Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank.
Social Engineering Examples·7 sources
iSpoof.cc was a UK-run, Bitcoin-paid subscription website, created around 30 November 2020, that sold caller-ID spoofing and related fraud tools "as a service." Subscribers, an estimated 59,000 registered users at peak, paid iSpoof between roughly £150 and £5,000+ per month to disguise their outgoing calls so a victim's phone displayed the name/number of a genuine bank, tax authority, or other trusted organisation.
Using this spoofed legitimacy plus add-on tools to intercept one-time passcodes and play recorded "verification" messages, iSpoof's criminal customers cold-called victims claiming to be bank fraud investigators (or equivalent government/retail staff), talked them through a bogus security check, and captured passwords, PINs and OTPs, which were then used to log into and drain the victims' real bank accounts.
The Metropolitan Police's Cyber Crime Unit began investigating under "Operation Elaborate" in June 2021, ultimately working with Eurojust, Europol, Dutch, US, Ukrainian, Australian, French and Irish authorities. In a coordinated international action, the FBI/Ukrainian authorities seized iSpoof's Kyiv-hosted server on 8 November 2022, after Fletcher had already been arrested at an east London address on 6 November, and 142 people were arrested worldwide (120 in the UK, 103 of them in London).
Fletcher pleaded guilty on 20 April 2023 to four fraud-related offences and was sentenced on 19 May 2023 at Southwark Crown Court to 13 years and 4 months in prison, in what UK authorities described as the country's largest-ever fraud investigation.
iSpoof.cc was a subscription "crime-as-a-service" website: for £150-£5,000+ per month, paid in Bitcoin, users bought caller-ID spoofing so their calls displayed as coming from a trusted number (typically a bank's genuine customer-service line), plus add-on features to play pre-recorded "verification" prompts and to intercept one-time passcodes/SMS codes sent by banks.
This let subscriber-fraudsters cold-call victims sounding exactly like their bank's fraud department (or, per Eurojust, retail companies and government/tax bodies), walk them through a fabricated "security check," and harvest passwords, PINs and OTPs in real time, then use those codes to log into and empty the victim's real account before the victim realized the call was fake.
The service was marketed openly via a Telegram channel ("iSpoof club") and had 59,000 registered users at its peak, with investigators later finding the seized server held 70 million rows of call/payment data; at points, up to 20 people per minute were being targeted by iSpoof-enabled calls.
Lure: a call (or accompanying SMS) that displayed a genuine-looking bank/government phone number due to caller-ID spoofing, opening with an "urgent security alert," for example "we've detected suspicious activity on your account," spoken by someone posing as bank fraud-department or tax-office staff, who then walked the victim through a fake "verification" process to "protect" the account.
Tell: no legitimate bank or government agency asks a customer to read out a full PIN or one-time passcode over the phone, and any inbound call urgently pressuring disclosure of OTPs/PINs under a security pretext, regardless of what the caller ID shows, is the classic vishing tell, since caller ID can be spoofed and was, at industrial scale, via this exact platform.
The Met's Cyber Crime Unit (Operation Elaborate, begun June 2021) infiltrated iSpoof and traced its Bitcoin payment records. In a coordinated international action, the site's server (by then relocated to Kyiv) was seized by US and Ukrainian authorities and taken offline on 8 November 2022; Tejay Fletcher was arrested at his girlfriend's house in east London two days earlier, on 6 November.
The action, supported by Eurojust, Europol and law enforcement from roughly 10 countries, produced 142 arrests worldwide (120 in the UK, 103 in London), with police explicitly pursuing platform users as well as the administrator. Fletcher was charged with making/supplying articles for use in fraud, participating in an organised crime group, and proceeds-of-crime offences; he pleaded guilty at Southwark Crown Court on 20 April 2023 to making or supplying articles for use in fraud, encouraging or assisting an offence, possessing criminal property, and transferring criminal property.
On 19 May 2023, Judge Sally Cahill KC sentenced him to 13 years and 4 months' imprisonment, telling him his "late expression of remorse is regret for being caught rather than empathy for your victims." The Met also sent warning texts to 70,000 identified UK victims/targets directing them to Action Fraud. The CPS has separately signalled intent to pursue confiscation proceedings against Fletcher's profits.
No consolidated public figure for convictions of the other 141+ arrestees was found in the sources reviewed.
iSpoof shows how vishing was industrialised into a commercial "crime-as-a-service" platform: a single administrator, not a bank insider or sophisticated hacker, supplied off-the-shelf caller-ID spoofing and OTP-interception tools that let tens of thousands of unrelated criminals run convincing bank-impersonation scams at scale (up to 20 victims targeted per minute at its peak), generating over £100 million in losses.
It underscores that caller ID is not a trust signal, since it can be trivially rented and spoofed, and that any phone-based request for a PIN or one-time passcode, however legitimate the displayed number looks, should be treated as a red flag. It's also a rare case where law enforcement targeted the tooling supply chain and its user base together (142 arrests, not just the administrator), illustrating both the scale of the platform economy behind social engineering fraud and a model for disrupting it.
