Case Library / Pretexting & Impersonation / iSpoof Caller-ID Spoofing-as-a-Service Platform (Tejay Fletcher)

iSpoof Caller-ID Spoofing-as-a-Service Platform (Tejay Fletcher)

Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank and government staff at industrial scale, generating over £100 million in global losses before a Metropolitan Police-led international takedown and Fletcher's 13-year, 4-month sentence.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

iSpoof.cc was a UK-run, Bitcoin-paid subscription website, created around 30 November 2020, that sold caller-ID spoofing and related fraud tools "as a service." Subscribers, an estimated 59,000 registered users at peak, paid iSpoof between roughly £150 and £5,000+ per month to disguise their outgoing calls so a victim's phone displayed the name/number of a genuine bank, tax authority, or other trusted organisation. Using this spoofed legitimacy plus add-on tools to intercept one-time passcodes and play recorded "verification" messages, iSpoof's criminal customers cold-called victims claiming to be bank fraud investigators (or equivalent government/retail staff), talked them through a bogus security check, and captured passwords, PINs and OTPs, which were then used to log into and drain the victims' real bank accounts. The Metropolitan Police's Cyber Crime Unit began investigating under "Operation Elaborate" in June 2021, ultimately working with Eurojust, Europol, Dutch, US, Ukrainian, Australian, French and Irish authorities. In a coordinated international action, the FBI/Ukrainian authorities seized iSpoof's Kyiv-hosted server on 8 November 2022, after Fletcher had already been arrested at an east London address on 6 November, and 142 people were arrested worldwide (120 in the UK, 103 of them in London). Fletcher pleaded guilty on 20 April 2023 to four fraud-related offences and was sentenced on 19 May 2023 at Southwark Crown Court to 13 years and 4 months in prison, in what UK authorities described as the country's largest-ever fraud investigation.

How the Attack Worked

iSpoof.cc was a subscription "crime-as-a-service" website: for £150-£5,000+ per month, paid in Bitcoin, users bought caller-ID spoofing so their calls displayed as coming from a trusted number (typically a bank's genuine customer-service line), plus add-on features to play pre-recorded "verification" prompts and to intercept one-time passcodes/SMS codes sent by banks. This let subscriber-fraudsters cold-call victims sounding exactly like their bank's fraud department (or, per Eurojust, retail companies and government/tax bodies), walk them through a fabricated "security check," and harvest passwords, PINs and OTPs in real time, then use those codes to log into and empty the victim's real account before the victim realized the call was fake. The service was marketed openly via a Telegram channel ("iSpoof club") and had 59,000 registered users at its peak, with investigators later finding the seized server held 70 million rows of call/payment data; at points, up to 20 people per minute were being targeted by iSpoof-enabled calls.

The Lure & the Tell

Lure: a call (or accompanying SMS) that displayed a genuine-looking bank/government phone number due to caller-ID spoofing, opening with an "urgent security alert," for example "we've detected suspicious activity on your account," spoken by someone posing as bank fraud-department or tax-office staff, who then walked the victim through a fake "verification" process to "protect" the account. Tell: no legitimate bank or government agency asks a customer to read out a full PIN or one-time passcode over the phone, and any inbound call urgently pressuring disclosure of OTPs/PINs under a security pretext, regardless of what the caller ID shows, is the classic vishing tell, since caller ID can be spoofed and was, at industrial scale, via this exact platform.

