In short
Sender ID manipulation occurs when the displayed sender identity is changed, spoofed, substituted or otherwise presented differently from the expected authorised identity. It can be associated with fraud, bypass, phishing or unauthorised routing, and it is one of the clearest indicators available that a message did not travel the route it was supposed to.
Two different problems
Manipulation at submission and manipulation in transit look similar on a handset but mean very different things. At submission, an unauthorised party declares a Sender ID it has no right to use — this is impersonation, and the target is the subscriber. In transit, an intermediary replaces the legitimate Sender ID with something else — usually a local mobile number — and the target is the operator's billing.
The second case is the one that exposes grey routing, because a legitimate, agreed route has no reason to rewrite a registered sender identity.
Why routes substitute senders
Alphanumeric Sender IDs are frequently restricted to A2P channels. A message terminating through a SIM box physically cannot present one, because it is being sent from a real SIM and inherits that SIM's MSISDN.
So a bank's OTP submitted as "BANKNAME" arrives from a local number nobody recognises. The subscriber's trust in the message drops, the bank's support desk fills up, and the operator is the party in the middle receiving both complaints.
Variation attacks
A subtler form substitutes a near-identical sender rather than a different one: a substituted character, an added full stop, different spacing, a lookalike glyph from another script. The result passes an exact-match registry check while being visually indistinguishable to a subscriber.
Detecting these requires normalised comparison against the registry — folding case, stripping punctuation, mapping confusable characters — rather than literal equality.
Proving it happened
Submission records show what was sent. Only the receiving device shows what arrived. Guardivia's Honeypot SMS Testing platform compares the two directly, reporting the received Sender ID alongside content, encoding, message parts and timing.
One caveat worth stating plainly: a changed Sender ID is a strong indicator, not automatic proof of fraud. Some networks legitimately normalise sender formats, and regulatory rules in certain markets require substitution. The verdict should correlate the change with route, Global Title, CDR, SMSC and operator evidence before a route is classified.