Professor
Professional
- Messages
- 1,477
- Reaction score
- 1,539
- Points
- 113
INTRODUCTION: Why Spoofing Is the Difference Between Success and Failure
The verification call is one of the most critical moments in any carding operation. You can perfectly select a card, bypass AVS and 3DS, but the moment a store agent, bank representative, or courier service picks up the phone, everything hinges on one thing — the number they see on their screen.If that number doesn't match the one linked to the card, your entire legend collapses. In one second, the order is canceled, the card is burned, and the account is blacklisted. This is precisely why Caller ID Spoofing is not just a useful option but an essential tool for anyone working with verification calls.
In 2026, the landscape has shifted dramatically. Up to 90% of incoming international traffic in unprotected network segments now consists of spoofed calls and other fraudulent traffic. Carriers and regulators have responded with increasingly sophisticated countermeasures. The STIR/SHAKEN framework, which the FCC now requires carriers to use, verifies that the originating carrier actually authorized the number displayed on your caller ID. Android has introduced fake call detection that can flag suspected spoofed calls. The game has changed.
This article covers every working method of number spoofing — from simple ready-made services to professional SIP telephony and extreme SIM swapping. You'll learn how to set up each method, its pros and cons, where it applies, and most importantly, how to avoid fatal mistakes.
CHAPTER 1: WHAT IS CALLER ID SPOOFING
Caller ID spoofing is a technology that allows you to change the number displayed on the receiving party's phone when you make a call. You call from one number, but the operator sees a completely different number on their screen — for example, the cardholder's number.How It Works Technically:
When you make a normal call, your phone sends a signal to your carrier's tower, which routes it to the recipient's network. Along with the signal, the caller's identifier (Caller ID) is transmitted. With spoofing, this identifier is replaced at the routing stage — either through SIP headers (in VoIP) or through an intermediary service that "inserts" itself into the connection chain.
Why It Matters in 2026:
Caller ID (ANI) is context, not identity. It can be spoofed. However, carriers are actively fighting back. According to the 2025 Europol Position Paper on Caller ID Spoofing, in unprotected network segments, up to 90% of incoming international traffic is now comprised of spoofed calls and other fraudulent traffic. Protecting against CLI spoofing has become a top security priority for 59% of global carriers.
CHAPTER 2: THE EVOLUTION OF SPOOFING DEFENSES
2.1 STIR/SHAKEN — The US Framework
STIR/SHAKEN is a caller ID authentication framework that uses digital certificates to verify whether an originating carrier authorized the phone number displayed on an incoming call. All major US voice service providers were required to implement STIR/SHAKEN by June 2021. Since then, the FCC has progressively tightened requirements — most significantly with the 2026 updates, which added annual recertification obligations and proposed enhanced Know Your Upstream Provider (KYUP) rules.STIR/SHAKEN helps carriers confirm whether a call is likely spoofed. Signed traffic between smaller carriers dropped significantly, sitting at just 17.5% in 2025.
What This Means for Spoofing:
- Calls from carriers that haven't implemented STIR/SHAKEN may be flagged or blocked
- Spoofed calls are more likely to be detected, especially if the originating carrier doesn't properly authenticate
- Financial services institutions face heightened spoofing risks in 2026 as impersonation scams continue to target their customers
2.2 Android Fake Call Detection
In 2026, Google introduced fake call detection, an industry-first protection that can detect and flag suspected spoofed calls when your contact and you are both using Phone by Google. This is a direct response to the growing threat of impersonation scams, which have caused an estimated $400 billion in global losses.How It Works:
- The system analyzes call patterns and anomalies
- It can flag calls that appear to spoof your contacts' numbers
- It provides a warning to the recipient before they answer
2.3 Carrier-Level Protections
Major carriers have deployed AI-powered solutions to identify high-risk traffic and improve how incoming calls are presented to end users. Solutions like AB Handshake's AI Shield combined with Vodafone's Procure & Connect Global CLI Trust layer create comprehensive real-time voice protection frameworks.CHAPTER 3: METHOD 1 — DEDICATED SPOOFING SERVICES
3.1 SpoofCard — The Most Popular Service
SpoofCard is the most well-known and easiest-to-use service for caller ID spoofing. It works through a mobile app (available for iOS and Android) or a web interface.Key Features:
- Cost: $2.99/month subscription + credits (approximately $0.10–0.20 per minute). One credit equals one minute of talk time.
- Functionality: Number spoofing, call recording, selection from pre-verified Caller IDs, ability to use a second number for private calls.
- Platforms: iOS, Android, web version.
Step-by-Step Instructions:
- Register. Go to spoofcard.com or download the app.
