# Caller authentication and fraud prevention in contact centers

Canonical: https://warmtransfer.net/knowledge/contact-center-caller-authentication

Last verified: 2026-09-30

Caller authentication and fraud prevention in contact centers involve verifying inbound identities, evaluating call origin signals, and mitigating spoofing threats[^4][^22]. Standards and vendor platforms use telephony-level verification, out-of-band mechanisms, and risk scoring to counter unauthorized access[^10][^2].

## NIST digital identity standards

NIST SP 800-63B-4 is dated August 26, 2025, and supersedes the previous SP 800-63B[^10]. The guideline dictates that verifiers and CSPs SHALL NOT prompt subscribers to use knowledge-based authentication or security questions when choosing passwords[^13]. 

Under NIST SP 800-63B-4, out-of-band authentication over the PSTN (SMS or voice) is classified as a restricted authenticator[^17]. For restricted authenticators, verifiers SHALL make alternative authenticator types available to all subscribers[^19]. Verifiers SHOULD consider risk indicators such as device swap, SIM change, and number porting before using the PSTN to deliver an out-of-band secret[^18]. Out-of-band authentication is not phishing-resistant[^16]. Additionally, NIST SP 800-63B-4 requires an out-of-band authentication to be treated as invalid unless it is completed within 10 minutes[^15].

Biometrics are permitted under NIST SP 800-63B-4 only as part of multi-factor authentication with a physical authenticator, never as a standalone factor[^11]. Furthermore, NIST SP 800-63B-4 prohibits biometric comparison based on voice[^20]. When biometrics are used, the system must operate at a false match rate of 1 in 10,000 or better for all demographic groups[^12]. WarmTransfer's reading of the sources is that a contact-center voiceprint program cannot be presented as a NIST SP 800-63B-4 conformant authenticator, because the guideline both bans voice comparison and forbids biometrics as a standalone factor, although NIST 800-63B does not bind private contact centers[^45].

## STIR/SHAKEN and call origin verification

Under 47 CFR 64.6301(a), voice service providers are required to authenticate caller ID for SIP calls they originate and to verify caller ID for SIP calls they receive, with STIR/SHAKEN implemented in their IP networks by June 30, 2021[^2]. RFC 8588 defines the SHAKEN attest claim with 3 values: A (full attestation of the calling identity), B (partial: the provider originated the call but cannot fully attest to the identity), and C (gateway: received from a gateway that does not support PASSporT or STI)[^22]. RFC 8588 also defines an origid claim holding a UUID that identifies the source of a call for traceback while staying opaque[^23]. WarmTransfer's reading of the sources is that even A-level SHAKEN attestation asserts only that the originating provider vouches for the caller's right to use the calling number; it does not show that the person on the line is the account holder, so it is a risk signal rather than caller authentication[^1].

Platforms surface STIR/SHAKEN data in webhooks and call headers:
- Twilio adds a StirVerstat parameter to inbound-call webhooks with values including TN-Validation-Passed-A/B/C, TN-Validation-Failed-A/B/C, or No-TN-Validation[^30].
- Twilio includes StirVerstat only when the incoming call carries a SHAKEN PASSporT identity header; calls without one have no verification parameter[^28].
- Twilio returns No-TN-Validation when the SHAKEN PASSporT is malformed, carries invalid phone numbers, or has a timestamp more than 1 minute old[^29].
- Webex Calling reads the verstat parameter on incoming calls and shows a caller-ID disposition on Cisco clients: Verified Caller, Possible Spam, or Potential Fraud[^52].
- Webex Calling shows Verified Caller for calls with verstat TN-Validation-Passed and attestation A[^51].
- Webex Calling shows Potential Fraud when verstat is TN-Validation-Failed[^48].
- When an administrator blocks calls that fail STIR/SHAKEN validation, Webex Calling does not offer the call to the user, releases it with cause 603, and logs it in the user's call history as blocked[^47].
- Webex Calling spam call indications apply only to Webex Calling locations in the United States and Canada; other locations present calls normally whatever the settings[^50].
- Mutare, a certified caller reputation provider for Webex Calling, returns a reputation score and can return a rule action of allow, block, or CAPTCHA for incoming PSTN calls[^49].

