2022-10-29
Data shows that in the first half of the year, the total volume of spam messages nationwide reached 19.9 billion, with an average of 7 spam messages per person per month; harassment calls totaled 39.2 billion, with an average of 14 per person per month. Since September 1, following the Ministry of Industry and Information Technology's requirements, the so-called "strictest mobile phone real-name registration system in history" has been fully implemented. How effective has it been in curbing the long-standing problem of telecom harassment?
This is an age without privacy. This is an age of endless ringing phones.
"I filled out a membership card form near the mall, and the very next day I got a spam text about invoice agency services," Ms. Huang told 21st Century Business Herald. "I used a pseudonym on the form, so after seeing the text, I was certain my personal info was leaked from that form."
Not only that, Ms. Huang's friend was also harassed by phone calls, with an even stranger experience. "He was just browsing a webpage without entering any personal information, yet the company behind the site sent him texts and called him."
Compared to the previous two cases, Ms. Wang's experience with telecom harassment is more severe, constituting fraud. According to reports, Ms. Wang purchased a flight ticket from Guangzhou to Beijing in August this year on the Hainan Airlines official flagship store on Alibaba Travel. Unexpectedly, the day before the flight, she received a text message notifying her that the flight was canceled, and she was asked to call a 400-number provided in the message to rebook the flight, with a rebooking fee of 20 yuan.
"I was out running errands at the time and didn't pay close attention to whether the SMS number was official. After calling back, the other party knew my name, flight details, and ID number precisely, which made me fully convinced." Ms. Wang told 21st Century Business Herald. Subsequently, the other party asked her to pay a 20-yuan rebooking fee to a designated account. It wasn't until she verified the information with the official channel that she realized she had been scammed.
What is more worrying is that such telecom harassment is no longer an isolated case but a widespread phenomenon. Recently, a mobile security app released the "2015 First Half China Internet Mobile Security Report" (hereinafter referred to as the "Report"), which conducted a systematic and professional investigation and analysis of six major mobile security issues, including spam messages and nuisance calls. The Report shows that as of June 2015, the total volume of spam messages nationwide reached 19.9 billion, with an average of 7 spam messages received per person per month; nuisance calls totaled 39.2 billion, with an average of 4 nuisance calls received per person per month.
Starting September 1, per MIIT requirements, the "strictest-ever real-name registration for mobile phones" is fully enforced, with carriers suspending service for users who fail to register in time. How effective is this real-name policy in curbing telecom harassment? What industry lies behind such harassment? What obstacles exist in legislation, enforcement, and regulation to tackle it? And what should users do in the face of telecom harassment?
Question: Why does user information get leaked?
In fact, during the rapid growth of the internet and mobile internet with rising user numbers, personal identity information and online activity data of over half of netizens have been leaked.
In July this year, the 12321 Reporting Center for Internet Abuse and Spam Information under the Internet Society of China released the "China Netizens' Rights Protection Survey Report 2015." The report shows that 78.2% of netizens had their personal identity information leaked, including names, phone numbers, home addresses, and ID numbers; 63.4% had their online activity information leaked, such as call logs, shopping records, and browsing history; and 49.9% had their personal communication information (e.g., instant messaging records, SMS) exposed.
"The black market industry chain (referred to as 'black industry') is now a market worth hundreds of billions, and telecom harassment and fraud is one part of it," Li Ming, who worked in corporate security for years, told 21st Century Business Herald. "From data acquisition and trafficking to carrying out harassment, a complete industrial chain has formed across these stages."
According to Li Ming, the current market price for real-time data (similar to user information from train stations, airlines, etc.) ranges from 10 to 20 yuan per entry, while enterprise data can sell for hundreds of thousands to millions of yuan depending on its value. In "black market" QQ groups, there are people hawking data every day.
Driven by enormous profits, the number of black-market practitioners is substantial, and telecom harassment and fraud have developed a highly streamlined division of labor to evade investigation and evidence collection. Among these, the information leakage stage has multiple possibilities: corporate user data systems hacked by cybercriminals; insider "moles" selling user data; malicious software, viruses, or Trojans on user phones stealing information; and malicious Wi-Fi intercepting data through ambush tactics... Users may have their personal information fully exposed without any awareness.
Regarding the aforementioned "flight cancellation" case, the reporter verified data system security with Alitrip and Hainan Airlines respectively. Alitrip staff told the reporter that its data system has passed security checks by public security authorities, while Hainan Airlines stated that it has its own risk prevention measures for strengthening ticket purchase channels and conducts independent security audits through third-party companies.
"No system is completely secure because it involves people. No matter how strict the management, if driven by profit, those with query access may collude with criminals," Li Ming pointed out. "But it's indeed hard to pinpoint which link went wrong."
Second question: Why are harassers hard to bring to justice?
"The number of communication fraud cases has exploded, with a solve rate so low it's embarrassing to mention, probably no more than 3 percent." Previously, a head of a major case unit from a provincial criminal investigation corps publicly stated.
According to available data, since 2008, telecom and information fraud cases in China have maintained an annual growth rate of 20% to 30%. In 2014, with high-pressure crackdowns by public security authorities and support from relevant departments, some progress was made in rectification efforts. However, since 2015, the incidence of such crimes in some regions has surged again: from January 1 to February 25, 2015, Shanghai reported 444 such cases, a 76% year-on-year increase. Among them, 419 cases were completed, up 89% year-on-year; the involved amount exceeded 70 million yuan, up 1260% year-on-year.
If rectifying communication fraud is already this challenging, let alone commercial spam messages like invoice agents, insurance sales, and corporate ads.
"Overall, for the most complained-about commercial telemarketing calls, China currently lacks clear legal regulations to govern them," said Xie Yongjiang, deputy director of the Internet Governance and Law Research Center at Beijing University of Posts and Telecommunications, in an interview with 21st Century Business Herald. Although Article 42 of the Public Security Administration Punishments Law stipulates provisions for repeatedly sending "other information" to disrupt others' normal life, "in practice, if a call doesn't harass you continuously but only comes once or twice occasionally, it's hard to classify it as 'disrupting normal life.'"
Beyond the legal gaps, bringing harassers to justice also involves cross-departmental collaboration. "Under current laws and regulations, fraud or harassment cases are handled by specific authorities. This creates a situation where behavioral data on harassment and fraud sits with the telecom regulator, but catching suspects requires police action," noted Hao Zhichao, deputy director of the 12321 Reporting Center under the Internet Society of China. Thus, strengthening coordination between the two departments is crucial.
"To strengthen coordination, we must first deepen research on the black industry chain," said Yan Li from the Industry and Planning Research Institute of the China Academy of Information and Communications Technology under the MIIT, in an interview with 21st Century Business Herald. In Yan's view, only by combining key "black industries" and pinpointing the "source" (advertisers, illegal device operators, or personal information traffickers) can a heavy blow be dealt to online harmful and spam information. "Therefore, holding joint meetings and formulating targeted plans to achieve 'precision' strikes would yield better results."
In addition, Yan Li also pointed out that the implementation of real-name registration enables the tracing of SMS and phone call initiators, providing a basis for tackling telecom harassment and a foundation for public security authorities to crack down on illegal activities using "black cards" and to file and investigate cases. "Achieving real-name registration is a prerequisite for ensuring a healthy market."
Three Questions: Why Can Operators Only Sigh at the Numbers?
"Unlike mobile security software, telecom operators cannot provide real-time alerts when users receive骚扰 calls. For suspicious numbers, operators can only choose to suspend service or let them through." Facing mounting pressure, an unnamed China Mobile insider admitted, "But when verifying suspicious numbers before suspension, operators face three major difficulties: evidence collection, cross-network coordination, and cross-regional challenges."
According to Article 40 of the Constitution of the People's Republic of China and Article 66 of the Telecommunications Regulations of the People's Republic of China, the freedom and confidentiality of communication of Chinese citizens are protected by law. "Therefore, without evidence, if operators shut down harassing calls, the harassers can sue and win every time," said Hao Zhichao.
"Short messages are easier to trace for evidence, but harassing calls are more troublesome," said the China Mobile insider. Currently, after receiving user complaints about harassing calls, China Mobile's standard approach is to have a dial-testing team call back to collect evidence, "but most numbers either don't answer or can't be reached."
Cross-network and cross-region issues also contribute to the current enforcement difficulties. It is understood that many harassment numbers involve cross-province operations. After users report to local operators, these operators must coordinate with provincial companies where the numbers are registered, which then escalate to municipal levels, making the process lengthy. Additionally, if tracing reveals the number belongs to another operator, the investigation hits a dead end.
Recently, under regulatory pressure, telecom operators have gradually shifted their stance. After this year's 3·15 Gala exposed issues such as spam calls, fraud via telecom tools, and violations of real-name registration for SIM cards, on March 16, the Ministry of Industry and Information Technology summoned executives from China Mobile, China Unicom, and China Telecom, and urgently instructed the three carriers and provincial communications administrations to investigate and strictly handle responsible units and individuals in accordance with laws and regulations.
"Telecom harassment is now tied to provincial operators' KPIs, with fines involved. Once harassment complaints exceed the set limit, each additional complaint about a harassing number results in fines of thousands of yuan," Hao Zhichao explained. "This rule has existed for the past two years, but enforcement has become increasingly strict recently."
Fourth question: What more can software vendors do?
Given the difficulty of thoroughly investigating information leaks in a short time, the challenge of bringing harassers to justice, and the limited role of carriers, terminal-based security software acts decisively, shielding users from much harassment. According to iiMedia Research data, as of Q2 2015, China's mobile security user base reached 487 million, up 14.86% year-on-year and 3.18% quarter-on-quarter. The penetration rate of mobile security software among mobile internet users hit 74.2%, showing steady growth.
The "power" of security software lies in its ability to let users flag spam messages or calls after receiving them. Other users, upon seeing these flags, can then choose to view/answer or reject/hang up based on their own situation and needs.
However, Hao Zhichao also pointed out that there is currently a lack of unified standards for identifying and handling harassing numbers. "Some numbers have been flagged up to 10,000 times on security guard platforms, yet they can still make outgoing calls—can't they just be shut down outright?"
In addition, the lack of standards is also reflected in the fact that some numbers marked as spam calls are actually from legitimate banks, telecom operators, and corporate customer service. Therefore, Liu Botao, Vice President of Dianhua Bang's Strategic Cooperation Department, believes that establishing a trusted number information service alliance, using big data analysis to improve marking accuracy, and partnering with phone manufacturers to encourage users to proactively correct errors, followed by unified manual call verification, may be the solution.
It is reported that the 12321 Reporting Center, under the guidance of relevant departments of the Ministry of Industry and Information Technology, is actively communicating with telecom operators and security vendors to propose regulations for identifying harassing numbers. In Hao Zhichao's view, big data analysis does have a certain basis in judging harassing numbers. "Current client-side tags are already sufficient to confirm a number's harassing behavior. In the future, we may set conditions to lock down harassing calls through comprehensive analysis of multiple indicators such as tagging channels, tagging frequency, and calling behavior, and directly shut them down. In case of errors, an appeal channel should also be reserved."
This also means that establishing a unified industry-wide reporting and complaint platform is crucial. However, the current situation is that security vendors operate independently with their own systems, leaving user reports scattered and making it difficult to form a collective force.
During the interview by 21st Century Business Herald reporters, several security vendors' executives expressed an open and cooperative attitude. However, an anonymous security expert noted that while the vision of a unified platform is good, implementation faces significant challenges. "If driven by enterprises, each company's data and commercial capabilities differ, making fairness in data sharing crucial. If driven by regulators, standardizing marking criteria across security software and establishing a complete reporting mechanism need consideration."
Question 5: What should users do themselves?
As victims of telecom harassment, users can only improve their situation by strengthening their own "offense" and "defense" strategies.
In terms of "defense," users should first enhance their awareness of protecting personal information. They should purchase phones through official channels, choose authorized after-sales repair centers, install security software and regularly scan for viruses, avoid clicking suspicious ads, texts, QR codes, or downloading unknown apps, refrain from connecting to free or unsecured Wi-Fi, and disable unnecessary services that may leak private data, such as location services.
Additionally, users should strengthen their personal rights awareness. According to Hao Zhichao, the 12321 reporting center's original intention in focusing on telecom harassment was to provide users with a channel for complaints. "We want to tell users that there is a place where this matter can be addressed," Hao said.
Beyond enhancing self-protection and rights-awareness, user participation in combating telecom harassment is also crucial. Statistics show that a security platform marks 4.59 million spam calls daily, and a PC manager marks 1.711 million, which pales in comparison to their hundreds of millions of users.
"The identification of harassing and scam calls can never rely solely on carrier testing teams to verify each one. The only way is to harness the power of the public, encouraging users to actively report and participate." Hao Zhichao pointed out, "Now a call may seem flagged dozens of times, but behind that, a large portion of users likely just ignore it."
In the interview, the aforementioned Ms. Wang also told 21st Century Business Herald reporters that she rarely marks spam calls or texts. "Sometimes, I just hang up when I see a spam call, but then I move on and don't think to mark it."
However, Xie Yongjiang pointed out that although there are currently complaint and reporting mechanisms with lower rights-protection costs and call-blocking software, their handling effectiveness and feedback mechanisms often fall short of expectations. Therefore, enhancing the restrictive role of these mechanisms and software against harassing numbers requires particular attention.