Post-case measures/lessons cited by authorities and reporting: banks urged to shift away from phone-based OTP/PIN verification toward in-app authentication; consumer warnings that banks and tax authorities never ask for full PINs/OTPs by phone; caller-ID cannot be trusted as proof of identity (push for STIR/SHAKEN-style caller authentication); Met Police ran a mass SMS outreach to 70,000 identified UK victims/targets directing them to Action Fraud; law enforcement adopted a "go after the users, not just the platform" model (100+ UK arrests beyond the administrator) to deter reliance on such services; CPS pursuing confiscation proceedings to strip Fletcher of profits as an additional deterrent.
Social Engineering Examples. “iSpoof Caller-ID Spoofing-as-a-Service Platform (Tejay Fletcher)”. Accessed 19 September 2026. https://socialengineeringexamples.com/ispoof-caller-id-spoofing-fletcher-2022
Fletcher and his co-administrators built iSpoof.cc as a self-service website, developing caller-ID spoofing, pre-recorded 'verification' message playback, and one-time-passcode interception features and packaging them as a monthly Bitcoin-paid subscription, a pattern consistent with a commercial crime-as-a-service model rather than a one-off tool built for personal use.
Building and hosting spoofing/OTP-interception tooling happens entirely outside any single victim organization's visibility; the realistic control is legal and infrastructure-level, meaning law enforcement and hosting/domain takedown action against the platform itself, which is what ultimately ended iSpoof rather than any bank-side defense.
iSpoof was promoted openly through a Telegram channel called 'iSpoof club,' recruiting an eventual 59,000 registered subscribers who paid roughly 150 to over 5,000 pounds a month, showing how a closed messaging app was used as a low-friction storefront for recruiting criminal customers at scale.
Platform marketing via closed channels like Telegram is hard for outsiders to police proactively, but messaging platforms and payment processors can monitor for known crime-as-a-service marketing patterns and cooperate with law enforcement takedown requests once identified, as happened here.
Subscriber-fraudsters typically worked from large volume-dialed or purchased phone-number lists rather than researching individual victims, consistent with mass, opportunistic vishing rather than the individualized OSINT profiling seen in targeted business email compromise or executive-impersonation schemes.
Mass volume-dialed targeting cannot be prevented by any single potential victim; the realistic control shifts to Stage 4, where the actual contact with a real person can be authenticated or challenged.
Using the platform, a subscriber placed a call that displayed the genuine name and number of a real bank, tax authority, or retailer, then opened with a fabricated urgent security alert while posing as fraud-department or government staff, relying on the victim's trust in caller ID as a legitimate identity signal.
Because caller ID can be spoofed, it should never be treated as proof of identity. Banks and telecoms can adopt caller-authentication standards such as STIR/SHAKEN, and customers can be trained to hang up and call the institution back on a known, independently verified number rather than trusting the displayed name or number.
The caller talked the victim through a bogus 'security verification' process, using the platform's recorded-message and OTP-interception tools to extract passwords, PINs, and one-time passcodes in real time while the victim believed they were confirming their own account's safety.
No legitimate bank, tax authority, or retailer will ever ask a customer to read out a full PIN or one-time passcode over the phone; consumer education and in-app fraud warnings that state this plainly, plus bank staff scripts that reinforce it, directly counter the live social-engineering step.
The captured credentials and OTPs were used immediately to log into the victim's real online banking session and transfer or withdraw funds, completing the theft before most victims realized the original call had been fraudulent.
Banks can add out-of-band transaction confirmation (e.g., in-app push approval rather than SMS OTP alone), step-up authentication for new payees, and behavioral/velocity fraud monitoring that flags a login and immediate large transfer following an OTP entry as high risk.
Subscription fees flowed back to the platform in Bitcoin, generating roughly 112.6 BTC in revenue for iSpoof's operators, with Fletcher personally receiving well over a million pounds that he spent on luxury vehicles and watches, illustrating the platform's own profit motive layered on top of each individual subscriber's fraud proceeds.
Removing the financial incentive requires proceeds-of-crime and confiscation action against platform operators, which the CPS pursued against Fletcher, combined with arresting the subscriber base itself (142 arrests, not just the administrator) so that demand for the service, not only its supply, is disrupted.
Browse by what this case has in common with others in the library.
An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims.
A Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures.
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.
P&G-hired competitive-intelligence contractors retrieved roughly 80 unshredded confidential Unilever hair-care documents from the trash before P&G.
Hours before Maharashtra's 2024 assembly election polling, BJP-amplified audio clips purporting to catch opposition leaders Supriya Sule and Nana Patole.
A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.
Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters.
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
Fraudsters spoofed Barclays' real phone number and hold music, posed as the bank's fraud team in a two-caller vishing script.
A Brighton-area kitchen fitter lost roughly £76,000, including four loans he was pressured into taking out.
A finance employee in Arup's Hong Kong office wired HK$200M (~US$25.6M) after a video conference in which the CFO and…
Two Scottish small businesses lost £31,000 and over £5,000 after callers impersonating bank fraud-team staff talked owners into wiring money.
A Metropolitan Police officer spotted customers' passports and tax-credit paperwork clearly visible through transparent bin bags left on the street.
Two Quebec fraudsters acting as courier and driver for an AI-voice-cloned "grandchild in crisis" vishing scheme that defrauded Saskatchewan seniors.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…
SABRIC's own Annual Crime Statistics reports document a sustained, industry-wide surge in vishing- and SIM-swap-driven digital banking fraud across South.
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…