## Amazon Connect Voice ID lifecycle

AWS ended support for Amazon Connect Voice ID effective May 20, 2026[^37]. The service stopped accepting new customers on May 20, 2025; only accounts that signed up before that date could keep using it until end of support[^40]. After May 20, 2026, Voice ID can no longer be accessed on the Amazon Connect console, the admin website, or the Contact Control Panel, and Voice ID resources can no longer be accessed[^38]. WarmTransfer's reading of the sources is that as of 2026-09-30, any instruction to configure Amazon Connect Voice ID for a new or existing deployment is obsolete because the service is past end of support[^41].

Prior to end of support, Voice ID functioned under the following parameters:
- It needed 30 seconds of net customer speech, excluding silence, to create an enrollment voiceprint[^35].
- It used 10 seconds of net speech to authenticate by default, adjustable between 5 and 10 seconds through the Authentication response time property, with shorter times trading away accuracy[^32].
- AWS told agents to confirm a first-time caller's identity with existing measures, such as a knowledge question or an SMS one-time passcode, before enrolling the caller in Voice ID, so that only genuine customers were enrolled[^36].
- Voice ID spoofing detection (for playback or synthesized speech) ran only when fraud detection was enabled in the flow; speaker authentication alone returned no spoofing score[^42].
- The authentication score ran from 0 to 100 with a default and recommended threshold of 90; AWS warned that thresholds above about 95 would force agents to verify nearly every caller[^43].
- AWS recommended starting the fraud threshold at its default of 50, where scores above the threshold indicate higher fraud risk[^39].
- Voice ID stored speaker audio, voiceprints, and speaker identifiers (plus fraudster audio and voiceprints when watchlists were used), encrypted with a customer-provided KMS key[^34].
- Fraudster watchlists launched in March 2023; domains created before then received a default watchlist holding all existing fraudsters[^44].

For ongoing operations, AWS points Voice ID customers to AWS Marketplace partner solutions such as Pindrop, or to a do-it-yourself one-time-PIN solution built on AWS End User Messaging SMS[^31]. To make sure all Voice ID customer data is deleted, AWS says to call the DeleteDomain API for every Voice ID domain in every AWS Region and every account[^33]. On Webex Contact Center, the Webex App Hub listing for Pindrop Passport, Protect, and Pulse requires an active Pindrop subscription, a Webex account, a paid Webex Contact Center license, and Control Hub administrator access[^21].

## Fraud threats and regulatory safeguards

Federal regulatory guidance and warnings address telephony-based fraud risks:
- 47 CFR 64.2010(h)(1) requires wireless (CMRS) providers to use secure authentication methods before executing a SIM change, and those methods may not rely on readily available biographical information, account information, recent payment information, or call detail information[^25].
- Wireless providers must review and, if needed, update their customer authentication methods regularly and at least once a year under 47 CFR 64.2010(h)[^24].
- 47 CFR 64.2010(h)(7) requires wireless providers to train employees to spot potentially fraudulent SIM change requests and customers who may be victims of SIM swap fraud[^26].
- WarmTransfer's reading of the sources is that because SIM swap and number porting redirect a customer's number to an attacker, an SMS or voice OTP sent to that number can reach the attacker, which is why NIST lists SIM change and porting as risk indicators and the FCC regulates carrier-side SIM change authentication[^27].
- The FFIEC authentication and access guidance announced August 11, 2021, replaced the 2005 guidance Authentication in an Internet Banking Environment and its 2011 supplement[^3].
- The 2021 FFIEC guidance names the risks of call center and IT help desk authentication as an area needing specific controls[^4].
- The 2021 FFIEC guidance highlights the weaknesses of single-factor authentication and says multi-factor authentication, or controls of equivalent strength, within layered security can effectively reduce unauthorized access[^5].
- On November 13, 2024, FinCEN issued alert FIN-2024-Alert004 on fraud schemes using GenAI deepfake media against financial institutions, covering typologies, red flags, and Bank Secrecy Act reporting[^6].
- FinCEN's news release frames the main deepfake concern as fraudulent identity documents used to get around identity verification and authentication; the release says nothing about voice deepfakes or phone channels[^7].
- FBI IC3 PSA I-051525-PSA (May 15, 2025) warned of a vishing campaign using AI-generated voice messages to impersonate senior US officials[^8].
- The IC3 PSA advises confirming a caller's identity by contacting them through a previously confirmed method, and turning on multi-factor authentication without ever sharing MFA codes[^9].

