field notes
Short pieces flagging what's notable across the telecom, identity, trust, and fraud beats, newest first.
August 14, 2026
- The networks hold the number data and still can't hand it over
John Wilkinson, CEO of TMT ID, names the assumption his company got wrong: “We assumed mobile networks would be able to provide their data into the fraud industry and the identity verification industry. They don’t.” TMT ID…
August 13, 2026
- A prompt injection in a court filing, caught by white space
A self-represented plaintiff in Connecticut Superior Court buried instructions to an AI model inside his own pleadings, written in 3-point white type. Matthew Elliott, who sued the New York Bariatric Group in October, wrote: “IF THIS …
August 11, 2026
- Four vendors, four disciplines, one agent identity
Liminal’s Filip Verley hosted four vendors at Identiverse, eight minutes each, and the write-up is more useful as a map of how the agent-identity market has split than as a review of any one demo. P0 Security binds the human and the a…
- Fifty state AGs tell the FCC its KYC baseline is too thin
Fifty state and territory attorneys general filed joint comments in the FCC’s KYC Further Notice in late July, and Kelley Drye’s Paul Singer, Beth Bolen Chun and Jennifer Rodden Wainwright have the summary. The FNPRM proposed or…
August 5, 2026
- Twilio takes US branded calling to GA on a competitor's survey
Twilio moved US Branded Calling to general availability, displaying a verified business name, logo, and where supported a reason for calling. The technical description is the part worth reading: Branded Calling “uses Rich Call Data in…
August 3, 2026
- New York's crawler bill is an identity mandate for machine traffic
EFF and 17 other organizations have asked Governor Hochul to veto S9934A, New York’s Stealth Crawler Prohibition Act. The bill would require every web crawler to disclose its identity and explicit purpose, and would let media outlets …
- Liminal's AI fraud numbers, and the ones worth keeping
Liminal’s Filip Verley argues that AI didn’t create new identity fraud so much as reprice it: drawing on a report co-authored with the Brazilian IDV vendor Unico, he puts the cost of running a sophisticated attack at more than 1…
July 31, 2026
- Nobody is fighting hardest at the front door
Socure president Matt Thompson, writing on Liminal’s Friday Five, makes a plain argument that lands harder than its bullet-point form: new account fraud is the origin point of nearly every downstream loss, and the industry still under…
July 30, 2026
- The House commerce subcommittee folds AI threats into the network-security conversation
Wiley’s recap of the July 22 House Energy and Commerce hearing on “Protecting Communications Networks and Improving Connectivity” is worth reading for what it says about where the AI-security conversation is heading — and …
- Surveillance pricing makes privacy the thing you pay for
Cory Doctorow’s latest is a clean statement of where consumer surveillance and pricing collide: surveillance pricing charges every customer a different price for the same transaction, keyed to the dossier data brokers hold on them. Th…
- Teams vishing is now a ransomware on-ramp
Sophos has documented a campaign it tracks as STAC4749 in which attackers pose as IT helpdesk staff over Microsoft Teams chats and voice calls, talk employees into starting a remote-support session, and — in at least three cases — end up de…
July 23, 2026
- A privacy-first trust framework starts by treating consolidated data as a liability
The Center for Democracy & Technology has published What is a Database?, a technical explainer by Hannah Quay-de la Vallee on the risks of government data consolidation. Limited, targeted data sharing between agencies has long been defe…
- STI-GA moves to vet governance authorities no national regulator stands behind
The Secure Telephone Identity Governance Authority — STI-GA, the ATIS-administered body that runs STIR/SHAKEN certificate governance in the US — has selected Numeracle to design a framework for vetting “non-jurisdictional governance a…
July 22, 2026
- FCC moves to close the Covered List's hardware-component loophole
At its July 22 open meeting, the FCC takes up a Third Report and Order and Third Further Notice of Proposed Rulemaking that would bar equipment authorization for devices containing “logic-bearing” hardware components produced by…
- NIST turns its mDL work from the technology to the harder half: adoption
Speaking at an NCCoE Cybersecurity Connections event, NIST identity program lead Ryan Galluzzo made a quietly telling pivot: the hard part of mobile driver’s licenses is no longer the cryptography. As Biometric Update reports, NIST an…
