Ofcom opened two separate formal investigations on 24 September 2026 into cloud and VoIP phone providers Vonage Business Limited and Voxbone SA, over concerns that phone numbers allocated to them may have been misused to facilitate scam calls and texts. The regulator says it has gathered information raising those concerns, and will examine whether each company complied with General Condition B1 — the rule covering the effective and efficient use of numbers and, crucially, a provider’s oversight of that use.
Two things need saying immediately, because the space between them is where the useful reading of this story sits. The first is that nothing has been found. An Ofcom investigation is an inquiry, not a verdict; no breach has been established against either company, and the regulator itself expects no outcome until “late spring 2027 or maybe even later”. Anyone treating today’s announcement as a finding of wrongdoing is reading it wrong. The second is that the standard Ofcom has articulated — what it expects any numbering provider to do — is public, specific, and immediately useful as a checklist for UK businesses choosing or reviewing a VoIP supplier. You do not need to wait eighteen months for a conclusion to act on it. Both companies are widely used by UK resellers and businesses to obtain virtual and cloud telephone numbers for call centres, VoIP systems and SIP trunking, so a substantial number of UK organisations are downstream of this regardless of how it resolves.
What Ofcom has actually announced
The investigations sit within an enforcement programme Ofcom launched in 2024 to check that UK telephone and text companies are using their allocated phone numbers efficiently and effectively, and are preventing “fake phone numbers” and “spoofed calls”. That programme is the ongoing supervisory activity; the two investigations announced this week are the point at which it has produced enough concern about specific companies to open formal cases.
The rule at issue, General Condition B1, is easy to misread as a technical provision about number allocation efficiency. The operative part for this story is the oversight limb. Ofcom’s position is that handing a business customer a block of numbers is not the end of a provider’s responsibility for what happens with them. Specifically, the regulator expects providers to carry out “know your customer” due diligence on business customers before handing over numbers, to keep monitoring the risk a customer poses after that, and to respond proactively when misuse is reported. Three duties, only one of which happens at signup.
Ofcom has also drawn a distinction that matters for anyone trying to work out whether their own provider is in scope of this kind of concern. The misuse in question is the use of allocated numbers to facilitate scam calls and texts — fraud. That is a different category from a customer generating a large volume of nuisance marketing, or silent and abandoned calls. Those are their own regulatory problems with their own rules, but they are not what this enforcement programme is aimed at. The target is numbering being used as infrastructure for fraud.
On timing and consequences, the regulator has been unusually frank. Investigations of this kind take a long time, and Ofcom does not expect an outcome before late spring 2027, possibly later. If a breach were found, the range of consequences runs from a requirement to change processes through to a financial penalty, depending on what the investigation establishes. Ofcom has additionally said that if it finds reasonable grounds to suspect other companies have broken the same rules, it may launch further investigations, which would appear on its enforcement bulletin page. That last sentence is the one a cautious business should note: the regulator is signalling that this is a sector–wide programme rather than two isolated cases.
If your VoIP numbers sit on a platform with weak customer vetting, the practical damage arrives long before any regulator reaches a conclusion, and it arrives through two channels. The first is reputation: call–blocking systems, mobile networks and handset apps increasingly score inbound calls by the behaviour of the numbering ranges and originating networks they come from. Share a platform with fraud traffic and your entirely legitimate sales and service calls start being flagged as suspected spam, sent to voicemail or simply not answered — and you will see it as a mysterious decline in answer rates rather than as an identifiable incident. The second is continuity: a business telephone number is an identity, printed on vehicles, contracts, invoices and years of directory listings. Any enforcement outcome requiring a provider to change how it allocates or reclaims numbers is an event upstream of your published main line. Neither risk depends on your provider being found to have done anything wrong.
How this got to a formal investigation
The chronology is short, because most of it is still ahead. It is worth laying out anyway, mainly so that the length of the road between an opened investigation and any consequence is clear.
The asymmetry in that timeline is the practical point. The regulatory process will take the better part of a year or more; the checks a business can run on its own provider take an afternoon. There is no version of this story in which waiting for Ofcom’s conclusion is the efficient response, because the questions worth asking are answerable now and the answers are useful whatever the investigations find.
What good looks like in a numbering provider
Ofcom’s three expectations — due diligence before allocation, ongoing monitoring, proactive response to reported misuse — make a serviceable maturity scale. The chart below is an indicative planning model, not measured data, ranking how much anti–abuse rigour different provisioning approaches represent.
