Sitemap
Press enter or click to view image in full size

Why Blocking Unverified SMS Messages Will Backfire on Irish Banks

3 min readJul 28, 2025

--

Before you scroll, remember 3 things:

  1. Network Operator ID checks apply only to branded short codes. Texts sent from everyday mobile numbers aren’t checked or labelled.
  2. From October 2025 unverified short codes will be blocked, but messages from normal numbers will still reach phones unchecked and unchanged.
  3. Once labelled texts disappear, people will trust whatever gets through, handing scammers who use normal numbers a free pass.

By labeling and blocking short codes, we’re training people to trust whatever slips through.

From our observations at MetaCert since SMS phishing started during the pandemic, most smart criminals have always sent scams from everyday mobile numbers because that looks normal to more than enough people.

Press enter or click to view image in full size

🚨 By blocking short codes, we’re training people to trust whatever slips through. Fraudsters don’t need to adapt. They just keep using the numbers the system politely ignores. ComReg’s sender ID checks overlook the only thing most smart criminals ever used: regular mobile numbers.

EU regulated Instant payments will make every tap more dangerous

From October 2025, money moves in seconds. Under new EU regulations, all banks across the EU including those in Ireland, must support instant payments, 24 hours a day, 7 days a week. Transfers will be processed in under 10 seconds, with no delays or safety nets. Just like crypto payments!

That means one unverified link can drain an account faster than a fraud team can blink. There’s no room for lag, no time for review. The protections banks rely on today simply won’t apply in this new environment. Instant payments demand instant trust decisions, and that’s exactly where phishing thrives.

Recap

  • Operator ID checks cover only branded short codes. Ordinary mobile numbers aren’t checked or labelled.
  • From October 2025 any unverified short code will be blocked, yet texts from normal numbers will still reach phones checked and unchanged.
  • Once those labelled texts disappear, people will trust whatever arrives, giving scammers who use everyday numbers a free pass.

A Practical Way for Banks to Lower Risk

It would be negligent to outline this growing risk without pointing to something constructive.

If banks want to reduce fraud losses without waiting on telecom reforms or consumer behaviour shifts, there is a simple path: give people the ability to check links before trust is triggered. Not after the damage is done.

That’s exactly what Link Verifier does. It’s a lightweight mobile solution built on Zero Trust principles that treats every link as untrustworthy until proven otherwise. Banks can offer it directly from inside their app, extending real protection across every interaction on a customer’s phone, not just inside the app itself.

As Bank of Ireland tell customers;

Stop. Think. Check.

MetaCert makes the “check” instant, reliable, and effortless.

📲 Try Link Verifier for free here.

--

--

Paul Walsh
Paul Walsh

Written by Paul Walsh

MetaCert CEO. Passionate about Cybersecurity, Blockchain, Crypto, Snowboarding & Red Wine. Part of the AOL team that launched AIM. Co-founded 2 W3C Standards.