## Applicability

Applies to: NIST SP 800-63B-4, AWS Amazon Connect Voice ID, IETF SHAKEN PASSporT, FCC STIR SHAKEN, Twilio Programmable Voice, Cisco Webex Calling, FCC CPNI rules, FFIEC Authentication guidance, FinCEN FIN-2024-Alert004, FBI IC3 PSA, and Pindrop for Webex Contact Center. Deployments: multi-tenant and any. Sources checked 2026-09-30. Webex Calling spam call indications are restricted to locations in the United States and Canada[^50]. NIST SP 800-63B-4 is dated August 26, 2025[^10]. The FCC caller ID authentication obligations took effect in IP networks by June 30, 2021[^2]. Amazon Connect Voice ID was closed to new customers on May 20, 2025, and reached end of support on May 20, 2026[^40][^37].

## What remains uncertain

Pindrop integration architecture and flow configuration for Webex Contact Center is not covered by the sources below. Independent efficacy evaluation of voice deepfake and spoof detection (e.g. ASVspoof results) is not covered by the sources below. Biometric privacy law duties for voiceprints (Illinois BIPA and Texas CUBI and similar) are not covered by the sources below. The Webex Calling verstat table row for TN-Validation-Passed with attestation B is not covered by the sources below. Webex Contact Center native caller verification patterns (OTP via Webex Connect or Flow Designer HTTP) are not covered by the sources below. Current voice biometric offerings and lifecycle status from other CCaaS vendors are not covered by the sources below. ATIS-1000074 SHAKEN attestation criteria for A/B/C assignment are not covered by the sources below. The FinCEN FIN-2024-Alert004 full red-flag list and SAR key term are not covered by the sources below.

