Why Caller ID Is Not Proof of Identity

Imagine that your phone rings. The caller ID shows your company’s name and phone number. The person on the other end says they’re a coworker, knows enough about the company to sound legitimate, and needs your help accessing a sensitive record.
Would you trust them?
A recent cyberattack involving healthcare company Astrana Health provides a good reason to think twice about messages like this.
What Happened to Astrana?
In September 2026, Astrana Health discovered suspicious activity involving a series of social engineering attempts.
According to the company’s filing with the U.S. Securities and Exchange Commission (SEC), attackers impersonated company personnel and spoofed Astrana Health’s main corporate telephone number while contacting their employees.
The goal was to convince those employees to provide unauthorized access to company systems.
Astrana’s cybersecurity team detected and responded to the activity, but the company determined that the incident was significant enough to report as a material cybersecurity incident because it potentially involved confidential and sensitive information.
This incident epitomizes a very simple lesson: Caller ID can lie.
What Is Caller ID Spoofing?
Caller ID spoofing allows a caller to disguise the number that appears on your phone. How does it work?
Instead of seeing an unfamiliar number, you might see the phone number of your company, bank, doctor’s office, government agency, or another organization you trust. This subterfuge makes social engineering much more convincing.
The caller can then add other information they’ve collected about the organization, often from public platforms or previous breaches. As a result, the attacker might know real employee names, departments, job titles, vendors, or internal terminology. Some of that information may come from company websites, social media, previous data breaches, and other publicly available sources.
By the time the phone rings, the attacker may already know enough to sound like they belong there.
How Impersonation Has Become a Huge Problem
This isn’t limited to one company. The FBI recently warned that scammers increasingly impersonate trusted organizations and officials through phone calls, texts, and emails. Between January 2025 and July 2026, the agency received nearly 61,000 complaints involving government or law-enforcement impersonation scams, with reported losses exceeding $1.6B.
Those scams targeted consumers, but the technique remains the same: Pretend to be someone the victim trusts, create a believable situation, and convince them to act.
Scammers can spoof legitimate phone numbers, email addresses, employee names, and credentials. Remember, social engineering isn’t only about stealing money. An attacker may also want access to sensitive information.
They could pretend to be an employee who needs a password reset. They might claim to be from IT and ask you to approve an MFA request. Someone posing as a manager could request a confidential customer file.
If you provide that access without properly verifying the person, then it could expose Personally Identifiable Information (PII), Protected Health Information (PHI), financial records, or other regulated information.
In other words, one convincing phone call can turn into a major compliance incident.
Familiar Information Is Not Authentication
To properly defend against these attacks, we need to change how we think about trust.
Knowing your manager’s name doesn’t prove someone is an employee. Knowing which department you work in doesn’t prove anything, either. Even seeing your company’s actual phone number on caller ID is no longer enough to ascertain someone’s real identity.
Treat those details as part of the conversation, not proof of identity.
If someone requests sensitive information, account changes, credentials, or access to a system, then follow your normal verification process every time.
Verify Through a Different Channel
Imagine that someone calls claiming to be your manager and asks you to send a confidential customer document immediately.
Don’t verify the request by asking, “Is this really you?” Of course they will say yes!
Instead, use a communication method you already know and trust. Hang up and call your manager using the number stored in your company directory. Send them a separate message through your normal workplace chat. Contact your IT department using its established internal number.
Most importantly, don’t use contact information provided by the suspicious caller to verify them. That defeats the purpose.
Attackers often want you to feel rushed so that you make mistakes and lower your usual defenses. They may claim a customer is waiting, an account is about to be disabled, a payment needs immediate approval, or an executive needs something before an important meeting. The pressure is intentional, but your company’s security procedures still apply, even when a situation is genuinely urgent.
Never provide your password or MFA code, approve an authentication request you didn’t initiate, or bypass normal access controls because someone says they need something immediately. If the request is legitimate, taking another minute to verify it shouldn’t be a problem.
Conclusion
The Astrana Health incident shows how convincing modern impersonation attacks have become. The attackers didn’t simply call from an obviously suspicious number. They impersonated employees while making calls that appeared to come from the company’s own corporate phone number.
That changes what we can trust in digital connections.
A familiar voice isn’t authentication. A familiar name isn’t authentication. These days, Caller ID isn’t authentication either.
When someone asks you for sensitive information or access to company systems, always verify the request through a separate, trusted method. The person on the phone may sound like they belong there, but you should still prove it through a verified communication system.


.png)


Comments