July 21, 2026
- Bitdefender's cross-channel scam numbers, filtered through GASA
GASA is surfacing Bitdefender’s 2026 Global Scam Intelligence Report, and the framing is one the trust world keeps circling back to: scams no longer live on a single channel. A deceptive ad leads to a fraudulent site, the interaction …
July 20, 2026
- CDT Europe: the EU-US border data deal bypasses fundamental-rights protections
CDT Europe, with 29 other civil-society organisations and academics, has sent an open letter to the Council of the EU warning that the Enhanced Border Security Partnership (EBSP) would mandate “continuous, systematic transfers of Euro…
- EFF: bills to unmask 'stealth crawlers' threaten the open web more than the crawlers do
The EFF pushes back on a new legislative boogeyman. “Stealth crawlers,” its Deeplinks post argues, are simply automated tools that collect public web data without disclosing the operator’s identity — and anonymous crawling…
July 18, 2026
- AI mania is eviscerating global decision-making
Nik Suresh, writing as Ludicity, has a knack for naming the thing everyone in the meeting is thinking and no one will say out loud. His latest — which shot up Hacker News over the weekend (via Simon Willison) — is about how “AI strate…
July 17, 2026
- ATIS closes the last mile of the SHAKEN-over-TDM problem
ATIS has published ATIS-1000107, SHAKEN: STI-CPS Discovery for Out-of-Band PASSporT Transmission Involving TDM Networks — the piece that makes out-of-band SHAKEN actually operable when a call crosses legacy switching. The framing in the ann…
July 15, 2026
- Ofcom puts KYC and Sender ID checks on mobile operators to fight messaging scams
Ofcom has finalised a package of rules and guidance requiring mobile providers to block, limit, and disrupt messaging scams. The context it cites: fraud accounts for an estimated 45% of all reported crime in England and Wales, £1.28 billion…
- Apple's China AI licence, and per-country rules for how AI gets used
Chinese regulators have granted Apple a licence to ship Apple Intelligence on iPhones in China, with Alibaba’s Qwen and Baidu as the technical partners — reported by the South China Morning Post (Alibaba-owned), alongside approvals fo…
- First Orion makes the RCS-over-push case for transactional alerts
First Orion has a head-to-head arguing RCS beats in-app push notifications for mission-critical transactional alerts — OTPs, fraud alerts, delivery tracking. The delivery argument is architectural: RCS gets carrier-level priority with autom…
- 49 state AGs press the FCC to choke off scammers' number supply
Forty-nine state attorneys general — the NAAG Anti-Robocall Multistate Litigation Task Force — filed reply comments urging the FCC to tighten numbering policy, the least-watched lever in the robocall fight. The mechanism they’re targe…
- Scam robocalls jump 24% in June, per YouMail data
TransNexus’s monthly read of YouMail’s Robocall Index shows overall robocalls up 3.4% month-on-month in June 2026 — a six-month high — though still down 4.6% against June 2025. The number to watch is scam volume: scam robocalls …
July 13, 2026
- Numeracle: number rotation is becoming a compliance risk, not a spam-label fix
Numeracle has a post arguing that number rotation — cycling flagged numbers out for fresh ones — has stopped working and is turning into a regulatory liability. The mechanics it lays out are sound: carriers now flag dormant, no-history numb…
- UK charges five over Russian Coms, the spoofing platform behind 1.8M scam calls
UK authorities have charged five London residents following a National Crime Agency investigation into Russian Coms, a caller-ID spoofing platform used to place more than 1.8 million scam calls. Live since 2020 — first as a handset, later a…
- Twilio takes Branded Calling international with a UK, Canada, and Germany beta
Twilio has expanded Branded Calling into public beta across the UK, Canada, and Germany, building on its US rollout. The pitch is the familiar one: replace anonymous digits with a verified Business Display Name on the recipient’s devi…
July 9, 2026
- ITU stands up a Focus Group on trust and identity for AI agents
The ITU has created a Focus Group on Trust and Identity for Humans and Agentic AI, chartered to build the terminology, reference architectures and trust frameworks for establishing who an AI agent is and whether its behavior can be trusted.…
July 8, 2026
- The FCC settles with Voximplant over a false robocall-mitigation certification
The FCC’s Enforcement Bureau has settled with Voximplant over the CPaaS provider’s Robocall Mitigation Database filing. Under the consent decree (DA-26-644, adopted July 8), Voximplant admitted its RMD certification was noncompl…
