Back to News

Ofcom Investigates Vonage and Voxbone Over Misused Phone Numbers - What UK Businesses Should Check

Ofcom Investigates Vonage and Voxbone Over Misused Phone Numbers - What UK Businesses Should Check

Ofcom opened two separate formal investigations on 24 September 2026 into cloud and VoIP phone providers Vonage Business Limited and Voxbone SA, over concerns that phone numbers allocated to them may have been misused to facilitate scam calls and texts. The regulator says it has gathered information raising those concerns, and will examine whether each company complied with General Condition B1 — the rule covering the effective and efficient use of numbers and, crucially, a provider’s oversight of that use.

Two things need saying immediately, because the space between them is where the useful reading of this story sits. The first is that nothing has been found. An Ofcom investigation is an inquiry, not a verdict; no breach has been established against either company, and the regulator itself expects no outcome until “late spring 2027 or maybe even later”. Anyone treating today’s announcement as a finding of wrongdoing is reading it wrong. The second is that the standard Ofcom has articulated — what it expects any numbering provider to do — is public, specific, and immediately useful as a checklist for UK businesses choosing or reviewing a VoIP supplier. You do not need to wait eighteen months for a conclusion to act on it. Both companies are widely used by UK resellers and businesses to obtain virtual and cloud telephone numbers for call centres, VoIP systems and SIP trunking, so a substantial number of UK organisations are downstream of this regardless of how it resolves.

2
Separate formal investigations opened on 24 September 2026 — one into Vonage Business Limited, one into Voxbone SA
B1
The General Condition under examination, covering effective and efficient use of allocated numbers and a provider’s oversight of how they are used
2024
Year Ofcom launched the enforcement programme these investigations fall under, targeting “fake phone numbers” and “spoofed calls”
8+ months
Minimum wait before any outcome. Ofcom expects a conclusion no earlier than late spring 2027, and says it may be later still

What Ofcom has actually announced

The investigations sit within an enforcement programme Ofcom launched in 2024 to check that UK telephone and text companies are using their allocated phone numbers efficiently and effectively, and are preventing “fake phone numbers” and “spoofed calls”. That programme is the ongoing supervisory activity; the two investigations announced this week are the point at which it has produced enough concern about specific companies to open formal cases.

The rule at issue, General Condition B1, is easy to misread as a technical provision about number allocation efficiency. The operative part for this story is the oversight limb. Ofcom’s position is that handing a business customer a block of numbers is not the end of a provider’s responsibility for what happens with them. Specifically, the regulator expects providers to carry out “know your customer” due diligence on business customers before handing over numbers, to keep monitoring the risk a customer poses after that, and to respond proactively when misuse is reported. Three duties, only one of which happens at signup.

Ofcom has also drawn a distinction that matters for anyone trying to work out whether their own provider is in scope of this kind of concern. The misuse in question is the use of allocated numbers to facilitate scam calls and texts — fraud. That is a different category from a customer generating a large volume of nuisance marketing, or silent and abandoned calls. Those are their own regulatory problems with their own rules, but they are not what this enforcement programme is aimed at. The target is numbering being used as infrastructure for fraud.

On timing and consequences, the regulator has been unusually frank. Investigations of this kind take a long time, and Ofcom does not expect an outcome before late spring 2027, possibly later. If a breach were found, the range of consequences runs from a requirement to change processes through to a financial penalty, depending on what the investigation establishes. Ofcom has additionally said that if it finds reasonable grounds to suspect other companies have broken the same rules, it may launch further investigations, which would appear on its enforcement bulletin page. That last sentence is the one a cautious business should note: the regulator is signalling that this is a sector–wide programme rather than two isolated cases.

The risk to your business is number reputation and number continuity — not guilt by association

If your VoIP numbers sit on a platform with weak customer vetting, the practical damage arrives long before any regulator reaches a conclusion, and it arrives through two channels. The first is reputation: call–blocking systems, mobile networks and handset apps increasingly score inbound calls by the behaviour of the numbering ranges and originating networks they come from. Share a platform with fraud traffic and your entirely legitimate sales and service calls start being flagged as suspected spam, sent to voicemail or simply not answered — and you will see it as a mysterious decline in answer rates rather than as an identifiable incident. The second is continuity: a business telephone number is an identity, printed on vehicles, contracts, invoices and years of directory listings. Any enforcement outcome requiring a provider to change how it allocates or reclaims numbers is an event upstream of your published main line. Neither risk depends on your provider being found to have done anything wrong.

