NEWS
California Phone Scams Still Run on Sold Number Lists
Imposter scams took $3.5 billion in 2025, while California’s DROP tool is finally deleting the broker lists that put your number on a scammer’s phone.
People reported losing $3.5 billion to imposter scams in 2025, the Federal Trade Commission said on June 15, 2026, nearly three times the 2020 total. Nearly one in three fraud reports last year was an impersonation, often a text or a call dressed up as a bank, a tax office, or a family emergency.
California spent 2026 building a different answer than another red-flag flyer. The Delete Request and Opt-out Platform, known as DROP, is a statewide switch aimed at the data brokers who sell the phone numbers those calls need. By August 25, more than 500,000 residents had signed up, and brokers had already reported deleting tens of millions of records.
The 54 Million Direct Dials
Alma Galvan, the San Francisco Bay Area communications director for the Better Business Bureau, puts the targeting in plain terms. “It can happen to anyone,” she said. “It doesn’t matter your education level. It doesn’t matter what you look like. Scammers will target anyone.”
They do not have to guess the number. On September 1, 2026, the California Privacy Protection Agency fined SalesIntel Research, a Virginia broker, $36,400 for missing the 2025 registry deadline. CalPrivacy said the firm sells more than 200 million professional contacts and 54 million mobile phone numbers, plus guesses about career changes, and markets a product that “de-anonymizes your website traffic” so a buyer gets “contact data, direct dials, [and] verified emails, ready for outreach.”
That is the hidden supply line behind a Bay Area spam text. A broker does not need a prior relationship with you. It buys, packages, and resells the identifiers a caller needs, then another firm can spoof a bank or a state agency on the other end.
CalPrivacy’s Tom Kemp, the agency’s executive director, tied the fine to the new processing duty that began on August 1, 2026. Brokers that stay off the registry also stay off the deletion loop, which is why the agency has been chasing no-shows rather than waiting for another awareness week.
This ongoing enforcement activity shows that CalPrivacy takes seriously the failure to register by the deadline. As a reminder, exposure to potential enforcement action is increasing now that data brokers have started processing requests through DROP.
Tom Kemp, executive director, California Privacy Protection Agency, September 1, 2026
The Better Business Bureau still cannot shut a fraud shop down. Galvan has said the group has no power to close anyone, and that it passes patterns to local government instead. The deletion law is the piece that actually reaches the list vendors.
More Than 500,000 Californians Already Hit Delete
Governor Gavin Newsom signed the Delete Act, Senate Bill 362, on October 10, 2023. The point was ugly and simple. Under the older California Consumer Privacy Act, a resident who wanted out of broker files had to chase each company, and there were already hundreds of them.
DROP went live on January 1, 2026. Brokers had to start processing on August 1. CalPrivacy’s August 25 release is the first public scoreboard, and it is not a wait-and-see memo.
DROP RESULTS AS OF AUGUST 25, 2026
- Sign-ups: More than 500,000 Californians registered, in a process the agency says generally takes less than 10 minutes.
- Brokers in the system: 654 data brokers are now part of DROP.
- Early processing: About 25% of those brokers had already reported that they processed deletion requests.
- Matches: 99.9% of consumers had already had a profile deleted by at least one broker, and the typical user had been removed by over 40 brokers.
Senator Josh Becker, a Democrat from Menlo Park and the author of the Delete Act, said the law is doing the job it was written to do, with deletion underway and enforcement hitting companies that break the privacy rules. Kemp told people who already signed up to log in and check status, and told everyone else the signup still takes a few minutes at privacy.ca.gov/drop.
CALIFORNIA’S DELETION CALENDAR
- October 10, 2023: Newsom signs the Delete Act, moving the data-broker registry to CalPrivacy and ordering a single deletion switch.
- January 1, 2026: DROP launches. Residents can submit one request to every active registered broker.
- August 1, 2026: Brokers must begin processing, then re-check and delete new matches at least every 45 days.
- August 25, 2026: CalPrivacy says more than 500,000 people have registered and brokers have reported tens of millions of deletions.
- September 1, 2026: SalesIntel Research is ordered to pay $36,400, post privacy metrics, and process future DROP requests.
The match is mechanical, which is the whole design. You enter a name, date of birth, ZIP code, email, and phone number, and you can add a mobile advertising ID, a connected-TV ID, or a vehicle identification number. DROP hashes those identifiers. Brokers hash their own files the same way and delete on a match, then they must keep new copies of you out of the pile. CalPrivacy’s consumer pages spell out how DROP processes deletion requests, including the 8-digit DROP ID you need if you want to check status later.
