On 28 August 2026, at the conclusion of a case that began in a shopping centre car park more than two years earlier, Mohammed Faiyaz Iqbal, 43, of Preston, Lancashire, was sentenced to three years and eight months in prison for operating a fake mobile phone mast out of the back of a van. City of London Police had arrested him on 24 May 2024 in the car park of the Trafford Shopping Centre, in the middle of an area where the public were reporting unusually large volumes of fraudulent text messages. Inside the van, officers found multiple mobile phones and an active “SMS Blaster” - a portable, illegitimate mobile base station - concealed inside purpose-built wooden compartments, wired into the vehicle’s power, connected to Wi-Fi components and fed by aerials mounted on the roof. It was the first known instance of UK law enforcement encountering an SMS Blaster in the field.
The reason this case matters to any UK business, rather than only to the people who received those texts, is the mechanism. An SMS Blaster does not send fraudulent messages through a mobile network. It persuades nearby handsets to leave the network entirely. By presenting itself as a more attractive cell than the legitimate one, and typically by forcing phones to drop from secure 4G or 5G down to elderly, weakly authenticated 2G, the device delivers its messages directly - which means every filter, every reputation system, every sender-ID rule and every piece of anti-fraud machinery that mobile operators have spent a decade building is simply not in the path. Virgin Media O2 says it has blocked more than one billion scam texts to date; none of that capability applies to a message that never touches the operator’s network. The texts in this case impersonated legitimate organisations including Royal Mail, and examination of Iqbal’s phones uncovered 7,859 compromised payment card details. For UK organisations, the practical consequence is uncomfortable but clear: when the technical layer of defence can be stepped around entirely, what is left is your brand, your customers’ expectations of how you communicate, and whether your staff know what to do with a message that looks exactly like one of yours.
What City of London Police actually found
The operation was, by the standards of modern fraud, strikingly physical. Iqbal was sitting in a van in a busy retail car park on a Friday in May 2024 because he had to be. An SMS Blaster is a short-range device: its practical reach runs from a few tens of metres out to something on the order of one to two kilometres in favourable conditions. There is no remote operation, no botnet, no bulletproof hosting in another jurisdiction. To reach victims, the operator must park within a short distance of them and leave the equipment running - which is precisely why officers were able to correlate a cluster of fraudulent SMS reports with a geographic area and then with a vehicle. The concealment told its own story: the hardware was not sitting loose on a seat but built into bespoke wooden compartments, hard-wired for power, with roof-mounted aerials and Wi-Fi components alongside the phones. This was not an experiment. It was equipment configured for repeated use.
What the subsequent investigation recovered moved the case from “novel device” to organised acquisitive crime. The 7,859 compromised payment card details found on the seized handsets are the harvest side of the operation - the outcome of recipients following a link in a message that appeared to come from a delivery company and entering their details on a convincing replica of a payment page. A search of Iqbal’s home produced further compromised banking material and three counterfeit UK driving licences. Those licences are the part of the case that most clearly demonstrates end-to-end planning: they were used to open impersonation bank accounts through which the proceeds could be laundered. Harvest, cash out, launder. The SMS Blaster was the delivery mechanism at the front of a complete supply chain, not the whole of it.
The court process was unusually compressed for a case of this type. Iqbal pleaded guilty at his first hearing on 9 March 2026, which earned him the maximum available credit. The judge’s starting point was five years and six months - sixty-six months - reduced by a third to the forty-four months imposed on 28 August. That arithmetic is worth noting for what it says about how seriously the courts are treating this conduct. A starting point above five years for fraud committed with a self-built radio device places it firmly in the bracket the sentencing framework reserves for planned, sophisticated offending against large numbers of victims. And this is no longer an isolated matter: since the Trafford arrest there have been further arrests and prosecutions in London, with five other criminals sentenced to more than 100 months in prison between them over the past year. Detective chief inspector Andrew Little of City of London Police framed the case as evidence of the lengths offenders will go to in order to target victims at scale.
Almost every anti-smishing control a UK business relies on sits inside the mobile network: sender-ID registries, operator-level filtering, spam scoring, blocklists and the reporting pipelines behind the free 7726 service. An SMS Blaster is engineered to make all of it irrelevant, because the message is transmitted directly to the handset from a rogue base station a few hundred metres away and never enters an operator’s infrastructure. The recipient sees a text that appears in the same conversation thread as genuine messages from the brand being impersonated. There is no header to inspect, no link-scanning gateway in the path, and nothing for your IT provider to configure. The only controls that still function are the ones that live with people and process: what your organisation has publicly committed to never asking for by text, how quickly a customer or member of staff can verify a message through a channel you control, and how fast a report reaches somebody who can act on it.
