DCUC, ACU Join With Other Groups in Urging FCC to Strengthen Rules on Fraud Calls, Impersonation Scams

WASHINGTON — The Defense Credit Union Council and America’s Credit Unions have joined banking, payments and other financial services trade groups in urging federal regulators to strengthen requirements aimed at stopping fraudulent calls that impersonate financial institutions and other legitimate businesses.

In joint comments filed with the Federal Communications Commission, the groups expressed support for proposed changes to the agency’s caller ID authentication rules and its requirements governing telecommunications providers that receive call traffic from other providers.

The Aug. 10 letter was signed by 13 organizations, including DCUC and America’s Credit Unions, along with the American Bankers Association, ACA International, American Financial Services Association, Bank Policy Institute, Consumer Bankers Association, Electronic Transactions Association, Financial Technology Association, Mortgage Bankers Association, National Council of Higher Education Resources, Payments Leadership Council and Student Loan Servicing Alliance.

‘Subtantial Harm’

The organizations said fraud and scams continue to cause substantial financial and emotional harm to consumers. They cited a Federal Trade Commission estimate that fraud and scam losses totaled $196 billion in 2024. Another report found that 6% of U.S. adults — an estimated 15.1 million people — said they were scammed out of money in 2025.

Banks, credit unions and other financial services providers frequently encounter scams in which criminals spoof the telephone numbers of trusted financial institutions, the groups said. Fraudsters may make calls appear to originate from a financial institution’s fraud department or customer service line and then persuade consumers to disclose sensitive account information that can be used to steal money.

The groups said the financial services industry spends billions of dollars annually educating and protecting consumers, investigating suspected criminal activity and helping victims recover funds, but said financial institutions cannot address the problem alone.

What’s at Issue

At issue is the FCC’s STIR/SHAKEN caller ID authentication framework, under which calls receive different levels of “attestation” from originating providers. The groups said weaknesses in the system can allow illegally spoofed calls to receive authentication that makes them appear legitimate.

Under the system, an A-level attestation indicates that the originating provider knows the caller and knows the caller has the legal right to use the telephone number displayed on caller ID. A B-level attestation means the provider knows the caller but does not know whether the caller has the right to use the number.

But an analysis conducted for the ABA of 12,900 calls that illegally spoofed telephone numbers belonging to 47 large banks, retailers and health care providers found that more than half received an A- or B-level attestation. The filing’s footnote says 80.2% of the calls examined received one of those two authentication levels.

The organizations said that when an illegally spoofed call receives an A- or B-level attestation, it can appear more trustworthy to consumers and may be less likely to be blocked.

Recommended Changes

Among the changes supported by DCUC, America’s Credit Unions and the other groups are:

  • Stronger verification before calls receive an A- or B-level attestation. The groups said originating providers should be required to verify that customers have the legal right to use the telephone number displayed on caller ID rather than relying on a customer’s general representation that it is authorized to use the number.
  • Specific “know-your-upstream-provider,” or KYUP, requirements. Telecommunications providers should be required to conduct due diligence on providers from which they receive call traffic.
  • Verification during onboarding. Downstream providers should collect specified information from upstream providers and verify its validity and authenticity before entering or renewing agreements.
  • Ongoing monitoring. Providers should monitor upstream providers’ compliance with FCC rules as well as the types of calls they transmit.
  • Action against providers carrying illegal calls. Providers should refuse or discontinue service when their review determines that an upstream provider is transmitting illegal calls.
  • Written policies and procedures. Voice service providers should establish specific policies and procedures for complying with KYUP requirements.
  • Stronger FCC enforcement. The groups urged the commission to provide sufficient funding and staffing to investigate violations and bring enforcement actions when appropriate.
    The organizations said existing FCC rules require downstream providers to take steps to ensure an upstream provider is not using their networks to carry a high volume of illegal traffic. But they argued the rules lack minimum requirements for due diligence, documentation, monitoring and responses to suspected illegal traffic.

Additional Support for Rule Change

The groups also backed changing the rule to make clear that providers must take measures to prevent an upstream provider from using their networks to transmit any illegal call rather than only a “high volume” of illegal traffic.
The trade groups said stronger requirements are particularly important for calls purporting to come from banks and credit unions because consumers may be more likely to trust a call displaying the number of a familiar financial institution.

“If an A-level attestation is applied to these calls without meaningful verification — as happens today — the authentication framework inadvertently strengthens the fraudster’s ability to deceive the consumer,” the groups said.

The organizations said adopting the FCC proposals would reduce consumer harm, increase accountability among telecommunications providers and improve the reliability of caller ID authentication.

“Illegal spoofed calls that impersonate banks, credit unions, and other legitimate businesses inflict serious harm on consumers and undermine trust in the U.S. telecommunications network,” the groups said.

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.