The experience is disorienting: your phone fills with return calls and voicemails from strangers, some confused, some furious, about calls "you" made that you never made. Your number is being spoofed: a robocaller is stamping your number onto their outbound caller ID, and the callback wave is landing on you. The first thing to understand is what did not happen: nobody hacked your phone, your account, or your system. Caller ID is (historically) an unverified field, and criminals type numbers into it, often rotating through thousands of legitimate numbers picked semi-randomly, frequently choosing numbers that share a victim's area code to make calls look local ("neighbor spoofing").
Why you cannot simply block it
The spoofed calls never touch your line, they originate on the scammer's infrastructure and only borrow your number's appearance, so there is nothing on your side to block or secure. This is the frustrating core of the situation: the abuse happens entirely in other people's call streams. What has changed the economics is STIR/SHAKEN: carriers now cryptographically attest whether a caller has the right to the number displayed, so spoofed calls increasingly carry weak attestation and get labeled or filtered downstream. It has reduced, not eliminated, the practice.
The actual playbook
- Ride it out first: spoofers rotate numbers constantly; most episodes fade within days to weeks as the campaign moves on. Painful, but true, and most cases need nothing more.
- Change your voicemail greeting during the wave: a brief "our number is being displayed on spam calls we are not making; we apologize if one reached you" turns furious callbacks into sympathetic ones and protects your reputation at very low cost.
- Report it: file with the FCC (consumercomplaints.fcc.gov) and FTC. Individual reports rarely trigger individual action, but they feed the enforcement data that takes down operations.
- Tell your provider: so they can annotate the number's history, and, for business numbers, check your standing with the carrier analytics registries so the episode does not leave your legitimate calls mislabeled afterward.
- Do not engage the callbacks beyond courtesy: and never "verify" anything for angry strangers; some callback waves attract their own secondary scammers.
If the labeling outlasts the episode
Occasionally the durable damage is reputational: after a spoofing wave, your legitimate outbound calls show "Spam Likely" because analytics engines absorbed the complaint volume. That is fixable: register the number and business name with the major carrier analytics programs, dispute the labeling, and confirm your own calls carry full attestation, the checklist here walks it. Persistent labeling despite clean attestation is worth escalating through your provider, who has registry channels individuals lack.
Could it be something else?
Two lookalikes worth ruling out: if callers report texts rather than calls, the same logic applies to SMS spoofing; and if callers reference actual conversations with "your company," that is impersonation fraud rather than blind spoofing, a different, more targeted problem worth documenting carefully (screenshots, numbers, dates) in case law enforcement or counsel gets involved.
The reassuring summary: spoofing is annoying, temporary, and not evidence of a breach. Greeting, reports, provider note, patience, and check your labeling once the wave passes.
Still have a question?
Real people answer our phones. Ask anything about business phone systems, no pitch attached.
Ask a human