

Those are about 4 million users (according to T-Mobile).

This blogpost for example explains, how to set up your own Asterisk server to spoof any caller ID you want. Basically an attacker needs access to the phone network – which nowadays is very easy due to VOIP – and a provider which allows the attacker to set the caller ID as part of the configuration or allows the configuration of your own Private Branch Exchange (PBX) like Asterisk. What many people do not know is, that the caller ID of everyone around the globe can be easily spoofed. But lets start at the beginning of the story:
