Call forwarding abuse occurs when an attacker redirects voice or SMS-delivered verification traffic to another device. It matters because the authentication system may see a successful delivery even though the rightful user never receives the code or alert.
How call forwarding abuse works
call forwarding abuse is a redirection attack against voice and SMS delivery paths. The attacker does not need to break the verification system itself, they only need to move the message or call to a different endpoint so the original user never sees it.
This matters because the delivery step often becomes an implicit trust signal in account recovery and step-up authentication. If forwarding is enabled or modified without strong protection, the system may treat a code or alert as successfully delivered even though the user is effectively cut out of the verification flow.
Where the abuse shows up
The abuse usually appears in two places. One is phone carrier or PBX forwarding, where an attacker changes routing so calls or texts reach a controlled device. The other is account or device settings, where forwarded calls or SMS are quietly enabled after a foothold is gained.
Attackers may prefer this path because it is subtle and can preserve normal-looking authentication events. The code may still be generated, sent, and marked as delivered, which can reduce suspicion while the attacker intercepts the factor.
Security implications
Call forwarding abuse can weaken MFA, account recovery, and help-desk verification when those processes rely on telephony delivery. It is especially dangerous when voice or SMS is used as a fallback or recovery channel rather than a primary control, because interception of that channel can unlock higher-value access.
It can also create a false sense of assurance in monitoring and user experience signals. A delivery success does not necessarily mean a human owner received the challenge, and that gap is what the attacker exploits.
How to reduce exposure
Mitigation depends on treating forwarding as a security-sensitive change, not just a convenience feature. Stronger factors, especially phishing-resistant authenticators, reduce the value of intercepted calls and texts, and account controls should assume that telephony delivery can be rerouted.
Teams should also watch for unexpected forwarding rule changes, recovery-channel edits, and telecom account takeover paths. NIST SP 800-63 Digital Identity Guidelines is useful here because it reinforces why out-of-band and fallback authenticators need careful assurance, and MITRE ATT&CK Enterprise Matrix helps map the abuse to credential access and adversary persistence behavior.
Risk and Threat Considerations
Call forwarding abuse creates a direct interception risk because it lets an attacker receive verification traffic intended for the rightful user. The main consequence is account takeover, but the same technique can also undermine recovery workflows and delay detection if the user only notices after access has already been granted.
Failure mechanism: The attacker changes or leverages forwarding so the authentication challenge, alert, or callback is delivered to an alternate endpoint while the legitimate recipient remains unaware.
Impact: The attacker can satisfy or bypass a delivery-based control, capture sensitive codes or alerts, and continue into privileged account access or recovery abuse.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-63 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Defines authenticator assurance and fallback delivery risks for identity verification |
| Recommendation — Prefer phishing-resistant authenticators and treat SMS or voice delivery as lower-assurance recovery factors. | ||
| MITRE ATT&CK | T1110 — Brute Force | Covers account access attempts that benefit from intercepted verification factors |
| Recommendation — Map intercepted verification channels to credential-access tradecraft and alert on anomalous login or recovery patterns. | ||
| NIST CSF 2.0 | PR.AA-05 — Authenticator Management | Applies because forwarding abuse undermines how authenticators and recovery channels are controlled |
| DE.CM-01 — Networks and systems are monitored to detect potential cybersecurity events | Supports monitoring for forwarding-rule changes and suspicious verification delivery patterns | |
| RS.AN-01 — Investigations are performed to ensure effective response and support the protection of assets | Supports investigation of suspected interception through forwarding abuse | |
| Recommendation — Review and protect recovery-channel changes as part of authenticator management. Monitor telecom and account settings for forwarding changes that precede suspicious authentication activity. Investigate forwarding-rule changes alongside sign-in and recovery events to determine compromise scope. | ||
Practitioner Guidance
What to watch for: Treat forwarding changes as a high-signal event when they touch recovery, MFA, or help-desk controlled channels. A forwarding rule that appears shortly before a login anomaly, password reset, or recovery attempt deserves immediate review.
Practitioner takeaway: If a control depends on reaching a phone number, then who controls that number and its forwarding path becomes part of the authentication trust boundary.