Back to News

Jailed for Running a Fake Mobile Tower: What the SMS Blaster Case Means for UK Businesses

Jailed for Running a Fake Mobile Tower: What the SMS Blaster Case Means for UK Businesses

On 28 August 2026, at the conclusion of a case that began in a shopping centre car park more than two years earlier, Mohammed Faiyaz Iqbal, 43, of Preston, Lancashire, was sentenced to three years and eight months in prison for operating a fake mobile phone mast out of the back of a van. City of London Police had arrested him on 24 May 2024 in the car park of the Trafford Shopping Centre, in the middle of an area where the public were reporting unusually large volumes of fraudulent text messages. Inside the van, officers found multiple mobile phones and an active “SMS Blaster” - a portable, illegitimate mobile base station - concealed inside purpose-built wooden compartments, wired into the vehicle’s power, connected to Wi-Fi components and fed by aerials mounted on the roof. It was the first known instance of UK law enforcement encountering an SMS Blaster in the field.

The reason this case matters to any UK business, rather than only to the people who received those texts, is the mechanism. An SMS Blaster does not send fraudulent messages through a mobile network. It persuades nearby handsets to leave the network entirely. By presenting itself as a more attractive cell than the legitimate one, and typically by forcing phones to drop from secure 4G or 5G down to elderly, weakly authenticated 2G, the device delivers its messages directly - which means every filter, every reputation system, every sender-ID rule and every piece of anti-fraud machinery that mobile operators have spent a decade building is simply not in the path. Virgin Media O2 says it has blocked more than one billion scam texts to date; none of that capability applies to a message that never touches the operator’s network. The texts in this case impersonated legitimate organisations including Royal Mail, and examination of Iqbal’s phones uncovered 7,859 compromised payment card details. For UK organisations, the practical consequence is uncomfortable but clear: when the technical layer of defence can be stepped around entirely, what is left is your brand, your customers’ expectations of how you communicate, and whether your staff know what to do with a message that looks exactly like one of yours.

7,859
Compromised payment card details recovered from the mobile phones seized alongside the SMS Blaster in the van
44 months
The sentence handed down on 28 August 2026 - three years and eight months, from a starting point of five years and six months reduced by a third for the guilty plea
2G
The insecure signal generation that nearby handsets were forced down to, so fraudulent texts could bypass operator security filters entirely
1bn+
Scam texts Virgin Media O2 says it has blocked to date - network-level protection that an SMS Blaster is specifically designed to sidestep

What City of London Police actually found

The operation was, by the standards of modern fraud, strikingly physical. Iqbal was sitting in a van in a busy retail car park on a Friday in May 2024 because he had to be. An SMS Blaster is a short-range device: its practical reach runs from a few tens of metres out to something on the order of one to two kilometres in favourable conditions. There is no remote operation, no botnet, no bulletproof hosting in another jurisdiction. To reach victims, the operator must park within a short distance of them and leave the equipment running - which is precisely why officers were able to correlate a cluster of fraudulent SMS reports with a geographic area and then with a vehicle. The concealment told its own story: the hardware was not sitting loose on a seat but built into bespoke wooden compartments, hard-wired for power, with roof-mounted aerials and Wi-Fi components alongside the phones. This was not an experiment. It was equipment configured for repeated use.

What the subsequent investigation recovered moved the case from “novel device” to organised acquisitive crime. The 7,859 compromised payment card details found on the seized handsets are the harvest side of the operation - the outcome of recipients following a link in a message that appeared to come from a delivery company and entering their details on a convincing replica of a payment page. A search of Iqbal’s home produced further compromised banking material and three counterfeit UK driving licences. Those licences are the part of the case that most clearly demonstrates end-to-end planning: they were used to open impersonation bank accounts through which the proceeds could be laundered. Harvest, cash out, launder. The SMS Blaster was the delivery mechanism at the front of a complete supply chain, not the whole of it.

The court process was unusually compressed for a case of this type. Iqbal pleaded guilty at his first hearing on 9 March 2026, which earned him the maximum available credit. The judge’s starting point was five years and six months - sixty-six months - reduced by a third to the forty-four months imposed on 28 August. That arithmetic is worth noting for what it says about how seriously the courts are treating this conduct. A starting point above five years for fraud committed with a self-built radio device places it firmly in the bracket the sentencing framework reserves for planned, sophisticated offending against large numbers of victims. And this is no longer an isolated matter: since the Trafford arrest there have been further arrests and prosecutions in London, with five other criminals sentenced to more than 100 months in prison between them over the past year. Detective chief inspector Andrew Little of City of London Police framed the case as evidence of the lengths offenders will go to in order to target victims at scale.

Why this bypasses everything you have bought

Almost every anti-smishing control a UK business relies on sits inside the mobile network: sender-ID registries, operator-level filtering, spam scoring, blocklists and the reporting pipelines behind the free 7726 service. An SMS Blaster is engineered to make all of it irrelevant, because the message is transmitted directly to the handset from a rogue base station a few hundred metres away and never enters an operator’s infrastructure. The recipient sees a text that appears in the same conversation thread as genuine messages from the brand being impersonated. There is no header to inspect, no link-scanning gateway in the path, and nothing for your IT provider to configure. The only controls that still function are the ones that live with people and process: what your organisation has publicly committed to never asking for by text, how quickly a customer or member of staff can verify a message through a channel you control, and how fast a report reaches somebody who can act on it.

How the case unfolded

24 May 2024 - Fraudulent texts cluster around Trafford
Members of the public in and around the Trafford Shopping Centre report receiving large numbers of fraudulent SMS messages. The geographic concentration of the reports is itself the investigative lead: unlike conventional smishing, which arrives from everywhere at once, these messages are tied to a place.
24 May 2024 - Arrest in the car park
City of London Police arrest Mohammed Faiyaz Iqbal, then 41, while he sits in a van in the shopping centre car park, in the same area from which the reports originate. The equipment is running at the time officers reach the vehicle.
24 May 2024 - The van is searched
Officers recover multiple mobile phones and an active SMS Blaster concealed in purpose-built wooden compartments, wired to the van’s power supply, connected to Wi-Fi components and served by aerials mounted on the roof. It is the first time UK law enforcement is known to have encountered such a device in operation.
Mid-2024 - Digital examination of the seized handsets
Forensic examination of the phones uncovers 7,859 compromised payment card details, establishing the scale of the harvesting operation behind the messages. The texts themselves had impersonated legitimate organisations including Royal Mail.
2024 - Search of the home address
A search of Iqbal’s Preston home recovers further compromised banking material and three counterfeit UK driving licences, used to open impersonation bank accounts for laundering the proceeds of the fraud.
2025–2026 - The technique spreads, and so do the prosecutions
Further SMS Blaster arrests and prosecutions follow in London. Over the past year, five other criminals are sentenced to more than 100 months in prison between them for offending involving the same class of device.
9 March 2026 - Guilty plea at the first hearing
Iqbal pleads guilty at his first appearance, securing the maximum one-third credit against whatever sentence the court would otherwise impose.
28 August 2026 - Sentenced to three years and eight months
The judge sets a starting point of five years and six months, reduced by a third for the early plea, giving a sentence of forty-four months. Detective chief inspector Andrew Little says the case shows the lengths offenders will go to in order to target victims at scale. Virgin Media O2 uses the conclusion of the case to urge the public to forward suspicious calls and texts, free of charge, to 7726.

Read as a sequence, the case describes a technique arriving, being caught, and then propagating anyway. The Trafford arrest in May 2024 was a first; by the time it reached sentencing in August 2026, five further offenders had already been sentenced for related offending. That is the pattern any business planning its fraud posture should assume - not that the prosecution closes the chapter, but that a successful prosecution is usually evidence the technique has become common enough to be encountered routinely. Equipment capable of doing this is neither rare nor expensive, and the operational bar is low: a vehicle, a power supply, an aerial and somewhere busy to park.

Where UK organisations are exposed to brand impersonation

An SMS Blaster attacks your customers and your staff, not your infrastructure - which is exactly why it slips past the way most UK small and medium organisations think about security. The chart below is a Cloudswitched indicative assessment, drawn from what we observe across small and medium client estates rather than from a national survey. It shows the proportion of organisations in which each exposure exists in some form.

