Home
 » ISP News, Key Developments » 
Sponsored Links

Ofcom Propose New Ban to Tackle Abuse of UK Mobile Networks

Monday, Jul 22nd, 2024 (11:23 am) - Score 9,440
Signal tower service concept

Market regulator Ofcom has proposed to ban UK telecoms operators from leasing Global Titles – numbers like +44 (for the United Kingdom) that support mobile services – to third parties. This is because such leasing can be misused to try and intercept messages and calls, disrupt the operation of networks and track the location of users of other networks.

According to the regulator, a small number of operators have been leasing their Global Title numbers to third parties, which can be done to facilitate the provision of legitimate mobile services. But Ofcom also found that this can make it easier for “bad actors” to abuse the system. As a result, +44 Global Titles are “one of the most significant and persistent sources of malicious signalling traffic affecting mobile networks globally“.

NOTE: Global Titles are used to send and receive signals that help locate and connect mobile phone users to networks and to one another.

The National Cyber Security Centre (NCSC) is also aware that +44 Global Titles have been exploited for malicious purposes, such as location tracking and the interception of SMS (text messages) used for 2-step verification (2SV) to target both UK residents and populations globally. Suffice to say that the regulator is aware of how this “gives rise to reputational risk to the UK as these harms have regularly been facilitated by the misuse of UK mobile numbers.”

Advertisement

Ofcom added that the current measures, such as the GSMA Global Title Leasing Code of Conduct and controls implemented by some Global Title lessors (e.g. signalling firewalls which block unauthorised message types and monitoring tools), have “not been effective at preventing malicious signalling“. As a result, they believe that intervention is now both “necessary and proportionate“.

Ofcom’s Proposal

We are proposing to strengthen our existing rules and introduce new rules to tackle misuse of Global Titles, in particular by:

• banning leasing of Global Titles to third parties by operators that hold UK mobile numbers;

• banning the creation of Global Titles from sub-allocated numbers by third parties;

• strengthening our rules to prohibit the misuse of Global Titles by operators that hold UK mobile numbers; and

• strengthening our rules to prohibit the creation of Global Titles from numbers not allocated for use.

Taken together, these proposals should significantly reduce malicious signalling from UK Global Titles, thereby providing material benefits to UK and international citizens. They should also enhance the transparency and accountability of operators that use Global Titles.

We consider that these proposals are appropriate and proportionate. They will result in a significant reduction in harm to UK and international citizens which we consider outweighs the adverse impacts on lessors and lessees that we have identified. Our assessment suggests that any adverse impacts are likely to be limited, in particular due to the availability of alternative ways of providing legitimate mobile services that are currently facilitated by the leasing of Global Titles.

We propose that the rules to prohibit misuse of Global Tiles by operators that hold UK mobile numbers and the rules to prohibit the creation of Global Titles from numbers not allocated for use should come into force immediately after the publication of our final decision.

Ofcom’s consultation on all this will remain open for feedback until 15th October 2024 and they’ve also provisionally proposed that the ban on leasing, alongside the ban on creating Global Titles from sub-allocated numbers, should then come into force from 1st January 2026. “This should provide the relevant parties with sufficient time to migrate to alternative solutions and dissolve legacy arrangements,” added the regulator.

Just to get a bit technical. The issue above specifically relates to the Signalling System No. 7 (SS7) protocol suite, which is used by 2G and 3G mobile networks (not 4G, which uses the Diameter protocol) to facilitate the provision of mobile services (e.g. authenticating handsets to the network, setting up and terminating calls, sending SMS messages, subscriber profile management and to facilitate roaming).

The above consultation is thus about the security risks arising from SS7 signalling associated with GTs formed from +44 mobile numbers. But users of 4G and 5G networks can also be affected by malicious SS7 signalling because 2G and 3G networks operate alongside 4G and 5G networks, providing fallback coverage in areas where 4G or 5G coverage is not yet available.

Advertisement

Share with Twitter
Share with Linkedin
Share with Facebook
Share with Reddit
Share with Pinterest
Mark-Jackson
By Mark Jackson
Mark is a professional technology writer, IT consultant and computer engineer from Dorset (England), he also founded ISPreview in 1999 and enjoys analysing the latest telecoms and broadband developments. Find me on X (Twitter), Mastodon, Facebook, BlueSky, Threads.net and .
Search ISP News
Search ISP Listings
Search ISP Reviews
Comments
8 Responses

Advertisement

  1. Avatar photo Rik says:

    Fantastic. Anything that can be done to stop these annoying calls from abroad is welcome to me. I work for an ISP and have to deal with the fallout of these malicious calls on a daily basis.

    1. Avatar photo Stewie says:

      I used to work for one but now work for an energy company and the amount of people using these scam numbers are so high, I feel sorry for those who they do con out of money

  2. Avatar photo Ferrocene Cloud says:

    You should not be able to do it, simple as. If you want to outsource it as a business, you deal with the consequences.

    This will probably shift companies into using their own UK voice gateways and routing the traffic overseas, but you can target their assets and target them with the law.

    All +44 numbers should be onshore, authenticated, held or managed by reputable companies with onshore assets and employees that can be held accountable in the event of abuse.

  3. Avatar photo Al says:

    Jfdi. That’s your job, OFCOM.DO.IT.
    For once.

  4. Avatar photo Frustrated says:

    What steps are being taken in the meantime? Jan 2026 is very slow.

    I’m sure many of these fraudsters are already known…..surely we should be going after them now?

  5. Avatar photo Stephen says:

    is this to combat “number spoofing” or something else entirely?

    1. Avatar photo GSMA CoP says:

      Something else entirely – this has got nothing to do with cli spoofing or most other means of using UK numbers to facilitate fraud against UK residents through misleading voice calls. Read the Ofcom consultation……….

  6. Avatar photo Acdeag says:

    Not sure I understood a word of this article 🙂

Comments are closed

Cheap BIG ISPs for 100Mbps+
Community Fibre UK ISP Logo
200Mbps
Gift: None
Youfibre UK ISP Logo
Youfibre £23.99
150Mbps
Gift: None
Virgin Media UK ISP Logo
Virgin Media £23.99
132Mbps
Gift: None
Plusnet UK ISP Logo
Plusnet £24.99
145Mbps
Gift: £145 Reward Card
NOW UK ISP Logo
NOW £25.00
100Mbps
Gift: None
Large Availability | View All
Cheap Unlimited Mobile SIMs
iD Mobile UK ISP Logo
iD Mobile £16.00
Contract: 24 Months
Data: Unlimited
Talkmobile UK ISP Logo
Talkmobile £16.95
Contract: 1 Month
Data: Unlimited
Smarty UK ISP Logo
Smarty £17.00
Contract: 1 Month
Data: Unlimited
ASDA Mobile UK ISP Logo
ASDA Mobile £19.00
Contract: 24 Months
Data: Unlimited
Three UK ISP Logo
Three £20.00
Contract: 24 Months
Data: Unlimited
Cheapest ISPs for 100Mbps+
toob UK ISP Logo
toob £18.00
150Mbps
Gift: None
Gigaclear UK ISP Logo
Gigaclear £19.00
300Mbps
Gift: None
Community Fibre UK ISP Logo
200Mbps
Gift: None
Beebu UK ISP Logo
Beebu £23.00
100 - 160Mbps
Gift: None
Hey! Broadband UK ISP Logo
150Mbps
Gift: None
Large Availability | View All
Promotion
Sponsored

Copyright © 1999 to Present - ISPreview.co.uk - All Rights Reserved - Terms , Privacy and Cookie Policy , Links , Website Rules , Contact
Mastodon