The bottom two rows describe a genuine commercial tension rather than laziness. Frictionless signup is a competitive advantage in this market — a business wanting a London number for a new campaign would rather have it in ten minutes than in three days — and every verification step loses some proportion of legitimate customers at the point of sale. A provider optimising purely for conversion will land at the bottom of that chart by following ordinary commercial logic. What Ofcom’s enforcement programme does is put a regulatory cost on the other side of that trade, so that the friction a provider removes for legitimate customers is not removed for free.
The jump worth noting is between the fourth and fifth rows, because it is the difference between a check and a control. Verifying a company at signup establishes who someone said they were on the day they bought the numbers. It does nothing about a customer whose behaviour changes six months later, or about numbers resold onward through a reseller chain. Continuing monitoring is what catches that, and it is also considerably more expensive to operate than a one–off check — which is precisely why it is the point at which providers diverge.
Most of the duty is continuous, not a signup checkbox
Count Ofcom’s three stated expectations and sort them by when they happen. Due diligence before handing over numbers occurs once, at onboarding. Monitoring the risk a customer poses, and responding proactively when misuse is reported, are both continuing obligations with no end date.
That ratio is the analytical heart of the story, and it is why “we verify our customers” is not by itself a sufficient answer from a provider. Fraud operations are not usually stopped by identity checks, because identity checks are a solved problem for anyone running a fraud operation at scale: companies can be incorporated cheaply, directors can be nominal, addresses can be rented, and documents can be obtained. A determined bad actor passes onboarding. What they cannot easily disguise is what their traffic subsequently looks like — call volumes, durations, answer rates, destination patterns, complaint signals — which is exactly the information that only continuous monitoring surfaces.
This also explains why the oversight limb of General Condition B1 is the interesting part of the rule. A condition requiring only pre–allocation checks would be satisfiable with a form. A condition covering oversight of how numbers are used sets an ongoing standard, which is much harder to meet and much more meaningful when met. Whatever these two investigations conclude, the standard itself is a reasonable one for a business to apply when choosing a supplier: not “did you check me?” but “what would you notice, and how quickly, if one of your customers started running a fraud operation on your platform?”
The reseller dimension deserves a specific mention, because it is where the chain typically becomes opaque. Both companies named are used by UK resellers as well as by businesses directly. When numbers pass through one or more intermediaries, the distance between the allocation holder and the end user grows, and so does the difficulty of knowing who is actually originating traffic. If you buy your numbers from a reseller — and many UK SMEs do, often without realising it — then the due diligence that matters to you is being performed, or not performed, at least one step further away than the company whose invoice you receive.
What a UK business should actually check
The rows below turn Ofcom’s standard into questions a business can put to its own provider, with badges indicating how much attention each typically needs in a UK SME.
The third row is the one businesses almost never have and would benefit from most. If nobody tracks the proportion of outbound calls that get answered, then a gradual decline caused by your numbers being flagged as suspected spam is simply invisible — it shows up as sales underperformance, or a sense that customers have gone quiet, rather than as a telephony problem anyone investigates. A baseline answer rate, recorded monthly, costs nothing and converts an untraceable commercial drift into a diagnosable one.
The seventh row is a security point rather than a supplier one, and it is worth separating clearly. Ofcom’s concern in these investigations is with providers’ oversight of their customers. But a compromised SIP trunk on your own account produces a superficially similar outcome — fraudulent traffic originating from your numbers — with the difference that you are the one liable for the call charges, and they accumulate fast. Weak or shared SIP credentials, unrestricted international dialling and no spend alerting are a standing exposure in a great many SME phone systems, and they sit squarely inside the kind of access control and secure configuration discipline that Cyber Essentials is designed to enforce.
What acting on this costs
The bands below are indicative planning figures for UK businesses reviewing their telephony supply chain and hardening their own position — not quotes.