Sends customers transactional texts containing a clickable link
86%
No published statement of what the business will never ask for by SMS
79%
Staff receive work-relevant texts on personal, unmanaged handsets
71%
No route for a customer to report a suspected impersonation of the brand
64%
Payment or bank-detail changes can be actioned without out-of-band verification
38%
Phishing and smishing simulation run at least annually for all staff
27%
Documented procedure for responding to impersonation of the brand
11%

The distribution matters more than any individual bar. The behaviours at the top are near-universal, and every one of them trains customers into the habit a fraudster needs: expect a text from us, expect it to contain a link, expect the link to want your details. The controls at the bottom - testing whether staff can recognise a fraudulent message, and having a procedure for the day somebody impersonates you - are rare. In other words, most UK organisations have industrialised the thing that makes smishing work while leaving the response side almost entirely unbuilt. That is not carelessness; SMS became a default business channel because it has an extraordinary open rate, and nobody sat down and decided to make it a fraud vector. But it does mean the exposure sits in the gap between marketing practice and security practice, which is precisely the gap nobody owns.

There is a second, quieter exposure that this case surfaces: the assumption that the network is doing the filtering. Operators genuinely are - the billion-plus texts Virgin Media O2 reports blocking are real defensive work, and for ordinary bulk smishing that machinery is effective. The trouble with reasoning from it is that it produces a security posture whose load-bearing assumption is that somebody else’s filter stands between your customers and a fraudulent message. An SMS Blaster removes that assumption in a few hundred metres of radius, for as long as a van is parked outside a retail park, a station, a stadium or an industrial estate. Any control whose failure mode is “the attacker simply does not use that path” is not a control you can build a plan on.

The number that decides the outcome

Of all the measures an organisation could take against impersonation, one determines whether an incident is a nuisance or a serious event: whether there is a documented, rehearsed procedure for responding to somebody impersonating your brand - who is told, who verifies, what is published, how customers are warned, and how quickly. It is not a technical control, it costs almost nothing, and in our experience it is the single strongest predictor of how an impersonation campaign ends. Our indicative assessment of UK small and medium organisations suggests very few have one.

11%
Cloudswitched indicative assessment: UK SMEs with a documented procedure for responding to fraudulent messages sent in their name

Eleven per cent is a low number with a straightforward explanation. Brand impersonation does not present as an IT incident. Nothing on your network is compromised, no alert fires, no system is down and no supplier can be called. The first sign is usually a customer telephoning to complain about a text you did not send, and the person who takes that call has no runbook, because the event does not belong to anybody. It is not quite a security incident, not quite a marketing problem, not quite a customer service matter - so it becomes all three, badly, at the speed of whoever happens to answer. Meanwhile the fraudulent messages keep arriving, because the operator’s van has not moved yet.

The organisations that handle it well have made two decisions in advance, and both are free. The first is a published, unambiguous statement of what the business will never do by text - never ask for card details, never ask for a password, never send a payment link, never request a redelivery fee - placed somewhere customers can find it in ten seconds, and repeated in the transactional messages themselves. The second is a single named owner for impersonation reports, with a stated route in from customers and staff and the authority to publish a warning without convening a meeting. Neither requires a purchase. Both convert an amorphous, embarrassing event into a procedure that runs.

Where the gaps usually sit

Smishing and brand-impersonation exposure - typical UK SME assessment
No published “we will never ask for this by text” statement customers can check High
Transactional SMS trains customers to expect and follow links High
No owner or runbook for reports that the brand is being impersonated High
Work-relevant messages received on personal handsets outside any management High
Payment or bank-detail changes accepted without out-of-band verification Medium
Staff awareness training does not cover SMS, only email phishing Medium
Multi-factor authentication delivered by SMS rather than by app or token Medium
No routine use of 7726 reporting by staff who receive suspicious messages Low

The badges reflect impact rather than effort, and the ordering is deliberate. The four rated high are all failures of communication discipline rather than technology, and all four are fixable in a morning by somebody with authority over the website and the message templates. The medium band is where technical work starts: moving multi-factor authentication off SMS and onto an authenticator app or hardware token removes an entire category of interception risk, and adding out-of-band verification to payment changes removes the mechanism by which a convincing message turns into a transfer. The single low-rated item is there because it is genuinely low-cost and genuinely useful at population scale - forwarding suspicious texts to 7726 is free, takes seconds, and feeds the intelligence that lets operators and law enforcement find the next van - but no individual organisation should mistake it for a defence of its own.

