⚠️ One sentence that summarizes the entire guide
The number on the display is not proof of identity. It never has been – it is an informational field declared by the party initiating the call, not something verified by the telephone network.
Therefore, the only effective response to a call "from the bank," "from the police," or "from the office" is: hang up and call back the number you found yourself – from the back of your payment card, from the official website, from the contract. Not the one from which you were called, and not the one provided by the caller.
CLI spoofing is impersonating someone else's phone number. The victim sees the number of their bank, police station, or tax office on the screen – and has no reason to doubt it. The rest of the scam builds on this one false foundation.
This guide explains why it is so easy to do, what Polish law has done about it since 2023, why the problem has not disappeared despite regulations, and – most importantly – what you can realistically do.
This material is for informational purposes only and does not constitute legal advice. We consciously do not describe how to perform spoofing – we explain the mechanism enough to understand and recognize it, without instructions for replication.
Where It Came From
The answer is uncomfortable: the telephone system was never designed to verify the caller's number. It relied on trust among a small number of operators who knew each other.
The American Federal Communications Commission described this very precisely in its 2020 decision:
“Technological advancements and marketplace developments in IP-based telephony have made caller ID spoofing easier and more affordable than ever before. (…) Driven in part by the rise of VoIP, the telecommunications industry has transitioned from a limited number of carriers that all trusted each other to provide accurate caller origination information to a proliferation of different voice service providers and entities originating calls, which allows consumers to enjoy the benefits of far greater competition but also creates new ways for bad actors to undermine this trust.”
In Polish: once, calls were initiated by a handful of operators who trusted each other and had a reason to care about their reputation. Internet telephony opened this gate to a vast number of entities – and the trust model remained the same. The FCC adds that previously, impersonating a number required advanced knowledge and expensive equipment, but today it is cheap and easy.
An analogy that clarifies this
The caller's number works like a sender's address on an envelope. The post office does not check it – it delivers the letter to where it is addressed, and what the sender wrote about themselves in the upper left corner is solely their declaration.
The difference is that with an envelope, everyone understands this. With a phone – they do not, because for decades the number has been practically reliable, and we have gotten used to trusting it.
Why It Can't Just Be Banned
This is the question everyone asks: since number substitution serves scammers, why don't operators turn it off?
Because the substitution of the presented number has completely legal and common applications. The FCC provides a direct example:
“Spoofing has legal and illegal uses. For example, medical professionals calling patients from their mobile phones often legally spoof the outgoing phone number to be the office phone number for privacy reasons, and businesses often display a toll-free call-back number. Illegal spoofing, on the other hand, occurs when a caller transmits misleading or inaccurate caller ID information with the intent to defraud, cause harm, or wrongly obtain anything of value.”
A doctor calling a patient from a private mobile phone displays the clinic's number. A large company with a hundred consultants shows one main number. A helpline presents a toll-free number. All of this is number substitution – and no one wants to ban it.
The same logic is embedded in Polish law. The statutory definition speaks of “unauthorized” use of someone else's address information – conversely, authorized use is not CLI spoofing in the meaning of the law. The British regulator Ofcom mandates blocking calls from abroad with a British number “except in a limited number of legitimate use cases”.
Thus, three independent legal systems say the same thing: the problem is not that number substitution is possible, but that it is necessary to distinguish authorized from fraudulent – and this is difficult and unreliable.
What Polish Law Has Done
As of September 25, 2023, the Act of July 28, 2023, on Combating Abuse in Electronic Communication is in effect. This is the first time it has named spoofing by name.