July 7, 2026
- Deepfake video calls and the case for continuous identity verification
Business email compromise used to be a text problem. Pindrop’s latest article argues it has “evolved from text to voice to live video”: the spoofed-email attacker now joins the video call wearing a synthetic face and voice…
- Papua New Guinea moves to criminalize deepfakes and voice cloning
Papua New Guinea’s ICT ministry has begun drafting laws to criminalize AI deepfakes, voice cloning and digital impersonation, with Acting Minister Peter Tsiamalili Jr. pledging that “no Papua New Guinean should have their face, …
July 2, 2026
- Companies are throttling employee AI use because it's too expensive
404 Media, working from leaks across Amazon, Adobe, Atlassian, Citi and more, reports the un-hyped version of the current AI moment: companies are actively throttling their employees’ AI use because the costs are spiraling. It’s…
- Google loses its final appeal on the €4.1 billion Android antitrust fine
The Court of Justice of the European Union has dismissed Google’s final appeal against a €4.1 billion ($4.7 billion) antitrust fine over its use of Android to lock in Chrome and Google Search as the defaults on the world’s domin…
- The FCC's July meeting carries an FNPRM on the Robocall Mitigation Database
Communications Daily reports that the FCC’s July open-meeting agenda includes a Further NPRM on the Robocall Mitigation Database — alongside a 2027 upper C-band auction, expanded Covered List rules, and an order relaxing broadband-lab…
- FBI seizes the NetNut residential-proxy platform behind the Popa botnet
Krebs reports the FBI seized hundreds of domains tied to NetNut, a sprawling residential-proxy service run by the publicly-traded Israeli firm Alarum Technologies (NASDAQ: ALAR). The takedown lands about two weeks after Krebs published rese…
- A Hide My Email flaw exposes the real address it's meant to mask
Michael Tsai rounds up reporting (via Joseph Cox and 404 Media) on a flaw in Apple’s Hide My Email: the feature that’s supposed to hand out a disposable alias will, under the right conditions, let almost anyone recover the perso…
- Signed-call coverage reaches 48.8% in TransNexus's June STIR/SHAKEN data
TransNexus’s June STIR/SHAKEN numbers put signed calls at termination at 48.8% — up 3.3 points on the month and, by their measure, the highest in 20 months. Full A-level attestation reached 30.8% of calls (up 1.1), and the count of or…
July 1, 2026
- AI impersonators of 112 public figures rated more authentic than the real thing
404 Media reports on a study in which researchers had AI impersonate 112 public figures, then asked people to compare the impersonations against the real thing. The result is the uncomfortable one: participants rated the AI versions as &ldq…
- Mintz reads the FCC's robocall enforcement as a deliberate shift upstream
Mintz attorneys Danielle Frappier and Jonathan Garvin read the last few months of FCC robocall activity as a deliberate change of target. They trace it to what Chairman Brendan Carr described in October 2025 as a “different approach&r…
- The FCC wants the Robocall Mitigation Database to be a gatekeeper, not a registry
The FCC released a draft Further Notice of Proposed Rulemaking on July 1 proposing a substantial expansion of the Robocall Mitigation Database, teed up for the July open meeting. The CommLaw Group, in a detailed client advisory, reads the d…
June 30, 2026
- Australia's SMS Sender ID Register goes live
Australia’s communications regulator has switched on its SMS Sender ID Register. From 1 July 2026, messages sent under a registered sender ID keep showing the brand name; messages using an unregistered sender ID must be labelled &ldqu…
- FCC Enforcement Bureau puts Digital Solutions on notice over suspected robocalls
Communications Daily reports that the FCC Enforcement Bureau has issued an initial determination order (docket 22-174) warning Digital Solutions that its downstream providers could be required to block, and to stop accepting, all traffic th…
- Gruber on the Supreme Court's geofence-warrant ruling
John Gruber’s ★ piece on a Supreme Court ruling that law enforcement’s use of a “geofence warrant” — the kind that asks Google for every device present in an area at a given time — counts as a Fourth Amendment &ldquo…
- Twilio's Compliance Toolkit reaches general availability
Twilio has moved its Compliance Toolkit to general availability. The feature list is the tell: HIPAA eligibility, “intelligent” intent-based protections, quiet-hours enforcement, and — the one worth pausing on — TCPA “Know…
June 26, 2026
- Turing's forgotten voice scrambler