Outcome

The Met's Cyber Crime Unit (Operation Elaborate, begun June 2021) infiltrated iSpoof and traced its Bitcoin payment records. In a coordinated international action, the site's server (by then relocated to Kyiv) was seized by US and Ukrainian authorities and taken offline on 8 November 2022; Tejay Fletcher was arrested at his girlfriend's house in east London two days earlier, on 6 November. The action, supported by Eurojust, Europol and law enforcement from roughly 10 countries, produced 142 arrests worldwide (120 in the UK, 103 in London), with police explicitly pursuing platform users as well as the administrator. Fletcher was charged with making/supplying articles for use in fraud, participating in an organised crime group, and proceeds-of-crime offences; he pleaded guilty at Southwark Crown Court on 20 April 2023 to making or supplying articles for use in fraud, encouraging or assisting an offence, possessing criminal property, and transferring criminal property. On 19 May 2023, Judge Sally Cahill KC sentenced him to 13 years and 4 months' imprisonment, telling him his "late expression of remorse is regret for being caught rather than empathy for your victims." The Met also sent warning texts to 70,000 identified UK victims/targets directing them to Action Fraud. The CPS has separately signalled intent to pursue confiscation proceedings against Fletcher's profits. No consolidated public figure for convictions of the other 141+ arrestees was found in the sources reviewed.

Why It Matters

iSpoof shows how vishing was industrialised into a commercial "crime-as-a-service" platform: a single administrator, not a bank insider or sophisticated hacker, supplied off-the-shelf caller-ID spoofing and OTP-interception tools that let tens of thousands of unrelated criminals run convincing bank-impersonation scams at scale (up to 20 victims targeted per minute at its peak), generating over £100 million in losses. It underscores that caller ID is not a trust signal, since it can be trivially rented and spoofed, and that any phone-based request for a PIN or one-time passcode, however legitimate the displayed number looks, should be treated as a red flag. It's also a rare case where law enforcement targeted the tooling supply chain and its user base together (142 arrests, not just the administrator), illustrating both the scale of the platform economy behind social engineering fraud and a model for disrupting it.

