the voice of customer experience technology
Front page
NewsCX Trust2h · 13:46 BST · 4 min read

Ofcom Probes Vonage and Voxbone Over Phone Scam Risks

Ofcom’s investigations into Vonage and Voxbone shine a light on the issue of phone-number misuse. While neither company has been found to have broken the rules, the probes raise a wider question for CPaaS providers and enterprises around who is accountable when a trusted voice channel is exploited

Ofcom investigates Vonage and Voxbone over potential phone-number misuse and scam risks

Ofcom has opened separate investigations into Vonage Business Limited and Voxbone SA over concerns that telephone numbers allocated to the companies may have been misused, including to perpetrate scams.

The UK regulator is not alleging that either company has run scam activity. Nor has it reached any findings. But its decision to investigate does bring a growing enterprise voice problem into sharper focus.

In its official statement, the regulator said:

“Ofcom has today opened two separate investigations into telecoms providers, Vonage Business Limited and Voxbone SA, relating to concerns that telephone numbers held by the companies are being misused, including to perpetrate scams.”

The potential reputational damage that could ensue cannot be overlooked.

A phone number is often the first point of contact between a business and its customers. When that number is used to make a scam look legitimate, the damage can stretch well beyond the individual victim.

What Is Ofcom Investigating?

Ofcom says it has gathered information that raised concerns about the use of numbers allocated to Vonage Business and Voxbone.

The investigations will assess whether the providers complied with General Condition B1. The rule covers the effective and efficient use of telephone numbers, alongside the steps communications providers take to oversee how those numbers are used.

Ofcom will also consider whether the companies took appropriate action to prevent numbers being misused by businesses or individuals they had transferred them to, and whether those numbers were being used in line with the National Telephone Numbering Plan.

In the announcement, Ofcom set out what it expects from providers that hold and allocate numbers:

  • Carry out “know your customer” checks on business customers

  • Keep risks under review by monitoring for potential misuse

  • Respond proactively when misuse is reported.

While it is unreasonable to expect a provider to control every interaction that passes through its network, it is their responsibility to ensure that the controls around number allocation, downstream customers, and suspected fraud are strong enough when things go wrong.

A Growing Trust Problem for Enterprise Voice

The knock-on effect of any potential wrongdoing is damaging customer trust.

Many enterprises now rely on a web of carriers, CPaaS vendors, resellers, and APIs to power outbound calls, customer notifications, authentication messages, and contact center services. This brings scale and flexibility. It can also make accountability harder to trace.

A customer who receives a convincing scam call is unlikely to distinguish between a number owner, a communications platform, a reseller, and the brand being impersonated.

They simply know that a number they trusted was used against them.

That can have a direct impact on customer behavior. Consumers may ignore legitimate calls from a bank, retailer, healthcare provider, or service team. They may also become reluctant to share information over the phone, even after dialing a verified number themselves.

It’s important to note that this issue may not end with Vonage and Voxbone. Indeed, in the release, Ofcom stated:

“Should we have reasonable grounds to suspect that any other companies have broken our rules we may launch further investigations which will be published on our enforcement bulletin page.”

The CPaaS Supply Chain Is Under Scrutiny

The cases involving Vonage and Voxbone are a reminder that phone numbers are not simply technical assets.

Ofcom allocates numbers in large blocks to communications providers, which may then transfer them to businesses or individuals.

In the modern enterprise voice market, that can create several layers between the original number holder and the person ultimately using it.

That is where the risk sits.

The more complex the supply chain becomes, the more important it is for providers to know who is using their numbers, spot suspicious behavior early, and intervene quickly.

KYC checks cannot become a one-time onboarding exercise. Monitoring, escalation paths, and the ability to suspend questionable activity matter just as much.

For the businesses buying voice services, there is a separate lesson. They need clarity over who controls their numbers, how fast a provider can act if a number is abused, and what protections exist around outbound calling and messaging.

Although the findings are not yet in, the lesson remains the same: protecting a number means protecting the trust attached to it.

You can find out more about the importance of trust in your CX operations by checking out these articles:

rate this story
helps rank stories across CX Today
The discussion0 takes · attributed & checked

Does this reflect your experience?

opening the room…
Read nextordered by techtelligence · every pick explained
same beat · CX Trust

When AI Agents Ignore “No,” Security Gets Real

24 Sept 2026
same beat · CX TrustWhy AI Is Pushing UK Businesses to Take Back Control of Their Data23 Sept 2026same beat · CX TrustThe EU AI Act Is a CX Problem Now22 Sept 2026