Statutory Definition
Article 3 paragraph 1 lists four prohibited abuses: generating artificial traffic, smishing, CLI spoofing, and unauthorized alteration of address information. CLI spoofing is defined as follows:
“unauthorized use or exploitation by a user or telecommunications entrepreneur initiating a voice call of address information indicating a natural person, legal person, or organizational unit without legal personality other than that user or telecommunications entrepreneur, serving to impersonate another entity, in particular for the purpose of causing fear, a sense of threat, or inducing the recipient of that call to a specific behavior, especially to provide personal data, unfavorable disposition of property, or installation of software”
Operator's Obligation
Article 16 is contained in one sentence and is unconditional:
“In order to prevent and combat CLI spoofing, the telecommunications entrepreneur blocks the voice call or hides the identification of the calling number for the end user.”
Article 19 adds that the operator must apply organizational and technical measures for monitoring, detecting, and exchanging information about spoofing. The law does not impose a specific technology – details can be specified in agreements with the President of UKE.
List of Numbers 'For Receiving Only'
This is the most ingenious element of the entire law and worth a separate explanation.
Article 17 mandates the President of UKE to maintain a public list of numbers intended solely for receiving voice calls, made available in the Public Information Bulletin. The entry occurs upon request – and the list of authorized entities is closed:
- banks, branches of foreign banks, and branches of credit institutions,
- National SKOK and cooperative savings and credit unions,
- investment firms, investment funds, and investment fund companies,
- payment institutions,
- insurance companies and reinsurance companies,
- units of the public finance sector,
- and separately – telecommunications operators, for their own customer service and helpline numbers.
The mechanism is simple and effective: if a bank reports its helpline number as “for receiving only,” then any outgoing call from that number is by definition spoofed – and operators must block it. The law gives them a specific deadline for this:
“The telecommunications entrepreneur providing voice call services shall immediately, no later than within 3 days from the date of entry of the number in the list (…) block incoming calls to its network using the number entered in this list.”
The President of UKE has 5 days to make the entry from the receipt of a complete application, and the list contains the number along with the date of entry and the date of possible removal. The provisions regarding the list come into force six months after the law, i.e., around March 2024.
Spoofing is a Crime
Article 31 provides for a penalty of imprisonment from 3 months to 5 years for anyone who, in order to gain financial or personal benefits or to cause harm, uses someone else's address information to induce the recipient to provide data, unfavorable disposition of property, installation of software, or providing passwords and access codes. In the case of lesser importance, a fine, restriction of freedom, or imprisonment for up to one year is threatened. An analogous Article 30 concerns smishing.
Separate financial penalties for operators who do not fulfill the obligation to block are also provided. Interestingly, the penalty for non-compliance with Article 16 came into force only a year after the obligation itself.
Important distinction: the purpose itself is a hallmark
Article 31 does not penalize every number substitution. It penalizes substitution “for the purpose of obtaining financial gain, personal gain, or causing harm to another person”. Displaying the clinic's number by a doctor is not a crime – and that is precisely what the legislator intended.
Why the Problem Has Not Disappeared Despite Regulations
Here we need to be honest, as an optimistic guide would be harmful in this matter.
Neither CERT Polska nor banks claim that the matter is resolved. CERT Polska states directly:
“Do not blindly trust the displayed number or the name of the caller. Criminals can falsify them!”
Bank Pekao formulates it identically: “Remember, criminals have the ability to spoof any phone number.” These are current messages published after the law came into effect.
There are several reasons, and it is worth knowing them, as they explain why caution is still on your side.
Poland Filters, But Does Not Authenticate
This is a technical difference with real consequences. The Polish model relies on detection and blocking – the operator must recognize a suspicious call and stop it. Effectiveness thus depends on what can be recognized.
An alternative approach is authenticating the number: cryptographically signing information about the caller so that the recipient's network can verify the signature. This is how the American STIR/SHAKEN works, mandated by the FCC for all voice service providers by June 30, 2021:
“That technology, known as STIR/SHAKEN, allows voice service providers to verify that the caller ID information transmitted with a particular call matches the caller's number.”
The system provides for three levels of certification. Level A means the operator confirms the subscriber's identity and their right to the number. Level B – identity yes, number no. Level C means only that the operator is the entry point to the network for a call that originated elsewhere – “such as a call that originated abroad”.