How this got to a formal investigation

The chronology is short, because most of it is still ahead. It is worth laying out anyway, mainly so that the length of the road between an opened investigation and any consequence is clear.

2024 — Ofcom launches the enforcement programme
The regulator opens a programme to check that UK telephone and text companies are using allocated phone numbers efficiently and effectively, and are preventing “fake phone numbers” and “spoofed calls”. This is supervisory activity across the sector rather than action against any named company, and it is the framework inside which everything that follows sits.
2024 onwards — the expectations are made explicit
Ofcom sets out what it expects of providers holding number allocations: “know your customer” due diligence on business customers before handing over numbers, continued monitoring of the risk a customer poses, and a proactive response when misuse is reported. These are the criteria any provider — and any business assessing one — can be measured against today.
Before September 2026 — information is gathered
Ofcom says it has gathered information raising concerns about the use of numbers allocated to both companies. This is the phase that converts programme–level supervision into company–specific concern, and the regulator has not detailed publicly what that information consists of.
24 September 2026 — two investigations opened
Ofcom announces separate formal investigations into Vonage Business Limited and Voxbone SA, examining whether each complied with General Condition B1 on the effective and efficient use of numbers and oversight of that use. Opening an investigation establishes nothing; it is the mechanism by which the regulator asks the question formally.
25 September 2026 — where matters stand
No breach has been found and no adverse conclusion has been reached against either company. Both remain in normal commercial operation, and UK businesses using their numbers are not facing any immediate regulatory consequence. What has changed is that a published standard now has two named test cases attached to it.
Late 2026 into 2027 — the investigations run
Ofcom gathers evidence and the companies respond. Investigations of this kind are document–heavy and slow, and the regulator has said as much. Nothing about this period is likely to be visible to a downstream business customer, which is precisely why waiting for it is a poor strategy.
Late spring 2027 or later — a possible outcome
Ofcom expects no conclusion before late spring 2027, and says it may be later still. Depending on findings, consequences could range from a requirement to change processes through to a financial penalty — or, equally possibly, a conclusion that no breach occurred. The realistic planning assumption for a business is that this question will be open for the whole of the coming year.
Beyond — the programme continues
Ofcom has stated that if it finds reasonable grounds to suspect other companies have broken the same rules, it may launch further investigations, published on its enforcement bulletin page. The signal is that this is a sector–wide supervisory push rather than two isolated cases, and that the standard applies to every provider holding UK number allocations.

The asymmetry in that timeline is the practical point. The regulatory process will take the better part of a year or more; the checks a business can run on its own provider take an afternoon. There is no version of this story in which waiting for Ofcom’s conclusion is the efficient response, because the questions worth asking are answerable now and the answers are useful whatever the investigations find.

What good looks like in a numbering provider

Ofcom’s three expectations — due diligence before allocation, ongoing monitoring, proactive response to reported misuse — make a serviceable maturity scale. The chart below is an indicative planning model, not measured data, ranking how much anti–abuse rigour different provisioning approaches represent.

Instant self–serve signup, card payment, numbers in minutes
11%
Email verification only before numbers are released
23%
Company registration number checked at signup
41%
Documented KYC — company, director and address verified
62%
KYC plus continuing monitoring of customer traffic and risk
78%
Plus a proactive, published response route when misuse is reported
89%
Plus contractual use restrictions that are actually enforced
94%

The bottom two rows describe a genuine commercial tension rather than laziness. Frictionless signup is a competitive advantage in this market — a business wanting a London number for a new campaign would rather have it in ten minutes than in three days — and every verification step loses some proportion of legitimate customers at the point of sale. A provider optimising purely for conversion will land at the bottom of that chart by following ordinary commercial logic. What Ofcom’s enforcement programme does is put a regulatory cost on the other side of that trade, so that the friction a provider removes for legitimate customers is not removed for free.