## Sources

[^1]: Even A-level SHAKEN attestation asserts only that the originating provider vouches for the caller's right to use the calling number; it does not show that the person on the line is the account holder, so it is a risk signal rather than caller authentication (inferred). Source: [RFC 8588: Personal Assertion Token (PaSSporT) Extension for Signature-based Handling of Asserted information using toKENs (SHAKEN)](https://www.rfc-editor.org/rfc/rfc8588.html), Sec. 4 attest claim. Checked 2026-09-30.
[^2]: 47 CFR 64.6301(a) requires voice service providers to authenticate caller ID for SIP calls they originate and to verify caller ID for SIP calls they receive, with STIR/SHAKEN implemented in their IP networks by June 30, 2021. Source: [47 CFR part 64 subpart HH — Caller ID Authentication](https://www.ecfr.gov/current/title-47/chapter-I/subchapter-B/part-64/subpart-HH), Sec. 64.6301(a)(2)(ii) and (a)(3). Checked 2026-09-30.
[^3]: The FFIEC authentication and access guidance announced August 11, 2021 replaced the 2005 guidance Authentication in an Internet Banking Environment and its 2011 supplement. Source: [OCC Bulletin 2021-36 Information Security: FFIEC Statement on Authentication and Access to Financial Institution Services and Systems](https://www.occ.gov/news-issuances/bulletins/2021/bulletin-2021-36.html), Summary / rescinded guidance list. Checked 2026-09-30.
[^4]: The 2021 FFIEC guidance names the risks of call center and IT help desk authentication as an area needing specific controls. Source: [OCC Bulletin 2021-36 Information Security: FFIEC Statement on Authentication and Access to Financial Institution Services and Systems](https://www.occ.gov/news-issuances/bulletins/2021/bulletin-2021-36.html), Highlights list. Checked 2026-09-30.
[^5]: The 2021 FFIEC guidance highlights the weaknesses of single-factor authentication and says multi-factor authentication, or controls of equivalent strength, within layered security can effectively reduce unauthorized access. Source: [OCC Bulletin 2021-36 Information Security: FFIEC Statement on Authentication and Access to Financial Institution Services and Systems](https://www.occ.gov/news-issuances/bulletins/2021/bulletin-2021-36.html), Highlights list. Checked 2026-09-30.
[^6]: On November 13, 2024 FinCEN issued an alert (FIN-2024-Alert004) on fraud schemes that use GenAI deepfake media against financial institutions, covering typologies, red flags and Bank Secrecy Act reporting. Source: [FinCEN Issues Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions](https://www.fincen.gov/news/news-releases/fincen-issues-alert-fraud-schemes-involving-deepfake-media-targeting-financial), News release body, first paragraphs. Checked 2026-09-30.
[^7]: FinCEN's news release frames the main deepfake concern as fraudulent identity documents used to get around identity verification and authentication; the release says nothing about voice deepfakes or phone channels. Source: [FinCEN Issues Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions](https://www.fincen.gov/news/news-releases/fincen-issues-alert-fraud-schemes-involving-deepfake-media-targeting-financial), News release body. Checked 2026-09-30.
[^8]: FBI IC3 PSA I-051525-PSA (May 15, 2025) warned of a vishing campaign using AI-generated voice messages to impersonate senior US officials. Source: [Senior US Officials Impersonated in Malicious Messaging Campaign (I-051525-PSA)](https://www.ic3.gov/PSA/2025/PSA250515), Opening section and vishing description. Checked 2026-09-30.
[^9]: The IC3 PSA advises confirming a caller's identity by contacting them through a previously confirmed method, and turning on multi-factor authentication without ever sharing MFA codes. Source: [Senior US Officials Impersonated in Malicious Messaging Campaign (I-051525-PSA)](https://www.ic3.gov/PSA/2025/PSA250515), Tips section. Checked 2026-09-30.
[^10]: NIST SP 800-63B-4 is dated August 26, 2025 and supersedes the previous SP 800-63B. Source: [NIST SP 800-63B-4 Digital Identity Guidelines: Authentication and Authenticator Management](https://pages.nist.gov/800-63-4/sp800-63b.html), Front matter, publication date and supersession note. Checked 2026-09-30.
[^11]: NIST SP 800-63B-4 allows biometrics only as part of multi-factor authentication with a physical authenticator, never as a standalone factor. Source: [NIST SP 800-63B-4 Digital Identity Guidelines: Authentication and Authenticator Management](https://pages.nist.gov/800-63-4/sp800-63b.html), Sec. 3.2.3 Use of Biometrics. Checked 2026-09-30.
[^12]: NIST SP 800-63B-4 requires a biometric system to operate at a false match rate of one in 10,000 or better for all demographic groups. Source: [NIST SP 800-63B-4 Digital Identity Guidelines: Authentication and Authenticator Management](https://pages.nist.gov/800-63-4/sp800-63b.html), Sec. 3.2.3.1 Biometric Performance Requirements. Checked 2026-09-30.
