UK’s First SMS Blaster Case: How Smishing Technology Can Bypass Mobile Network Security
A UK fraud case involving sophisticated “SMS blaster” technology has highlighted how criminals are adapting their methods to bypass protections designed to block malicious text messages.
On 1 September 2026, City of London Police confirmed that a man had been sentenced to three years and eight months in prison following an investigation into equipment capable of acting as a rogue mobile antenna and broadcasting fraudulent SMS messages directly to nearby phones.
When the equipment was seized in May 2024, police said it represented the first known instance of UK law enforcement encountering this particular type of SMS blaster.
The case demonstrates why phishing and impersonation fraud can no longer be assessed solely by looking for suspicious telephone numbers, obvious spelling mistakes or unusual web links. Criminals are increasingly using technology designed to make fraudulent communications appear more credible and to bypass established security controls.
What Is an SMS Blaster?
An SMS blaster is equipment capable of operating as an illegitimate mobile phone mast or rogue antenna.
Rather than sending a fraudulent message through a conventional mobile network, the device can cause nearby phones to connect to it and then broadcast SMS messages directly to those devices.
According to City of London Police, this can allow criminals to bypass telecommunications safeguards designed to identify or block suspicious sender names and harmful links.
That capability can make fraudulent messages more convincing.
Consumers have become accustomed to receiving legitimate text messages from banks, delivery companies, government departments and other organisations. Fraudsters attempt to exploit that familiarity by sending messages that appear to originate from trusted brands.
When traditional network-level protections are circumvented, an otherwise suspicious message may reach a victim without being filtered in the way they expect.
What Happened in the UK Case?
City of London Police said Mohammed Faiyaz Iqbal was arrested in May 2024 while sitting in a van at the Trafford Centre in Manchester.
Officers had identified the vehicle as being in the vicinity of large numbers of fraudulent SMS messages.
A search of the van uncovered an SMS blaster installation concealed inside purpose-built compartments. Police recovered power sources, Wi-Fi equipment and aerials installed into the vehicle, with the system reportedly active when officers found it.
The messages impersonated legitimate organisations, including Royal Mail, and were designed to persuade recipients to provide personal and payment information.
Police later examined mobile phones associated with the operation and identified 7,859 compromised payment-card details.
Further searches also uncovered compromised banking material and three counterfeit UK driving licences, which police said were being used to establish impersonation bank accounts for laundering criminal proceeds.
Iqbal pleaded guilty in March 2026 and was sentenced on 28 August.
Why This Is Different From Conventional Smishing
Smishing is phishing conducted through SMS text messages.
Traditional smishing campaigns may use spoofed sender information, compromised accounts or large-scale messaging platforms to distribute fraudulent links.
SMS blasters introduce another layer of sophistication because the criminal infrastructure can operate locally and interact directly with nearby mobile devices.
City of London Police has described the equipment as capable of bypassing telecommunications network security protocols.
This matters because consumers often rely on technological protections without necessarily being aware of them.
A person may reasonably assume that:
- Their mobile provider blocks known malicious senders.
- A familiar sender name indicates authenticity.
- Fraudulent links are automatically filtered.
- Messages arriving within an existing SMS thread are genuine.
- Mobile networks prevent unauthorised messages from reaching their device.
Those protections can reduce risk, but the UK cases demonstrate why they cannot eliminate it.
Criminals Are Combining Cyber and Financial Fraud
The investigation also illustrates how modern fraud rarely remains confined to a single technique.
The SMS message is only the initial contact.
A successful operation may involve several stages:
- Creating convincing fraudulent messages.
- Impersonating a trusted organisation.
- Directing victims to malicious websites.
- Collecting personal information.
- Obtaining payment-card details.
- Compromising bank accounts.
- Creating false identities.
- Moving or laundering criminal proceeds.
This overlap between cyber-enabled activity, identity fraud and financial crime is increasingly important for organisations assessing their exposure.
Conflict International’s Cyber Security Services support organisations responding to cyber incidents, compromised accounts and digital-security risks affecting businesses and their information.
