WASHINGTON, July 29, 2026 — The tools to fight phishing, robocalls and spam have multiplied over the past decade, but the criminals behind them keep adapting faster than any single defense can keep up, industry experts said Wednesday during a Broadband Breakfast Live Online panel.
Panelists said that there were no simple answers to the knot of problems. Authentication frameworks, traceback efforts, call blocking and enforcement all help, but only together, and only if consumers stay vigilant as scammers exploit cheap Internet-based calling and now artificial intelligence.
The rise of internet calling is what created both problems in the first place, according to Josh Bercu, executive director of the Industry Traceback Group at the trade association USTelecom. "It's become cheap and easy for you and me to call anyone around the country and around the world," he said. "Well, guess what? It's also cheap and easy for the bad guys to blow up our phones, call us from anywhere in the world."
That shift eliminated the old physical trust of wired networks. "If I'm providing service to the bank, I know they're the bank. I'm literally laying wire to the bank," Bercu said. "That all changed with the advent of internet calling platforms where I can say I'm a bank, and I might not be a bank."
The limits of STIR/SHAKEN
Much of the conversation centered on STIR/SHAKEN (Secure Telephone Identity Revisited and Signature-based Handling of Asserted Information Using toKENs), the call authentication protocol that both experts said was oversold. "Starshaken was never meant to be a silver bullet," said Joel Bernstein, vice president and head of U.S. public policy and government affairs at Somos. "This is a way we get to some level of understanding, and it's only in conjunction with other things."
Bernstein argued the industry needs to move toward a system he called right-to-use, which attaches cryptographic tokens to individual callers. "When I call, I have a cryptographic token that says, this is Joel Bernstein. Joel's been vetted," he said, describing a bank recognizing both the caller and itself as legitimate.
Even so, authentication has not solved the problem, Bercu said, because bad actors now obtain legitimate numbers. "Some bad callers now get access to numbers. So they can get the authentication. They have the right to use the number. They're still making bad calls."
Part of the challenge stems from a philosophical reversal in how carriers operate, Bernstein noted, recalling the Tom Wheeler-era FCC. "Competition, competition, competition. We want everybody in," he said. "Well, that opened the door to the bad guys. Now we're realizing, maybe it wasn't. [It] all started off great, but now it's been poisoned."
Calls, texts and emails
... continue reading