[^13]: NIST SP 800-63B-4 says verifiers and CSPs SHALL NOT prompt subscribers to use knowledge-based authentication or security questions when choosing passwords. Source: [NIST SP 800-63B-4 Digital Identity Guidelines: Authentication and Authenticator Management](https://pages.nist.gov/800-63-4/sp800-63b.html), Sec. 3.1.1.2 Password Verifiers. Checked 2026-09-30.
[^14]: The explicit KBA prohibition found in SP 800-63B-4 is scoped to password selection, so the document does not by that sentence alone ban a contact center from asking knowledge questions; it simply gives KBA no standing as an authenticator (inferred). Source: [NIST SP 800-63B-4 Digital Identity Guidelines: Authentication and Authenticator Management](https://pages.nist.gov/800-63-4/sp800-63b.html), Sec. 3.1.1.2 read against the authenticator types listed in Sec. 3.1. Checked 2026-09-30.
[^15]: NIST SP 800-63B-4 requires an out-of-band authentication to be treated as invalid unless it is completed within 10 minutes. Source: [NIST SP 800-63B-4 Digital Identity Guidelines: Authentication and Authenticator Management](https://pages.nist.gov/800-63-4/sp800-63b.html), Sec. 3.1.3.2 Out-of-Band Verifiers. Checked 2026-09-30.
[^16]: NIST SP 800-63B-4 states that out-of-band authentication is not phishing-resistant. Source: [NIST SP 800-63B-4 Digital Identity Guidelines: Authentication and Authenticator Management](https://pages.nist.gov/800-63-4/sp800-63b.html), Sec. 3.1.3 Out-of-Band Devices. Checked 2026-09-30.
[^17]: NIST SP 800-63B-4 classifies out-of-band authentication over the PSTN (SMS or voice) as a restricted authenticator. Source: [NIST SP 800-63B-4 Digital Identity Guidelines: Authentication and Authenticator Management](https://pages.nist.gov/800-63-4/sp800-63b.html), Sec. 3.1.3.3 Authentication Using the Public Switched Telephone Network. Checked 2026-09-30.
[^18]: NIST SP 800-63B-4 says verifiers SHOULD consider risk indicators such as device swap, SIM change and number porting before using the PSTN to deliver an out-of-band secret. Source: [NIST SP 800-63B-4 Digital Identity Guidelines: Authentication and Authenticator Management](https://pages.nist.gov/800-63-4/sp800-63b.html), Sec. 3.1.3.3 Authentication Using the Public Switched Telephone Network. Checked 2026-09-30.
[^19]: For restricted authenticators, NIST SP 800-63B-4 says verifiers SHALL make alternative authenticator types available to all subscribers. Source: [NIST SP 800-63B-4 Digital Identity Guidelines: Authentication and Authenticator Management](https://pages.nist.gov/800-63-4/sp800-63b.html), Sec. 3.2.9 Restricted Authenticators. Checked 2026-09-30.
[^20]: NIST SP 800-63B-4 prohibits biometric comparison based on voice. Source: [NIST SP 800-63B-4 Digital Identity Guidelines: Authentication and Authenticator Management](https://pages.nist.gov/800-63-4/sp800-63b.html), Sec. 3.2.3 Use of Biometrics, presentation attack detection requirements. Checked 2026-09-30.
[^21]: The Webex App Hub listing for Pindrop Passport, Protect and Pulse requires an active Pindrop subscription, a Webex account, a paid Webex Contact Center license and Control Hub administrator access. Source: [Pindrop Passport Protect and Pulse - Webex App Hub](https://apphub.webex.com/applications/pindrop-passport-protect-and-pulse-pindrop), Listing requirements section. Checked 2026-09-30.
[^22]: RFC 8588 defines the SHAKEN attest claim with three values: A (full attestation of the calling identity), B (partial: the provider originated the call but cannot fully attest to the identity) and C (gateway: received from a gateway that does not support PASSporT or STI). Source: [RFC 8588: Personal Assertion Token (PaSSporT) Extension for Signature-based Handling of Asserted information using toKENs (SHAKEN)](https://www.rfc-editor.org/rfc/rfc8588.html), Sec. 4 attest claim. Checked 2026-09-30.
[^23]: RFC 8588 defines an origid claim holding a UUID that identifies the source of a call for traceback while staying opaque. Source: [RFC 8588: Personal Assertion Token (PaSSporT) Extension for Signature-based Handling of Asserted information using toKENs (SHAKEN)](https://www.rfc-editor.org/rfc/rfc8588.html), Sec. 5 origid claim. Checked 2026-09-30.
[^24]: Under 47 CFR 64.2010(h), wireless providers must review and, if needed, update their customer authentication methods regularly and at least once a year. Source: [47 CFR 64.2010 Safeguards on the disclosure of customer proprietary network information](https://www.ecfr.gov/current/title-47/chapter-I/subchapter-B/part-64/subpart-U/section-64.2010), Sec. 64.2010(h), authentication review provision. Checked 2026-09-30.
[^25]: 47 CFR 64.2010(h)(1) requires wireless (CMRS) providers to use secure authentication methods before executing a SIM change, and those methods may not rely on readily available biographical information, account information, recent payment information or call detail information. Source: [47 CFR 64.2010 Safeguards on the disclosure of customer proprietary network information](https://www.ecfr.gov/current/title-47/chapter-I/subchapter-B/part-64/subpart-U/section-64.2010), Sec. 64.2010(h)(1). Checked 2026-09-30.