And here lies the crux: level C does not contain any statement about the caller's identity. Even in a country that has implemented full authentication, calls from abroad remain a weak link.
The British regulator considered authentication and consciously opted out
This is the best evidence that the problem is structurally difficult, not due to someone's negligence. Ofcom analyzed the introduction of number authentication and wrote:
“Although we think that CLI authentication has the potential to be effective at preventing some harmful calls from spoofed numbers, we have decided not to proceed with CLI authentication at this time. This is because CLI authentication on its own is unlikely to sufficiently hinder scam calls that originate overseas, and it'd be complex, costly and time-consuming to implement. We think that other measures could reduce number spoofing scams effectively and more quickly.”
Instead, the UK opted for solutions similar to the Polish ones: a Do Not Originate list – equivalent to our UKE list – and a mandate to block calls from abroad impersonating domestic numbers.
Calls from Abroad
All three systems – Polish, British, and American – have the same weak point. A call initiated outside the country reaches the domestic network through an interconnection gateway and loses a significant part of its context. Ofcom mandated operators to block such calls when presenting a British number, but does so with exceptions for legitimate uses – because a Brit calling from abroad with a British SIM card is a completely normal situation.
The List Covers Only Some Numbers
The UKE list protects numbers that have been reported – and only those whose owner belongs to the closed list of authorized entities. The number of your clinic, school, courier company, or neighbor cannot be on it. A scammer impersonating these numbers will not encounter this barrier.
There are simply no Polish statistics on voice spoofing
We checked the full text of the 2025 annual report from CERT Polska. The words “spoofing” and “vishing” do not appear in it even once. The report details phishing, ransomware, and sector incidents – it does not isolate phone scams.
This means that no one in Poland publishes the number of blocked spoofing calls or the number of victims. If you come across an article providing such data as official – it is worth checking where it came from.
The American numbers that are sometimes cited – over 58 billion robocalls in 2019 and damages amounting to $10.5 billion – come from private company research from 2019, cited by the FCC in footnotes. They are not statistics from the regulator or current data.
How to Recognize That a Number is Spoofed
The honest answer is: by the number itself – you can't. There is no feature on the display that distinguishes a real call from a spoofed one. Therefore, recognition must rely on the content of the conversation, not the number.
| Signal | Why It's a Signal |
|---|---|
| The bank's helpline number is calling | Helplines usually serve to receive calls, not to make them. Some of them are on the UKE list precisely as “for receiving only” |
| Time pressure | “We need to act immediately” shuts down verification. A real institution will wait for you to call back |
| Request for a code from an SMS, password, or PIN | No bank asks for this. This is a rule without exceptions |
| Request to install an app | Remote desktop applications give control of the device to a foreign person |
| Instruction to transfer funds to a “safe account” | Such an account does not exist. The police and the Polish Bank Association: “a real advisor will never ask for this” |
| Instruction to keep it secret | This is to cut you off from someone who would say: this is a scam |
| The caller discourages you from calling back | This is the only thing that exposes them – so they will protest |
| SMS “confirming” that the bank is calling | mBank states directly: “We do not send SMS messages to confirm that we are calling from mBank” |
Pay attention to one reverse pattern, described by CERT Polska in the 2025 report: sometimes it is not a scammer calling you, but an SMS or email urging you to call the specified number. CERT describes that a common element of these campaigns is “an attempt to induce the recipient to establish telephone contact at the specified number”, and in the conversation, there is a request to install remote access software. In this case, the number is real – because it belongs to the scammer – and no block will work.
What You Can Realistically Do
The Principle That Suffices in 99 Percent of Cases
Hang up and call back the number you found yourself.
Not the one from which you were called. Not through “call back” in the call history. Not the number dictated by the caller. Only the number from the back of your payment card, from the official website of the institution, or from the contract.
This is the recommendation of CERT Polska: “To verify the caller, hang up and call back, checking the correctness of the number beforehand. You can compare it with the number on the organization's website.”
