A Narrow Rule, a Big Number
On July 1, 2026, Switzerland's telecom regulator, the Federal Office of Communications (BAKOM), extended a mandatory caller-ID spoofing block from landlines to mobile numbers. The mechanism is unglamorous: transit providers must mark incoming international calls displaying a Swiss number, and if a call's origin cannot be technically verified, the caller ID is stripped so the terminating provider can flag it as "unknown" or block it outright (BAKOM, Identification of the Calling Line). Landline numbers were covered starting January 1, 2026; mobiles followed six months later.
The early results are hard to argue with. Switzerland's National Cybersecurity Centre (NCSC) reports that fraudulent calls impersonating authorities — the "fake police" and "fake bank" scams that have become a staple of European phone fraud — ran at more than 400 reports a month from January through June 2026. In July, after the mobile-number rule took effect, that figure fell below 100: a drop of more than 75% (NCSC/BACS press release). Swisscom alone says it now blocks roughly one million spoofed calls a month on its network (SRF).
Steelmanning the Mandate
Caller-ID spoofing is not a victimless nuisance. It is the delivery mechanism for a specific, high-harm fraud pattern: a caller displays a real Swiss police or bank number, exploits the borrowed trust, and pressures an often elderly victim into transferring money within minutes. Consumer-protection advocates pushed parliament for exactly this kind of intervention (itmagazine.ch), and the case for it is genuinely strong: the harm is concentrated, technically fixable at the network layer, and the fix doesn't require anyone to read or judge the content of a call. That last point matters. Unlike content moderation mandates or identity-verification schemes that force platforms to inspect what people say, this is a plumbing fix — it targets a forged technical header, not speech. A regulator ordering telecom carriers to authenticate number provenance is closer to requiring email providers to check SPF/DKIM records than to requiring a platform to police user speech.
Why the Design Still Deserves Scrutiny
Even a well-targeted rule has costs, and they're worth naming rather than waving away. First, false positives: any traveling Swiss resident whose provider can't cleanly attest to their own number when roaming, any legitimate call center or VoIP reseller using number ranges across borders, risks getting flagged as "unknown" or blocked outright. BAKOM's public materials describe the blocking logic but not an appeals or whitelisting channel for wrongly-flagged legitimate callers — that's a gap regulators should close before, not after, disputes pile up.
Second, the fix is a regional one, and fraud is not. Austria adopted similar mandatory call-labeling roughly a year before Switzerland, and Swiss reporting on the rollout notes that after Austrian incidents fell sharply, fraud crews simply pivoted to spoofing German and British numbers instead (SRF). Switzerland's 75% drop in authority-impersonation reports is a real, immediate win for Swiss residents — but it says more about where fraud crews currently find it easiest to operate than about fraud volume shrinking globally. Absent parallel moves by neighboring regulators, or cross-border coordination on call authentication standards, the likely medium-term effect is displacement rather than elimination. Switzerland's overall cyber-fraud reporting for the first half of 2026 — 27,128 voluntary reports, still down from 35,700 a year earlier — suggests fraud overall is easing, not just relocating, but the authority-impersonation channel specifically is the one most directly addressed by this rule, and it's the one showing the sharpest, most attributable drop.
The Model Worth Copying
What makes this a rare case study in good telecom regulation is its narrowness. BAKOM didn't mandate identity verification for callers, didn't require carriers to retain call content, and didn't ask providers to make judgment calls about who is or isn't a legitimate caller — it required carriers to stop passing along headers they know are forged. That's a low-friction, technically precise intervention with a measurable, attributable outcome, which is the standard proportionate regulation should be held to and rarely is. The lesson for other regulators eyeing scam-call crackdowns isn't "block more aggressively" — Austria's experience shows blocking alone doesn't eliminate fraud, it relocates it. The lesson is that a technical-layer fix, scoped tightly to a forged signal rather than to speech or content, can produce a 75% reduction in a specific, well-defined harm within one billing cycle. Regulators reaching for broader mandates — mandatory age verification, real-name registration, content-inspection requirements — should note how much smaller, and how much more effective, this one was.