- Add funds. Purchase a subscription ($2.99/month) and credits for calls.
- Go to "Make a Call."
- Enter the target number — the store, bank, or courier service you're calling.
- Enter the spoofed number — the cardholder's number.
- Optionally change the caller name (Caller ID Name).
- Click "Call." The operator will see the cardholder's number.
Advantages:
- Minimal entry barrier — no technical knowledge needed
- Works with mobile and landline numbers
- Call recording available — you can replay and analyze calls
Disadvantages:
- Paid model — minutes cost money
- Call quality depends on internet connection
- Not all numbers can be spoofed — some carriers block spam calls
- In 2026, SpoofCard and similar services face increased carrier scrutiny
When to Use: Quick one-time verification calls when you don't have time to set up VoIP, or when you're a beginner.
3.2 Alternative Services
| Service | Features | Price |
|---|---|---|
| Bluff My Call | Allows spoofing to any number | ~$10 per minute package |
| SpoofTel | Similar to SpoofCard, often cheaper | $5–15 per package |
| Phoner | Second number with Caller ID change capability | $5–10/month |
| TextPlus | Call masking, private texting, VoIP calling | Free–$10/month |
| Line2 | Multiple number management, VoIP calling | $10–15/month |
| Hushed | Private calling, multiple numbers | $5–10/month |
| Sideline | Second number for business | $10/month |
3.3 Critical Mistakes with Dedicated Services
| Mistake | Consequence | Fix |
|---|---|---|
| Not testing before calling | Operator sees your real number | Always test-call your second number first |
| Using one service for all calls | Account blocked for suspicious activity | Rotate services and accounts |
| Calling from the same IP used for carding | System links call to order | Use different proxies for carding and calling |
| Ignoring call quality | Operator hears echo, delays — raises suspicion | Use stable internet, avoid public Wi-Fi |
| Not having a backup | Service fails mid-operation | Always have a secondary spoofing method ready |
CHAPTER 4: METHOD 2 — VOIP TELEPHONY (MOST FLEXIBLE)
4.1 What Is VoIP and Why It's the Best Choice
VoIP (Voice over IP) is a technology that transmits voice over the internet. When you call via VoIP, the signal doesn't go through the traditional telephone network but through an IP network, allowing you to control virtually all connection parameters — including Caller ID.Why VoIP Beats Dedicated Services:
- Cheaper. A minute of calling through a SIP provider costs pennies ($0.005–0.05) vs. $0.10–0.20 with SpoofCard.
- More flexible. You can spoof any number, change it on the fly, configure routing.
- More reliable. With proper configuration, audio quality is higher than with intermediary services.
- Scalable. You can connect multiple SIP accounts and rotate them.
4.2 Step-by-Step Setup via a SIP Provider
General Principle: Most VoIP providers allow you to manually set the number displayed to the recipient. When you make a call, you simply fill in the "From" field in the SIP request with any number.Detailed Instructions (Example: Zadarma):
- Register on the Zadarma website. Complete your profile, connect a virtual number (if needed).
- Go to "Settings → SIP Connection → CallerID" (or if using an PBX, "My PBX → Internal Numbers → CallerID").
- Select the number to display when making calls. This can be the cardholder's number.
- Configure a softphone. Download any SIP client (Zoiper, X-Lite, MicroSIP), enter SIP account details (login, password, server).
- Make a test call. Call your second number and confirm the Caller ID is spoofed correctly.
For Advanced Users — Setup via SIP Trunk:
If you have access to a SIP trunk or your own PBX (e.g., 3CX), spoofing is configured at the trunk level:
- In the outgoing trunk settings, specify a constant in the "Caller ID" field.
- Or set the number in the "SIP ID" field.
- Ensure the provider doesn't block spoofing (not all operators allow it at the trunk level).
Other SIP Providers with Spoofing Support:
| Provider | Features | Price |
|---|---|---|
| CommPeak | Allows Caller ID configuration in SIP account (From, P-Asserted-Identity, Remote-Party-ID) | From $0.005/min |
| VoIP.ms | Phone Book with CallerID Number Override function | From $0.01/min |
| MikoPBX | SIP support with outgoing route configuration | Varies |
4.3 Technical Details for Advanced Users
During a SIP call, Caller ID is transmitted in SIP message headers. The main headers that affect number display are:| Header | Purpose |
|---|---|
| From | Main header containing the caller's number. Most providers use this for Caller ID |
| P-Asserted-Identity (PAI) | Used for identity verification. Some providers require it for spoofing |
| Remote-Party-ID | Alternative header for Caller ID |
Recent Research: Semantic ambiguities in SIP implementations enable caller-ID and message-origin spoofing in the majority of tested server-client combinations, even when TLS and authentication are correctly deployed. This means that even with proper security, spoofing remains possible through header manipulation.
