Skip to content
Naked Security Naked Security

Robocalls now flooding US phones with 200m calls per day

According to a new report, nearly 30% of all US calls placed in the first half of 2019 were garbage, as in, nuisance, scam or fraud calls.

This is unlikely to surprise anybody who owns a phone: according to a new report, nearly 30% of all US calls placed in the first half of this year were garbage, as in, nuisance, scam or fraud calls. That puts the approximate volume of sludge coming into people’s phones at a mind-boggling 200 million unwanted calls per day.

The TNS 2019 Robocall Investigation Report comes from Transaction Network Services (TNS), which markets a big-data analytics engine that aims to suppress unwanted calls to consumers by applying machine learning, as well as an authentication hub to help carriers combat illegal spoofing and to help consumers fend off robocalls.

TNS’s analysis crunched approximately one billion daily calls, placed via hundreds of carriers. TNS defines “high-risk” robocalls – i.e., scam/fraudulent calls – as those that try to shake down targets for personal information and/or money. It defines “nuisance” robocalls as those that are, well, just nuisances that lack malicious intent and that don’t reflect negligent non-compliance.

“Nuisance” calls aren’t always defined to exclude scams, but we can look to the UK for what strikes me as an example of TNS’s definition…

A few years back, Home Logic, a UK firm that offers energy-saving solutions, was made £50,000 lighter thanks to a penalty issued by the Information Commissioner’s Office (ICO) for making marketing calls to people who had made it clear – via the free Telephone Preference Service (TPS)  – that they didn’t want to be contacted in that way.

It was a tech glitch, Home Logic said at the time. What happened was that it licensed the numbers it used to make marketing calls from third-party providers. It then uploaded that data to an electronic dialer system that screened the numbers against the TPS register. One of the third-party providers left it up to Home Logic UK to ensure that the data supplied was screened against the TPS.

Technical issues knocked the system out for 90 days out of 220 between April 2015 and March 2016. That didn’t slow down Home Logic, though: the unsolicited marketing calls kept right on coming, but with no screening against the TPS register.

The rate of this type of non-malicious nuisance call is rising faster than the malicious type that tries to scam you, TNS found.

Here’s that plus more key findings from the report:

Nuisance calls are increasing at a faster rate than high-risk calls. Nuisance calls increased 38% from the third quarter of 2018 to the second quarter of 2019, while high-risk calls grew only 28% over that period.

Robocall hijacking of mobile numbers has more than doubled. “Hijacking” a number is TNS’s term for what we more frequently refer to as illegal spoofing of a caller ID. A year ago, the Federal Communications Commission (FCC) slapped (or proposed) some huge fines on robocallers for using spoofed numbers, one of which represented the first major enforcement action against a company that allegedly “commandeered” consumers’ phone numbers.

TNS reports that 1 in 1,700 mobile numbers are now being commandeered by robocall spoofers every month, which is more than double last year’s rate of 1 in 4,000 mobile numbers. As a result, TNS says, 2.5% of people whose phone numbers have been hijacked have disconnected their phone number.

When it proposed its fines last year, the FCC pointed to one of those people: a poor soul whose phone number was hijacked in order to plague people. The Arizona woman said she received more than five calls a day on her cell phone, all coming from irate people complaining about the telemarketing calls they got from “her” phone number. In fact, the calls were coming from Affordable Enterprises, whose shtick was to sic its robots on unsuspecting people in order to telemarket home improvement and remodeling services.

TNS noted that in one extreme case, the company witnessed a spoofer that used a legitimate mobile number to place over 36,000 calls in a three-day period.

TNS notes that the faster growth rate of nuisance calls, as opposed to high-risk calls, may have to do with the fact that, due to regulatory action from the FCC, carriers have begun to block illegal calls.

Robocallers may shift focus to smaller, regional carrier networks. TNS reports that the top six US carriers represent 70% of total calls for the time period it analyzed, but only 12% of high-risk calls were placed from numbers owned by these carriers.

Robocallers are shifting from spoofing VoIP numbers to toll-free numbers. TNS found that the share of Voice over IP (VoIP) number spoofing dropped, but that the percentage of calls originating from toll-free numbers more than doubled from 12% last year to 25% in the first half of the year. That means that more than 8 in 10 calls from the top 10 toll-free numbers are either nuisance or high-risk calls – what TNS calls “a challenge to leading brands whose legitimate numbers are being spoofed in an attempt to trick consumers.”

Neighbor spoofing and “snowshoe spamming” are growing more sophisticated. Neighbor spoofing – that’s when robocallers display a phone number similar to your own on your caller ID, to increase the likelihood that you’ll pick up – now accounts for 25% of all bad calls. We learned about a particularly pernicious form of this a few months ago: hospitals are being suffocated by robocalls, with spam callers spoofing phone numbers to place calls to hospitals that look for all the world like the calls were placed internally.