What proportionate protection costs

Very little of the work here is procurement. The dominant costs are policy, configuration, message-template changes and a modest amount of staff time, which is why the bands below are far smaller than most security line items. They are indicative ranges for UK organisations covering first-year setup and administration, not a quotation, and they exclude the SMS platform costs a business already incurs.

Business size Typical exposure Proportionate response Indicative first-year cost
1–10 staff Owner and staff use personal mobiles for work; occasional customer texts sent from a shared platform or a handset Published “we will never ask” statement; link-free or clearly branded transactional templates; app-based multi-factor authentication instead of SMS codes; named owner for impersonation reports; a short staff briefing on smishing and 7726 £450 – £1,500
11–50 staff Regular transactional SMS to customers; finance function handling payment and bank-detail requests; mixed personal and company handsets The above, plus out-of-band verification for all payment and bank-detail changes; annual smishing simulation alongside phishing; mobile device management for company handsets; a one-page impersonation runbook with a named decision-maker £1,800 – £5,500
51–150 staff Marketing and service both sending SMS; multiple sites, some in busy public locations; supplier and customer payment flows at volume The above, plus registered sender identities and consolidated SMS sending; quarterly simulation with role-specific content; brand-impersonation monitoring; incident response plan including a customer-notification path; Cyber Essentials scope reviewed to include mobile £5,500 – £15,000
151–500 staff High-volume customer messaging, franchised or dispersed sites, regulated obligations around customer communications and fraud reporting The above, plus formal customer-communications policy with legal sign-off; rehearsed public warning process; takedown retainer for cloned payment pages; board-level fraud reporting; supplier assurance covering messaging partners £15,000 – £38,000

Compare those bands with what the alternative costs. The Cyber Security Breaches Survey has consistently found that the material cost of an incident to a UK small or medium organisation is dominated by lost working time, recovery effort and disruption rather than by fines or ransoms. A brand-impersonation campaign is expensive on precisely those measures: an inbound call volume nobody planned for, a customer base that has to be contacted and reassured, refunds and chargebacks to process, and a reputational conversation that runs for weeks after the van has driven away. With 7,859 sets of card details recovered in this single case, the downstream cost was borne by thousands of people and by the organisations whose names were used to reach them - none of whom had any technical means of preventing it.

Two postures towards impersonation

No UK business can stop somebody parking a van near its customers. What a business controls is whether the message that arrives has anything to work with - whether the recipient has been trained by years of legitimate communication to click without thinking, and whether the organisation can respond in hours rather than days once it learns what is happening. That is the whole of the difference between the two columns below, and almost none of it is a purchase.

Reactive posture

What most UK SMEs do today

  • Assumes the mobile network filters fraudulent texts before they arrive
  • Sends customers links by SMS with no way for them to verify authenticity
  • No published statement of what the business will never ask for by text
  • Impersonation reports arrive by chance and land on whoever answers
  • Staff awareness training covers email phishing only
  • Multi-factor authentication delivered as SMS codes to personal handsets
  • Payment and bank-detail changes accepted on the strength of a message
  • First customer warning goes out days later, after a meeting

Proactive posture

Where Cloudswitched takes you

  • Assumes the message will reach the handset and plans for what happens next
  • Transactional messages are link-free or verifiable against a published pattern
  • A clear, findable “we will never ask for this by text” commitment customers know
  • A named owner and a stated reporting route for suspected impersonation
  • Simulation and briefing cover SMS, voice and messaging apps as well as email
  • Authentication moved to an app or hardware token, off the SMS channel
  • Out-of-band verification mandatory for every payment or bank-detail change
  • A rehearsed notification path that warns customers the same working day

Nothing in the right-hand column asks a business to stop using SMS. That would be poor advice; text remains the most reliable way to reach a customer with a delivery slot, an appointment reminder or a one-time reference, and abandoning it would hand fraudsters an uncontested channel. The point is narrower and cheaper: make your legitimate messages structurally different from the fraudulent ones, tell customers in advance what that difference looks like, and be able to act the same day when somebody copies you anyway. Every organisation that has come through an impersonation campaign well did those three things before it started, not during.