Security Concern: Authenticated users with outbound-call privileges can inject arbitrary SIP headers such as P-Asserted-Identity and Remote-Party-ID, enabling Caller ID spoofing on outgoing SIP calls in environments where the PBX operates as a trusted SIP peer.
Tip: If spoofing via "From" doesn't work, try configuring P-Asserted-Identity or Remote-Party-ID — some providers use these instead.
4.4 Typical VoIP Setup Mistakes
| Mistake | Consequence | Fix |
|---|---|---|
| Provider doesn't allow spoofing | Call goes out with your real number | Choose a provider that allows spoofing (Zadarma, CommPeak) |
| CallerID not specified in SIP account settings | Number not spoofed | Check the CallerID field in your provider's dashboard |
| Wrong number format | Spoofing fails | Use international format (+1XXXXXXXXXX for US) |
| Poor internet connection | Interruptions, echo, delays | Use wired internet or quality Wi-Fi |
| No test call | You don't know if spoofing works | Always test before the real call |
CHAPTER 5: METHOD 3 — MOBILE APPLICATIONS
5.1 Second Number Apps
Some applications (e.g., TextNow, Google Voice, OnPhone) allow you to choose which number is displayed when you call. However, they offer limited selection — only numbers tied to your account.Instructions:
- Install the app (TextNow, OnPhone, Phoner).
- Register and get a virtual number.
- In call settings, select which number to display.
- Make the call.
Limitation: You can't spoof just any number — only the one the app gave you. This isn't full spoofing, it's using a second number.
5.2 Apps with Caller ID Spoofing
Some applications (e.g., SpoofCard, Phoner) let you spoof any number directly from the interface.Examples:
| App | Functionality | Price |
|---|---|---|
| SpoofCard | Full Caller ID spoofing, call recording | $2.99/month + credits |
| Phoner | Second number + Caller ID spoofing | $5–10/month |
| Fake Caller ID | Number spoofing, limited free calls | Free / $5 |
5.3 Important Warning About Mobile Apps in 2026
Google and Apple are actively fighting spoofing apps. Android has introduced a new fake call detection feature that can flag suspected spoofed calls when your contact and you are both using Phone by Google. This means that even if you spoof the number, the system may warn the recipient about possible fraud.CHAPTER 6: METHOD 4 — SIM SWAPPING (EXTREME)
6.1 What Is SIM Swapping
SIM swapping (SIM swapping) is an attack where a fraudster transfers the victim's phone number to a SIM card they control, gaining full control over the number. This is not just spoofing a number for a call — it's taking over the entire number.How It Works:
- The fraudster gathers information about the victim (full name, date of birth, passport details).
- Calls the mobile carrier's store or uses an online channel, posing as the victim.
- Claims the SIM card was lost or damaged and requests a new SIM with the same number.
- Gains control over the number, including SMS for 2FA.
The Scale of the Problem: SIM swap fraud cases exploded 1,055% in the UK in 2025 according to Cifas. An estimated 25% of mobile subscribers in some markets have been affected. Carriers are now implementing real-time detection systems that can identify abnormal SIM or port-out activity within milliseconds.
6.2 Why This Method Is Extremely Risky
- Requires complete cardholder data. Without passport details, date of birth, and other personal information, it won't work.
- High detection risk. Carriers are constantly improving SIM swap protection. Hayo's updated platform includes advanced SIM swap detection capabilities that flag abnormal SIM or port-out activity within milliseconds.
- Criminal liability. This is not just fraud — it's a serious crime investigated at the intelligence agency level.
- Increased security measures. Mobile providers now offer additional verification requirements to help protect accounts.
When to Use: Almost never. This method is only justified in exceptional cases where the stakes are extremely high. For routine verification calls, it's not needed.