Statuses are blunt: deleted, exempted, opted-out of sale, record not found, or pending. Brokers have up to 90 days to report what they did. Pending does not mean the request died. It means that shop has not finished the first pass.
Bank Impersonators Took Nearly $1 Billion
The costliest impersonation, the FTC said, often starts as a fake security alert from a bank. People are talked into moving money to “protect” it, and the loss is often limited only by what is sitting in the account. That is the call that sounds official because it uses your real bank’s name, and sometimes a number that looks local.
A national TV correspondent described one of those calls in July 2026 and said it nearly pulled an entire account before a branch stopped the transfer. The pressure script is the same one Galvan hears in the Bay Area: stay on the line, treat delay as danger, and do not use a number you already trust.
THE MONEY IMPOSTERS TOOK
| Category | 2024 | 2025 |
|---|---|---|
| Business impersonators (bank impersonators the highest in 2025) | $866 million | nearly $1 billion |
| Government impersonators | $789 million | about $920 million |
| All imposter scams | $3.5 billion | |
| All reported fraud | about $16 billion |
All reported fraud in 2025 was the highest on the FTC’s books and about 25% above 2024. Christopher Mufarrige, director of the Bureau of Consumer Protection, said fraud undercuts markets that depend on truthful information, and that the commission will use every tool it has against government and business impersonation.
One of those tools is the Impersonation Rule, finalized in 2024. The FTC said it has brought a dozen cases under the rule and obtained over $70 million in redress. From June 15 to June 26, 2026, it also ran the Never Ever campaign with the Elder Justice Coordinating Council, spelling out moves a real bank or agency will not make.
Galvan’s bank advice is older than DROP and still the right second step. Know whether you actually opted in to texts from your bank. After a scare call, hang up and use the number on the back of the card, not the first search result and not the number in the message, because a fraud shop can buy an ad and plant a fake line. “It’s up to us to do that little extra step,” she said.
Job Texts That Ask You to Like Videos
In the Bay Area, Galvan said the most common pitch is a task scam. A text offers easy, repetitive online work, often liking YouTube videos, and it reads like a side job. The age range she sees runs from the early 20s to the late 60s. “It attracts consumers that are looking for a job,” she said.
The bait is a high salary and a logo you already know. The site behind it may be days old. Galvan tells people to look up the domain on Whois.com and to insist on a real interview, then she adds the catch that did not exist a few years ago: generative AI can fake the recruiter’s voice and the video.
There are so many different versions of this scam, and it doesn’t target one individual.
Alma Galvan, San Francisco Bay Area communications director, Better Business Bureau
A live video is no longer proof of a live person. The homework has to happen before the offer feels warm, because the playbook is built to skip that pause. If the company is real, it can survive a day of checking. If it was registered last Tuesday and already has a dozen openings at luxury pay, it probably cannot.
The IRS Still Starts With a Letter
Tax impersonators still work because a back-tax threat feels like a deadline. The IRS’s own page on how the IRS contacts you is narrower than the scare script. The first contact is normally U.S. mail. Email and texts go out only if you opt in. Automated phone messages, when they happen, send you to IRS.gov and do not share specific account details.
A live caller who wants a PIN, a gift card, or an immediate wire is not working a tax case. Hang up. If you need a real line, the IRS publishes 800-829-1040. Ask for a reference number if you want one, then call that published number, not the one on your screen.
State shops get cloned too. The California Department of Public Health’s CDPH scam phone calls warning says impersonators ask for money and other sensitive details. Real CDPH calls, the department said, stick to public-health work such as disease contact tracing and will never ask for a Social Security number or a credit card.
Family emergency calls use the same panic clock. Galvan described a common version: a college-age relative who was supposedly arrested at the U.S.-Mexico border and needs bail now. AI has made the voice match easier. “It sounds like the person,” she said. “It sounds legitimate.” Families that pick a code word the caller would not know have a test that spoofed audio still fails. After you hang up, call the person from the number already saved in your phone.
Package texts are quieter and easier to tap. An unknown number says a USPS, Amazon, or FedEx shipment is stuck and wants a click. Galvan’s test is memory: what you ordered, who is bringing it, and whether you opted in to alerts. California requires opt-in for many texts, so a delivery ping you never signed up for is already a warning. Short links such as bit.ly can hide the real destination. One click can drop software onto a phone if the system is not up to date.