| Business profile | Typical scope | Indicative cost | What you get for it |
|---|---|---|---|
| Micro business, one main number | Establish who holds the allocation, confirm porting position in writing, check SIP credentials and international dialling limits | £0 – £600 | A written answer to “whose platform are we actually on, and how fast could we leave?” — mostly obtainable by asking |
| Small business with a call–handling operation | Supplier due diligence questions put formally, answer–rate baseline established, spoofing report route identified, trunk security reviewed | £600 – £2,500 | Early warning of number reputation damage, and a supplier who knows you are asking the questions Ofcom is asking |
| SME running outbound sales or a contact centre | Number estate inventory, carrier–level visibility through any reseller, call analytics with answer–rate monitoring, tested porting plan, fraud spend alerting | £2,500 – £12,000 | Outbound performance you can actually diagnose, and a documented exit that does not start from scratch when you need it |
| Business considering a provider change | Requirements review with anti–abuse posture as an explicit selection criterion, migration design, number porting, parallel running, staff transition | £3,000 – £25,000 | A move made on your timetable and for your reasons, rather than in response to an enforcement outcome next year |
| Any business, ongoing | Monthly answer–rate tracking, annual supplier review, spend alerting on the trunk, a named owner for the telephony relationship | £0 – £2,000 a year | The cheapest early–warning system available for a problem that otherwise presents as unexplained commercial underperformance |
Two things stand out about those numbers. The first is that the top row is close to free, because most of it consists of asking your provider questions they should be able to answer immediately. The second is that nothing in this table is urgent in the way a security patch is urgent — there is no deadline here, and a business that does none of it faces no immediate consequence. That is exactly why it tends not to happen, and why the businesses that do it will mostly be the ones that had a reason to look.
Two ways to hold a telephony supplier relationship
Reactive posture
What most UK SMEs have today
- Provider chosen on price per seat and features, with anti–abuse posture never raised as a question
- No knowledge of who ultimately holds the allocation for the numbers the business trades under
- Outbound answer rates unmeasured, so reputation damage presents as unexplained sales underperformance
- Porting treated as a theoretical option, never tested, with no idea of the lead time
- SIP credentials set once at install, shared between systems, with no cap on international dialling
- No route known for reporting that the business’s own number is being spoofed by someone else
- Contract unread on what happens to numbers if the provider faces enforcement or fails
Proactive posture
Where Cloudswitched VoIP services take you
- Supplier assessed on the same three criteria Ofcom applies — due diligence, ongoing monitoring, proactive response to misuse
- The full chain documented: which carrier holds the allocation, which reseller sits in between, who to escalate to
- A monthly answer–rate baseline, so number reputation damage is diagnosable rather than invisible
- Porting position confirmed in writing and lead times known before they are needed
- Trunk credentials managed properly, international dialling restricted to what the business actually uses, spend alerting on by default
- A known, tested route for reporting spoofing of your own numbers to the provider
- Contract terms understood for number continuity under enforcement, insolvency or acquisition
Almost everything in the right–hand column is information rather than expenditure. Knowing who holds your allocation, confirming your porting position, restricting international dialling and recording an answer–rate baseline are tasks measured in emails and afternoons. The reason the left–hand column is so common is not cost but ownership: business telephony is a service that works until it doesn’t, sits with whoever set it up years ago, and has no natural review point. A regulator opening two investigations into number misuse is as good a prompt as any to give it one.
These map directly onto the standard Ofcom has articulated, and a competent provider will answer all four without difficulty. One: who holds the range allocation for our numbers — you, or an upstream carrier, and which one? Two: what “know your customer” checks do you perform on business customers before releasing numbers, and what continuing monitoring do you apply to customer traffic afterwards? Three: if we report that our numbers are being spoofed, or that fraud traffic appears to originate from your platform, what is the process and what is your response time? Four: if we chose to port our numbers away, what is the process and the realistic lead time? Keep the replies. The answers are useful in themselves, and the manner of answering is informative too — a provider that treats question two as intrusive has told you something that the answer itself would not have. None of this is adversarial; these are the questions the regulator is asking the sector, and a supplier with a good story is generally pleased to tell it.
What this means for the wider UK telephony picture
This investigation lands in a year when a great deal of UK business telephony is in motion anyway. The retirement of the old analogue network is pushing organisations onto IP telephony on a fixed deadline, which means a large number of businesses are choosing a VoIP provider right now, frequently for the first time, and frequently under time pressure. The selection criteria in that situation tend to be price, features and how quickly the supplier can install. Anti–abuse posture is not on the list, and this week’s announcement is a reasonable argument for adding it — particularly since a migration is the one moment when changing supplier costs nothing extra.
There is a security reading too. Scam calls and texts are the delivery mechanism for a substantial proportion of fraud against UK businesses and individuals, and number spoofing is what makes them credible. An invoice fraud attempt is far more effective when the caller display shows a plausible UK landline; a payment–diversion approach works better when the text appears to come from a recognisable sender. Enforcement aimed at the numbering layer is therefore attacking the supply chain of social engineering rather than its symptoms, which is a more durable approach than asking staff to be more suspicious. It is also slower, which is why staff awareness and payment verification processes remain the controls that actually protect a business this quarter.
