Home
 » ISP News, Key Developments » 
Sponsored Links

Ofcom UK Propose New Rules to Tackle Mobile Messaging Scams

Wednesday, Oct 29th, 2025 (9:19 am) - Score 320
Three-UK-Parcel-Fraud-scam

Ofcom has today announced a “comprehensive package of planned measures” that are designed to improve protection for mobile phone users against messaging scams. According to the regulator, some 50% of UK mobile users said they received a suspicious message between Nov 2024 and Feb 2025 via text or iMessage, but it’s hoped today’s changes may reduce that figure.

Most of the United Kingdom’s major broadband, phone and mobile network operators have already implemented various technical measures to tackle things like Nuisance Calls, Scam Calls and Scam Texts (e.g. mobile operators block an estimated 600 million+ messages each year). But these aren’t always 100% effective, and there are still plenty of operators and device manufacturers that could do more.

NOTE: An estimated 100 million suspicious messages were reported to UK mobile operators through the 7726 service in the year to April 2025.

In particular, scammers often use mobile messaging services to reach victims at a mass scale and manipulate them into making payments or sharing sensitive information (e.g. pretending to be government services or parcel delivery firms – business messaging scams).

Advertisement

Sometimes they may even impersonate a friend or family member texting from a different number, often asking for money in a fabricated emergency situation (i.e. person-to-person messaging scams). This criminal activity causes significant financial and emotional harm to UK people and businesses and damages their confidence in vital communications services.

Ofcom-How-Messaging-Scams-Work

The Proposed Rules for Tackling Messaging Scams

Person to Person (P2P) Messaging

In order to tackle person-to-person messaging scams, Ofcom are proposing that mobile providers must: 

  • set volume limits for pay-as-you-go SIM cards. This will make it harder for scammers to message large numbers of potential victims at once; 
  • block numbers used by scammers. Providers must use scam reports from customers and third parties – such as law enforcement – about phone numbers and web links that are being used to perpetrate scams. They must then prevent scammers from sending messages from these numbers;  
  • block scam messages in transit. Providers must identify and block scam messages being carried on their networks by detecting malicious sender IDs, weblinks, and phone numbers.  

Business Messaging

To disrupt business messaging scams, the regulator is proposing that mobile operators and ‘aggregators’ that transmit businesses’ mobile messages must: 

  • conduct upfront and ongoing due diligence checks. Effective “Know Your Customer” checks must be carried out on new business message senders to prevent criminals from sending mass texts. Similarly, “Know Your Traffic” checks should be completed, including reviewing account activity and promptly investigating reports of fraud; 
  • prevent use of fake sender names (known as Alphanumeric Sender IDs). Providers must corroborate business message senders’ Sender IDs, which show who a business mobile message came from, against information they’ve gathered about the business (to check, for example, that a business that purports to be hairdresser is not sending parcel delivery messages – indicating a scammer). They must also maintain a policy on protected sender ID lists and generic sender IDs (such as ‘customer service’); 
  • apply incident management processes. Where scam activity is identified, root out criminals who are using business messaging services and hold companies to account where they have not conducted appropriate checks; and 
  • block scam messages in transit. Providers must act on scam reports from users and third parties to detect and block malicious weblinks and phone numbers. 

The measures are designed to “further disrupt scammers, raise the bar across the mobile industry and address current gaps in protection for consumers and businesses“. But some of the proposals, like the idea of putting volume limits on PAYG SIMs, could impact legitimate consumers too if not carefully considered. This is especially relevant given how most PAYG plans are more like normal Pay Monthly services today, albeit often on shorter 30-day terms (i.e. the definition between what is Pay Monthly and PAYG has become somewhat confused).

However, we understand that the volume limits would focus more on how many messages get sent via a SIM over a specific period of time, which we presume would be set to try and separate automated activity from human usage. Most, but not all, mobile operators in the UK already set such limits (varies between 100 per hour to tens of thousands a month), but even when adopted their application and enforcement can vary a lot (e.g. sometimes further texts are blocked, while in other cases accounts get sent for manual review). Ofcom seems to be seeking to standardise a more effective approach.

Advertisement

Ofcom are also proposing new rules for all mobile operators and aggregators to ensure the requirements are effective and to minimise the risk that providers block legitimate messages. These include: a right to challenge where numbers or messages are blocked; and requirements relating to reviewing policies, training staff, record keeping, compliance with data protection legislation and the continued transmission of legitimate messages.

