Decoding the world of cybersecurity

Business texting faces tougher Ofcom controls

Ofcom’s new mobile messaging rules place stronger duties on operators and aggregators to block scam messages and control sender ID abuse.

Business texting faces tougher Ofcom controls
Summary
  • Ofcom has finalised rules and guidance for scam messages sent through P2P and A2P mobile channels.
  • The measures cover volume limits, scam-number blocking, sender ID controls, KYC checks, KYT checks, and incident management.
  • The rules place telecoms trust, business impersonation, and messaging supply chain controls under closer regulatory scrutiny.

Ofcom has finalised new rules and guidance for mobile operators and business messaging aggregators, aimed at reducing scam messages sent through UK mobile networks and business messaging services.

The measures cover both person-to-person messaging and application-to-person messaging, the channel used by organisations for one-time passcodes, delivery updates, banking alerts, appointment reminders, and customer-service notifications. Ofcom’s statement page says the rules are intended to prevent criminals from accessing messaging services and to stop their activity where they have gained access.

Under the new framework, mobile operators will be required to set volume limits for pay-as-you-go SIMs, block numbers used by scammers, receive scam reports from customers and third parties, and identify and block scam messages in transit. For application-to-person messaging, mobile operators and aggregators will need to conduct due diligence, prevent fake alphanumeric sender IDs, carry out ongoing Know Your Traffic checks, and apply incident management processes when scam activity is identified.

The sender ID measures are central to the business risk. Alphanumeric sender IDs allow messages to display a brand or organisation name rather than a telephone number. Used properly, they help organisations communicate with customers clearly. Abused by criminals, they turn mobile messaging into an impersonation channel.

That affects organisations even when their own systems are not compromised. A bank, logistics company, healthcare provider, retailer, employer, or public body can be impersonated through messages that look legitimate to recipients. The result can be payment fraud, account takeover, credential theft, reputational damage, and pressure on customer-service teams responding to abuse of the organisation’s name.

Ofcom’s rules also address the messaging supply chain. Business messages may pass through multiple aggregators, platforms, and mobile network operators before reaching a recipient. Weak onboarding or traffic monitoring at one point in that chain can create abuse routes that are hard for recipients to detect and difficult for legitimate brands to shut down quickly.

The regulator says P2P rules will come into effect on 18 January 2027, while A2P rules will come into effect on 15 July 2027. Providers will also need processes for record keeping, staff training, reviewing policies, handling false positives, and complying with data protection law.

The rules will not remove the need for organisations to manage their own communications controls. Businesses still need an inventory of authorised sender IDs, clear ownership of messaging providers and aggregators, abuse-reporting routes, and customer guidance when impersonation campaigns occur. Security, fraud, marketing, legal, and communications teams all have a stake in how messages are sent and protected.

Mobile messaging now sits close to digital identity infrastructure. It is used for authentication, recovery, payment confirmation, service updates, and public-sector communication. Ofcom’s intervention recognises that trust in those channels depends on controls across telecoms providers and aggregators, not only on the organisations whose names appear on messages.

×