Owning the problem of telecom-based attacks
In 2022, Regions’ customers and non-customers reported a record number of telecom-based attacks that sought to abuse Regions’ brand name. Threat actors conducted text-based attacks, or “smishing,” and voice-based attacks, or “vishing,” against both wide audiences and highly targeted recipients.
The attacks impersonated Regions and its vendors to deceive recipients into believing fraud had occurred on their accounts. They involved robocalling, mass text message schemes, and spoofed phone calls. The threat actor would then deceive the victim into allowing access to their financial accounts to conduct fraud. Smishing events also targeted Regions associates in executive impersonation schemes meant to convince them to purchase gift cards.
Traditionally, many organizations have viewed these scams as a telecom sector problem because the calls and text messages occur outside their own networks. Customer and employee training helps make people harder targets, but threat actors continue to innovate in how they abuse telecom networks and make their deceptive messages appear credible.
Hope is not a strategy. Through brand protection efforts and partnerships with effective vendors, organizations can take ownership of the problem and work to mitigate brand abuse across channels, including telecom.

How YouMail’s technology helps
Beginning in 2023, Regions Bank partnered with YouMail Protective Services to mitigate telecom-based threats by identifying the source of illegal calls and text messages. By tracking phone numbers and analyzing call patterns, YouMail provided crucial evidence to telecom providers regarding the abuse of their services, including call recordings that revealed the true intent of a call.
YouMail’s detection network expands what Regions can collect beyond direct customer and associate reports. Without installing anything on the Regions network or requiring customers to install a YouMail app, YouMail detected dozens of calling campaigns and worked with Regions to distinguish legitimate calls from those perpetrated by threat actors. Its knowledge of telecom traffic helped isolate fraudulent calls among legitimate traffic from known Regions vendors.
For malicious robocalling and human-led calling campaigns, YouMail worked on Regions’ behalf with industry groups to trace calls to their true origin and shut them down. Threat actors exploit weaknesses in telecom networks to display phone numbers they do not own or hide caller ID altogether. Traceback investigations follow calls through cooperating telecom providers to identify their origin in the United States or abroad, leading to identification of the actors and termination of the accounts they abuse.
For text-based attacks, including executive impersonation schemes, YouMail identifies the originator’s telecom provider and works with it to shut down the phone number. When groups known for tollbooth-themed smishing attacks target banking customers, YouMail also works with providers to find and shut down other numbers used by the same group.
YouMail also works with telecom carriers to add Regions’ phone numbers to Do Not Originate lists, helping mitigate attempts to make fraudulent calls appear to originate from Regions-owned numbers.
A proactive approach with measurable results
By partnering with YouMail, Regions was able to defend forward and impose costs on threat actors. Defending forward means taking proactive action outside Regions’ own network to detect and disrupt malicious activity at its source. Shutting down the actors’ infrastructure forces them to build, buy, or compromise additional infrastructure.
Discouraging this activity can lead threat actors to shift tactics or targets. While peer institutions kept reporting certain scams, Regions had already stopped seeing them. Regions’ overall reported telecom phishing events dropped by 55%, and telecom phishing events that led to fraud dropped by 37%.
Fewer phishing events mean less harm to customers and fewer contact center interactions related to telecom-based fraud. Regions also has a mechanism to act on customer-reported attacks. This approach helps defend the brand and maintain customers’ trust, even when attacks happen outside the bank’s own network.