This one action completely nullifies spoofing – because the scammer controls what you see on the display, but does not control the number you will call them back.
The sentence that concludes this is: “Thank you, I am hanging up and will call back the number from my card”. You do not need to justify it. A real employee will consider it reasonable. A scammer will start protesting – and that is the answer.
Verifying the Advisor in the Banking App
Three major banks allow you to check the identity of the caller without hanging up. PKO BP states it directly: “During a conversation with a bank employee, say that you want to verify their identity in the IKO app”. Bank Pekao: “ask for verification of their identity in PeoPay or Pekao24 or hang up”. In mBank, the consultant sends a notification themselves.
The defensive rule in mBank is formulated without a loophole: if the notification is absent or the caller claims that “they cannot send you such a notification, e.g., due to technical problems” – “hang up as soon as possible to avoid fraud”. “Technical problems” are not an excuse, but a signal.
mBank adds one more sentence that dismantles a popular trick: “We do not send SMS messages to confirm that we are calling from mBank”. An SMS “confirming” the identity of the caller is therefore false by definition.
UKE List – A List of Numbers That Never Call
This is a tool that almost no one knows about, yet it is public. The list of numbers designated solely for receiving calls – UKE calls it the DNO list – is available without logging in:
- information page:
bip.uke.gov.pl/wykaz-dno/ - the table with numbers:
numeracja.uke.gov.pl/pl/orvc_tables
The UKE instruction states about the numbers entered: “Calls cannot be made from a number entered in the list – it is intended solely for receiving calls.”
The logic is the opposite of intuitive and therefore useful: the presence of a number on the list means that every incoming call from that number is spoofed. The list contains the number along with the dates of entry and removal.
We were unable to read how many numbers are in the list or whether it has a search function – the table loads with a script, and the UKE service blocks automatic access. Check it yourself in your browser.
Settings on the Phone
Android. In the Google Phone app, there is a “Call Filtering” feature, available via Phone → More → Settings → Spam and Call Filtering. You can choose a level: “Maximum protection,” “Medium protection,” or “Basic protection,” and on newer Pixel phones, there is “Automatic call filtering.” Note: Google’s descriptions largely refer to Pixel phones, and we have not confirmed that the feature works the same on all Androids in Poland.
iPhone. In the Polish Apple manual, the relevant section is titled “Classifying and Blocking Calls”. We were unable to read the exact path in the settings from the official documentation, so we do not provide it – instead of guessing, look for this section in the iPhone manual on the Apple support page.
Beware of Two False Senses of Security
Call filtering does not protect against spoofing. Filters work on unknown and suspicious numbers – and spoofing is precisely about making the number look known and trusted. A call “from the bank” will pass through the filter, as it is supposed to work.
Orange's Cyber Shield does not apply to voice calls. It is a network protection service – blocking dangerous websites and phishing. We checked the product page and there is not a single mention of voice calls or spoofing. Do not assume that it protects you from this. We have not verified the anti-fraud services of Play, T-Mobile, and Plus.
Caller Identification Apps
Apps that show “who is calling” usually require access to the address book and send it to the provider – along with the numbers of your friends who have not consented to this. This is a real privacy cost.
We did not find an official position from UODO, CERT Polska, or UKE on this matter, so we do not attribute this assessment to any authority and do not recommend any specific app. We only signal that the choice is not free.
Where to Report a Suspicious Call
Here is a correction to what is often written – including our earlier guide on loan scams.
| Channel | What It Accepts |
|---|---|
Form incydent.cert.pl | Has a separate category “Suspicious Phone”. The form asks for complete information about the call, who the caller pretended to be, and what they urged. This is the proper channel for voice calls |
| SMS to number 8080 | Only SMS. The law speaks of reports “from short message service (SMS) recipients.” Free of charge. You cannot report a voice call there |
| mObywatel, service “Safe Online” | Reporting a malicious site, scam, or other incident |
| Your bank | If the caller impersonated a bank – report it on the official helpline. Banks have their own anti-fraud teams |
| Police | If there was a loss or attempted fraud. Spoofing is a crime under Article 31 of the law |
When reporting, record: the number from which you were called, the exact date and time, who the caller pretended to be, and what they demanded. If emails came with “documents” – keep them with headers, do not delete.
