union’s member-service floor - and the gaps only show up after the contract is signed.
    Passive biometrics solution stopping AI voice cloning fraud where security questions fail, for bank call centers
    A fraudster needs about three seconds of a customer’s voice — pulled from a voicemail greeting, a social video, or a prior call — to produce a clone that matches the original with roughly 85% accuracy (McAfee Labs). That clone can then read back the very answers a bank’s security questions are built to protect: mother’s maiden name, last transaction amount, date of birth. A passive biometrics solution closes that gap by authenticating the caller from the natural, physical characteristics of their voice while they speak - not from a memorized answer a clone can simply recite.
    Listen to the Blog
    0:00 0:00
    Build the impossible, together

    Schedule a discovery call to accelerate your roadmap.

    Most digital transformations fail. Yours doesn’t have to. Let’s create a success story worth sharing.





      Consent Preferences