Taking UK small and medium estates as a whole, our assessment of readiness against SMS-based impersonation - measured across published commitments, message design, staff awareness, authentication channel, payment verification and response procedure - sits a long way behind how heavily the channel is used.

33
Typical UK SME readiness against SMS impersonation and smishing - Cloudswitched indicative score out of 100

Thirty-three is a mid-to-low score assembled from a few consistent patterns. Most organisations score reasonably on staff awareness in general terms, because email phishing training has become routine, and poorly on everything specific to messaging. Almost none publish a communications commitment customers could check a suspicious text against. Very few have moved authentication off SMS. Fewer still have decided in advance who owns an impersonation report. The organisations scoring well are not the ones spending most; they are the ones that treated customer communication as part of their security posture rather than as a marketing asset that happens to reach a phone.

The one thing to do this month

Write and publish a single short page titled something like How we will and will not contact you. State plainly which channels your organisation uses, what a genuine message from you looks like, and the things you will never do - never ask for card details or a password by text, never send a payment link out of the blue, never request a fee to release a delivery. Put the page at a memorable address, link it from the footer of your website and from your transactional message templates, and name one person who owns reports of impersonation. That is an afternoon of work, costs nothing, and it is the only control in this article that keeps functioning when the message arrives from a rogue base station in a car park rather than through a mobile network.

At a glance

Detail Position as of 4 September 2026
Defendant Mohammed Faiyaz Iqbal, 43, of Preston, Lancashire
Sentence Three years and eight months (44 months) imprisonment, imposed 28 August 2026
Sentencing arithmetic Starting point five years and six months, reduced by one third for a guilty plea entered at the first hearing on 9 March 2026
Investigating force City of London Police
Arrest 24 May 2024, in a van in the Trafford Shopping Centre car park, in the area where fraudulent SMS messages were being reported
Equipment recovered An active SMS Blaster plus multiple mobile phones, concealed in purpose-built wooden compartments, wired to power, with Wi-Fi components and rooftop aerials
What an SMS Blaster is A fake, portable mobile base station that tricks nearby handsets into connecting to it instead of a legitimate operator
How it evades filtering Typically forces handsets to drop from secure 4G or 5G down to vulnerable 2G, delivering messages directly and bypassing operator security filters entirely
Operating range Short - from a few tens of metres up to roughly 1–2km, so the operator must be physically near the targets while running
Messages sent Smishing texts impersonating legitimate organisations including Royal Mail, designed to obtain payment and personal details
Card details compromised 7,859 sets recovered from examination of the seized phones
Laundering infrastructure Further compromised banking material at the home address, plus three counterfeit UK driving licences used to open impersonation bank accounts
Precedent First known instance of UK law enforcement encountering an SMS Blaster
Wider enforcement Further arrests and prosecutions in London; five other criminals sentenced to more than 100 months in prison between them over the past year
Operator response Virgin Media O2 reports blocking more than one billion scam texts to date and urges the public to report suspicious calls and texts free to 7726
Direct effect on UK businesses None from the prosecution itself - the exposure is that staff and customers can be targeted with messages carrying your name that no network filter will ever see

The pattern this fits into

Set alongside what we have reported over recent weeks, this case belongs to a familiar family: a control that everyone assumed was doing the work turns out to have an obvious way around it. Our coverage of the NCSC’s warning about internet-exposed edge devices made the point that organisations defend what they have written down, and the things nobody inventoried are the ones that get found. An SMS Blaster is the same observation pointed at a channel rather than a device: nobody inventoried the assumption that the mobile network sits between a fraudster and a customer, so nobody noticed when a van in a car park removed it.

The accountability question is the other constant. When a fraudulent text carrying your name reaches your customer, there is no supplier to escalate to and no service credit to claim - a situation with the same shape as the one we examined in our reporting on broadband fault accountability for UK businesses, where the organisations that fared best were the ones that had settled in advance who owns a problem that technically belongs to nobody. The same lesson runs through our analysis of the Gamma buyout and what it means for voice continuity: communications channels are business-critical infrastructure, and the time to decide how you will keep talking to customers under adverse conditions is before the conditions arrive.