Defenses

Post-case measures/lessons cited by authorities and reporting: banks urged to shift away from phone-based OTP/PIN verification toward in-app authentication; consumer warnings that banks and tax authorities never ask for full PINs/OTPs by phone; caller-ID cannot be trusted as proof of identity (push for STIR/SHAKEN-style caller authentication); Met Police ran a mass SMS outreach to 70,000 identified UK victims/targets directing them to Action Fraud; law enforcement adopted a "go after the users, not just the platform" model (100+ UK arrests beyond the administrator) to deter reliance on such services; CPS pursuing confiscation proceedings to strip Fletcher of profits as an additional deterrent.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Platform build and tooling development: Fletcher and his co-administrators built iSpoof.cc as a self-service website, developing caller-ID spoofing, pre-recorded 'verification' message playback, and one-time-passcode interception features and packaging them as a monthly Bitcoin-paid subscription, a pattern consistent with a commercial crime-as-a-service model rather than a one-off tool built for personal use.
Countering Stage 1: Building and hosting spoofing/OTP-interception tooling happens entirely outside any single victim organization's visibility; the realistic control is legal and infrastructure-level, meaning law enforcement and hosting/domain takedown action against the platform itself, which is what ultimately ended iSpoof rather than any bank-side defense.
2
Marketing and subscriber acquisition: iSpoof was promoted openly through a Telegram channel called 'iSpoof club,' recruiting an eventual 59,000 registered subscribers who paid roughly 150 to over 5,000 pounds a month, showing how a closed messaging app was used as a low-friction storefront for recruiting criminal customers at scale.
Countering Stage 2: Platform marketing via closed channels like Telegram is hard for outsiders to police proactively, but messaging platforms and payment processors can monitor for known crime-as-a-service marketing patterns and cooperate with law enforcement takedown requests once identified, as happened here.
3
Target list building: Subscriber-fraudsters typically worked from large volume-dialed or purchased phone-number lists rather than researching individual victims, consistent with mass, opportunistic vishing rather than the individualized OSINT profiling seen in targeted business email compromise or executive-impersonation schemes.
Countering Stage 3: Mass volume-dialed targeting cannot be prevented by any single potential victim; the realistic control shifts to Stage 4, where the actual contact with a real person can be authenticated or challenged.
4
Caller-ID spoofing and pretext call: Using the platform, a subscriber placed a call that displayed the genuine name and number of a real bank, tax authority, or retailer, then opened with a fabricated urgent security alert while posing as fraud-department or government staff, relying on the victim's trust in caller ID as a legitimate identity signal.
Countering Stage 4: Because caller ID can be spoofed, it should never be treated as proof of identity. Banks and telecoms can adopt caller-authentication standards such as STIR/SHAKEN, and customers can be trained to hang up and call the institution back on a known, independently verified number rather than trusting the displayed name or number.
5
Live social engineering and OTP/PIN capture: The caller talked the victim through a bogus 'security verification' process, using the platform's recorded-message and OTP-interception tools to extract passwords, PINs, and one-time passcodes in real time while the victim believed they were confirming their own account's safety.
Countering Stage 5: No legitimate bank, tax authority, or retailer will ever ask a customer to read out a full PIN or one-time passcode over the phone; consumer education and in-app fraud warnings that state this plainly, plus bank staff scripts that reinforce it, directly counter the live social-engineering step.
6
Account takeover and fund extraction: The captured credentials and OTPs were used immediately to log into the victim's real online banking session and transfer or withdraw funds, completing the theft before most victims realized the original call had been fraudulent.
Countering Stage 6: Banks can add out-of-band transaction confirmation (e.g., in-app push approval rather than SMS OTP alone), step-up authentication for new payees, and behavioral/velocity fraud monitoring that flags a login and immediate large transfer following an OTP entry as high risk.
7
Objective completion, monetization, and reinvestment: Subscription fees flowed back to the platform in Bitcoin, generating roughly 112.6 BTC in revenue for iSpoof's operators, with Fletcher personally receiving well over a million pounds that he spent on luxury vehicles and watches, illustrating the platform's own profit motive layered on top of each individual subscriber's fraud proceeds.
Countering Stage 7: Removing the financial incentive requires proceeds-of-crime and confiscation action against platform operators, which the CPS pursued against Fletcher, combined with arresting the subscriber base itself (142 arrests, not just the administrator) so that demand for the service, not only its supply, is disrupted.
Quick Facts
Victim
Thousands of UK and global bank customers, with more than 200,000 people targeted in the UK alone and roughly 70,000 UK victims/targets subsequently contacted by police; secondary reporting names Barclays, HSBC, NatWest, Santander, Lloyds, Halifax, First Direct, Nationwide and TSB among the banks impersonated by iSpoof-enabled callers (not independently confirmed by a primary source), alongside government tax offices and retail companies
Location
United Kingdom (Metropolitan Police-led "Operation Elaborate," Southwark Crown Court prosecution); iSpoof's infrastructure was hosted in the Netherlands then Kyiv, Ukraine, and its user base and victims spanned the US, UK, Netherlands, Australia, France and Ireland among other countries
Date
Platform active 30 November 2020 to 8 November 2022 (created Dec 2020; Met Police "Operation Elaborate" investigation began June 2021; international takedown and server seizure 8 Nov 2022; Fletcher arrested 6 Nov 2022, pleaded guilty 20 April 2023, sentenced 19 May 2023)
Impact
UK losses exceeded £43 million; global losses estimated at over £100 million (both per CPS and Eurojust). iSpoof itself grossed roughly 112.6 BTC (~£3.2 million / EUR 3.7 million) in subscription revenue over about 16 months. Tejay Fletcher personally received at least £1.3 million from the site per the CPS (Eurojust cites GBP 1.7-1.9 million in profit to the "main administrator"); he had spent proceeds on a £230,000 Lamborghini, two Range Rovers (£110,000), and an £11,000 Rolex. CPS intended to pursue confiscation proceedings.
Status
Confirmed
Case Type
Real-World Incident
Sector
Financial Services & Insurance, Government & Public Sector, Retail & E-commerce
Threat Actor
Organized Crime
Related

Related Cases

New Jersey Life-Insurance-Beneficiary Pretexting of Elderly Widows/Widowers

An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims, telling them their…

Incident 2020Read →

FraudGPT Underground Chatbot

A Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures, but when Cisco Talos tried…

Incident 2023Read →

WPP Deepfake CEO Scam Attempt

Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…

Incident 2024Read →