The jump worth noting is between the fourth and fifth rows, because it is the difference between a check and a control. Verifying a company at signup establishes who someone said they were on the day they bought the numbers. It does nothing about a customer whose behaviour changes six months later, or about numbers resold onward through a reseller chain. Continuing monitoring is what catches that, and it is also considerably more expensive to operate than a one–off check — which is precisely why it is the point at which providers diverge.

Most of the duty is continuous, not a signup checkbox

Count Ofcom’s three stated expectations and sort them by when they happen. Due diligence before handing over numbers occurs once, at onboarding. Monitoring the risk a customer poses, and responding proactively when misuse is reported, are both continuing obligations with no end date.

2 of 3
Of the three duties Ofcom says it expects of providers holding number allocations, two are continuing obligations — ongoing risk monitoring and proactive response to reported misuse — rather than one–off checks performed at signup

That ratio is the analytical heart of the story, and it is why “we verify our customers” is not by itself a sufficient answer from a provider. Fraud operations are not usually stopped by identity checks, because identity checks are a solved problem for anyone running a fraud operation at scale: companies can be incorporated cheaply, directors can be nominal, addresses can be rented, and documents can be obtained. A determined bad actor passes onboarding. What they cannot easily disguise is what their traffic subsequently looks like — call volumes, durations, answer rates, destination patterns, complaint signals — which is exactly the information that only continuous monitoring surfaces.

This also explains why the oversight limb of General Condition B1 is the interesting part of the rule. A condition requiring only pre–allocation checks would be satisfiable with a form. A condition covering oversight of how numbers are used sets an ongoing standard, which is much harder to meet and much more meaningful when met. Whatever these two investigations conclude, the standard itself is a reasonable one for a business to apply when choosing a supplier: not “did you check me?” but “what would you notice, and how quickly, if one of your customers started running a fraud operation on your platform?”

The reseller dimension deserves a specific mention, because it is where the chain typically becomes opaque. Both companies named are used by UK resellers as well as by businesses directly. When numbers pass through one or more intermediaries, the distance between the allocation holder and the end user grows, and so does the difficulty of knowing who is actually originating traffic. If you buy your numbers from a reseller — and many UK SMEs do, often without realising it — then the due diligence that matters to you is being performed, or not performed, at least one step further away than the company whose invoice you receive.

What a UK business should actually check

The rows below turn Ofcom’s standard into questions a business can put to its own provider, with badges indicating how much attention each typically needs in a UK SME.

Reviewing your VoIP and numbering supplier
You do not know who ultimately holds the allocation for your numbers High
No idea what due diligence your provider performs on the customers it shares a platform with High
Answer rates on outbound calls never measured, so reputation damage would be invisible High
No tested porting position — you do not know how quickly you could move numbers elsewhere High
Numbers bought through a reseller with no visibility of the underlying carrier Mid
No route to report to your provider that your own number is being spoofed Mid
SIP trunk credentials weak or shared, so your own account could originate traffic you did not place Mid
Contract never reviewed for what happens to your numbers if the provider faces enforcement Low

The third row is the one businesses almost never have and would benefit from most. If nobody tracks the proportion of outbound calls that get answered, then a gradual decline caused by your numbers being flagged as suspected spam is simply invisible — it shows up as sales underperformance, or a sense that customers have gone quiet, rather than as a telephony problem anyone investigates. A baseline answer rate, recorded monthly, costs nothing and converts an untraceable commercial drift into a diagnosable one.

The seventh row is a security point rather than a supplier one, and it is worth separating clearly. Ofcom’s concern in these investigations is with providers’ oversight of their customers. But a compromised SIP trunk on your own account produces a superficially similar outcome — fraudulent traffic originating from your numbers — with the difference that you are the one liable for the call charges, and they accumulate fast. Weak or shared SIP credentials, unrestricted international dialling and no spend alerting are a standing exposure in a great many SME phone systems, and they sit squarely inside the kind of access control and secure configuration discipline that Cyber Essentials is designed to enforce.

What acting on this costs

The bands below are indicative planning figures for UK businesses reviewing their telephony supply chain and hardening their own position — not quotes.

