More than 100 people have been arrested after one of the UK’s biggest anti-fraud operations.
Working with global law enforcement partners, the Metropolitan Police service took down iSpoof, which has been described as an “international one stop spoofing shop” that helped scammers dupe thousands of victims.
Police said more than 200,000 potential victims in the UK were targeted by the fraudulent website.
Victims are believed to have lost tens of millions of pounds, while those behind the site earned almost £3.2 million across one 20 month period.
What is iSpoof?
iSpoof enabled criminals to hide behind false identities and disguise their phone number so it appeared that they were calling from a trusted source or legitimate organisation.
Scammers using the site were found to have posed as representatives from banks such as Barclays, Santander, HSBC, Lloyds, Halifax, First Direct, NatWest, Nationwide, and TSB.
In the 12 months until August 2022, around 10 million fraudulent calls were made globally via iSpoof, with around 3.5 million of those made in the UK.
The suspected organiser of the website was arrested in East London earlier this month. He has been charged with several offences and remanded in custody.
Recommended
- Professional services firms ‘bearing brunt’ of cyber attacks
- Killnet group claims responsibility for European Parliament cyber attack
- Government announces mass funding amid EU R&D shortfall
Detective Superintendent Helen Rance, who leads on cybercrime for the Met, said: “By taking down iSpoof we have prevented further offences and stopped fraudsters targeting future victims.
“Our message to criminals who have used this website is we have your details and are working hard to locate you, regardless of where you are.”
Europol Executive Director Catherine De Bolle added: “The arrests today send a message to cybercriminals that they can no longer hide behind perceived international anonymity.”
UK’s biggest anti-fraud operation
The Met said its Cyber Crime Unit began investigating iSpoof in June 2021.
As part of the operation, investigators infiltrated the site and began gathering information alongside international partners.
In a statement, the Met said the iSpoof website server contained a “treasure trove” of information in 70 million rows of data. Bitcoin records were also traced following the takedown.
Because the pool of potential suspects is so large, investigators said they will initially focus on UK users and those who have spent at least £100 worth of Bitcoin to use the site.
Contacting Victims
Losses reported to Action Fraud as a result of iSpoof are estimated to stand at around £48 million. However, the watchdog warned that because fraud is “vastly underreported” the full amount could be much higher.
The Met also revealed it plans to contact more than 70,000 victims across the country in the wake of the takedown.
“We are actively contacting those numbers this week asking owners to visit our website for more information and to report any fraud losses online,” the service said in a statement.
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





