Key Points
- Mohammed Faiyaz Iqbal, age 43, from Preston, was arrested in his van at Trafford Centre car park on May 24, 2024.
- Detectives found a concealed SMS “blaster” system with power supplies, Wi-Fi equipment and roof antennas that enabled him to send mass fraud messages.
- These messages posed as Royal Mail and other organizations to deceive the recipients into providing them with their personal and payment information – “smishing” fraud.
- Investigating the devices revealed that there were 7,000 compromised payment credentials; fake UK driving licences and banking credentials were seized from his premises.
- On March 9, 2026, he pled guilty and was sentenced to three years and eight months imprisonment on August 28, 2026.
- This case represents one of the first instances of law enforcement in the UK dealing with the SMS blaster device.
Trafford (Manchester Mirror) September 01, 2026 — A man who targeted shoppers and visitors from his van using a hidden mass‑texting device has been jailed after police swooped on him in the centre’s car park. Mohammed Faiyaz Iqbal, 43, of Maple Crescent, Preston, was arrested on May 24, 2024 following an operation that connected his vehicle to a large volume of fraudulent SMS messages being sent to mobile phones in the vicinity.
- Key Points
- What happened at Trafford Centre and how was the fraudster caught?
- What did police find in the van and at the suspect’s home?
- What charges were brought and what sentence was imposed?
- What did senior officers and telecoms leaders say about the case?
- How did agencies collaborate to tackle the SMS blaster scam?
- Background of the development
- Prediction: how this development can affect shoppers and the wider public
What happened at Trafford Centre and how was the fraudster caught?
As reported by journalists at the Manchester Evening News, police became suspicious after detecting a spike in fraudulent text messages originating from the uk/local/trafford/">Trafford Centre area, prompting officers to search Iqbal’s van while it was parked in the car park. Inside the front cabin, officers found multiple mobile phones, and in the rear they discovered a sophisticated SMS “blaster” system concealed within custom wooden compartments. The setup included power supplies, Wi‑Fi equipment and antennas integrated into the van’s roof, all linked to applications on the phones, enabling the device to broadcast texts directly to nearby handsets.
The messages were designed to look like they came from legitimate organisations, including Royal Mail, and urged recipients to click links and provide personal or payment information a tactic known as “smishing”. A typical message read: “Sorry we missed you as no one was home to sign your parcel. Rearrange a redelivery to your home address please visit…”, with some variants suggesting payment might be required.
What did police find in the van and at the suspect’s home?
According to the City of London Police’s Dedicated Card and Payment Crime Unit (DCPCU), the equipment in the van functioned as an unauthorised mobile antenna that bypassed telecoms security measures to send SMS messages en masse without needing victims’ phone numbers. When seized in May 2024, it marked one of the first recorded instances of UK enforcement encountering an SMS blaster in a criminal investigation.
Further digital forensics on Iqbal’s devices uncovered 7,000 compromised payment details, while searches at his residence revealed additional banking information and three forged UK driving licences intended for creating impersonation bank accounts to launder illicit funds.
What charges were brought and what sentence was imposed?
Iqbal faced multiple charges: one count of fraud by false representation, one count of possessing articles for use in fraud, one count of acquiring and possessing criminal property, one count of possession of false identity documents, and one count of unauthorised use of wireless telegraphy apparatus. He pleaded guilty at an initial hearing on March 9, 2026 and was sentenced on August 28, 2026 to three years and eight months in prison. The judge indicated that a five‑year and six‑month term would have been appropriate but applied a one‑third reduction in line with sentencing guidelines for guilty pleas.
What did senior officers and telecoms leaders say about the case?
Detective Chief Inspector Andrew Little, from the City of London Police’s DCPCU, said:
“This case illustrates the changing landscape of fraud and the extent to which offenders will go to target victims on a large scale. The confiscation of this equipment is a crucial move in countering emerging threats that aim to evade established telecommunications protections. We will persist in collaborating partners across and telecommunications identify, and bring to justice those responsible for fraud.”
Murray Mackenzie, Director of Fraud Prevention at Virgin Media O2, said: “Ensuring the safety of our customers and the public from fraud is a primary concern for us. We are always prepared to work alongside law enforcement and industry colleagues to disrupt scam networks and hold criminals accountable. While this conviction is a success for our fraud prevention initiatives, it also highlights the extreme measures that offenders will take to inflict financial and emotional distress on the public. At Virgin Media O2 we’ve blocked over 1 billion texts to customers, but to further stop scammers, we urge people to report suspicious calls and texts for free to 7726.”
How did agencies collaborate to tackle the SMS blaster scam?
The conviction followed joint work between DCPCU officers and mobile network operators including BT, Virgin Media O2, Vodafone, Three and Sky, as well as the National Cyber Security Centre and Ofcom. The DCPCU is a collaborative unit comprising the City of London Police, the Metropolitan Police and UK Finance, and is fully funded by UK Finance, which represents the British banking and financial services sector.
Background of the development
SMS blaster devices are specialist tools that can broadcast large volumes of text messages to phones within a specific geographic area by acting as an unauthorised transmitter, effectively circumventing network‑level anti‑spam protections. Unlike traditional phishing campaigns that rely on harvested contact lists, these devices enable offenders to target potentially hundreds of people simultaneously without prior access to their numbers. The technology has drawn increasing attention from UK law enforcement and telecoms regulators as fraudsters seek new ways to evade detection and scale up “smishing” operations that impersonate trusted brands such as Royal Mail, banks and delivery firms.
Prediction: how this development can affect shoppers and the wider public
This case is likely to heighten vigilance among shoppers, delivery recipients and small businesses who regularly receive parcel notifications, as it demonstrates that fraudulent texts can originate from nearby vehicles rather than distant call centres. For the public, the immediate effect may be greater scepticism toward unsolicited messages requesting personal data or payments, alongside increased reporting of suspicious texts to shortcodes such as 7726, which telecoms firms use to block scam numbers. For retailers and logistics companies, the development could accelerate investment in customer education and verified notification channels, while regulators and network operators may prioritise technical countermeasures to detect and disrupt unauthorised transmitters in busy public spaces.