Business profile Typical scope Indicative cost What you get for it
Micro business, one main number Establish who holds the allocation, confirm porting position in writing, check SIP credentials and international dialling limits £0 – £600 A written answer to “whose platform are we actually on, and how fast could we leave?” — mostly obtainable by asking
Small business with a call–handling operation Supplier due diligence questions put formally, answer–rate baseline established, spoofing report route identified, trunk security reviewed £600 – £2,500 Early warning of number reputation damage, and a supplier who knows you are asking the questions Ofcom is asking
SME running outbound sales or a contact centre Number estate inventory, carrier–level visibility through any reseller, call analytics with answer–rate monitoring, tested porting plan, fraud spend alerting £2,500 – £12,000 Outbound performance you can actually diagnose, and a documented exit that does not start from scratch when you need it
Business considering a provider change Requirements review with anti–abuse posture as an explicit selection criterion, migration design, number porting, parallel running, staff transition £3,000 – £25,000 A move made on your timetable and for your reasons, rather than in response to an enforcement outcome next year
Any business, ongoing Monthly answer–rate tracking, annual supplier review, spend alerting on the trunk, a named owner for the telephony relationship £0 – £2,000 a year The cheapest early–warning system available for a problem that otherwise presents as unexplained commercial underperformance

Two things stand out about those numbers. The first is that the top row is close to free, because most of it consists of asking your provider questions they should be able to answer immediately. The second is that nothing in this table is urgent in the way a security patch is urgent — there is no deadline here, and a business that does none of it faces no immediate consequence. That is exactly why it tends not to happen, and why the businesses that do it will mostly be the ones that had a reason to look.

Two ways to hold a telephony supplier relationship

Reactive posture

What most UK SMEs have today

  • Provider chosen on price per seat and features, with anti–abuse posture never raised as a question
  • No knowledge of who ultimately holds the allocation for the numbers the business trades under
  • Outbound answer rates unmeasured, so reputation damage presents as unexplained sales underperformance
  • Porting treated as a theoretical option, never tested, with no idea of the lead time
  • SIP credentials set once at install, shared between systems, with no cap on international dialling
  • No route known for reporting that the business’s own number is being spoofed by someone else
  • Contract unread on what happens to numbers if the provider faces enforcement or fails

Proactive posture

Where Cloudswitched VoIP services take you

  • Supplier assessed on the same three criteria Ofcom applies — due diligence, ongoing monitoring, proactive response to misuse
  • The full chain documented: which carrier holds the allocation, which reseller sits in between, who to escalate to
  • A monthly answer–rate baseline, so number reputation damage is diagnosable rather than invisible
  • Porting position confirmed in writing and lead times known before they are needed
  • Trunk credentials managed properly, international dialling restricted to what the business actually uses, spend alerting on by default
  • A known, tested route for reporting spoofing of your own numbers to the provider
  • Contract terms understood for number continuity under enforcement, insolvency or acquisition

Almost everything in the right–hand column is information rather than expenditure. Knowing who holds your allocation, confirming your porting position, restricting international dialling and recording an answer–rate baseline are tasks measured in emails and afternoons. The reason the left–hand column is so common is not cost but ownership: business telephony is a service that works until it doesn’t, sits with whoever set it up years ago, and has no natural review point. A regulator opening two investigations into number misuse is as good a prompt as any to give it one.

36
Indicative telephony supply–chain readiness, out of 100, for a typical UK SME that cannot say who holds its number allocation, has never measured outbound answer rates, and has not tested its porting position
Four questions to put to your provider — in writing, this week

These map directly onto the standard Ofcom has articulated, and a competent provider will answer all four without difficulty. One: who holds the range allocation for our numbers — you, or an upstream carrier, and which one? Two: what “know your customer” checks do you perform on business customers before releasing numbers, and what continuing monitoring do you apply to customer traffic afterwards? Three: if we report that our numbers are being spoofed, or that fraud traffic appears to originate from your platform, what is the process and what is your response time? Four: if we chose to port our numbers away, what is the process and the realistic lead time? Keep the replies. The answers are useful in themselves, and the manner of answering is informative too — a provider that treats question two as intrusive has told you something that the answer itself would not have. None of this is adversarial; these are the questions the regulator is asking the sector, and a supplier with a good story is generally pleased to tell it.

