A UK fraudster used an SMS blaster hidden inside a van to send scam messages at scale, with police recovering 7,859 compromised payment card details.

UK’s First SMS Blaster Fraudster Sentenced After Thousands of Card Details Recovered

The420 Web Correspondent
7 Min Read

A 43-year-old man has been sentenced to three years and eight months in prison after using an SMS blaster to send fraudulent text messages to people across the UK.

Mohammed Faiyaz Iqbal, from Preston in Lancashire, was arrested in May 2024 after police linked his van to an area from which large numbers of suspicious SMS messages were being transmitted. Officers later discovered an SMS blaster hidden inside specially built compartments in the vehicle.

UK authorities said the equipment was the first known SMS blaster they had encountered in the country.

Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions

What is an SMS blaster and how does smishing work?

An SMS blaster is specialised equipment that can act like a rogue mobile transmitter, sending messages directly to phones in a particular area rather than relying entirely on conventional mobile-network messaging routes.

That makes the technology attractive to fraudsters because it can allow large numbers of nearby people to receive scam messages in a short period.

The messages in this case allegedly impersonated legitimate organisations, including Royal Mail. Recipients were directed towards fraudulent requests designed to obtain payment information and personal details.

This type of text-message fraud is known as smishing — essentially phishing carried out through SMS. Instead of an email, the criminal uses a text message to create urgency and persuade the recipient to click a link, provide information or make a payment.

Fraud equipment was hidden inside a van

Iqbal was arrested on May 24, 2024, while sitting inside a van at the Trafford Shopping Centre car park.

When officers searched the vehicle, they found several mobile phones in the front section. The SMS blaster was concealed towards the rear inside purpose-built wooden compartments.

Investigators said the system included power sources, Wi-Fi components and aerials mounted on the roof of the van. The equipment was switched on and being operated alongside applications installed on mobile phones.

According to authorities, the system was capable of bypassing conventional telecommunications safeguards and transmitting fraudulent SMS messages directly to mobile devices in the surrounding area.

The use of a mobile vehicle was significant because it allowed the equipment to be taken into areas with large concentrations of potential victims.

Nearly 8,000 compromised card details found

The investigation uncovered evidence extending beyond the text messages themselves.

Officers examining Iqbal’s mobile phones found 7,859 compromised payment card details. Police also searched his home, where they recovered additional banking-related material and three counterfeit UK driving licences.

Investigators alleged that the false identity documents were being used to establish impersonation bank accounts and help move criminal proceeds.

Iqbal was charged with several offences, including fraud by false representation, possession of articles for use in fraud, acquiring and possessing criminal property, possession of false identity documents and unauthorised use of wireless telegraphy apparatus.

He pleaded guilty at his first hearing on March 9, 2026.

On August 28, 2026, the court sentenced him to three years and eight months in prison. The court determined that five years and six months would have been the appropriate sentence, but reduced the term by one-third because of his guilty plea.

Police and telecom companies joined the investigation

The investigation involved the Dedicated Card and Payment Crime Unit, mobile network operators, the National Cyber Security Centre and Ofcom.

BT, Virgin Media O2, VodafoneThree and Sky also assisted investigators.

The case highlights a broader concern for law enforcement. Fraudsters are not relying only on fake websites and stolen databases; they are also experimenting with specialised hardware that can interfere with the normal way people receive communications.

That creates a difficult challenge for mobile networks because the fraudulent message can arrive directly on a person’s phone and may appear convincing enough to trigger an immediate response.

Virgin Media O2 said it had blocked more than one billion scam texts to date. The company has urged customers to report suspicious messages by forwarding them to 7726, a free reporting service used by UK mobile networks.

The service allows operators to investigate reported messages and potentially block malicious senders.

Authorities warn users not to trust unexpected texts

The case is a reminder that a message appearing on a phone is not proof that it came from the organisation named in the message.

Users should avoid clicking links in unexpected texts or entering banking and personal information after receiving an unsolicited request. A message claiming that a parcel is waiting, a payment has failed or an account needs urgent verification can be designed specifically to create panic before the recipient has time to check its authenticity.

UK authorities have advised anyone who loses money or discloses financial information following a phishing or smishing attack to contact their bank immediately and report the incident.

The significance of the Iqbal case extends beyond one fraudster. It shows how criminals can combine traditional social-engineering tactics with specialised telecommunications equipment to reach potential victims at scale.

For mobile users, the basic defence remains the same: stop before clicking, verify the organisation independently and never provide banking credentials or payment information simply because a text message appears genuine.

What this means for you: Never assume an SMS is genuine because it arrives directly on your phone or appears to come from a familiar company. If a message asks you to click a link, make a payment or provide banking details, open the organisation’s official website or app yourself and verify the request independently.

If you have already entered financial information or made a payment after responding to a suspicious message, contact your bank immediately and report the fraud to the relevant authorities. Early action can give banks and investigators a better chance of limiting further losses.

Stay Connected