UK’s First SMS Fraudster Convicted After Thousands of Stolen Credit Card Details Seized
UK’s First SMS Blaster Fraudster Sentenced After Thousands of Card Details Recovered
Sentencing and Investigation
A 43-year-old individual from Preston, Lancashire, received a three-year and eight-month prison sentence for operating an SMS blaster device concealed within a vehicle to distribute fraudulent messages across the United Kingdom. Law enforcement recovered 7,859 compromised payment card details linked to the operation, marking the first known instance of such technology being used in the country.
The SMS Blaster Device
The suspect, identified as Mohammed Faiyaz Iqbal, was apprehended in May 2024 after police connected his van to a location associated with the transmission of high volumes of suspicious text messages. During a search of the vehicle, investigators discovered an SMS blaster system housed in custom-built compartments at the rear of the van. The device included power supplies, Wi-Fi components, and roof-mounted aerials, enabling it to transmit messages directly to mobile phones in proximity.
How SMS Blasters Work
SMS blasters function as rogue mobile transmitters, bypassing standard network infrastructure to deliver messages to targeted devices within a specific geographic area. This method allows fraudsters to overwhelm recipients with scam content, often impersonating trusted entities such as Royal Mail. The messages typically create a sense of urgency, prompting individuals to click malicious links or divulge sensitive information.
Investigation and Evidence
During the investigation, law enforcement examined Iqbal’s mobile devices and uncovered 7,859 payment card records. Additional evidence included counterfeit UK driving licenses and banking-related materials, suggesting efforts to establish fraudulent accounts and launder illicit funds. Iqbal faced multiple charges, including fraud by false representation, possession of tools for fraudulent activity, and unauthorized use of wireless communication equipment.
Charges and Sentence
Iqbal pleaded guilty in March 2026, leading to a reduced sentence of three years and eight months after the court considered his cooperation. The case involved collaboration between the Dedicated Card and Payment Crime Unit, mobile network operators, the National Cyber Security Centre, and Ofcom. Major telecom providers such as BT, Virgin Media O2, VodafoneThree, and Sky contributed to the probe.
Industry Concerns and Advice
Authorities highlighted the growing threat of hardware-based fraud, as criminals increasingly exploit specialized equipment to circumvent traditional security measures. Investigators noted that the mobile nature of the SMS blaster allowed the suspect to target densely populated areas, maximizing the reach of fraudulent communications. The technology’s ability to bypass network safeguards raises concerns for mobile operators, as messages can appear legitimate and prompt immediate action from recipients.
UK authorities emphasized that users should not assume the authenticity of unsolicited text messages. They advised against clicking links or sharing financial details in response to unexpected requests. Examples of common smishing tactics include notifications about pending deliveries, failed payments, or urgent account verification.
Conclusion
The case underscores the evolving tactics of cybercriminals, who combine social engineering with advanced telecommunications tools to exploit vulnerabilities. Mobile users are urged to verify requests independently by contacting organizations through official channels rather than relying on message content. For individuals who suspect they have been targeted, immediate action is critical. Contacting banks and reporting incidents to relevant authorities can help mitigate further damage. The incident serves as a cautionary example of how traditional fraud techniques are being augmented with technological innovation to compromise user security.