How the case unfolded
Read as a sequence, the case describes a technique arriving, being caught, and then propagating anyway. The Trafford arrest in May 2024 was a first; by the time it reached sentencing in August 2026, five further offenders had already been sentenced for related offending. That is the pattern any business planning its fraud posture should assume - not that the prosecution closes the chapter, but that a successful prosecution is usually evidence the technique has become common enough to be encountered routinely. Equipment capable of doing this is neither rare nor expensive, and the operational bar is low: a vehicle, a power supply, an aerial and somewhere busy to park.
Where UK organisations are exposed to brand impersonation
An SMS Blaster attacks your customers and your staff, not your infrastructure - which is exactly why it slips past the way most UK small and medium organisations think about security. The chart below is a Cloudswitched indicative assessment, drawn from what we observe across small and medium client estates rather than from a national survey. It shows the proportion of organisations in which each exposure exists in some form.
The distribution matters more than any individual bar. The behaviours at the top are near-universal, and every one of them trains customers into the habit a fraudster needs: expect a text from us, expect it to contain a link, expect the link to want your details. The controls at the bottom - testing whether staff can recognise a fraudulent message, and having a procedure for the day somebody impersonates you - are rare. In other words, most UK organisations have industrialised the thing that makes smishing work while leaving the response side almost entirely unbuilt. That is not carelessness; SMS became a default business channel because it has an extraordinary open rate, and nobody sat down and decided to make it a fraud vector. But it does mean the exposure sits in the gap between marketing practice and security practice, which is precisely the gap nobody owns.
There is a second, quieter exposure that this case surfaces: the assumption that the network is doing the filtering. Operators genuinely are - the billion-plus texts Virgin Media O2 reports blocking are real defensive work, and for ordinary bulk smishing that machinery is effective. The trouble with reasoning from it is that it produces a security posture whose load-bearing assumption is that somebody else’s filter stands between your customers and a fraudulent message. An SMS Blaster removes that assumption in a few hundred metres of radius, for as long as a van is parked outside a retail park, a station, a stadium or an industrial estate. Any control whose failure mode is “the attacker simply does not use that path” is not a control you can build a plan on.
The number that decides the outcome
Of all the measures an organisation could take against impersonation, one determines whether an incident is a nuisance or a serious event: whether there is a documented, rehearsed procedure for responding to somebody impersonating your brand - who is told, who verifies, what is published, how customers are warned, and how quickly. It is not a technical control, it costs almost nothing, and in our experience it is the single strongest predictor of how an impersonation campaign ends. Our indicative assessment of UK small and medium organisations suggests very few have one.
Eleven per cent is a low number with a straightforward explanation. Brand impersonation does not present as an IT incident. Nothing on your network is compromised, no alert fires, no system is down and no supplier can be called. The first sign is usually a customer telephoning to complain about a text you did not send, and the person who takes that call has no runbook, because the event does not belong to anybody. It is not quite a security incident, not quite a marketing problem, not quite a customer service matter - so it becomes all three, badly, at the speed of whoever happens to answer. Meanwhile the fraudulent messages keep arriving, because the operator’s van has not moved yet.
The organisations that handle it well have made two decisions in advance, and both are free. The first is a published, unambiguous statement of what the business will never do by text - never ask for card details, never ask for a password, never send a payment link, never request a redelivery fee - placed somewhere customers can find it in ten seconds, and repeated in the transactional messages themselves. The second is a single named owner for impersonation reports, with a stated route in from customers and staff and the authority to publish a warning without convening a meeting. Neither requires a purchase. Both convert an amorphous, embarrassing event into a procedure that runs.
Where the gaps usually sit
The badges reflect impact rather than effort, and the ordering is deliberate. The four rated high are all failures of communication discipline rather than technology, and all four are fixable in a morning by somebody with authority over the website and the message templates. The medium band is where technical work starts: moving multi-factor authentication off SMS and onto an authenticator app or hardware token removes an entire category of interception risk, and adding out-of-band verification to payment changes removes the mechanism by which a convincing message turns into a transfer. The single low-rated item is there because it is genuinely low-cost and genuinely useful at population scale - forwarding suspicious texts to 7726 is free, takes seconds, and feeds the intelligence that lets operators and law enforcement find the next van - but no individual organisation should mistake it for a defence of its own.
