Neighbor Spoofing: Why Scam Calls Come From Your Own Area Code (and Sometimes Your Own Number)
Four in ten FTC Do Not Call complaints this summer named a number in the complainant's own area code. That is neighbor spoofing — robocallers faking a local caller ID so you pick up. Here is how it works, what the Truth in Caller ID Act and STIR/SHAKEN do about it, and how to stop it reaching you.
Updated 2026-09-03 · By Andrew Pickett, OmegaIT
What neighbor spoofing is
Caller ID is a claim, not a credential. The system placing a call declares the number it wants displayed, and with VoIP software that is a one-line setting. Neighbor spoofing is the tactic of setting that display to a number that shares the target's area code — and often the next three digits, the exchange or NPA-NXX — so that the call looks like it comes from someone nearby: a neighbor, a local business, the school. People answer local-looking calls at far higher rates than out-of-state or toll-free ones, and the robocall industry optimizes for answer rate.
The scale shows up in the complaint data. Of the 289,434 FTC Do Not Call complaints filed between July 27 and September 2, 2026 that recorded the complainant's area code, 116,494 — 40% — named a calling number in that same area code. Genuine local calls account for some of that, but these are complaints about unwanted calls, overwhelmingly robocalls (68% of all complaints in the period), and a robocall campaign has no reason to be local to its victim except to look local.
The displayed number usually belongs to someone. Only 0.25% of the geographic US numbers named in complaints during the period had a prefix that is not assigned to any carrier in NANPA's records; the campaigns pick real, in-service prefixes precisely so the number passes a sniff test. The unlucky owners of those numbers get the angry callbacks — our spoofed-number guide is for them. When a number page on this site says a prefix is *not* assigned to any carrier, that is a rare and decisive tell that the caller ID was fabricated outright.
The law: Truth in Caller ID Act
Spoofing itself is not illegal in the US — a doctor calling from a personal cell may lawfully display the practice's main number, and a domestic-violence shelter may hide its outbound line. What the Truth in Caller ID Act of 2009 (codified at 47 U.S.C. § 227(e)) prohibits is transmitting misleading or inaccurate caller-ID information "with the intent to defraud, cause harm, or wrongfully obtain anything of value". Neighbor spoofing to sell a fake debt program or impersonate the IRS falls squarely inside that. The FCC can impose forfeitures per violation, and it has: multi-million-dollar penalties against spoofing operations are a regular feature of its enforcement releases, summarized in our FCC enforcement guide.
The 2019 TRACED Act extended the FCC's reach — longer statute of limitations for spoofing violations, no warning required before a fine, and a mandate for caller-ID authentication across the phone network. The FCC's spoofing consumer guide is the plain-English summary of what the rules cover and how to complain.
The technology: STIR/SHAKEN
STIR/SHAKEN is the industry's answer. When a call is placed, the originating carrier attaches a digitally signed attestation stating how confident it is that the caller is entitled to use the displayed number: A (full — the carrier knows the customer and the number is theirs), B (partial — knows the customer, not the number) or C (gateway — the call arrived from elsewhere and the carrier vouches for nothing). The terminating carrier verifies the signature and can show a checkmark or "Caller Verified" for A-attested calls, or feed the attestation into its spam scoring. Large US voice providers were required to implement it in the IP portions of their networks by June 30, 2021, with smaller providers following on later deadlines; every provider must also be registered in the FCC's Robocall Mitigation Database to have its traffic accepted by other carriers. The FCC's call authentication page tracks the program.
It has helped, and it has limits. A spoofed call originated by a compliant US carrier now arrives with a B or C attestation, or unsigned, and gets scored accordingly — that is part of why carriers can label so much traffic "Scam Likely" or "Spam Risk". But calls that enter the US through a gateway provider from overseas typically carry only a C attestation, non-IP legacy network segments cannot carry signatures at all, and an operation that has obtained numbers from a compliant carrier can have its calls A-attested and still be a scam. Authentication tells you the number was not faked; it does not tell you the call is welcome.
How to stop it reaching you
- Turn on your carrier's neighbor-spoofing filter. Verizon's Call Filter and the other carriers' apps can block or silence calls from numbers that share your own area code and prefix — the signature of neighbor spoofing — with an exception for your saved contacts. Our carrier guides for Verizon, AT&T and T-Mobile cover the settings.
- Silence or screen unknown callers on the phone. iPhone's Silence Unknown Callers and Screen Unknown Callers (guide) and Android's Call Screen and unknown-number blocking (guide) send unsaved numbers to voicemail or make them state their business first. Neighbor-spoofed robocalls almost never leave a message.
- Stop treating "local" as a reason to answer. The single behavioral change that defeats neighbor spoofing is to give a local unknown number exactly the skepticism you give an out-of-state one. If it matters, there will be a voicemail.
- Never call back a local number to "see who it was". If it was spoofed you reach a bystander; if it was the campaign's own line you reach the sales floor.
A call that displays *your own number* is a special case worth knowing: no legitimate network ever does that, so it is a 100% reliable scam tell. It is a lazy variant of neighbor spoofing — the campaign uses the target number as the display number — and usually carries a "your account has been compromised" script. Hang up.
Report it, and check the number
Report spoofed calls to the FCC at its consumer complaint center (choose Phone → Unwanted Calls, and mention spoofing) and to the FTC at DoNotCall.gov or ReportFraud.ftc.gov if there was a scam pitch. Complaints are how the FCC and the industry traceback group find the originating provider behind a campaign; the FTC's complaints are published daily and this site imports them, so the number you report will show the complaint within hours to the next person who searches it.
And before you decide about any local unknown number, look it up. The number page shows Do Not Call and FCC complaints, what people say the calls were about, whether the prefix is assigned to a carrier and to which one, and — for a neighbor-spoofed number — often a string of reports saying "this is my number and I did not call you". Your own area code's page lists the most-reported numbers in it this month, which is a fast way to recognize a campaign currently working your neighborhood.
Sources
Got a call from an unknown number?
Look it up free — carrier, location, FCC complaints and first-hand reports.
Related
FAQs
Why do scam calls come from my own area code?
Because people answer local-looking numbers more often. Robocall systems set the displayed caller ID to a number sharing your area code and often your exchange. In the FTC's Do Not Call complaints for late July to early September 2026, 40% named a number in the complainant's own area code.
Is caller ID spoofing illegal?
Spoofing with intent to defraud, cause harm or wrongfully obtain anything of value is illegal under the Truth in Caller ID Act (47 U.S.C. § 227(e)), enforced by the FCC. Displaying a different number for a legitimate reason — a business's main line, a shelter hiding its outbound number — is lawful.
Does STIR/SHAKEN stop neighbor spoofing?
It makes it visible rather than impossible. Carriers sign calls with an attestation of how sure they are the caller may use the number; spoofed calls arrive with weak or no attestation and get scored as suspicious. Calls entering from overseas gateways and legacy non-IP segments are still gaps.
Someone called me from my own phone number. How?
The caller simply typed your number into the caller-ID field. No network does this legitimately, so a call from your own number is always a scam. Your phone and account are not compromised; hang up and block nothing (there is nothing to block).
Should I call a local number back to find out who it was?
No. If the number was spoofed you will reach an innocent bystander who is probably already fielding angry callbacks; if it belongs to the campaign you reach its sales floor. Look the number up instead.