Amy Jordan, Ofcom’s Strategy Delivery Director, said:

“Messaging scams can have a devastating impact on their victims. Our plans will ensure that mobile firms consistently apply proven measures to thwart these crimes. That means locking scammers out of networks and blocking hundreds of millions more scams from getting through to people and businesses each year.”

Ofcom’s related consultation on all this is now open for responses until by 5pm on 28th January 2026 and, after that, they aim to publish their final decision sometime during summer 2026.

Share with Twitter
Share with Linkedin
Share with Facebook
Share with Reddit
Share with Pinterest
Mark-Jackson
By Mark Jackson
Mark is a professional technology writer, IT consultant and computer engineer from Dorset (England), he also founded ISPreview in 1999 and enjoys analysing the latest telecoms and broadband developments. Find me on X (Twitter), Mastodon, Facebook, BlueSky, Threads.net and .
Search ISP News
Search ISP Listings
Search ISP Reviews
Comments
3 Responses

Advertisement

  1. Avatar photo Simon M says:

    “some 50% of UK mobile users said they received a suspicious message between Nov 2024 and Feb 2025 via text or iMessage”

    Likely the other 50% didn’t realise it was a suspicious message and got scammed…

  2. Avatar photo Kyle says:

    How about they sort out the price rise scams, facilitated by their own lack of oversight?

  3. Avatar photo john says:

    “Providers must identify and block scam messages being carried on their networks by detecting malicious sender IDs, weblinks, and phone numbers.”

    Hmm suspicious wording. I would hope for end-to-end encrypted services such as iMessage that the spam filters on the receiving device would be sufficient to meet the new requirement? If they are literally required to ‘block scam messages being carried’ then that could be a worrying escalation of the government’s war on our privacy.

Leave a Reply

Your email address will not be published. Required fields are marked *

NOTE: Your comment may not appear instantly (it may take several hours) due to static caching and moderation checks by the anti-spam system. Please be patient. We will reject comments that spam, troll, post via known fake IP/proxy servers or fall foul of our Online Safety and Content Policy.
Javascript must be enabled to post (most browsers do this automatically)

Privacy Notice: Please note that news comments are anonymous, which means that we do NOT require you to enter any real personal details to post a message and display names can be almost anything you like (provided they do not contain offensive language or impersonate a real persons legal name). By clicking to submit a post you agree to storing your entries for comment content, display name, IP and email in our database, for as long as the post remains live.

Only the submitted name and comment will be displayed in public, while the rest will be kept private (we will never share this outside of ISPreview, regardless of whether the data is real or fake). This comment system uses submitted IP, email and website address data to spot abuse and spammers. All data is transferred via an encrypted (https secure) session.
Cheap BIG ISPs for 100Mbps+
Community Fibre UK ISP Logo
200Mbps
Gift: None
Youfibre UK ISP Logo
Youfibre £23.99
150Mbps
Gift: None
Virgin Media UK ISP Logo
Virgin Media £23.99
132Mbps
Gift: None
Plusnet UK ISP Logo
Plusnet £24.99
145Mbps
Gift: £145 Reward Card
NOW UK ISP Logo
NOW £25.00
100Mbps
Gift: None
Large Availability | View All
Cheap Unlimited Mobile SIMs
iD Mobile UK ISP Logo
iD Mobile £16.00
Contract: 24 Months
Data: Unlimited
Talkmobile UK ISP Logo
Talkmobile £16.95
Contract: 1 Month
Data: Unlimited
Smarty UK ISP Logo
Smarty £17.00
Contract: 1 Month
Data: Unlimited
ASDA Mobile UK ISP Logo
ASDA Mobile £19.00
Contract: 24 Months
Data: Unlimited
Three UK ISP Logo
Three £20.00
Contract: 24 Months
Data: Unlimited
Cheapest ISPs for 100Mbps+
toob UK ISP Logo
toob £18.00
150Mbps
Gift: None
Gigaclear UK ISP Logo
Gigaclear £19.00
300Mbps
Gift: None
Community Fibre UK ISP Logo
200Mbps
Gift: None
Beebu UK ISP Logo
Beebu £23.00
100 - 160Mbps
Gift: None
Hey! Broadband UK ISP Logo
150Mbps
Gift: None
Large Availability | View All
Promotion
Sponsored

Copyright © 1999 to Present - ISPreview.co.uk - All Rights Reserved - Terms , Privacy and Cookie Policy , Links , Website Rules , Contact
Mastodon