Hackaday points to a Popular Mechanics piece on Delilah, the portable speech-encryption system Alan Turing built late in WWII and then more or less vanished from the record. It was, in many ways, an early stab at digital voice encryption — …
- Branded Calling goes live on Telnyx
Telnyx has flipped on Branded Calling as a generally available feature: outbound calls can now carry a verified business name, logo, and call reason, with the pitch that this lifts answer rates on US calls to T-Mobile and Verizon. It’…
- John Gruber's remembrance of Om Malik
John Gruber’s tribute to Om Malik, who died on June 24 after a long fight with a failing heart. It’s a piece about a twenty-year friendship, but also about the path both men walked: Malik went from “the bloggiest of quick-…
- Two thousand people tried to phish an AI email assistant, and the secret held
Simon Willison points to Fernando Irarrázaval’s hackmyclaw.com challenge: email “Fiu,” an assistant built on the OpenClaw agentic framework and wired to a real mailbox, calendar, and files, and try to make it cough up a se…
- YouMail flags a summer rise in package-delivery smishing
YouMail’s consumer blog warns that package-delivery scams are climbing again — the “there’s a problem with your delivery” notifications that land by text, email, or call impersonating USPS, UPS, FedEx, and DHL, then …
June 25, 2026
- A German court treats Google's AI as its agent
Simon Willison flags Bruce Schneier on a recent German ruling that Google can be held liable for errors its AI overviews introduce. Schneier’s framing is the part worth keeping: “AI agents are agents of the person or organizatio…
June 24, 2026
- The service desk is still the soft spot
A Specops-sponsored piece on BleepingComputer walks through why social-engineering attacks against the IT service desk keep working: the help desk is the designated human override for identity verification, and password resets and account-r…
- Pindrop finds AI text detectors carry demographic bias
Pindrop’s research team tested 16 AI-text-detection systems against a large, demographically labeled corpus and found the bias is “real, model-specific, and most dangerous where attributes intersect.” The work is headed to…
- Stop Scams UK's blocked-SIMs program wins an award
Stop Scams UK reports that its Blocked SIMs program has won an international award for, in its phrasing, burning down a cross-sector fraud route — a coordinated effort in which telecoms and banks share signals to identify and cut off the SI…
- Zoom and BrightHire put deepfake detection inside the interview
Zoom and BrightHire are partnering to fight candidate fraud in remote hiring, including deepfake detection built into live interviews — catching, in real time, the cases where the person on camera isn’t who, or what, they claim to be.…
- 988 georouting, done with FIPS codes instead of location
ATIS’ Emergency Services Interconnection Forum has published ATIS-0500049, GeoRouting for 988 Voice Calls, which specifies how carriers route 988 Lifeline calls to the right local crisis center. The mechanism is deliberately blunt: st…
June 23, 2026
- GASA's RedVDS case study and the rentable infrastructure of scams
GASA’s case study on RedVDS is worth reading less for the takedown than for the framing. “Modern scam operations do not depend only on individual fraudsters sending deceptive messages,” the post argues. “Increasingly…
- Scattered Spider's guilty pleas, and the phone-channel through-line
Two members of Scattered Spider pleaded guilty on the first day of what was meant to be a six-week trial, Brian Krebs reports: Thalha Jubair, 20, and Owen Flowers, 18, over the 2024 attack that crippled Transport for London. The headline is…
- Age verification rides in on the KIDS Act compromise
The House Energy and Commerce Committee’s bipartisan KIDS Act — the chamber’s vehicle for the long-running Kids Online Safety Act — strips out the duty-of-care provision 76 senators have backed, which is the headline The Record …
- 332 comments and counting on the FCC's OSP know-your-customer proposal
TransNexus takes an early read on the comment flood landing on the FCC’s Further Notice of Proposed Rulemaking on originating-provider KYC. The rules would require OSPs to collect a name, physical address, government-issued ID number,…
June 18, 2026
- Apple's Core AI, the on-device successor to Core ML
Via Michael Tsai’s roundup, Apple’s WWDC26 Core AI is the framework successor to Core ML: a modern, memory-safe Swift API for running models entirely on device, a set of Python libraries for converting, authoring, and optimizing…
June 17, 2026
- The FCC's plan to end phone anonymity, on 404 Media
