Nothing on a phone call, text, or email proves who actually sent it — and that single gap drains billions of dollars a year from families, seniors, and the companies whose names get borrowed without permission.
A caller ID, an email header, and a text message sender field can all say whatever the sender wants. The numbers below are why that gap matters, and why a verified sender identity standard is worth building.
According to the FBI IC3 group at www.ic3.gov
The FBI's Internet Crime Complaint Center (IC3) received 859,532 complaints in 2024, reporting losses exceeding $16.6 billion — a 33% increase over 2023. Almost none of this requires technical sophistication on the attacker's side; it requires only that the victim trust who appears to be contacting them.
Older adults are the most targeted and the most damaged group in these figures, and the trend is accelerating.
Tech support fraud, romance scams, and cryptocurrency fraud were the top categories affecting older adults. Each of those categories typically opens with a message or call impersonating someone the victim has reason to trust — a company, a romantic interest, or an advisor — which is precisely the trust that sender verification is designed to make harder to fake.
A specific, high-volume slice of this problem: calls and messages spoofed to look like they're coming from a federal agency.
In every case, the caller relies on the same weakness: nothing in today's phone, data, or messaging systems cryptographically proves who is actually calling. Caller ID can be spoofed outright. A verified sender identity standard closes exactly this gap — the enduser's device can confirm the sender's claimed identity before the victim ever has to decide whether to trust a stranger's voice.
The same trust gap is exploited against companies, not just consumers. Robocall operations record a message that name-drops an airline, hotel chain, or travel site the victim already trusts, then route anyone who engages to an unrelated call center. The brand did nothing wrong and has no way to stop its name from being used — there is no verified sender field standing between the caller and the enduser's phone.
Airlines sit in the same exposed position: a recorded call claiming to be "your airline" about a delayed flight, a fare refund, or a loyalty-account issue is functionally indistinguishable to the enduser from a real one, because nothing on the call cryptographically ties it to the airline's actual identity. The airline absorbs reputational damage and customer-service costs from calls it never placed, on top of whatever the victim loses to the scam itself. A verified sender identity standard would let an airline's calls (and a bank's, an airline partner's, or a government agency's) carry a check the enduser's device can confirm — collapsing the exact gap that made the Abramovich, TripAdvisor, and Marriott case possible.
STIR/SHAKEN proved that call authentication works at carrier scale. Extending a verified sender identity standard — to phone, text, and email alike — is a policy and engineering choice, not a technical impossibility. The FCC's Call Authentication Trust Anchor docket (WC Docket No. 17-97) is the open, active proceeding where that extension is being decided right now.