Chinese Student Caught in London for Massive Smishing Attack Using Rogue SMS Tower | July 2026

In July 2026, a Chinese student was sentenced in London for conducting a large-scale smishing campaign using an SMS blaster disguised in a black SUV. The attacker broadcast a rogue mobile signal across Greater London, tricking thousands of smartphones into connecting to his fake base station and injecting fake government and banking SMS messages. The texts led victims to credential-stealing phishing websites. The operation bypassed mobile carriers entirely, making detection extremely difficult. UK police and telecom providers collaborated to track and arrest the suspect. This case marks a turning point in mobile cybersecurity threats.

Jul 03, 2025 - 14:46
Updated: 8 days ago
103.2k
Chinese Student Caught in London for Massive Smishing Attack Using Rogue SMS Tower | July 2026

Quick answer: An SMS blaster is a portable fake mobile tower. In this London case, a student drove around with one in a car, forced nearby phones to connect and sent fraudulent texts posing as Gov.uk and banks, each with a phishing link. He was sentenced to more than a year in prison. Never tap links in unexpected texts; open your bank's app directly.

Key takeaways

  • An SMS blaster is a fake base station that forces nearby phones to connect, then pushes texts without using the real carrier network.
  • Because the texts skip carrier spam filters, a message can appear in the same thread as a genuine bank alert.
  • Never click a link in an unexpected bank or government text, and open the bank's own app instead.

Table of Contents

A Chinese student, Ruichen Xiong, has been sentenced to more than a year in prison after admitting he operated a mobile “SMS blaster” that pushed thousands of fraudulent text messages to phones across Greater London. UK investigators say the case demonstrates how criminals are upgrading classic phishing tactics by turning cars into roaming, rogue phone masts.

How the Scam Worked

Xiong drove a black Honda CR‑V containing a suitcase‑sized SMS blaster.
The device created a fake cell tower that broadcast a stronger signal than nearby legitimate masts. Any smartphone within roughly one kilometre locked onto the rogue tower automatically (a behaviour baked into mobile standards). While victims’ devices were connected, the blaster injected bogus texts that looked as though they came from trusted senders such as “Gov.uk” or major banks. Each message carried a link to a phishing page that harvested logins, card data, or other personal details.

Why This Attack Was Hard to Spot

  • Mobile carriers’ spam filters never saw the messages – they bypassed the operator network completely.

  • The tower was on the move, making radio‑frequency sweeps difficult.

  • The campaign lasted just five days in March 2026, limiting the forensic window.

Who Caught Him

The Dedicated Card and Payment Crime Unit (DCPCU) – a specialist task force funded by UK banks – worked with BT, Virgin Media O2, Vodafone, Three, and Sky to track irregular signal activity. Officers eventually traced the strongest rogue signal to Xiong’s parked SUV, seized the equipment, and matched it to the illegal texts reported by victims.

Technical Details in Plain English

  • False base station – a portable transmitter that impersonates a real cell tower.

  • Signal boosting – the device cranks transmission power so nearby phones pick it over legitimate masts.

  • Message injection – once a phone is attached, the tower can drop SMS messages straight onto the device without carrier involvement.

  • No SIM required – the blaster acts at the radio layer, not through a mobile subscription.

Lessons for Organisations and the Public

Multi‑layer verification
Do not trust urgent links delivered by SMS alone. Use official apps or bookmark genuine URLs.

Carrier‑level defenses
UK operators now share rogue‑tower telemetry in real time; similar partnerships are vital worldwide.

Device hardening
Modern phones that support 4G/5G network authentication (AKA “Cell‑ID verification”) should keep the feature enabled; it helps reject rogue 2G/3G towers.

Law‑enforcement coordination
This conviction shows banking groups, telecoms, and police can dismantle advanced fraud when data is shared quickly.

The Bigger Picture

Mobile‑based phishing (smishing) is outgrowing email scams because text messages feel personal and immediate. With off‑the‑shelf hardware, criminals can now skip telecom gateways entirely and target phones over the air. Cyber‑crime units expect more “drive‑by” base‑station attacks, especially near events where large crowds gather.

Conclusion

If a text claims to be from a government agency, bank, or delivery firm and asks you to click a link or confirm personal information, stop. Open your bank’s official app, call the organisation directly, or type the web address yourself.
Behind a simple SMS could be a moving, high‑power tower designed to steal your identity in seconds.

Related reading

Reference

For the authoritative details, see CERT-In (India).

Frequently Asked Questions

Smishing is a type of phishing where attackers send fraudulent SMS messages to trick victims into revealing personal or financial information.

Ruichen Xiong is a Chinese student sentenced in London for launching a mass smishing campaign using rogue mobile base stations.

Xiong used an SMS blaster that functioned as a fake mobile tower to inject SMS messages directly into smartphones.

The fake mast broadcast a stronger signal than legitimate towers, causing nearby devices to automatically connect.

Victims received fake texts appearing to be from trusted sources like “Gov.uk” urging them to verify information or click links.

The goal was to harvest credentials, steal personal data, and potentially gain unauthorized access to accounts.

Tens of thousands of potential victims across Greater London were targeted between March 22–27, 2025.

The moving nature of the vehicle-mounted fake tower and its ability to bypass mobile networks made detection challenging.

It’s a fake cell tower that impersonates legitimate mobile infrastructure to hijack connections and perform attacks.

Providers like Vodafone, BT, and Three collaborated with law enforcement to trace and shut down the rogue signal.

DCPCU is a UK police unit funded by the banking industry to fight financial and cybercrime.

Yes, the SMS messages included links to fake websites that mimicked government portals to steal sensitive info.

Mobile devices automatically connect to the strongest signal nearby, which the rogue tower exploited.

Yes, messages were programmed and broadcast via custom scripts and phishing payloads crafted to look legitimate.

Xiong received over a year in prison, highlighting the seriousness of mobile cybercrime.

Yes, similar attacks can happen anywhere mobile networks exist, especially in densely populated cities.

Avoid clicking on suspicious links, verify sources, and use official apps or websites for sensitive tasks.

Report it to your mobile provider, delete it, and never click on embedded links.

Not always. Because messages are injected outside traditional channels, they may evade device-level detection.

Older mobile standards like 2G and 3G are more susceptible to false base station attacks.

Yes, smishing uses SMS and fake cellular signals, whereas phishing often occurs via email or websites.

Yes, the attacker used a suitcase-sized SMS blaster with radio amplification capabilities.

Up to 1 km in radius, depending on power and environment.

Some newer phones offer options to restrict cell network access or prioritize encrypted networks.

Agencies are increasing monitoring and encouraging stronger telco partnerships, but evolving threats remain.

Black markets and DIY kits are making such tools more accessible than before.

Yes, the attacker could redirect victims to fake login pages mimicking banking apps or portals.

Disabling mobile data or Wi-Fi when not needed can reduce exposure, but won’t fully prevent rogue connections.

With improved telemetry and real-time signal tracing, detection is improving but still challenging.

It’s a newer evolution of mobile fraud, combining physical signal manipulation with social engineering.

Experts expect more roaming smishing attacks as mobile threat actors adopt portable base station technology.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.