CHAPTER 7: COMPARISON TABLE OF METHODS
| Criterion | Dedicated Services | VoIP/SIP | Mobile Apps | SIM Swapping |
|---|---|---|---|---|
| Difficulty | Low | High | Low | Very High |
| Cost | $0.10–0.20/min | $0.005–0.05/min | $5–10/month | Very High |
| Flexibility | Medium | High | Low | Absolute |
| Reliability | Medium | High | Medium | High |
| Detection Risk | Medium | Low | Medium | Very High |
| Best For | Beginners | Experienced carders | Quick calls | Extreme cases only |
CHAPTER 8: STEP-BY-STEP ALGORITHM FOR A SUCCESSFUL VERIFICATION CALL
Step 1: Prepare Your Legend
Before the call, gather all cardholder data:- Full name
- Billing and shipping address
- Card number (last 4 digits)
- Date of birth
- Order number (if available)
- Items in the order
Step 2: Configure Spoofing
Choose your spoofing method based on the situation:- One-time call → SpoofCard or mobile app
- Series of calls → VoIP (cheaper and more reliable)
- Critical verification → VoIP with a quality SIP provider
Step 3: Test Call
Always test-call your second number before the main call. Check:- Whether the number is spoofed correctly
- Call quality
- Whether the name displays (if important)
Step 4: The Main Call
- Call during business hours in the cardholder's time zone
- Speak confidently, don't hesitate
- Be ready to answer questions (keep your script visible)
Step 5: After the Call
- Record the result (approved / declined / documents requested)
- If successful — continue the operation
- If something went wrong — burn the card and account
CHAPTER 9: ALL POSSIBLE ERRORS AND HOW TO FIX THEM
Error 1: Not Testing the Spoof Before the Call
How It Shows: You call, and the operator sees your real number.Fix: Always test-call your second number or a friend's number first.
Error 2: Using One Service for All Calls
How It Shows: The service blocks your account for suspicious activity.Fix: Rotate services. If you use SpoofCard for one order, use VoIP or another service for the next.
Error 3: Ignoring the Cardholder's Time Zone
How It Shows: You call the bank at 3 AM in the cardholder's time zone. The operator sees the spoofed number, but a call at odd hours raises suspicion.Fix: Always consider the cardholder's time zone and call during business hours (9:00–18:00).
Error 4: Spoofing Without a Legend
How It Shows: You call from the cardholder's number but don't know what to say. The operator asks questions, and you hesitate.Fix: Prepare a script before the call. Know the cardholder's name, address, recent transactions.
Error 5: Ignoring Call Quality
How It Shows: Voice cuts out, echo, delay. The operator becomes suspicious.Fix: Use a stable internet connection. For VoIP, choose a provider with good quality. Don't call through public Wi-Fi.
Error 6: Spoofing a Number That Doesn't Match the Legend
How It Shows: You spoofed +1 212... (New York), but the cardholder lives in California.Fix: The number must fully match the cardholder's data — area code, state, country.
Error 7: Ignoring Carrier Restrictions
How It Shows: Calls with spoofed numbers are blocked by carrier anti-fraud systems.Fix: Research the carrier's rules in the country you're calling. If spoofing is restricted, use other methods.
Error 8: Not Having a Backup Spoofing Method
How It Shows: Your primary service fails during the call.Fix: Always have a secondary spoofing method ready.
Error 9: Using the Same VoIP Provider for All Calls
How It Shows: Provider flags your account for suspicious activity.Fix: Rotate providers. Maintain multiple SIP accounts.
Error 10: Not Documenting Successful Calls
How It Shows: You repeat the same mistakes.Fix: Keep a log of what works and what doesn't. Learn from every call.
CHAPTER 10: PROFESSIONAL RECOMMENDATIONS
- Always have a backup spoofing method. If the primary service fails, switch to the backup.
- Don't call from the same account more than 2–3 times. Spoofing services may block you for suspicious activity.
- Use VoIP for long calls. It's cheaper and the quality is better.
- Check that spoofing works for both the number and the name. Some operators see not just the number but also the caller's name.
- Consider anti-fraud systems. In 2026, many operators use AI to detect spoofing. The more natural your voice sounds and the better your legend, the higher your chances of success.
- Stay updated on carrier regulations. In Russia, for example, the "Antifraud" system blocks more than 1.14 million fraudulent calls per day. Operators are required to transmit data about suspicious numbers to the state system.
- Use different proxies for carding and calling. If you call from the same IP used for the carding operation, the system may link them.
- Keep call recordings. If a call goes well, review it later to identify areas for improvement.
- Test your setup regularly. What worked last month may not work today.
- Maintain multiple SIP accounts. If one gets flagged, you have others ready.
CONCLUSION
Number spoofing is not just a "feature" — it's a critical tool. Without it, you risk not only losing the order but also burning the card, account, and legend.Choose Your Method Wisely:
- Beginners → SpoofCard or similar services
- Experienced carders → VoIP/SIP telephony
- Quick calls → Mobile apps
Always remember: spoofing is only half the success. The other half is your confidence, knowledge of the legend, and ability to conduct the conversation.
Final Warning: Caller ID (ANI) is context, not identity. It can be spoofed. But carriers and security systems are getting smarter. The days of easy spoofing are fading. The carders who will succeed in 2026 and beyond are those who understand not just how to spoof, but why it works, when it fails, and how to adapt when the defenses change.