What this means for the wider UK telephony picture

This investigation lands in a year when a great deal of UK business telephony is in motion anyway. The retirement of the old analogue network is pushing organisations onto IP telephony on a fixed deadline, which means a large number of businesses are choosing a VoIP provider right now, frequently for the first time, and frequently under time pressure. The selection criteria in that situation tend to be price, features and how quickly the supplier can install. Anti–abuse posture is not on the list, and this week’s announcement is a reasonable argument for adding it — particularly since a migration is the one moment when changing supplier costs nothing extra.

There is a security reading too. Scam calls and texts are the delivery mechanism for a substantial proportion of fraud against UK businesses and individuals, and number spoofing is what makes them credible. An invoice fraud attempt is far more effective when the caller display shows a plausible UK landline; a payment–diversion approach works better when the text appears to come from a recognisable sender. Enforcement aimed at the numbering layer is therefore attacking the supply chain of social engineering rather than its symptoms, which is a more durable approach than asking staff to be more suspicious. It is also slower, which is why staff awareness and payment verification processes remain the controls that actually protect a business this quarter.

For organisations pursuing Cyber Essentials, the relevant hook is the part of this that is genuinely within your own boundary. Your telephony platform is an account–based service reachable from the internet; your SIP trunk has credentials; your phone system has an administrative interface; and international dialling is a spend exposure that fraud operators actively target through compromised PBXs. Those are access control and secure configuration questions of exactly the kind the scheme exists to force an organisation to answer. The question of whether your provider vets its other customers is outside your control. The question of whether your own account could originate traffic you did not place is not.

Finally, a note on proportion. Two investigations into named companies, with no findings and an outcome eighteen months away at the earliest, is not a reason for any business to change supplier in a hurry. It is a reason to know the answers to four questions you should be able to answer anyway. The businesses that come out of the next year well will be those that treated this as a prompt to understand their own telephony supply chain — not those that reacted to a headline about companies that have, to date, been found to have done nothing wrong.

The story at a glance

Item Detail
What happened Ofcom opened two separate formal investigations on 24 September 2026
Who is being investigated Vonage Business Limited and Voxbone SA — separately, in two distinct cases
The concern That phone numbers allocated to them may have been misused to facilitate scam calls and texts
The rule at issue General Condition B1 — effective and efficient use of numbers, and oversight of that use
The wider programme An Ofcom enforcement programme launched in 2024 targeting “fake phone numbers” and “spoofed calls”
What Ofcom expects of providers “Know your customer” due diligence before handing over numbers, continuing monitoring of customer risk, and proactive response when misuse is reported
What counts as misuse here Using allocated numbers to facilitate scam calls and texts — distinguished from nuisance marketing or silent and abandoned calls
Has anything been found No. These are investigations, not findings; no breach has been established against either company
Expected timescale Ofcom expects no outcome before late spring 2027, and says it may be later still
Possible consequences Depending on findings, a requirement to change processes or a financial penalty — or a conclusion that no breach occurred
Could others follow Ofcom has said it may launch further investigations if it finds reasonable grounds to suspect other companies, published on its enforcement bulletin page
Why UK businesses are affected Both companies are used by UK resellers and businesses for virtual and cloud numbers, call centres, VoIP systems and SIP trunking
The practical business risk Number reputation — legitimate calls flagged as suspected spam — and number continuity if allocation processes change upstream
Your own exposure to check SIP trunk credentials, international dialling limits and spend alerting — a compromised trunk produces fraud traffic you are billed for
Free first step Ask your provider, in writing, who holds your number allocation, what KYC and monitoring they perform, how to report spoofing, and what porting would involve

This story connects to several we have covered recently, and together they describe a single year in UK business telephony and supplier risk. Vodafone’s copper switch–off and the wider PSTN retirement are the reason so many UK businesses are choosing a VoIP provider right now — which makes this the moment when adding anti–abuse posture to the selection criteria costs nothing. Cambium Networks entering administration is the same supplier–risk question in hardware: what happens to you when the company behind your infrastructure has a bad year. The Citizens Advice research on chatbots blocking customers is worth reading alongside the escalation question here — knowing how to reach a human at your provider matters most on the day something is wrong with your numbers. And the reporting on UK police data held on Microsoft Azure makes the general point that a supplier risk accepted once and never revisited is the one that eventually surfaces as news.

