The message lands in the same thread where your bank always texts you. Same name at the top, same conversation you have scrolled through a hundred times, tucked right under last month’s fraud alert. It asks you to confirm a charge, and there is a link. Nothing about it looks off, because nothing about it is off, at least not in any way your phone is willing to show you. The sender is not your bank. The sender is someone with a laptop and an email account.

That uncomfortable scenario was, until very recently, trivially easy to pull off against most phones in the United States. A team of computer scientists at the University of California, San Diego spent months pulling apart the plumbing that carries text messages, and what they found was a gap wide enough to walk a convincing impersonation straight through.

The trouble starts with a feature almost nobody remembers asking for. Back in the early 2000s, carriers wanted to popularise texting, so they wired up gateways that let you send a text by emailing it. Email an address like a phone number at the carrier’s domain, and the message pops out the other end as an SMS. Convenient, sure. But email and text are different languages, with different rules about who sent what, and somebody has to translate between them.

That somebody is the gateway, and translation is where things get lost.

“Email and text messaging weren’t designed to work together,” says Stefan Savage, a professor in UC San Diego’s Department of Computer Science and Engineering and one of the paper’s senior authors. He reaches for an image to make the awkwardness concrete: “It’s a little bit like reading postcards to someone over the phone and needing to figure out where the sender and recipient information and the message itself are.”

And every carrier figures it out slightly differently. The team probed the gateways of the big U.S. networks, Verizon, T-Mobile, Google Fi, AT&T, and a clutch of smaller operators, treating each one as a black box and feeding it malformed email after malformed email to see what came out. Email systems do have anti-spoofing defences with names like SPF, DKIM and DMARC, and the gateways all claimed to support them. The problem was the seams. Leave one header empty here, slip a stray character there, and a message that should have been rejected sailed through wearing whatever sender name the attacker fancied.

How a Stray Character Becomes a Phone Number

The really clever part happens once that email-turned-text reaches the handset. Phones try to be helpful: they check the sender against your contacts and show you a friendly name instead of a string of digits. The researchers discovered that a carefully crafted email address could hijack that lookup. On an iPhone, an address beginning with a phone number followed by the characters “=?” gets chopped at exactly the wrong spot, and the bit left over is read as a genuine phone number. Android had its own version of the bug, where Google Messages saw an all-numeric email address, decided it must really be a number, and quietly stripped out the @ and the dot until it became one.

So an attacker does not just spoof some random email. They can make your phone believe a message came from a specific number, a five-digit short code, or even a plain word like the name of a bank.

What makes this genuinely nasty, rather than merely clever, is what phones do next. To keep your conversations tidy, messaging apps bundle everything from one contact into a single thread, whether it arrived by SMS, iMessage or anything else. Apple’s app is especially eager about this, the researchers found, merging messages across phone numbers and email addresses into one continuous conversation without flagging which channel each one came in on. Spoof the right identity and your forged message does not start a suspicious new thread. It drops into the middle of a real one. There is a small caveat for the attacker, mind you: they generally cannot see the replies, since those go to the real contact.

“There are no standards for converting emails to texts and that opens the door to all sorts of vulnerabilities,” says Sumanth Rao, the paper’s first author and a computer science PhD student at the Jacobs School of Engineering.

The technical requirements for an attacker are, frankly, depressingly modest. You need a computer that can send email, some fiddly off-the-shelf software, a domain of your own, and the victim’s phone number, which is hardly a state secret. From the number you can usually look up the carrier, and from the carrier you can look up the gateway, because the carriers publish the addresses themselves. The same researchers also showed how to dress a forged message up as a “verified” business, complete with a recognisable logo, and how to fake an entire group chat in which the attacker plays every part except the victim.

The Long Tail of a Twelve-Year-Old Bug

Some of this had been sitting in plain sight for an alarmingly long time. The iPhone parsing quirk appears in Apple’s libraries going back to at least 2012, and the Android one to around 2016. These were not freshly minted holes; they were old assumptions nobody had thought to stress-test.

The whole edifice, the researchers argue, rests on a quiet bit of faith that none of us agreed to. We assume a text is what it says it is. “People don’t realize that there’s no guarantee that text messages have integrity,” says Savage. “You can’t count on authenticity.”

Here is the better news. Before publishing, the team disclosed everything to the affected companies, and the response was unusually brisk. T-Mobile patched its gateways within a day of being told; Verizon within five. Google fixed the flaw in Google Messages and Apple fixed the iPhone parsing bug, assigning it a formal vulnerability identifier in the process. Verizon is going further and plans to switch off the ability to send texts by email altogether by the end of March 2027, a path AT&T had already taken. The industry’s standards body, the GSMA, is updating its security guidance so carriers elsewhere can tighten the same loose joints.

So the front door has been bolted, at least in the US. What the work really exposes, though, is less a single bug than a habit of building. Whenever two old systems that were never meant to talk are bolted together for convenience, the gaps in the translation become someone’s opportunity, and those gaps tend to lurk for years before anyone goes looking. The next one is probably already out there, waiting in the seam between two services nobody thought to question.

The research, “Lost in Translation: Text Message Spoofing via Email,” received a Distinguished Paper Award at the 47th IEEE Symposium on Security and Privacy.


Frequently Asked Questions

Could someone really fake a text from my bank without hacking anything?

Yes, and that was the unsettling core of this research. By emailing a carrier’s text gateway with a few deliberately malformed details, an attacker could make a phone display their message as coming from a trusted name or number, no account breach required. The major US carriers and both Apple and Google have since patched the specific flaws, but the technique worked against ordinary phones for years.

Why was a forged text able to slip into an existing conversation?

Messaging apps group everything from one contact into a single thread to keep things tidy, and they tend to trust the sender label without verifying it. Apple’s app was the most aggressive, merging messages across email and phone numbers into one conversation, so a spoofed message could appear mid-thread rather than starting a suspicious new one. That bundling is convenient, but it quietly assumes every sender is who they claim to be.

Is my phone safe now?

For the specific attacks in this study, largely yes, provided your phone is updated, since Apple, Google and the major carriers have deployed fixes. Verizon is even planning to retire email-to-text entirely by early 2027. The deeper lesson is harder to patch: similar translation gaps may exist wherever two incompatible systems have been stitched together.

How hard would this have been to actually carry out?

Surprisingly easy by the standards of serious attacks. It needed only a computer able to send email, some common software, a domain, and your phone number, which is rarely hard to find. That low barrier is exactly why the researchers treated it as urgent rather than theoretical.