ELINT · Electronic Intelligence

SMS blasters bypass the network, and two September convictions show the cost

A false base station never touches an operator's core. Every control built to stop scam messaging sits inside the network it skips. Detection has to move to the radio layer.

Two convictions, five weeks apart

On 14 September 2026 a Singapore court sentenced Ong Kak Seng, a 28-year-old Malaysian national, to one year and nine months' imprisonment and a S$1,500 fine for operating an SMS blaster from a car between 12 October and 18 November 2025 [1]. Prosecutors put the output at more than 10,500 phishing messages, with more than 31,820 mobile phones falling inside the device's coverage area [1]. He was arrested on 18 November 2025 in an islandwide operation by the Singapore Police Force's Police Intelligence Department and Commercial Affairs Department [1]. He had been recruited after incurring an RM80,000 debt and was paid RM1,000 a day to drive through densely populated areas for ten to twelve hours at a stretch [1].

In the United Kingdom, City of London Police published in September 2026 the outcome of the first SMS blaster seizure made by UK law enforcement [2]. Mohammed Faiyaz Iqbal, 43, was sentenced on 28 August 2026 to three years and eight months, reduced by a third from five years and six months for a guilty plea [2]. The equipment was concealed in purpose-built wooden compartments inside a van, with power sources and roof-mounted aerials [2]. Investigators recovered 7,859 compromised payment card details from his phones [2]. The charge list included unauthorised use of wireless telegraphy apparatus alongside the fraud counts, which is the more instructive half: the underlying offence is unlicensed transmission [2]. The case was run by the Dedicated Card and Payment Crime Unit, a joint City of London Police, Metropolitan Police and UK Finance unit, working with BT, Virgin Media O2, Vodafone Three, Sky, the NCSC and Ofcom [2].

The counts are not comparable

Published figures measure different quantities and should not be read as a series. Singapore counted messages sent and handsets inside coverage [1]. Toronto Police counted network events: Project Lighthouse produced three arrests and warrants executed on 31 March 2026, with tens of thousands of devices connected and more than 13 million network disruptions recorded from a device first detected in downtown Toronto in November 2025 [3]. The force noted those disruptions could temporarily block access to legitimate cellular networks, including emergency calling [3]. A message count, a handset count and a disruption count are three different denominators.

Equipment pricing is inconsistent in the record. Philippine authorities valued one seized unit at US$9,500 in January 2025 [4]; trade reporting puts the wider range from low thousands of dollars to about US$35,000 [5]. Effective radius is reported at roughly 500 to 2,000 metres [6].

The mechanism is not in dispute. The device presents itself as a base station and induces nearby handsets to fall back to 2G, which does not require the network to authenticate itself to the handset. That allows the operator to deliver a message to a phone without knowing its number, and to set the sender name without verification [6].

Why the existing controls do not see it

Sender ID registries, aggregator vetting, operator spam filtering and SIM registration all sit inside the network. A blaster manufactures the message locally and pushes it straight into handsets, so no carrier system ever carries or inspects it [7]. In the Singapore case the police issued a public scam advisory on 12 November 2025 while the device was still operating, which is the shape of the problem: the warning was possible, the interception was not [7].

Malaysia's position illustrates the enforcement gap. Deputy Communications Minister Teo Nie Ching has said that because the devices are portable, enforcement relies heavily on public tip-offs to locate syndicates [8]. MCMC and police have run successive operations since September 2024 — Op Pancing, Op Fake BTS and Op Delusi — concentrated in Kuala Lumpur and Johor Bahru [8]. Possession or use of unauthorised transmitting equipment carries up to RM1 million or ten years under the Communications and Multimedia Act 1998 [8]. Stricter SIM registration standards took effect on 27 February 2026 [8]. SIM registration is a control on subscriptions. A blaster does not use one.

A regional supply problem

The GSMA's Asia Pacific mobile industry taskforce, whose operator members include CelcomDigi, Maxis, M1 and Singtel, has asked governments to criminalise the sale, purchase, possession and use of these devices, to disrupt manufacture and distribution across borders, and to have regulators act on unlicensed spectrum use [9]. Julian Gorman, the GSMA's head of Asia Pacific, said there is "no legitimate reason" for these devices to be purchasable over the internet [9]. The taskforce names Cambodia, Indonesia, Japan, Malaysia, New Zealand, the Philippines, South Korea, Taiwan, Thailand and Vietnam as affected markets, and cites survey figures of 8% of ASEAN consumers scammed in twelve months and close to US$700 billion lost to digital scams across Asia [9]. Those last two are industry survey numbers, not official statistics.

