How Ofcom is combatting mobile messaging scams
By Stefano Nicoletti, Mobile Ecosystem Forum (MEF)
This month Ofcom published its final statement on the battle against mobile messaging scams. It has introduced a new regulatory framework for both person-to-person (P2P) and application-to-person (A2P) messaging in the UK. The framework should significantly reduce the likelihood that consumers or businesses will receive scam messages. And it should also strengthen trust in mobile messaging as a method of communication.
Ofcom has adopted a pragmatic approach, which took account of the extensive feedback it received from the industry during the consultation process. MEF’s submissions are referenced throughout the final statement.
The Scale of the Problem
Ofcom’s intervention is driven by the continuing scale of fraud and scam activity.
According to the regulator:
Fraud accounts for approximately 45% of all reported crime in England and Wales.
UK consumers lost £1.28 billion to fraud in 2025.
Mobile operators are already blocking at least 600 million suspected scam messages every year.
More than 100 million suspicious messages are reported annually.
An estimated 100 million suspicious messages still reach consumers each year, despite existing filtering and blocking measures.
Around 40% of UK mobile users reported receiving at least one suspicious message in the previous three months.
The Key Changes
P2P Messaging
For P2P messaging, Ofcom will require operators to:
Introduce and maintain volume limits for PAYG SIMs.
Automatically block messaging activity once those limits are reached.
Receive and process scam reports from customers and trusted third parties.
Block numbers associated with scam activity.
Detect and block messages containing scam URLs and scam telephone numbers.
A2P Messaging
For A2P messaging, mobile operators and aggregators will be required to:
Conduct stronger Know Your Customer (KYC) checks during onboarding.
Implement ongoing Know Your Traffic (KYT) monitoring.
Verify and control the use of alphanumeric Sender IDs.
Introduce incident management processes for identified scam activity.
Pass fraud prevention obligations through the supply chain.
Block messages containing known scam URLs or telephone numbers.
The implementation dates are:
18 January 2027 for P2P requirements.
15 July 2027 for A2P requirements.
Clarifying the Role of MSPs and Intermediaries
A particularly important outcome concerns the treatment of Messaging Service Providers (MSPs) and intermediaries.
MEF argued that regulatory obligations should be focused on parties that are responsible for message conveyance and risk management and should not inadvertently capture entities acting only as intermediaries.
Ofcom ultimately refined its approach, clarifying the definition of aggregators and excluding intermediaries that merely facilitate relationships where the business sender maintains a separate contractual relationship with a provider responsible for message transmission.
This clarification improves legal certainty and helps ensure that obligations are directed at organisations that are genuinely in a position to manage messaging traffic and fraud risks.
Sender ID Controls Without a Mandatory Registry
Ofcom also considered whether to introduce a compulsory centralised Sender ID registry.
The regulator ultimately concluded that such an approach would be disproportionately burdensome at this stage and that the underlying policy objectives could be achieved through other measures.
Instead, the final framework introduces stronger controls around how Sender IDs are issued, verified and monitored. Providers will be expected to verify that requested alphanumeric Sender IDs are consistent with the business identity established during onboarding and KYC checks. They will also be required to maintain policies restricting the use of protected Sender IDs, generic Sender IDs and misleading variations designed to impersonate legitimate brands.
In addition, ongoing KYT monitoring will be required to identify suspicious Sender ID activity, including unusual traffic patterns, newly introduced Sender IDs and changes that may indicate fraudulent behaviour. These obligations must also be flowed through the A2P supply chain via contractual arrangements.
While a mandatory registry is not being introduced, providers should therefore expect greater scrutiny of how Sender IDs are verified, governed and protected. The focus of the final framework is not registration itself, but accountability, verification and monitoring.
What Does This Mean for MEF Members?
For aggregators, operators and enterprise messaging providers active in the UK market, preparation should begin now.
Businesses should assess:
Customer onboarding and KYC procedures.
KYT monitoring capabilities.
Sender ID governance policies.
Supply-chain contractual obligations.
Incident response and fraud management processes.
Compliance record-keeping and staff training arrangements.
To support industry readiness, MEF will be developing a dedicated training programme focused on the new UK requirements. The objective will be to help aggregators and other messaging providers understand the final obligations, identify implementation priorities and share operational best practices ahead of the January and July 2027 compliance deadlines.
As implementation begins, the final statement provides a clearer regulatory baseline for the UK messaging ecosystem. It places greater emphasis on KYC, KYT, sender identity verification, supply-chain accountability and intelligence-led fraud prevention, while avoiding some of the more burdensome interventions that were considered during the consultation process. For the messaging industry, the focus now shifts from consultation to implementation.
ABOUT THE AUTHOR
Stefano Nicoletti is from MEF (Mobile Ecosystem Forum) a global trade body established in 2000 and headquartered in the UK with members across the world. As the independent voice of the mobile ecosystem, MEF focuses on cross-industry best practices, anti-fraud and monetisation. The Forum provides its members with global and cross-sector platforms for networking, collaboration and advancing industry solutions.
Web: https://mobileecosystemforum.com/
Twitter/X: https://x.com/mef
LinkedIn: https://www.linkedin.com/company/mobile-ecosystem-forum