What proportionate protection costs
Very little of the work here is procurement. The dominant costs are policy, configuration, message-template changes and a modest amount of staff time, which is why the bands below are far smaller than most security line items. They are indicative ranges for UK organisations covering first-year setup and administration, not a quotation, and they exclude the SMS platform costs a business already incurs.
| Business size | Typical exposure | Proportionate response | Indicative first-year cost |
|---|---|---|---|
| 1–10 staff | Owner and staff use personal mobiles for work; occasional customer texts sent from a shared platform or a handset | Published “we will never ask” statement; link-free or clearly branded transactional templates; app-based multi-factor authentication instead of SMS codes; named owner for impersonation reports; a short staff briefing on smishing and 7726 | £450 – £1,500 |
| 11–50 staff | Regular transactional SMS to customers; finance function handling payment and bank-detail requests; mixed personal and company handsets | The above, plus out-of-band verification for all payment and bank-detail changes; annual smishing simulation alongside phishing; mobile device management for company handsets; a one-page impersonation runbook with a named decision-maker | £1,800 – £5,500 |
| 51–150 staff | Marketing and service both sending SMS; multiple sites, some in busy public locations; supplier and customer payment flows at volume | The above, plus registered sender identities and consolidated SMS sending; quarterly simulation with role-specific content; brand-impersonation monitoring; incident response plan including a customer-notification path; Cyber Essentials scope reviewed to include mobile | £5,500 – £15,000 |
| 151–500 staff | High-volume customer messaging, franchised or dispersed sites, regulated obligations around customer communications and fraud reporting | The above, plus formal customer-communications policy with legal sign-off; rehearsed public warning process; takedown retainer for cloned payment pages; board-level fraud reporting; supplier assurance covering messaging partners | £15,000 – £38,000 |
Compare those bands with what the alternative costs. The Cyber Security Breaches Survey has consistently found that the material cost of an incident to a UK small or medium organisation is dominated by lost working time, recovery effort and disruption rather than by fines or ransoms. A brand-impersonation campaign is expensive on precisely those measures: an inbound call volume nobody planned for, a customer base that has to be contacted and reassured, refunds and chargebacks to process, and a reputational conversation that runs for weeks after the van has driven away. With 7,859 sets of card details recovered in this single case, the downstream cost was borne by thousands of people and by the organisations whose names were used to reach them - none of whom had any technical means of preventing it.
Two postures towards impersonation
No UK business can stop somebody parking a van near its customers. What a business controls is whether the message that arrives has anything to work with - whether the recipient has been trained by years of legitimate communication to click without thinking, and whether the organisation can respond in hours rather than days once it learns what is happening. That is the whole of the difference between the two columns below, and almost none of it is a purchase.
Reactive posture
What most UK SMEs do today
- Assumes the mobile network filters fraudulent texts before they arrive
- Sends customers links by SMS with no way for them to verify authenticity
- No published statement of what the business will never ask for by text
- Impersonation reports arrive by chance and land on whoever answers
- Staff awareness training covers email phishing only
- Multi-factor authentication delivered as SMS codes to personal handsets
- Payment and bank-detail changes accepted on the strength of a message
- First customer warning goes out days later, after a meeting
Proactive posture
Where Cloudswitched takes you
- Assumes the message will reach the handset and plans for what happens next
- Transactional messages are link-free or verifiable against a published pattern
- A clear, findable “we will never ask for this by text” commitment customers know
- A named owner and a stated reporting route for suspected impersonation
- Simulation and briefing cover SMS, voice and messaging apps as well as email
- Authentication moved to an app or hardware token, off the SMS channel
- Out-of-band verification mandatory for every payment or bank-detail change
- A rehearsed notification path that warns customers the same working day
Nothing in the right-hand column asks a business to stop using SMS. That would be poor advice; text remains the most reliable way to reach a customer with a delivery slot, an appointment reminder or a one-time reference, and abandoning it would hand fraudsters an uncontested channel. The point is narrower and cheaper: make your legitimate messages structurally different from the fraudulent ones, tell customers in advance what that difference looks like, and be able to act the same day when somebody copies you anyway. Every organisation that has come through an impersonation campaign well did those three things before it started, not during.
Taking UK small and medium estates as a whole, our assessment of readiness against SMS-based impersonation - measured across published commitments, message design, staff awareness, authentication channel, payment verification and response procedure - sits a long way behind how heavily the channel is used.
Thirty-three is a mid-to-low score assembled from a few consistent patterns. Most organisations score reasonably on staff awareness in general terms, because email phishing training has become routine, and poorly on everything specific to messaging. Almost none publish a communications commitment customers could check a suspicious text against. Very few have moved authentication off SMS. Fewer still have decided in advance who owns an impersonation report. The organisations scoring well are not the ones spending most; they are the ones that treated customer communication as part of their security posture rather than as a marketing asset that happens to reach a phone.