Hospitals are also suffering from vishing attacks from voice phishers: spearphishers who pose as employees at government agencies and demand to speak to a specific, named physician as they try to finagle confidential information out of the doctors, such as medical license numbers and Drug Enforcement Agency (DEA) numbers – information with which fraudsters can illegally procure drugs to then sell on the black market.

The new twist noted by TNS: “snowshoe spamming.” That’s when spammers spoof calls over several telephone numbers in low volume, and then rapidly churn through them to evade detection.


Bill Versen, chief product officer at TNS, said in a press release about the report that while the top six US carriers – AT&T, CenturyLink, Comcast, Sprint, T-Mobile and Verizon – are getting better at identifying these calls, the focus now has to shift to the same place that the perpetrators are now targeting: smaller networks.

The report suggests the need for diligence as the battlefront may shift to smaller regional and rural carriers.

Legislative update

In May 2019, the US Senate passed an anti-robocalling bill. That bill, the TRACED Act, would have created an interagency task force to address robocalls and extend the FCC’s statute of limitations for going after the fraudsters.

In July, the House passed its own version, the Stopping Bad Robocalls Act (HR 946). Sen. Ed Markey said at the time that both the House and Senate bills would be headed to conference and combined into one piece of legislation for the president’s consideration and possible signature.

If President Trump does sign it into law, the House bill would make it easier for the government to impose tougher penalties on illegal robocallers and demand that carriers deploy call authentication protocols such as SHAKEN/STIR at a faster pace.

But as the carriers have pointed out, SHAKEN/STIR isn’t a robocalling panacea. It’s expensive, for one thing. Nor does it signify which calls are illegal or not. Plus, with so many of these calls coming from overseas, the universal adoption needed to make SHAKEN/STIR really work is hard to imagine.

8 Comments

Providers are just waiting for that special funding from the Fed to “fix” the issue that they know how to “fix” already..

Reply

The infrastructure to support 30 percent of all calls is not free and has to be costing the providers a lot of money. That suggests to me that the providers are somehow making money on those calls, otherwise they would be proactively taking countermeasures. We are unfortunate in having [redacted] as our provider, and they have been resisting countermeasures at every turn as being “too expensive”.

Reply

I feel ya Wilbur; I’m also on [Redacted]. While they claim the best (plans|signal|support), they likely profit by calls to and from [redacted] or even [R Edacted&redacted], who likewise has the best (network|features|phones). Therefore they spin requests with “expensive” and “complex,” reticent with true motive.
Now that I think about it, everyone I’ve ever met is also stuck on [redacted], who’s terrible and money-grubbing as the rest.
Don’t forget this is way harder than other tech they’ve figured out.

Reply

Had three of these calls yesterday :/
How about we bribe a “extended warrantee” sales person to give up their employer, start a go fund me to hire a fixer, I doubt anyone would anyone mind. If a million people donated 10 cents (comes to 100k), and they wanted to give life in prison (100 years) that would be roughly 53 seconds each, less time if more donated.
Just a day dream.

Reply

I got 5 calls from sombody named warren yesterday within 4hrs showing up as 5 different states it was supposed to be about diabetic merchandise i was supposed to have asked about. The 1st and 2nd time i informed him i did not have diabetics nor did anyone on my house not to call me again ,and hung up within 5 mins i got a call again from the same person,so i hung up on the 5th call i told him he sure traveled fast that CV he had called me 5 times in 4 hrs from 5 different states,he hung up that time so far he hasnt called me back

Reply

What Wilbur said. Son & I use 2 seperate pre-pay MVNO (Android) carriers. We each get 4 – 12 such calls weekly. Each carrier offers (for an extra $4) the “Special Fix App” – as if they’ve not invoked ‘Bloatware’ (which can’t be removed) enough? One very ‘spammy’ week, I took my fone to the ‘Pre-Paid Storefront’ and requested they open an FCC complaint. The only ‘Proactive Response’? They pushed the “Add $4 to your monthly payment” fix.

Reply

Our government allowed “businesses” to call us on our cell phones. It was a horrible idea and I said so at the time. They owe every person with a cell phone millions of dollars for aggravation. Too bad it is not the only or the worst idea they will inflict on us.

Reply

If you are a phone network provider and you will provide “call blocking” only for an additional price upcharge on your phone plan it serves to make the provider no better than the scammer calling. We will help you block calls if you pay..isn’t helping the consumer more like a ransom.

Reply

Leave a Reply

Your email address will not be published. Required fields are marked *

Subscribe to get the latest updates in your inbox.
Which categories are you interested in?
You’re now subscribed!