[^26]: 47 CFR 64.2010(h)(7) requires wireless providers to train employees to spot potentially fraudulent SIM change requests and customers who may be victims of SIM swap fraud. Source: [47 CFR 64.2010 Safeguards on the disclosure of customer proprietary network information](https://www.ecfr.gov/current/title-47/chapter-I/subchapter-B/part-64/subpart-U/section-64.2010), Sec. 64.2010(h)(7). Checked 2026-09-30.
[^27]: Because SIM swap and number porting redirect a customer's number to an attacker, an SMS or voice OTP sent to that number can reach the attacker, which is why NIST lists SIM change and porting as risk indicators and the FCC regulates carrier-side SIM change authentication (inferred). Source: [NIST SP 800-63B-4 Digital Identity Guidelines: Authentication and Authenticator Management](https://pages.nist.gov/800-63-4/sp800-63b.html), Sec. 3.1.3.3, read with 47 CFR 64.2010(h). Checked 2026-09-30.
[^28]: Twilio includes StirVerstat only when the incoming call carries a SHAKEN PASSporT identity header; calls without one have no verification parameter. Source: [Trusted Calling with SHAKEN/STIR](https://www.twilio.com/docs/voice/trusted-calling-with-shakenstir), StirVerstat section caveat. Checked 2026-09-30.
[^29]: Twilio returns No-TN-Validation when the SHAKEN PASSporT is malformed, carries invalid phone numbers or has a timestamp more than one minute old. Source: [Trusted Calling with SHAKEN/STIR](https://www.twilio.com/docs/voice/trusted-calling-with-shakenstir), StirVerstat values list. Checked 2026-09-30.
[^30]: Twilio adds a StirVerstat parameter to inbound-call webhooks with values such as TN-Validation-Passed-A/B/C, TN-Validation-Failed-A/B/C or No-TN-Validation. Source: [Trusted Calling with SHAKEN/STIR](https://www.twilio.com/docs/voice/trusted-calling-with-shakenstir), Section on SHAKEN/STIR verification status of inbound calls (StirVerstat). Checked 2026-09-30.
[^31]: AWS points Voice ID customers to AWS Marketplace partner solutions such as Pindrop, or to a do-it-yourself one-time-PIN solution built on AWS End User Messaging SMS. Source: [Amazon Connect Customer Voice ID end of support](https://docs.aws.amazon.com/connect/latest/adminguide/amazonconnect-voiceid-end-of-support.html), Intro paragraph and section Do-it-yourself solutions with AWS End User Messaging SMS. Checked 2026-09-30.
[^32]: Amazon Connect Voice ID used 10 seconds of net speech to authenticate by default, adjustable between 5 and 10 seconds through the Authentication response time property, with shorter times trading away accuracy. Source: [Flow block in Connect Customer: Set Voice ID](https://docs.aws.amazon.com/connect/latest/adminguide/set-voice-id.html), Section Properties > Authentication response time. Checked 2026-09-30.
[^33]: To make sure all Voice ID customer data is deleted, AWS says to call the DeleteDomain API for every Voice ID domain in every AWS Region and every account. Source: [Amazon Connect Customer Voice ID end of support](https://docs.aws.amazon.com/connect/latest/adminguide/amazonconnect-voiceid-end-of-support.html), Section Managing your Voice ID data. Checked 2026-09-30.
[^34]: Voice ID stored speaker audio, voiceprints and speaker identifiers (plus fraudster audio and voiceprints when watchlists were used), encrypted with a customer-provided KMS key. Source: [Use real-time caller authentication with Voice ID in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/voice-id.html), Section What data is stored?. Checked 2026-09-30.
[^35]: Amazon Connect Voice ID needed 30 seconds of net customer speech, excluding silence, to create an enrollment voiceprint. Source: [Use real-time caller authentication with Voice ID in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/voice-id.html), Section How much speech is needed for enrollment and authentication. Checked 2026-09-30.
[^36]: AWS told agents to confirm a first-time caller's identity with existing measures, such as a knowledge question or an SMS one-time passcode, before enrolling the caller in Voice ID, so that only genuine customers were enrolled. Source: [Use real-time caller authentication with Voice ID in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/voice-id.html), Section How Voice ID works > Customer enrollment, step 1. Checked 2026-09-30.
[^37]: AWS ended support for Amazon Connect Voice ID effective May 20, 2026. Source: [Amazon Connect Customer Voice ID end of support](https://docs.aws.amazon.com/connect/latest/adminguide/amazonconnect-voiceid-end-of-support.html), Page intro paragraph. Checked 2026-09-30.
[^38]: After May 20, 2026, Voice ID can no longer be accessed on the Amazon Connect console, the admin website or the Contact Control Panel, and Voice ID resources can no longer be accessed. Source: [Use real-time caller authentication with Voice ID in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/voice-id.html), End of support notice box at top of page. Checked 2026-09-30.
