Banana Navy
Catalog FR
Lab · Threat modeling IA · Fiche détaillée

Caller ID / ANI spoofing

the caller presents a spoofed number or call identifier (Caller ID, ANI) to pass as a known or legitimate source before any verification. Impersonation is automatable at scale over a voice channel.

SheetF1
CategoryS-TB7-01 (spoofing, identité de l'appelant)
Layers1 · Call Entry, 12 · Identity & Context Check
Systemvoicebot IA

never treat an identifier alone (number, ANI) as proof of identity; cross-check with known context (CRM), out-of-band verification or a challenge on every sensitive action; a progressive trust policy based on the action's risk.

The threat

the caller presents a spoofed number or call identifier (Caller ID, ANI) to pass as a known or legitimate source before any verification. Impersonation is automatable at scale over a voice channel.

Angle mortWhy classic frameworks miss it

frameworks treat the call identifier as a trusted attribute; over a voice channel the number is data produced by the attacker, not proof. This is entry spoofing, not a downstream authentication flaw.

MitigationProposed approach

never treat an identifier alone (number, ANI) as proof of identity; cross-check with known context (CRM), out-of-band verification or a challenge on every sensitive action; a progressive trust policy based on the action's risk.

The proposed control
no sensitive action validated on the identifier alone.

Expected evidence
trace that spoofing the number is no longer enough to trigger a critical action.

SourcesReferences and public research

MITRE ATLAS 2026.07AML.T0043 Craft Adversarial Data
Recherche publiquePublic research sources: MITRE ATLAS 2026.07 (verified technique mapping), OWASP GenAI (catégories par abus de modèle), and the public risk-voicebot (aivansoul/risk-voicebot) template defining the 20 checkpoints. No client registry data: generic sheet, no rating, no verdict.
couche 1 · Call Entrycouche 12 · Identity & Context Check

Explore the 20 security layers

MITRE ATLAS 2026.07 · OWASP GenAI · risk-voicebot