Write and publish a single short page titled something like How we will and will not contact you. State plainly which channels your organisation uses, what a genuine message from you looks like, and the things you will never do - never ask for card details or a password by text, never send a payment link out of the blue, never request a fee to release a delivery. Put the page at a memorable address, link it from the footer of your website and from your transactional message templates, and name one person who owns reports of impersonation. That is an afternoon of work, costs nothing, and it is the only control in this article that keeps functioning when the message arrives from a rogue base station in a car park rather than through a mobile network.
At a glance
| Detail | Position as of 4 September 2026 |
|---|---|
| Defendant | Mohammed Faiyaz Iqbal, 43, of Preston, Lancashire |
| Sentence | Three years and eight months (44 months) imprisonment, imposed 28 August 2026 |
| Sentencing arithmetic | Starting point five years and six months, reduced by one third for a guilty plea entered at the first hearing on 9 March 2026 |
| Investigating force | City of London Police |
| Arrest | 24 May 2024, in a van in the Trafford Shopping Centre car park, in the area where fraudulent SMS messages were being reported |
| Equipment recovered | An active SMS Blaster plus multiple mobile phones, concealed in purpose-built wooden compartments, wired to power, with Wi-Fi components and rooftop aerials |
| What an SMS Blaster is | A fake, portable mobile base station that tricks nearby handsets into connecting to it instead of a legitimate operator |
| How it evades filtering | Typically forces handsets to drop from secure 4G or 5G down to vulnerable 2G, delivering messages directly and bypassing operator security filters entirely |
| Operating range | Short - from a few tens of metres up to roughly 1–2km, so the operator must be physically near the targets while running |
| Messages sent | Smishing texts impersonating legitimate organisations including Royal Mail, designed to obtain payment and personal details |
| Card details compromised | 7,859 sets recovered from examination of the seized phones |
| Laundering infrastructure | Further compromised banking material at the home address, plus three counterfeit UK driving licences used to open impersonation bank accounts |
| Precedent | First known instance of UK law enforcement encountering an SMS Blaster |
| Wider enforcement | Further arrests and prosecutions in London; five other criminals sentenced to more than 100 months in prison between them over the past year |
| Operator response | Virgin Media O2 reports blocking more than one billion scam texts to date and urges the public to report suspicious calls and texts free to 7726 |
| Direct effect on UK businesses | None from the prosecution itself - the exposure is that staff and customers can be targeted with messages carrying your name that no network filter will ever see |
The pattern this fits into
Set alongside what we have reported over recent weeks, this case belongs to a familiar family: a control that everyone assumed was doing the work turns out to have an obvious way around it. Our coverage of the NCSC’s warning about internet-exposed edge devices made the point that organisations defend what they have written down, and the things nobody inventoried are the ones that get found. An SMS Blaster is the same observation pointed at a channel rather than a device: nobody inventoried the assumption that the mobile network sits between a fraudster and a customer, so nobody noticed when a van in a car park removed it.
The accountability question is the other constant. When a fraudulent text carrying your name reaches your customer, there is no supplier to escalate to and no service credit to claim - a situation with the same shape as the one we examined in our reporting on broadband fault accountability for UK businesses, where the organisations that fared best were the ones that had settled in advance who owns a problem that technically belongs to nobody. The same lesson runs through our analysis of the Gamma buyout and what it means for voice continuity: communications channels are business-critical infrastructure, and the time to decide how you will keep talking to customers under adverse conditions is before the conditions arrive.
Finally, the direction of travel. Our reporting on the UK’s 5G and AI connectivity gap covered the migration of the mobile estate towards newer, better-authenticated generations - the same migration that makes a forced downgrade to 2G such an effective attack while legacy support persists. And our coverage of the Lords amendment on an AI kill switch described a Parliament increasingly willing to legislate for the moment a system has to be stopped. Both threads converge on the point this prosecution makes concretely: technical controls fail in ways that are entirely predictable, and the organisations that come through are the ones that decided beforehand what they would do about it.
Make your legitimate messages impossible to imitate
Cloudswitched helps UK businesses close the gap this case exposes: a published communications commitment customers can check, transactional messages designed so a fake is obvious, multi-factor authentication moved off SMS, out-of-band verification on payment changes, smishing simulation for staff and a named owner with a rehearsed response - all of it aligned to the Cyber Essentials controls your customers and insurers already ask about.
Talk to us about Cyber Essentials CertificationFrequently asked questions
The network cannot protect your customers from a message in your name
This prosecution shows what happens when an attacker steps around the filtering everyone relies on. What is left is the discipline of your own communications and the readiness of your staff - both of which sit inside the Cyber Essentials control set. Cloudswitched takes UK businesses through certification and the practical work around it, from scoping mobile devices and access control to smishing awareness and a rehearsed response for the day somebody uses your name.
Talk to us about Cyber Essentials Certification


