Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank and government staff at industrial scale, generating over £100 million in global losses before a Metropolitan Police-led international takedown and Fletcher's 13-year, 4-month sentence.
Reviewed by the Social Engineering Examples team.
iSpoof.cc was a UK-run, Bitcoin-paid subscription website, created around 30 November 2020, that sold caller-ID spoofing and related fraud tools "as a service." Subscribers, an estimated 59,000 registered users at peak, paid iSpoof between roughly £150 and £5,000+ per month to disguise their outgoing calls so a victim's phone displayed the name/number of a genuine bank, tax authority, or other trusted organisation. Using this spoofed legitimacy plus add-on tools to intercept one-time passcodes and play recorded "verification" messages, iSpoof's criminal customers cold-called victims claiming to be bank fraud investigators (or equivalent government/retail staff), talked them through a bogus security check, and captured passwords, PINs and OTPs, which were then used to log into and drain the victims' real bank accounts. The Metropolitan Police's Cyber Crime Unit began investigating under "Operation Elaborate" in June 2021, ultimately working with Eurojust, Europol, Dutch, US, Ukrainian, Australian, French and Irish authorities. In a coordinated international action, the FBI/Ukrainian authorities seized iSpoof's Kyiv-hosted server on 8 November 2022, after Fletcher had already been arrested at an east London address on 6 November, and 142 people were arrested worldwide (120 in the UK, 103 of them in London). Fletcher pleaded guilty on 20 April 2023 to four fraud-related offences and was sentenced on 19 May 2023 at Southwark Crown Court to 13 years and 4 months in prison, in what UK authorities described as the country's largest-ever fraud investigation.
iSpoof.cc was a subscription "crime-as-a-service" website: for £150-£5,000+ per month, paid in Bitcoin, users bought caller-ID spoofing so their calls displayed as coming from a trusted number (typically a bank's genuine customer-service line), plus add-on features to play pre-recorded "verification" prompts and to intercept one-time passcodes/SMS codes sent by banks. This let subscriber-fraudsters cold-call victims sounding exactly like their bank's fraud department (or, per Eurojust, retail companies and government/tax bodies), walk them through a fabricated "security check," and harvest passwords, PINs and OTPs in real time, then use those codes to log into and empty the victim's real account before the victim realized the call was fake. The service was marketed openly via a Telegram channel ("iSpoof club") and had 59,000 registered users at its peak, with investigators later finding the seized server held 70 million rows of call/payment data; at points, up to 20 people per minute were being targeted by iSpoof-enabled calls.
Lure: a call (or accompanying SMS) that displayed a genuine-looking bank/government phone number due to caller-ID spoofing, opening with an "urgent security alert," for example "we've detected suspicious activity on your account," spoken by someone posing as bank fraud-department or tax-office staff, who then walked the victim through a fake "verification" process to "protect" the account. Tell: no legitimate bank or government agency asks a customer to read out a full PIN or one-time passcode over the phone, and any inbound call urgently pressuring disclosure of OTPs/PINs under a security pretext, regardless of what the caller ID shows, is the classic vishing tell, since caller ID can be spoofed and was, at industrial scale, via this exact platform.
The Met's Cyber Crime Unit (Operation Elaborate, begun June 2021) infiltrated iSpoof and traced its Bitcoin payment records. In a coordinated international action, the site's server (by then relocated to Kyiv) was seized by US and Ukrainian authorities and taken offline on 8 November 2022; Tejay Fletcher was arrested at his girlfriend's house in east London two days earlier, on 6 November. The action, supported by Eurojust, Europol and law enforcement from roughly 10 countries, produced 142 arrests worldwide (120 in the UK, 103 in London), with police explicitly pursuing platform users as well as the administrator. Fletcher was charged with making/supplying articles for use in fraud, participating in an organised crime group, and proceeds-of-crime offences; he pleaded guilty at Southwark Crown Court on 20 April 2023 to making or supplying articles for use in fraud, encouraging or assisting an offence, possessing criminal property, and transferring criminal property. On 19 May 2023, Judge Sally Cahill KC sentenced him to 13 years and 4 months' imprisonment, telling him his "late expression of remorse is regret for being caught rather than empathy for your victims." The Met also sent warning texts to 70,000 identified UK victims/targets directing them to Action Fraud. The CPS has separately signalled intent to pursue confiscation proceedings against Fletcher's profits. No consolidated public figure for convictions of the other 141+ arrestees was found in the sources reviewed.
iSpoof shows how vishing was industrialised into a commercial "crime-as-a-service" platform: a single administrator, not a bank insider or sophisticated hacker, supplied off-the-shelf caller-ID spoofing and OTP-interception tools that let tens of thousands of unrelated criminals run convincing bank-impersonation scams at scale (up to 20 victims targeted per minute at its peak), generating over £100 million in losses. It underscores that caller ID is not a trust signal, since it can be trivially rented and spoofed, and that any phone-based request for a PIN or one-time passcode, however legitimate the displayed number looks, should be treated as a red flag. It's also a rare case where law enforcement targeted the tooling supply chain and its user base together (142 arrests, not just the administrator), illustrating both the scale of the platform economy behind social engineering fraud and a model for disrupting it.
Post-case measures/lessons cited by authorities and reporting: banks urged to shift away from phone-based OTP/PIN verification toward in-app authentication; consumer warnings that banks and tax authorities never ask for full PINs/OTPs by phone; caller-ID cannot be trusted as proof of identity (push for STIR/SHAKEN-style caller authentication); Met Police ran a mass SMS outreach to 70,000 identified UK victims/targets directing them to Action Fraud; law enforcement adopted a "go after the users, not just the platform" model (100+ UK arrests beyond the administrator) to deter reliance on such services; CPS pursuing confiscation proceedings to strip Fletcher of profits as an additional deterrent.
An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims, telling them their…
A Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures, but when Cisco Talos tried…
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…