Privacy & Social · September 28, 2026
What to Do When Scammers Spoof Your Business Phone Number
A practical response plan for documenting caller ID spoofing, protecting customers, working with your phone provider, and preserving trust.

First, confirm whether the calls actually came through your phone system or only displayed your number. Save reports from customers, review provider and account logs, secure your phone and voicemail accounts, and contact your voice provider’s fraud team. File accurate reports with the FCC and FTC when appropriate, and publish a short customer warning if the scam is active. Tell customers to verify unexpected calls through a contact method they find independently on your official website.
Caller ID spoofing happens when a caller deliberately changes the name or number shown to the recipient. A scammer can make a call appear to come from your main business line even when your company’s phones were never used. Customers may call back, complain, post negative reviews, or distrust a real call from the company. The display alone does not prove that your phone account was hacked.
Spoofing, account compromise, number porting, and an incorrect spam label are different problems. Provider logs may show no outgoing call when the displayed number was simply copied. Unexpected call records, voicemail changes, forwarding rules, administrator activity, or billing can point to a real account problem. Classify the event before announcing a cause.
In the United States, federal rules prohibit knowingly sending misleading or inaccurate caller ID information with intent to defraud, cause harm, or wrongfully obtain anything of value. Some caller ID changes have lawful uses, so spoofing is not automatically illegal in every situation. Laws and reporting duties vary. This article is general education, not legal advice; serious losses, threats, or disputed access may require qualified legal or security help.
A practical step-by-step approach
01Confirm what customers are seeing
Ask affected callers for the date, time, number displayed, caller name shown, summary of the message, callback instructions, and any voicemail or screenshot. Request only information needed to understand the incident. Do not ask customers to share passwords, payment-card details, one-time codes, or complete identity documents. Keep one incident log so patterns are visible.
02Separate spoofing from account compromise
Compare customer reports with your carrier portal, phone-system logs, call recordings, extensions, forwarding rules, voicemail, and invoices. If the reported calls do not appear in company records, caller ID spoofing may be more likely. If records show unauthorized activity, treat the matter as a possible account compromise and escalate promptly.
03Secure the systems you control
Change exposed administrator and voicemail credentials, remove unknown users and forwarding destinations, end unfamiliar sessions, and review recovery email and phone details. Enable multifactor authentication where the provider supports it and restrict administrative access to people who need it. Preserve suspicious records before making changes that could erase useful evidence.
04Contact your phone provider
Ask the carrier or hosted-phone provider for its fraud, spoofing, and spam-label process. Provide your account authority, affected number, incident timeline, sample reports, and relevant logs. Ask whether the provider can review call authentication, outbound configuration, recent account changes, number-port activity, and any label affecting legitimate calls. A provider may investigate, but no single carrier can guarantee that all spoofed calls will stop.
05Report the incident accurately
The FCC complaint center currently directs people whose own number is being spoofed to choose the unwanted calls or texts issue and the sub-issue for a spoofed number. The FCC explains that an informal complaint may support enforcement and trend analysis but does not promise an individual resolution. Report related fraud to the FTC at ReportFraud.ftc.gov, and consider IC3 when the incident involves cyber-enabled fraud or financial harm.
06Warn customers without spreading panic
When the campaign is active, place one dated notice on your official website and verified profiles. Say that criminals may be displaying the company number, describe what the business will never request by phone, and provide a verified way to reconnect. Advise customers to hang up and use a number or page they find independently. Do not publish unverified identities or repeat sensitive victim details.
07Help affected customers take safe action
A customer who shared money or information should stop contact, preserve messages and payment details, and contact the relevant bank, card issuer, payment app, or other provider promptly. Direct people to official FTC guidance rather than collecting their financial records yourself. If identity information was misused, IdentityTheft.gov can help create a recovery plan. Do not promise reimbursement or recovery.
08Protect normal business calls and monitor trust
Train staff to recognize callbacks from confused customers and give them one approved explanation. Keep public contact details consistent across your website, business listings, invoices, and profiles. Track complaint volume, spam labels, call completion, customer questions, and review mentions. Update or retire the public warning when the evidence shows the campaign has ended.
Information to gather
A clear record makes it easier to choose the right channel, communicate accurately, and avoid unnecessary repetition. Start with:
- Customer-reported date, time, displayed number, caller name, message, and callback instruction
- Carrier, phone-system, voicemail, forwarding, administrator, billing, and number-port records
- Restricted screenshots, recordings, voicemails, and incident timeline
- Carrier fraud ticket, account-security changes, and spam-label review
- FCC, FTC, IC3, payment-provider, or local report confirmations when relevant
- Approved customer notice and independently verified contact method
- Monitoring owner, staff response language, and follow-up date
What not to do
Pressure can lead to decisions that create a second reputation problem. Avoid:
- Assuming a spoofed caller ID proves that the company phone system was hacked
- Calling every reported recipient, collecting excessive personal data, or asking for passwords or codes
- Naming an alleged scammer publicly without reliable evidence and qualified review
- Paying someone who claims they can instantly stop all spoofing or remove every spam label
- Deleting provider logs, voicemails, recordings, or account notices before preserving evidence
- Promising that a carrier, regulator, law-enforcement agency, or reputation firm will stop the calls by a deadline
Frequently asked questions
Does caller ID spoofing mean our phone account was hacked?
Not necessarily. A scammer may transmit your number as caller ID without accessing your account. Compare customer reports with carrier, phone-system, administrator, voicemail, forwarding, and billing records. If company records show unauthorized calls or changes, secure the account and ask the provider to investigate a possible compromise.
Can our phone carrier stop someone from spoofing our number?
A provider can review the account, investigate configuration or porting problems, explain its spoofing process, and help with some call-authentication or labeling issues. But calls cross several networks, and bad actors can change tactics. No carrier or outside firm can guarantee that every spoofed call will stop immediately.
Should we change our business phone number?
Usually not as a first step. Changing a well-known number can disrupt customers, listings, advertising, contracts, and account recovery while a scammer may simply copy the new number. Confirm the problem, secure the account, involve the provider, and assess the business impact before considering a number change.
What should a customer warning say?
Keep it short and factual. Say that unauthorized callers may be displaying the company number, explain what your business will never request by phone, and direct people to a verified contact page or number they locate independently. Include a date and update the notice as facts change. Do not identify a suspected person without reliable evidence.
Can a reputation company guarantee that caller ID spoofing will stop?
No. A responsible provider can organize evidence, coordinate accurate carrier and agency reports, prepare customer communications, correct inconsistent contact information, and monitor reputation effects. Outcomes depend on the callers, phone providers, network controls, regulators, evidence, applicable law, platforms, search engines, and other third parties. No provider can guarantee timing or complete prevention.
Primary resources
Policies and features can change. Review the current source before submitting a request:
- FCC: Caller ID Spoofing
- FCC: unwanted calls, texts, and spoofed-number complaints
- FTC: phone scams and caller ID spoofing
- FTC: Impersonation of Government and Businesses Rule
- FTC: scams and your small business
- FBI IC3: call center and impersonation fraud