| TL;DR: Banks use phone calls to warn customers about fraud. But fraudsters can now make those calls appear to come from the bank itself, and AI is making familiar voices easier to imitate too. We spoke with TNS about what banks can still rely on when the signals people once used to recognize a legitimate caller can be copied. |
When New York nurse Avalon Grimes received a call from someone claiming to be from the fraud department at U.S. bank Chase, the number on her screen matched the Chase customer-service number printed on the back of her debit card.
But it wasn’t Chase.
The caller persuaded Grimes to transfer her money to another account, and she lost the savings she had been putting aside for a new home.
Her case shows why a familiar number no longer answers a basic question: who is actually calling? That matters for banks, which still need to reach customers about urgent account issues. In one survey, 70% of consumers said they had avoided a call because they feared fraud, only to later discover it was legitimate.
We spoke with Sharon Oddy, Vice President of Marketing at Transaction Network Services (TNS), about what happens when fraud weakens the communication channel banks use to fight it.
The Scam Can End. The Suspicion Doesn’t.
Grimes’ case involved caller ID spoofing. In simple terms, the fraudster made the call appear to come from a number they were not actually calling from.
The tactic works because the number on the screen used to tell you something about who was calling before you even answered. You might not know the person calling, but if your bank’s familiar number appeared, you had a reason to pick up.
Fraudsters can now borrow that familiarity to make an impersonation more convincing.
The FBI has warned about criminals posing as financial institution staff to obtain login details and one-time passcodes before taking over accounts. Since January 2025, its Internet Crime Complaint Center has received more than 5,100 complaints about account takeover fraud, with reported losses exceeding $262 million.
But TNS argues that measuring the money lost to an individual scam misses another cost.

That loss of trust is harder to measure.
Yet people have not simply stopped trusting banks. A 2026 Morning Consult survey for the American Bankers Association found that banks were the institution respondents trusted most to protect them from fraud. Among people who had received a fraud alert from their bank, 96% said those alerts were valuable.
Customers can trust their bank and still hesitate to trust a call claiming to come from it.
So if the phone number alone is no longer enough, what can tell them the call is genuine?
A Call Can Be Authenticated and Still Need Another Check
The telecom industry already has an answer to part of this problem.
It is called STIR/SHAKEN, a framework used by phone networks to digitally sign calls and provide information about how confidently the originating provider can vouch for the caller’s right to use a number.
The highest level is called A attestation. According to the Federal Communications Commission, it means the provider can confirm the identity of its subscriber and that the subscriber is authorized to use the phone number associated with the call.
That is useful. But there is an important distinction between authenticating how a call entered the network and knowing that everything about the call is legitimate.
TNS found that distinction showing up in its own data.
In its 2026 Robocall Investigation Report, TNS found that up to 13% of traffic using invalid numbers in 2025 was nevertheless signed with A attestation. The company points to improper attestation and techniques such as SIM boxes, which can make fraudulent traffic appear to originate from within otherwise legitimate networks, as part of the problem.
That does not mean STIR/SHAKEN has failed.
“STIR/SHAKEN is a critical layer, not the whole solution,” Oddy told SaaSTake.
A security check can be valid when it runs and still miss what changes afterward, a gap we explored in Finzly’s approach to continuous security assurance.
For banks making phone calls, the next question is whether they can protect their own numbers rather than depend on a single network signal to establish trust.
If the Number Isn’t Enough, What Else Can a Call Prove?
Banks therefore need other ways to establish that a call really originated with them.
TNS addresses this by authenticating calls and protecting a bank’s numbers from spoofing. Branded calling then builds on that.
Its Enterprise Authentication and Spoof Protection checks calls originating from a financial institution’s registered numbers and is designed to identify attempts to use those numbers without authorization. Its branded calling technology can then display identifying information such as the organization’s name and logo on supported devices.
The order matters. Authentication has to happen before branding can add much reassurance. Otherwise, a recognizable name or logo risks becoming just another signal that can be copied.
TNS points to an unnamed large US bank as one example. According to a case study published by TNS, the bank deployed the technology after fraudsters impersonated the institution. TNS says more than 130,000 spoofed calls were blocked in the first few months.
The unnamed case study does not report how that affected fraud losses or customer response rates.
Instead of waiting for a customer to recognize a suspicious conversation, the attempt to use the bank’s number can be challenged before the customer has to decide whether to trust the person speaking.
But the risk runs both ways.
Banks call customers. Customers also call banks.
And that side of the conversation is changing too.
What If the Familiar Voice Isn’t Enough Either?
For years, contact centers have used several pieces of information to help establish who is calling. A phone number can be one signal. A password or one-time code can be another. Some institutions have also used voice biometrics.
AI complicates the last of those.
Oddy told SaaSTake that AI-generated voice technology can be combined with caller ID spoofing so that a fraudster appears to be calling from a consumer’s number while also imitating the way that person speaks.
“Some financial institutions that implemented ‘my voice as my password’ several years ago need to rethink this type of security,” she said.
That does not mean every voice-authentication system can be defeated by an AI clone. But it does make a familiar voice less useful as proof on its own.
The FBI has warned that criminals can use AI-generated voices to impersonate known people. In banking, the problem can therefore run in both directions: a customer may need evidence that the bank is really calling, while the bank needs evidence that the person contacting its call center really is the customer.
Recognizing an identity is only part of the job. As we found in our look at Oak’s approach to enterprise identity, security increasingly depends on whether the signals around that identity support it.
For a bank, the phone number can provide some of those additional signals.
And that is where a recent change at TNS becomes relevant.
A Phone Number Can Tell a Bank More Than Who to Call
Beginning in January 2026, several commercial platforms formerly operated by iconectiv became part of TNS after Koch Equity Development acquired iconectiv.
The platforms give TNS access to additional information about phone numbers, including signals that can help banks assess whether a number still matches what they know about a customer.
A bank may know that a customer has a particular mobile number. But there are other questions it can ask. Has the number recently been moved to another carrier? How long has the SIM been associated with it? What type of line is it? Which provider currently owns it?
Phone-number intelligence from the former iconectiv platforms can provide signals including line type, SIM tenure, porting history and service-provider ownership.
Together, those details give a bank more context for deciding whether an interaction matches what it expects.
Oddy described the combination to SaaSTake as answering “both halves of the trust question”: whether the legitimate bank number calling a customer is being identified correctly, and whether the number contacting the bank still belongs to the actual customer.
That is a useful way to understand why the two sets of capabilities belong together.
TNS already had technology aimed at authenticating and protecting calls originating from a bank. The former iconectiv platforms add information that can help assess the phone number on the other side.
The phone number has not stopped being useful as an identity signal. It has stopped being enough to simply recognize it.
The Phone Call Now Has to Establish Itself First
TNS argues that voice should not sit outside fraud prevention as merely the channel used to deliver a warning.
“Financial institutions that treat call authentication and spoof protection as core trust infrastructure, not a telecom afterthought, are in a much stronger position to catch fraud earlier,” Oddy told SaaSTake.
That does not mean banks need to abandon the phone. Customers still value fraud alerts, and sometimes a direct conversation is exactly what is needed.
What is changing is what has to happen before that conversation can be trusted.
Go back to Avalon Grimes.
The number on her screen matched the customer-service number on the back of her Chase debit card. At one time, seeing those numbers match might have felt like verification.
The fraudster was able to reproduce the signal, but not the bank behind it.
Before a bank can use a phone call to verify what is happening in a customer’s account, it increasingly has another identity to establish first.
The call itself.