On the 404 Media podcast, Joseph Cox walks through the FCC’s proposal to require voice providers to collect, verify, and store every new and renewing customer’s full name, physical address, and government-issued ID number. The C…
- Gruber and Anil Dash on the epic story of Markdown
John Gruber joined The Vergecast with Anil Dash to tell the origin story of Markdown — the 2002 bet on Apple and blogs, Textile as inspiration, and Aaron Swartz as the format’s most valuable beta tester. What makes this more than nost…
June 15, 2026
- Anthropic's safety conviction as a business superpower
Ben Thompson’s read on the government directive suspending foreign-national access to Fable 5 and Mythos 5 is the sharpest framing I’ve seen of the whole episode. His move is to separate the actions from the justifications. Anth…
- The first domain seizure under the TAKE IT DOWN Act
The Justice Department has seized CFAKE.com and SOCFAKE.com, sites that allegedly hosted nonconsensual AI-generated nude images and videos of women. As BleepingComputer notes, it appears to be the first publicly announced domain seizure und…
- The FCC's effective shutdown order against SK Teleco
The FCC Enforcement Bureau has issued what amounts to a shutdown order against SK Teleco after the provider failed to come into compliance with the agency’s robocall rules. The bureau had warned the company in April that it appeared t…
- YouMail's May index: 4.1 billion robocalls, and the framing that travels with it
Americans got just over 4.1 billion robocalls in May, per the YouMail Robocall Index — about 132.8 million a day, 1,537 a second, roughly 12.5 per person. The figure is down about 2.1% from April and 14.9% from May 2025, with scam and telem…
June 12, 2026
- FCC Enforcement Bureau opens a robocall case over calls to a 911 center
Communications Daily reports that the FCC Enforcement Bureau has notified Florida-based VoIP provider Aspireistic that it is under investigation for “originating apparently illegal robocall traffic” — including calls to a public…
- An RMD removal in motion: FCC tells Mexico IP Phone to show cause
Communications Daily reports that the FCC Enforcement Bureau has found the New Mexico-based VoIP provider Mexico IP Phone’s Robocall Mitigation Database certification “apparently deficient” and directed the company to show…
June 11, 2026
- Warner's critical-infrastructure bill names an AI model as the threat
Senate Intelligence ranking member Mark Warner has introduced the Combat Emerging Threats to Critical Infrastructure Act, per Inside Cybersecurity, directing CISA to take the lead on updating the sector-specific plans called for under the B…
- The decide-execute-deliver sandwich, or why coding agents haven't replaced engineers
Narayanan and Kapoor’s latest extends their “AI as normal technology” thesis to the case everyone keeps invoking — software engineering — and it’s the measured counterweight to the existential-threat framing. Their f…
- Why every chatbot keeps writing about a lighthouse keeper named Elias Thorne
Ask ChatGPT, Claude, Gemini, or Grok to “tell me a story” and there’s a good chance you’ll meet Elias Thorne — a clockmaker, a lighthouse keeper, or a librarian, depending on the model. Samantha Cole’s piece fo…
- TransNexus's May robocall-volume read, the monthly counterpart to the signing data
TransNexus has posted its robocall trends for May 2026, the volume-side companion to the STIR/SHAKEN signing statistics it publishes from the same dataset — signed and unsigned calls observed across the hundreds of providers using its tools…
June 10, 2026
- The numbering fight is really about what a phone number is for
A second round of comments in the FCC’s numbering-rules proceeding lands in the same register as the first: Communications Daily reports that various groups and companies are warning the Commission that some of the proposed changes wo…
- TransNexus's May STIR/SHAKEN numbers: watch coverage, not participation
TransNexus has posted its May STIR/SHAKEN statistics, the latest in a monthly series it has run since April 2021, drawn from signed calls received by hundreds of voice service providers using its tools. It’s a small, consistent datase…
June 9, 2026
- An AI email agent falls for the same phishing that fools people
BleepingComputer reports on a phishing simulation run against OpenClaw, an autonomous email agent, across a range of configuration profiles. The finding: the agent “was susceptible to tactics commonly used to compromise human users,&r…
- Early comments urge caution on extending numbering-access rules to all providers
Communications Daily reports that early commenters are urging the FCC to move carefully on an NPRM that would extend certification and disclosure requirements to all providers that receive telephone numbering resources — direct-access appli…
