Ofcom puts KYC and Sender ID checks on mobile operators to fight messaging scams
Ofcom · source ↗
Ofcom has finalised a package of rules and guidance requiring mobile providers to block, limit, and disrupt messaging scams. The context it cites: fraud accounts for an estimated 45% of all reported crime in England and Wales, £1.28 billion was lost to criminals in 2025, and 40% of UK mobile users received at least one suspicious message in the past three months. Providers already block an estimated 600 million-plus scam messages a year; Ofcom wants consistency across the sector.
The substance is the same authenticated-sender and upstream-accountability logic driving the voice beat, applied to messaging. For person-to-person scams: collect scam-message intelligence, block scammer numbers, block scam messages in transit by detecting malicious weblinks and numbers, and set volume limits on pay-as-you-go SIMs. For business messaging, the interesting part: operators and aggregators must run “Know Your Customer” checks on new business senders and ongoing “Know Your Traffic” checks, and must corroborate Alphanumeric Sender IDs against what they know about the business — so a sender purporting to be a hairdresser can’t blast parcel-delivery texts. Separately, strengthened guidance tells telcos to withhold the caller ID of calls that appear to come from a UK mobile roaming abroad unless they can verify it — the spoofing analogue.
Know Your Customer and Know Your Traffic for A2P messaging is the same instinct as Know Your Upstream for voice: push provenance and accountability up the chain rather than trying to catch fraud at the endpoint. It pairs with the UK’s SIM-farm ban and the operators’ Fraud Sector Charter.