Finally, the direction of travel. Our reporting on the UK’s 5G and AI connectivity gap covered the migration of the mobile estate towards newer, better-authenticated generations - the same migration that makes a forced downgrade to 2G such an effective attack while legacy support persists. And our coverage of the Lords amendment on an AI kill switch described a Parliament increasingly willing to legislate for the moment a system has to be stopped. Both threads converge on the point this prosecution makes concretely: technical controls fail in ways that are entirely predictable, and the organisations that come through are the ones that decided beforehand what they would do about it.

Make your legitimate messages impossible to imitate

Cloudswitched helps UK businesses close the gap this case exposes: a published communications commitment customers can check, transactional messages designed so a fake is obvious, multi-factor authentication moved off SMS, out-of-band verification on payment changes, smishing simulation for staff and a named owner with a rehearsed response - all of it aligned to the Cyber Essentials controls your customers and insurers already ask about.

Talk to us about Cyber Essentials Certification

Frequently asked questions

What exactly is an SMS Blaster?
It is a fake, portable mobile base station - in this case built into the back of a van, concealed in purpose-built wooden compartments, wired to the vehicle’s power and connected to aerials on the roof. It works by presenting itself to nearby handsets as a mobile cell worth connecting to, so phones leave their real operator and attach to the device instead. Typically it does this by forcing handsets to drop from secure 4G or 5G down to older, weakly authenticated 2G signal. Once a phone is attached, the operator can push text messages straight to it. Because those messages never enter a mobile operator’s network, none of the filtering, sender-ID checking or spam scoring that normally protects subscribers has any opportunity to act on them.
Could my business be targeted by one of these?
Your premises are unlikely to be the target as such; the device targets whoever happens to be within range, which is a few tens of metres up to roughly one or two kilometres. What that means in practice is that your staff and your customers can be caught in the radius of an attack aimed at a busy area - a retail park, a station, a stadium, a city centre or an industrial estate. The business risk is not that your systems are compromised but that messages carrying your name reach people who trust you. In this case the fraudulent texts impersonated legitimate organisations including Royal Mail, and 7,859 sets of card details were recovered from the seized phones. Any recognisable brand that texts its customers is an available disguise.
Can our mobile operator or IT provider block these messages?
Not in the path. This is the uncomfortable core of the story. Operators do a great deal of effective filtering - Virgin Media O2 reports blocking more than one billion scam texts to date - but all of that machinery sits inside the network. An SMS Blaster transmits directly to the handset from a rogue base station a few hundred metres away, so there is nothing for a filter to inspect and nothing for your IT provider to configure. Reporting still matters: forwarding suspicious texts free to 7726 feeds the intelligence that helps operators and law enforcement locate the equipment, which is how these cases start. But no filtering product will stop the message arriving, which is why the controls that work are the human and procedural ones.
Why does forcing phones onto 2G matter so much?
2G was designed in an era when the threat model assumed base stations were trustworthy. Its authentication is one-way in practice: the handset proves itself to the network, but the network is not required to prove itself convincingly to the handset. Modern 4G and 5G connections authenticate in both directions, which makes impersonating a legitimate cell far harder. Because handsets retain 2G support for coverage and compatibility reasons, an attacker can present conditions that push a phone to fall back to it, and at that point the phone will attach to equipment in a van without any indication to the user that something is wrong. Downgrade is the whole trick; everything else follows from it.
What should our staff actually do if they receive a suspicious text?
Three things, in order. Do not tap the link, however plausible the message and however much it resembles others in the same conversation thread - fraudulent messages can appear alongside genuine ones from a brand. Verify independently: go to the organisation’s website by typing the address, or call a number you already hold, rather than any contact detail in the message. Then report it: forward the text free to 7726, and tell whoever owns this in your organisation so a pattern can be spotted if several people are receiving the same thing. That last step is the one most businesses have not set up, and it is what turns a handful of individual near-misses into an early warning.
We send customers transactional texts. Should we stop?
No - withdrawing from the channel would inconvenience customers and hand fraudsters an uncontested space. The objective is to make your genuine messages structurally distinguishable from fakes. Publish what a real message from you looks like and what you will never ask for. Prefer messages that do not require the recipient to follow a link, or that reference something only a genuine customer relationship would know, such as an order reference the customer already holds. Keep sending consistent, so an inconsistent message stands out. And never use text to request payment details, password resets or a fee to release a delivery, because every time a legitimate business does that it makes the fraudulent version more credible.
Does this affect SMS-based multi-factor authentication?
It is a good reason to move away from it, alongside the older and better-known risks of SIM-swap fraud and message interception. SMS one-time codes were always the weakest of the mainstream second factors; their advantage was that they work on any handset with no setup. Against an attacker who can manipulate the radio environment, that advantage looks thinner. An authenticator app or a hardware security key removes the mobile network from the authentication path entirely, costs little or nothing to adopt, and is the direction every serious assurance framework has been pointing for years. For most UK organisations this is a configuration change and a staff communication, not a project.
How does Cyber Essentials relate to any of this?
Cyber Essentials will not stop a rogue base station - no certification can - but the scheme’s controls address most of the ways a smishing message turns into a loss. Secure configuration and access control limit what a stolen credential is worth; the requirement to bring mobile devices used for organisational data into scope forces the conversation about personal handsets that this case makes concrete; and the discipline of documenting what is in scope surfaces exactly the assumptions that go unexamined otherwise. Certification also gives you a defensible answer for customers, insurers and enterprise procurement, all of whom increasingly ask what you do about fraud aimed at your customers rather than only at your network.
Is this technique becoming more common in the UK?
The evidence points that way. The May 2024 Trafford arrest was the first known instance of UK law enforcement encountering an SMS Blaster, and by the time that case reached sentencing in August 2026 there had been further arrests and prosecutions in London, with five other criminals sentenced to more than 100 months in prison between them over the past year. That is a technique moving from novelty to routine within roughly two years. The economics explain it: the equipment is portable, the operating requirement is simply to park somewhere busy, and the yield in this single case ran to 7,859 sets of card details. Enforcement is clearly working, but prosecutions typically follow adoption rather than preventing it.
What would you do first if we asked you to look at this for us?
Start with the customer-facing side, because it is free and it is what fails hardest. That means publishing a clear statement of how you will and will not contact people, reviewing every transactional message template against it, and naming one person who owns reports that somebody is impersonating you. Next, take the technical steps that remove the payoff: move multi-factor authentication off SMS to an app or token, and require out-of-band verification for any payment or bank-detail change. Then extend awareness training beyond email to cover text, voice and messaging apps, and run one simulation to see where you actually stand. For most organisations of fifty to a hundred and fifty staff that is a few weeks of part-time effort, and it closes the majority of the exposure this case illustrates.