Enforcement records point at a distribution layer rather than isolated operators. Philippine agencies arrested a Malaysian national in January 2025 described as the head of a syndicate supplying IMSI catchers, seizing a unit branded "Octopus 5G" with a signal jammer, antenna, phones and SIM cards [4]. In August 2025 the National Bureau of Investigation arrested two Malaysians in Cebu City with an IMSI catcher, routers and RF modules [10]. Eric Priezkalns, writing on that case, cautions against reading nationality or device type as evidence of espionage when the recorded conduct is fraud [10]. The pattern in the court record is organised fraud using unlicensed transmitters, and should not be reported as anything else without evidence.

Detection that works at the radio layer

Eleanor Holtmanns and Silke Holtmanns set out the operator-side options: radio fingerprinting and anomaly detection built from neighbouring-cell measurement reports, flagging any 2G base station appearing in a market that has retired 2G, identifying broken handover failures, watching signalling volume spikes, and correlating signal strength across base stations [11]. Device-side detection apps exist, including FBSDetector, SnoopSnitch and CellGuard, but are constrained by how little the baseband exposes [11]. Their central operational point is that speed of detection governs whether law enforcement can act at all, because the emitter is moving [11].

A peer-reviewed system published in Sensors derives behavioural rules from base station specifications, converts them to a state machine, and reports 98% detection accuracy against a 5G RAN simulator, with lower overhead than seven machine-learning comparators [12]. Simulator results are not field results and should be read as a design signal, not a deployment figure.

Handset-side controls are blunt but available: disabling 2G, supported on Android 12 and later, and Lockdown Mode on iOS [6]. Android 16 added notifications for connections to suspected false base stations [5].

What to do

  • Treat unexplained 2G presence in a market that has retired 2G as an incident signal rather than a coverage artefact, and route it to security rather than to radio planning [11].
  • Instrument handover failure rates and signalling volume by cell, and retain the telemetry long enough to reconstruct the track of a moving emitter [11].
  • Accept that there will be no message-layer evidence. Investigations start from radio telemetry and physical location, not from message logs or sender IDs [7].
  • Require 2G to be disabled on corporate handsets issued to executives, finance staff and anyone handling payment authorisation, where the device platform supports it [6].
  • For operators: build the tip-off channel the enforcement model actually depends on, and make sure a report can reach a spectrum-monitoring team the same day [8].

The domain point

This has been handed to fraud teams, and it is not a fraud control problem. The instrument is an unlicensed transmitter in licensed spectrum. The evidence is radio-frequency telemetry. The response is direction-finding against a moving emitter, followed by physical seizure. Organisations that maintain a spectrum monitoring or electronic warfare competence already hold the relevant skills; the messaging security stack does not, and cannot be made to.

Sources

Every R3KONX article cites its primary material. 12 sources, in order of first citation. Links open the original publication.

  1. 'SMS blaster' in car sent over 10,500 phishing messages as man drove around Singapore AsiaOne · 2026-09-14
  2. Man sentenced following first UK seizure of SMS blaster fraud equipment used to spam members of the public City of London Police · 2026-09
  3. Toronto police make arrests in text-message cyberattack, 13M disruptions reported Global News · 2026-04-23
  4. Authorities arrest Malaysian allegedly supplying IMSI scamming devices Philippine Daily Inquirer · 2025-01-22
  5. Risky Bulletin: SMS blasting incidents are rising Risky Business News · 2025-07-21
  6. What an SMS blaster is, and how to protect yourself from malicious SMS messages while traveling Kaspersky · 2025-07-11
  7. What is an SMS blaster? Singapore's case, and why the usual scam checks failed Centre for Cybersecurity Innovation · 2026-09-15
  8. Fake BTS gadgets let scammers strike, telcos now on the hook with stricter SIM rules Malay Mail · 2026-02-23
  9. GSMA Asia Pacific Mobile Industry Taskforce Calls for Government and Law Enforcement Support to Stamp Out SMS Blaster Device Threat GSMA · 2025-09-23
  10. Two Malaysians Arrested for Using an IMSI-Catcher in the Philippines Commsrisk · 2025-08-27
  11. How to Detect SMS Blasters Commsrisk · 2026-06-30
  12. SMDFbs: Specification-Based Misbehavior Detection for False Base Stations Sensors (MDPI) · 2023-11-29

Researched and written by the R3KONX analysis desk from the primary material cited below. Figures drawn from court reporting, police statements and industry surveys are not directly comparable: message counts, phones-in-range counts and network-disruption counts measure different things, and the industry survey figures cited are self-reported rather than official statistics. Corrections to event@r3konx.asia.

R3KONX 2027

Work in this domain? So does the programme

4–6 May 2027, World Trade Centre Kuala Lumpur. Curated talks, hands-on training and The BattleGrid.