- Pindrop can flag an AI voice — but not who's responsible for the call
Pindrop introduces its new Chief Product Officer, Nicholas Holland (most recently AI product strategy at HubSpot), in a fireside-chat writeup that doubles as a positioning statement. The line to note isn’t the personal-story framing b…
June 2, 2026
- DNA Finland turns on Hiya's network-level call protection, consumer and business at once
DNA, the Finnish operator in the Telenor Group, has launched Hiya Protect for both consumer and business subscribers under the local brand DNA Numerovahti — “number guardian.” Calls are analyzed at the network level via a synchr…
June 1, 2026
- Meta's AI support bot socially engineered into handing over Instagram accounts
Brian Krebs reports that the Instagram accounts of the Obama White House and the Chief Master Sergeant of the Space Force were defaced after instructions circulated on Telegram showing how to trick Meta’s AI support assistant into acc…
May 28, 2026
- Bandwidth: branded calling needs reputation and authentication underneath it
Bandwidth argues that branded calling is necessary but not sufficient — that without a number-reputation layer underneath and pre-call authentication alongside, “a logo is just a coat of paint on a shaky foundation.” The post la…
May 27, 2026
- GASA's FALKIN: 22,661 bank-fraud operator signals, with account takeover at 69%
GASA’s FALKIN team has published a snapshot of 22,661 bank-tagged signals collected over six weeks from Telegram channels, dark-web forums, and live attack infrastructure. The breakdown is stark: “account takeover and credential…
May 25, 2026
- FBI flags Kali365, a phishing service built on OAuth device-code abuse
The FBI has put out a warning about Kali365, a phishing-as-a-service platform that surfaced in April 2026 and is sold through Telegram to attackers who want into Microsoft 365 accounts without bothering to steal passwords or intercept MFA c…
May 22, 2026
- Call-tracking execs plead guilty to powering tech-support phone fraud
Two former executives of a call-tracking and analytics company have pleaded guilty to concealing a years-long tech-support fraud scheme. Ex-CEO Adam Young and ex-CSO Harrison Gevirtz ran C.A. Cloud Attribution from 2017 to 2022, supplying t…
- FTC settles with Cox Media Group over 'active listening' ad-targeting claims
The FTC has settled with Cox Media Group and two marketing firms — New Hampshire’s MindSift and Wisconsin’s 1010 Digital Works — for $930,000 total over their pitch for an “active listening” advertising product. The …
- Non-human identity becomes a SASE vendor category
Diana Goovaerts at FierceTelecom reports on the way SASE vendors — Versa Networks, Cisco, Palo Alto Networks — are scrambling to bolt non-human-identity controls onto their platforms before agentic AI floods enterprise networks with workloa…
May 21, 2026
- Calypso espionage campaign targets telecom carriers with new implants
Researchers at Lumen’s Black Lotus Labs and PwC Threat Intelligence have detailed a Chinese cyber-espionage campaign hitting telecom providers with two new implants — a Linux post-exploitation framework dubbed Showboat and a Windows b…
May 20, 2026
- First Orion makes the outbound-sales case for branded calling
First Orion makes the outbound-sales case for branded calling — putting a company’s name and logo on the recipient’s handset before they answer. The hook is a stark figure: just 19% of U.S. adults generally answer calls from num…
- Telnyx maps EU AI Act Article 50 onto voice AI
Telnyx has a compliance guide for EU AI Act Article 50, which becomes enforceable on 2 August 2026 and requires that AI-generated voice be watermarked and that deployers be able to tell authentic audio from a deepfake. The sharpest point: t…
- Telnyx argues voice-AI trust belongs at the network layer
In a companion piece, Telnyx makes the case that voice-AI trust has to live at the network layer. The hook is a Mobile World Congress 2026 demo by Resemble AI: 140 attendees tried to tell AI-generated audio from real recordings and averaged…
- The FCC's KYUP proposal aims to expose the upstream providers that carry illegal calls
Light Reading reports on the FCC’s proposed Know-Your-Upstream-Provider rules, which it frames as requirements “designed to expose providers that enable illegal calls and root them out of the voice ecosystem.” It’s a…
- Wiley Rein walks through the FCC's KYUP and STIR/SHAKEN FNPRM
Wiley Rein has posted a detailed walkthrough of the May 20 FCC Further Notice proposing significant changes to know-your-upstream-provider (KYUP) rules, the STI-GA, and STIR/SHAKEN call authentication. The firm summarizes the FCC as proposi…
May 19, 2026