The network cannot protect your customers from a message in your name

This prosecution shows what happens when an attacker steps around the filtering everyone relies on. What is left is the discipline of your own communications and the readiness of your staff - both of which sit inside the Cyber Essentials control set. Cloudswitched takes UK businesses through certification and the practical work around it, from scoping mobile devices and access control to smishing awareness and a rehearsed response for the day somebody uses your name.

Talk to us about Cyber Essentials Certification
Tags:Cyber EssentialsIT SupportNetworkingVirtual CIO
CloudSwitched

London-based managed IT services provider offering support, cloud solutions and cybersecurity for SMEs.

CloudSwitched Service

Cyber Essentials Certification

End-to-end Cyber Essentials Plus certification and ongoing security services for UK businesses

Learn More

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

13
  • Internet & Connectivity

Bandwidth Planning for Growing UK Businesses: A Practical Guide to Sizing Your Internet Connection in 2026

13 Sep, 2026

Almost every UK business sizes its internet connection exactly once. Someone signs a lease, an installer quotes what is available at the postcode, a number is...

Read more
12
  • Database Reporting

Data Warehouse vs Reporting Database: A UK Business Guide to Choosing the Right Architecture for Business Intelligence in 2026

12 Sep, 2026

Most UK businesses do not choose a data warehouse architecture deliberately. They arrive at one by accident, usually at the point where a monthly management...

Read more
11
  • AI

AI Feature Prototyping: A UK Business Guide to Validating AI Product Ideas Before Committing Engineering Budget in 2026

11 Sep, 2026

Almost every expensive AI failure in a UK business starts the same way: somebody demonstrated something impressive in a chat window, everybody in the room...

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.