For organisations pursuing Cyber Essentials, the relevant hook is the part of this that is genuinely within your own boundary. Your telephony platform is an account–based service reachable from the internet; your SIP trunk has credentials; your phone system has an administrative interface; and international dialling is a spend exposure that fraud operators actively target through compromised PBXs. Those are access control and secure configuration questions of exactly the kind the scheme exists to force an organisation to answer. The question of whether your provider vets its other customers is outside your control. The question of whether your own account could originate traffic you did not place is not.
Finally, a note on proportion. Two investigations into named companies, with no findings and an outcome eighteen months away at the earliest, is not a reason for any business to change supplier in a hurry. It is a reason to know the answers to four questions you should be able to answer anyway. The businesses that come out of the next year well will be those that treated this as a prompt to understand their own telephony supply chain — not those that reacted to a headline about companies that have, to date, been found to have done nothing wrong.
The story at a glance
| Item | Detail |
|---|---|
| What happened | Ofcom opened two separate formal investigations on 24 September 2026 |
| Who is being investigated | Vonage Business Limited and Voxbone SA — separately, in two distinct cases |
| The concern | That phone numbers allocated to them may have been misused to facilitate scam calls and texts |
| The rule at issue | General Condition B1 — effective and efficient use of numbers, and oversight of that use |
| The wider programme | An Ofcom enforcement programme launched in 2024 targeting “fake phone numbers” and “spoofed calls” |
| What Ofcom expects of providers | “Know your customer” due diligence before handing over numbers, continuing monitoring of customer risk, and proactive response when misuse is reported |
| What counts as misuse here | Using allocated numbers to facilitate scam calls and texts — distinguished from nuisance marketing or silent and abandoned calls |
| Has anything been found | No. These are investigations, not findings; no breach has been established against either company |
| Expected timescale | Ofcom expects no outcome before late spring 2027, and says it may be later still |
| Possible consequences | Depending on findings, a requirement to change processes or a financial penalty — or a conclusion that no breach occurred |
| Could others follow | Ofcom has said it may launch further investigations if it finds reasonable grounds to suspect other companies, published on its enforcement bulletin page |
| Why UK businesses are affected | Both companies are used by UK resellers and businesses for virtual and cloud numbers, call centres, VoIP systems and SIP trunking |
| The practical business risk | Number reputation — legitimate calls flagged as suspected spam — and number continuity if allocation processes change upstream |
| Your own exposure to check | SIP trunk credentials, international dialling limits and spend alerting — a compromised trunk produces fraud traffic you are billed for |
| Free first step | Ask your provider, in writing, who holds your number allocation, what KYC and monitoring they perform, how to report spoofing, and what porting would involve |
This story connects to several we have covered recently, and together they describe a single year in UK business telephony and supplier risk. Vodafone’s copper switch–off and the wider PSTN retirement are the reason so many UK businesses are choosing a VoIP provider right now — which makes this the moment when adding anti–abuse posture to the selection criteria costs nothing. Cambium Networks entering administration is the same supplier–risk question in hardware: what happens to you when the company behind your infrastructure has a bad year. The Citizens Advice research on chatbots blocking customers is worth reading alongside the escalation question here — knowing how to reach a human at your provider matters most on the day something is wrong with your numbers. And the reporting on UK police data held on Microsoft Azure makes the general point that a supplier risk accepted once and never revisited is the one that eventually surfaces as news.
Do you know whose platform your phone numbers actually sit on?
Cloudswitched provides hosted telephony, Teams Voice and SIP services to UK businesses — including the parts of the supply chain most organisations have never mapped: which carrier holds your allocation, what your porting position really is, how your trunk is secured against fraud, and whether anyone would notice if your outbound answer rates started falling. If you are choosing a VoIP provider as part of the copper switch–off, this is the right moment to ask the questions Ofcom is asking.
Talk to us about VoIP & Phone SystemsFrequently asked questions
Ask the questions now; the answers take a year
Ofcom’s investigations will not conclude until late spring 2027 at the earliest, and nothing has been found against anyone. But the standard the regulator has set out — due diligence before numbers are released, continuing monitoring of how they are used, and a proactive response when misuse is reported — is a perfectly good test to apply to your own supplier today. Cloudswitched helps UK businesses map their telephony supply chain, secure their SIP trunks against toll fraud, establish a porting position before they need one, and choose providers on more than price per seat.
Talk to us about VoIP & Phone Systems