No one will notify you that the call has been blocked
We checked this in the text of the law: Articles 16 and 19 mandate the operator to block the call or hide the number, but do not provide any obligation to inform the recipient. All informational obligations in this law concern SMS senders and public entities.
The practical conclusion: the lack of information about a blocked call proves nothing – neither that the system works nor that it does not work.
If You Run a Business or Institution
If your organization belongs to the circle of authorized entities – a bank, SKOK, investment firm, fund, payment institution, insurance company, or a unit of the public finance sector – you can register your helpline number in the UKE list and ensure that no one will impersonate it.
- The application is submitted to the President of UKE at their electronic delivery address.
- It must be signed with a qualified, trusted, or personal signature.
- The application must include a document confirming the right to dispose of the number.
- The President of UKE makes the entry within 5 days of receiving a complete application, and operators block calls within 3 days of the entry.
- Instruction:
bip.uke.gov.pl/jak-uzyskac-wpis-w-wykazie-dno/
There is one condition that is absolute: calls cannot be made from such a number. If your helpline calls back customers, you need a separate number for that.
Frequently Asked Questions
Can you tell by the display that a number is spoofed?
No. There is no distinguishing feature. Therefore, recognition relies on the content of the conversation – time pressure, requests for codes, installation of apps, or transfers – and not on the number.
If there is a law, why do they still call me?
Because the Polish model relies on detection and blocking, not on cryptographic authentication of the number. Effectiveness depends on what the operator recognizes. Additionally, there are calls from abroad – a weak point of every system, including the American STIR/SHAKEN, where calls from outside the network receive a certification that does not contain any statement about the caller's identity.
Is calling back the displayed number a good idea?
No, it is not verification. You will reach the real owner of the number, who knows nothing – and if the number belongs to a scammer, you will confirm to them that you are answering. Call only the number found independently.
Can I demand that the operator block a specific number?
We have not verified whether and under what conditions Polish operators offer such a service – we could not reach the product pages. Ask your operator directly. Keep in mind that blocking a specific number is not very effective against spoofing, as the scammer can change the displayed number at will.
How many such scams are there in Poland?
It is unknown. The annual report from CERT Polska for 2025 does not contain the word “spoofing” or “vishing,” and UKE does not publish statistics on blocked calls in the places we reached. Any number presented as “official statistics on spoofing in Poland” requires checking the source.
Is impersonating a number always a crime?
No. Punishable is unauthorized substitution made for a specific purpose – financial or personal gain or causing harm. A doctor displaying the clinic's number or a company showing the main number does not commit a crime.
Related Materials
- Loan Scam Using Your Data – the most common scenario in which spoofing is used.
- Banking and Internet Scams in Poland: Phishing, Spoofing, Fake BLIK – broader context.
- Grandchild and Policeman Scams – how to remotely protect parents in Poland.
- Voice Cloning and Grandchild Scam – when the voice on the line sounds familiar.
- How to Secure Your PESEL Number Step by Step – when data has already leaked.
One sentence to send to parents
The number on the display can be spoofed – even the bank number and the police number. If someone calls and demands something, hang up and call back the number you find yourself. That's all.
As of August 28, 2026. This material is for informational purposes only and does not constitute legal advice. We have consciously indicated what could not be confirmed at the source: the number of numbers in the UKE list, statistics on blocking effectiveness, anti-fraud services of operators other than Orange, the exact path of the function on iPhone, and the existence of a European equivalent of the American STIR/SHAKEN. We also do not describe how to perform spoofing – this is a defensive guide.
Comments (0)
No comments yet. Be the first!