OFFICIAL CONTACT RULES THE CALLS BREAK
- IRS: First contact is mail. Texts only with opt-in. Hang up on a live demand for money, then use a number published on IRS.gov.
- Your bank: Unexpected texts are a warning if you never opted in. Call the number on the card, not the number in the message.
- CDPH: Legitimate calls stay on health work and never ask for a Social Security number or a credit card.
- Family emergency: Use a household code word, then call the saved contact. An unrecognized number plus an urgent wire is the tell.
- Delivery texts: No surprise link, no URL shortener, no data entry to “release” a package you do not remember ordering.
Utility impersonators add prepaid cards, gift cards, and third-party apps as the only way to keep the lights on. West Sacramento warned residents early this year about a postcard that claimed they had to enroll in a “program” for utility-upgrade funds. If the account is real, the county or PG&E can say so on a number you already have. Creative workers also get fake radio and TV bookings that ask for a fee to appear. Public-radio producers book guests directly, and they do not invoice a $200 door charge.
What a DROP Request Cannot Wipe Away
DROP is not a force field. CalPrivacy says a request does not erase first-party data you gave a business yourself, such as an email you typed into a store account. It does not erase publicly available records. Statutory exemptions can leave some files in place, which is why a status can come back as exempted instead of deleted.
If a broker cannot make an exact match, it may still have to stop selling what it holds. That is the opted-out status, and it is a weaker result than a full delete, which is why the agency keeps telling people to add extra identifiers. A new phone, a maiden name, or a second email can turn a miss into a hit on the next 45-day pass.
Caller ID is not a safety check either. Scammers can make a handset show a bank, a clinic, or a government line. The FTC’s own contact mix for 2025 losses shows why hanging up is not the whole job: people still lose money through sites, apps, social posts, email, and texts, not only through a ringing phone. Cutting the broker file shrinks the inbound list. It does not freeze every other door.
About 25% of the 654 brokers had reported processing by August 25, which also means most had not yet posted a result. The 90-day reporting clock is still running on that first wave. A pending row in your DROP profile is a wait, not a verdict.
Hang Up, Then Dial a Number You Trust
Galvan said people often feel foolish after they send the money, and that the useful move is to file anyway so the next household sees the pattern. The BBB’s Scam Tracker is built for that. It is a nonprofit log, not a takedown button. The FTC takes reports at ReportFraud.ftc.gov. The FCC takes unwanted-call complaints at fcc.gov/complaints. The California Attorney General, local police, the IRS, CDPH, and PG&E each want copies when their name was the costume.
WHERE TO FILE AFTER A HIT
- FTC: ReportFraud.ftc.gov for the fraud itself, including bank and government impersonation.
- FCC: fcc.gov/complaints, under unwanted calls and texts, if the number or the spoof is the issue.
- IRS: phishing@irs.gov for texts and mail, and the Treasury Inspector General for Tax Administration hotline at 800-366-4484 for suspicious calls.
- California: the Attorney General’s consumer page, the Identity Theft Registry if accounts were opened, and the agency whose name was used.
If funds moved, the bank still has to hear from you on its printed number. If a password or a card went out, the lockup is the same one any stolen-account case uses: freeze credit, rotate logins, and tell the IRS if a Social Security number was in the mix.
The red-flag list is not wrong. A panic story, a fresh job site, a short link, and a request for a PIN are still the tells. The part the checklists keep missing is the file that made the phone ring. More than 500,000 Californians have already put that file into DROP. The brokers who sell the next 54 million direct dials now have to look for those names every 45 days, or explain to CalPrivacy why they did not.
-
AI3 months agoFable 5 Came Back Under a Commerce On-Off Switch
-
AI4 months agoGoogle’s SpaceX GPU Lease Has a Sept. 30 Deadline
-
CRYPTO4 months agoPlasma One’s XPL Locks Face a 1.81 Billion Cliff
-
APPS4 months agoDGO’s Rs 549 World Cup Pass Cost Fans Sleep and Data
-
AI4 months agoMoonshot AI’s $30 Billion Ask Became a $35 Billion Close
-
NEWS4 months agoColorOS 17 Device List Spans Oppo, OnePlus and Realme
-
GAMING4 months agoXbox Cuts 3,200 Jobs After Five Years of Thin Returns
-
GAMING3 months agoThe RTX 4050 Under Rs 70,000 Hides a Wattage Gap