[^39]: AWS recommended starting the Voice ID fraud threshold at its default of 50, where scores above the threshold indicate higher fraud risk. Source: [Flow block in Connect Customer: Set Voice ID](https://docs.aws.amazon.com/connect/latest/adminguide/set-voice-id.html), Section Configuration tips. Checked 2026-09-30.
[^40]: Amazon Connect Voice ID stopped accepting new customers on May 20, 2025; only accounts that signed up before that date could keep using it until end of support. Source: [Amazon Connect Customer Voice ID end of support](https://docs.aws.amazon.com/connect/latest/adminguide/amazonconnect-voiceid-end-of-support.html), Page intro paragraph. Checked 2026-09-30.
[^41]: As of 2026-09-30, any instruction to configure Amazon Connect Voice ID for a new or existing deployment is obsolete because the service is past end of support (inferred). Source: [Amazon Connect Customer Voice ID end of support](https://docs.aws.amazon.com/connect/latest/adminguide/amazonconnect-voiceid-end-of-support.html), Page intro paragraph compared with access date. Checked 2026-09-30.
[^42]: Voice ID spoofing detection (for playback or synthesized speech) ran only when fraud detection was enabled in the flow; speaker authentication alone returned no spoofing score. Source: [Use real-time caller authentication with Voice ID in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/voice-id.html), Section Voice spoofing detection. Checked 2026-09-30.
[^43]: The Voice ID authentication score ran from 0 to 100 with a default and recommended threshold of 90; AWS warned that thresholds above about 95 would force agents to verify nearly every caller. Source: [Flow block in Connect Customer: Set Voice ID](https://docs.aws.amazon.com/connect/latest/adminguide/set-voice-id.html), Sections Properties > Voice authentication and Configuration tips. Checked 2026-09-30.
[^44]: Voice ID fraudster watchlists launched in March 2023; domains created before then got a default watchlist holding all existing fraudsters. Source: [Use real-time caller authentication with Voice ID in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/voice-id.html), Section Known fraudster detection > Default watchlist, note. Checked 2026-09-30.
[^45]: A contact-center voiceprint program cannot be presented as a NIST SP 800-63B-4 conformant authenticator, because the guideline both bans voice comparison and forbids biometrics as a standalone factor; NIST 800-63B does not bind private contact centers (inferred). Source: [NIST SP 800-63B-4 Digital Identity Guidelines: Authentication and Authenticator Management](https://pages.nist.gov/800-63-4/sp800-63b.html), Sec. 3.2.3 Use of Biometrics. Checked 2026-09-30.
[^46]: Webex Calling shows Possible Spam, not Verified Caller, for calls with verstat TN-Validation-Passed and attestation B. Source: [Secure Calling and Spam mitigation](https://help.webex.com/en-us/article/8j6te9/Secure-Calling-and-Spam-mitigation), Section Verstat value and attestation, table row TN-Validation-Passed / B. Checked 2026-09-30.
[^47]: When an administrator blocks calls that fail STIR/SHAKEN validation, Webex Calling does not offer the call to the user, releases it with cause 603 and logs it in the user's call history as blocked. Source: [Secure Calling and Spam mitigation](https://help.webex.com/en-us/article/8j6te9/Secure-Calling-and-Spam-mitigation), Section Call disposition and reporting. Checked 2026-09-30.
[^48]: Webex Calling shows Potential Fraud when verstat is TN-Validation-Failed. Source: [Secure Calling and Spam mitigation](https://help.webex.com/en-us/article/8j6te9/Secure-Calling-and-Spam-mitigation), Section Verstat value and attestation, table. Checked 2026-09-30.
[^49]: Mutare, a certified caller reputation provider for Webex Calling, returns a reputation score and can return a rule action of allow, block or CAPTCHA for incoming PSTN calls. Source: [Secure Calling and Spam mitigation](https://help.webex.com/en-us/article/8j6te9/Secure-Calling-and-Spam-mitigation), Section Certified caller reputation providers with Webex Calling. Checked 2026-09-30.
[^50]: Webex Calling spam call indications apply only to Webex Calling locations in the United States and Canada; other locations present calls normally whatever the settings. Source: [Secure Calling and Spam mitigation](https://help.webex.com/en-us/article/8j6te9/Secure-Calling-and-Spam-mitigation), Scope / geographic applicability statement. Checked 2026-09-30.
[^51]: Webex Calling shows Verified Caller for calls with verstat TN-Validation-Passed and attestation A. Source: [Secure Calling and Spam mitigation](https://help.webex.com/en-us/article/8j6te9/Secure-Calling-and-Spam-mitigation), Section Verstat value and attestation, table. Checked 2026-09-30.
[^52]: Webex Calling reads the verstat parameter on incoming calls and shows a caller-ID disposition on Cisco clients: Verified Caller, Possible Spam or Potential Fraud. Source: [Secure Calling and Spam mitigation](https://help.webex.com/en-us/article/8j6te9/Secure-Calling-and-Spam-mitigation), Section Verstat value and attestation. Checked 2026-09-30.