Do you know whose platform your phone numbers actually sit on?

Cloudswitched provides hosted telephony, Teams Voice and SIP services to UK businesses — including the parts of the supply chain most organisations have never mapped: which carrier holds your allocation, what your porting position really is, how your trunk is secured against fraud, and whether anyone would notice if your outbound answer rates started falling. If you are choosing a VoIP provider as part of the copper switch–off, this is the right moment to ask the questions Ofcom is asking.

Talk to us about VoIP & Phone Systems

Frequently asked questions

Have Vonage or Voxbone been found guilty of anything?
No. Ofcom has opened formal investigations, which is the mechanism by which a regulator asks a question properly — it establishes nothing in itself. Ofcom says it has gathered information raising concerns about the use of numbers allocated to both companies, and will examine whether each complied with General Condition B1. No breach has been found, no adverse conclusion has been reached, and the regulator expects no outcome before late spring 2027 at the earliest. It is entirely possible that one or both investigations conclude with no breach established. Any coverage treating this as a finding of wrongdoing is misreading what has been announced.
We use one of these providers. Should we switch immediately?
Not on the basis of this announcement. Switching telephony provider is disruptive, involves number porting with its own lead times and risks, and there is currently nothing established against either company to justify doing it in a hurry. What is worth doing immediately is the free part: establish who holds your number allocation, ask your provider in writing what due diligence and ongoing monitoring they perform, confirm your porting position and lead times, and start measuring outbound answer rates so you would notice reputation damage if it occurred. If you were already planning a review or a migration, add anti–abuse posture to your selection criteria. That is a proportionate response to an investigation with no findings.
What is General Condition B1 in plain terms?
It is the regulatory condition covering the effective and efficient use of allocated telephone numbers and, importantly for this story, a provider’s oversight of how those numbers are used. The second limb is what makes it relevant to scam calls. A condition about efficiency alone would be a technical matter of not hoarding number ranges. A condition that also covers oversight sets an ongoing expectation that a provider knows, and takes responsibility for, what its customers do with the numbers it hands them. In practice Ofcom has spelled out what that means: know your customer checks before allocation, continuing monitoring of the risk a customer poses, and a proactive response when misuse is reported.
How would number misuse actually hurt our business?
Through two channels, neither of which requires your provider to be found at fault. The first is reputation: call–blocking systems, mobile networks and handset apps increasingly score inbound calls by the behaviour of the originating network and numbering ranges. If fraud traffic shares your platform, your legitimate sales and service calls can start being flagged as suspected spam, diverted to voicemail or simply not answered — and because almost nobody measures answer rates, that presents as unexplained commercial underperformance rather than as a telephony fault. The second is continuity: your main number is an identity printed on vehicles, contracts and invoices, and any enforcement outcome affecting how a provider allocates numbers is an event upstream of it.
What questions should we put to our provider?
Four, in writing, and keep the replies. Who holds the range allocation for our numbers — you or an upstream carrier, and which one? What know your customer checks do you run on business customers before releasing numbers, and what continuing monitoring applies to customer traffic afterwards? If we report that our numbers are being spoofed, or that fraud appears to originate from your platform, what is the process and the response time? And if we chose to port our numbers away, what is the process and the realistic lead time? A competent provider answers all four readily. The manner of the answer is informative too — a supplier treating the second question as intrusive has told you something the answer alone would not have.
Why does ongoing monitoring matter more than signup checks?
Because identity verification is a solved problem for anyone running a fraud operation at scale. Companies can be incorporated cheaply, directors can be nominal, addresses can be rented and documents can be obtained, so a determined bad actor passes onboarding. What is much harder to disguise is what the traffic subsequently looks like — call volumes, durations, answer rates, destination patterns and complaint signals all diverge sharply from legitimate business use. That information only exists after the numbers are in use, which is why two of Ofcom’s three stated expectations are continuing obligations rather than one–off checks, and why “we verify our customers” is not on its own a sufficient answer from a provider.
We buy our numbers through a reseller. Does that change anything?
It adds a layer you should map. Both companies named are used by UK resellers as well as by businesses directly, and when numbers pass through one or more intermediaries the distance between the allocation holder and the end user grows — as does the difficulty of knowing who is originating traffic on the underlying platform. Many UK SMEs buy through a reseller without realising it, because the invoice carries the reseller’s name. The practical step is simply to ask who the underlying carrier is and who holds the allocation. That is not a hostile question and any reputable reseller will answer it; you need to know because it determines who your escalation route actually runs to when something goes wrong.
How do we tell if our own numbers are being spoofed?
Usually you find out from the people receiving the calls. The signal is inbound contact from members of the public or other businesses asking why you rang them, complaining about a call you did not make, or reporting a scam approach that displayed your number. Take those reports seriously rather than dismissing them as confusion; a cluster of them is the clearest indicator available. Number spoofing does not involve any compromise of your systems — the caller display is simply being falsified elsewhere — so there is nothing to find in your own logs. What you can do is report it to your provider promptly, which is why knowing that reporting route in advance is worth the five minutes it takes to establish.
Could fraud traffic come from our own phone system?
Yes, and this is the part of the problem genuinely inside your control. A compromised SIP trunk or phone system produces fraudulent outbound traffic from your numbers, with the significant difference that you are billed for the calls — and toll fraud accumulates very quickly, typically overnight or across a weekend when nobody is watching. The usual causes are unremarkable: weak or shared SIP credentials, an administrative interface exposed to the internet, default passwords never changed, and no restriction on international dialling. The defences are equally unremarkable — strong unique credentials, dialling restricted to the destinations you actually call, and spend alerting so an unusual pattern raises an alarm within hours rather than at the month–end invoice.
Does this affect our Cyber Essentials position?
The provider investigation does not — what another company does with its customer vetting sits outside your boundary and outside your scope. What does fall in scope is your own telephony: it is an account–based service reachable over the internet, your SIP trunk has credentials, your phone system has an administrative interface, and both are subject to the access control and secure configuration requirements the scheme sets. Phone systems are a classic scoping blind spot because they are often bought and managed by someone outside the IT function and never entered into an asset inventory. If your PBX, handsets or trunk are not currently on that inventory, this is a reasonable prompt to add them.