Why Brand Impersonation Creates Business Risk
Although consumers may be the immediate target, businesses whose identities are impersonated can also suffer consequences.
Fraudsters frequently exploit brands that people recognise and trust.
Common targets can include:
- Banks.
- Delivery companies.
- Government departments.
- Retailers.
- Telecommunications companies.
- Utility providers.
- Online platforms.
The organisation being impersonated may have had no security breach at all.
Nevertheless, customers receiving fraudulent messages bearing its name may associate the scam with the genuine company.
This can create:
- Increased customer complaints.
- Reputational damage.
- Pressure on support teams.
- Fraud-reporting costs.
- Customer distrust of legitimate communications.
Businesses should therefore consider impersonation risk as part of their wider fraud and cyber-security planning.
Stolen Data Can Support Further Fraud
The recovery of thousands of compromised payment-card details in this case demonstrates that the objective is often broader than obtaining a single fraudulent payment.
Personal and financial information can potentially support further criminal activity.
Depending on the information obtained, criminals may attempt:
- Account takeover.
- Payment-card fraud.
- Identity impersonation.
- Fraudulent applications.
- Social-engineering attacks.
- Further targeted phishing.
- Creation of mule or impersonation accounts.
Information collected through one successful campaign may therefore remain valuable long after the original fraudulent message was sent.
Conflict International’s Fraud and Financial Investigation Services support organisations and individuals dealing with suspected financial fraud, complex transactions and associated evidence.
Employees Can Also Be Targeted
Smishing is not exclusively a consumer problem.
Employees increasingly use mobile devices for work, including accessing email, authentication systems, banking platforms and corporate applications.
A fraudulent text message could impersonate:
- A senior executive.
- An IT administrator.
- A delivery company.
- A bank.
- A supplier.
- A cloud-service provider.
- A government department.
The objective may be to persuade an employee to enter credentials, approve a payment or disclose sensitive information.
Businesses should therefore ensure that security awareness programmes cover SMS and mobile-device threats alongside conventional email phishing.
Employees should understand that the apparent sender of a text message is not, by itself, proof of authenticity.
What Can Businesses Do to Reduce Smishing Risk?
No single control can prevent every social-engineering attack.
However, organisations can reduce their exposure by combining technical safeguards with clear internal procedures.
Businesses should consider:
- Training staff to recognise suspicious SMS requests.
- Requiring independent verification of unusual payment instructions.
- Avoiding authentication processes that rely solely on information contained in an SMS.
- Using multi-factor authentication appropriately.
- Monitoring for brand impersonation.
- Establishing procedures for employees to report suspicious messages.
- Reviewing account activity following suspected compromise.
- Ensuring incidents are escalated quickly to cyber-security teams.
Where financial information has been disclosed, immediate action may also be required to protect affected accounts and preserve relevant evidence.
Individuals Should Be Cautious Even When a Message Looks Genuine
City of London Police recommends that suspicious texts are forwarded to 7726, the free service used by mobile providers to investigate and potentially block malicious senders.
Recipients should also avoid relying solely on the contact details or links contained within an unexpected message.
If a text appears to come from a bank, delivery company or other organisation, the safer approach is generally to contact that organisation independently using details obtained from an official source.
Unexpected requests involving payment information, passwords or security credentials should always justify additional scrutiny.
Fraud Technology Continues to Evolve
The UK SMS blaster cases demonstrate how criminals are adapting technology to overcome safeguards introduced by telecommunications companies, banks and other organisations.
The technology itself may be sophisticated, but the ultimate objective remains familiar: convincing a victim to trust a fraudulent communication.
For businesses, this reinforces the importance of viewing fraud and cyber risk together.
Technical controls remain essential, but organisations also need procedures capable of detecting suspicious activity and responding quickly when those controls are bypassed.
If your organisation has experienced a suspected phishing or smishing incident, compromised account, data exposure or financial fraud, Conflict International can assist with cyber-security response and fraud-related enquiries in the UK and internationally.
Contact Conflict International to discuss your requirements and determine the appropriate scope of support for the matter.