- First Orion frames call authentication as finance's defense against APP fraud
First Orion argues call authentication is now non-negotiable for financial institutions, casting the phone channel as simultaneously a bank’s most critical and most exploited line to customers. The standout claim: only 32% of institut…
- GASA rebuilt its State of Scams methodology to stop overcounting losses
The Global Anti-Scam Alliance has published the methodology behind its 2026 State of Scams reports, and the headline change is a deliberately more conservative way of counting losses. “For 2026, we made a conscious decision to change …
- Vonage exposes PSTN branded calling as an API, with First Orion's INFORM underneath
Vonage has published a walkthrough for wiring PSTN Branded Calling into its Voice API through First Orion, so that outbound calls “display your company name, logo, and call purpose” on the handset instead of a bare number. The t…
- What frontline practitioners say actually prevents fraud against older adults
GASA’s Research Working Group convened around Prof. Mark Button’s study on what actually works to prevent fraud against older adults — a population that gets targeted like everyone else but absorbs far heavier financial and emot…
- Eight of the largest US carriers stand up a joint cybersecurity group
AT&T, Charter, Comcast, Cox, Lumen, T-Mobile, Verizon and Zayo are now working together in a communications cybersecurity group set up to share threat information and coordinate a faster collective response to attacks. It is, in effect,…
May 18, 2026
- STIR certificate transparency draft heads for Proposed Standard
Russ Housley has requested publication of draft-ietf-stir-certificate-transparency-02 as a Proposed Standard, on behalf of the STIR working group. The request hit the STIR list on May 18 and moves the document to the next step in the IETF p…
May 14, 2026
- Bouygues Telecom turns on network-level branded calling in France
Hiya announces that Bouygues Telecom has deployed Branded Call across its network, making it the first French mobile operator to offer business caller identity to all subscribers at the network level. The service launches in June 2026, with…
May 13, 2026
- SHAKEN's PASSporT spec gets a revision as 8588bis is requested for publication
Ben Campbell has requested publication of draft-ietf-stir-8588bis-01 as a Proposed Standard for the STIR working group — a revision of RFC 8588, the “PASSporT Extension for SHAKEN” that defines how SHAKEN attestation is actually…
May 11, 2026
- Bandwidth lays out its full robocall and contact-center fraud stack
Bandwidth has published a comprehensive rundown of how it fights illegal robocalls, scam calls, toll fraud, and spam across its network. The post opens with the FTC’s tally of more than $12.5 billion in consumer fraud losses in 2024 —…
- TCPA class actions set a Q1 record — even as the growth rate cools
Eric Troutman’s TCPAWorld has the numbers, and they are eye-watering: more TCPA class actions were filed in the first quarter of 2026 than in any quarter in history, with March alone setting records at 283 cases filed and 220 of them …
May 8, 2026
- Roger Anderson's Caller-ID Vouching and Vetting
Roger Anderson of Jolly Roger Telephone Company has posted a new Internet-Draft, Caller-ID Vouching and Vetting (CIDVV), that proposes verifying caller identity by reachability. The mechanism: before the real call goes out, the originator&r…
May 4, 2026
- Truecaller's Global Insights report tallies 68 billion spam and fraud calls
Truecaller has published its first Global Insights Report since 2021, and the headline number is stark: 68 billion spam and fraud calls identified globally in 2025. Indonesia tops the ranking, where 79% of all calls from unknown numbers wer…
- YouMail clocks March U.S. robocalls at 4.2 billion, ending the sub-4B streak
YouMail’s monthly Robocall Index recap puts March 2026 U.S. robocall volume at 4.2 billion calls — 135.7 million per day, roughly 1,600 per second — a 9.8% month-over-month increase that ends “six consecutive months of staying b…
March 11, 2026
- The Campaign Registry's CNP migration tool ends 10DLC vendor lock-in
Bandwidth walks through what The Campaign Registry’s new Campaign CNP Migration Tool means for business texting: campaign service providers can now move 10DLC campaigns to a new connectivity partner without re-registering from scratch…
February 1, 2026
- TNS's 2026 Robocall Report: the non-Tier-1 STIR/SHAKEN gap is widening, not closing
TNS’s 2026 Robocall Investigation Report — the annual FCC-cited data drop — landed in February. The Tier-1 headline number is familiar enough: top-tier inter-carrier signed traffic averaged ~85% across 2025, ending the year at 85.4% i…