I just received a call from a small-town insurance agent who said he was returning my call. I never called the agent, and when I call him back he said “this was the number that showed up on my caller ID”.
So my number was spoofed. I understand someone is making their number show up as mine on the caller ID, and that it’s not necessarily illegal.
Question…is my phone still secure? Can whoever is doing this receive calls or texts intended for my phone? Or, is this just a caller ID trick?
I’m concerned about the texts because I use those for login/authentication.
Thank you!
In many cases, this is a simple spoof which alters the displayed number on the end of the person receiving the call – not a compromised phone, and does not allow access.
However, there is a reason security professionals say not to use SMS for authentication flows: SMS is not secure. It is better than not having 2FA, but you should move towards a true token-based 2FA rather than SMS.