Ask the questions now; the answers take a year

Ofcom’s investigations will not conclude until late spring 2027 at the earliest, and nothing has been found against anyone. But the standard the regulator has set out — due diligence before numbers are released, continuing monitoring of how they are used, and a proactive response when misuse is reported — is a perfectly good test to apply to your own supplier today. Cloudswitched helps UK businesses map their telephony supply chain, secure their SIP trunks against toll fraud, establish a porting position before they need one, and choose providers on more than price per seat.

Talk to us about VoIP & Phone Systems
Tags:VoIPCyber EssentialsIT SupportVirtual CIO
CloudSwitched

London-based managed IT services provider offering support, cloud solutions and cybersecurity for SMEs.

CloudSwitched Service

VoIP & Phone Systems

Hosted telephony, Teams Voice and modern business communication solutions

Learn More

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

25
  • Web Development

Headless CMS vs Traditional CMS: A UK Business Guide to Choosing the Right Website Architecture in 2026

25 Sep, 2026

A headless CMS separates where content is stored and managed from where it is displayed. That is the whole idea, and it is a genuinely good idea for...

Read more
24
  • Virtual CIO

Virtual CIO vs IT Consultant: A UK Business Guide to Understanding the Difference Before You Hire in 2026

24 Sep, 2026

The difference between a virtual CIO and an IT consultant is not a difference of skill, seniority or subject knowledge. The same individual can credibly do...

Read more
23
  • Network Admin

Network Documentation: A UK Business Guide to Building a Network Map That Actually Gets Used in 2026

23 Sep, 2026

Network documentation is the thing every UK business agrees it should have and almost none of them actually has in a usable state. There is usually something:...

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.