“Russian Coms” Vishing Platform Busted

Infosecurity Magazine · Medium sophistication
Last updated July 30, 2026

UK authorities charged five people linked to “Russian Coms,” a vishing (phone-scam) platform used to make large volumes of spoofed calls that appeared to come from trusted organizations. Victims were told their accounts were under fraud and were pressured to move money to “safe” accounts controlled by criminals.

How the attack worked

UK authorities charged five people connected to a vishing platform known as "Russian Coms." The platform allowed fraudsters to spoof caller ID so that outbound calls appeared to come from pre-selected, trusted numbers. Victims received calls that seemed to originate from banks, telecommunications companies, or law enforcement agencies, immediately establishing a false sense of legitimacy before any request was made.

Once the caller had the victim's attention, the scam followed a consistent script: claim the victim's account showed fraudulent activity, then pressure the victim to transfer funds to a different account described as a way to "safeguard" their money. This combination of urgency and a false sense of protection was the core mechanism used to extract funds.

Why it succeeded

The platform was reportedly marketed through Snapchat, Instagram, and Telegram as a cybercrime-as-a-service offering. It included features designed to make scam calls sound and feel professional, such as hold music, encrypted calls, voice-changing services, instant handset wipe, and 24/7 support. This level of polish helped fraudsters sound convincing to targets who had no reason to doubt the call's origin.

Because the spoofed caller ID displayed a trusted-looking number, victims had little immediate way to distinguish a fraudulent call from a genuine one. The pressure to act quickly, combined with the appearance of institutional authority, reduced the likelihood that a victim would pause to verify the request independently.

What to watch for

  • Unsolicited calls claiming your account has fraudulent activity
  • Requests to transfer money to a "safe" or "new" account to protect funds
  • Caller ID showing a familiar bank, telecom, or law enforcement number, since this can be spoofed
  • Calls that create urgency around financial action

Building resistance

Organizations and individuals can reduce exposure to this type of scam by treating inbound caller ID as unverified information rather than proof of identity. Any call requesting a fund transfer or account action, especially one framed as urgent fraud protection, should be independently verified by contacting the organization through a known official number rather than any number or process suggested during the call itself.

Finance and accounts payable teams, executives, and customer-facing staff are useful audiences for reinforcing this behavior, since they are more likely to be targeted with pretexts involving account activity or fund movement. Awareness that criminals increasingly rely on professional-grade tooling, voice changing, hold music, and dedicated support, to make scam calls sound legitimate can help staff maintain healthy skepticism even when a call sounds polished and credible.

Key findings

  • “Russian Coms” was described as a vishing platform used by fraudsters to spoof caller ID and hide their identity.
  • Victims were commonly targeted with calls that appeared to come from banks, telecoms providers, or law enforcement.
  • A typical scam flow was: claim the victim’s account has fraudulent activity, then persuade the victim to transfer funds to another account “to safeguard them.”
  • The platform was marketed via Snapchat, Instagram, and Telegram and offered features that made scams easier (e.g., voice-changing, encrypted calls, and handset wipe).
  • Authorities previously prosecuted related fraud-enablement services, including an MFA-bypass service (OTP.Agency).

Who’s being targeted

  • Commonly targeted roles: All employees, Finance / Accounts Payable, Executives, Customer-facing staff (call centers).
  • Affected industries: Finance and Insurance, Telecommunications, Government / Law Enforcement (impersonated).
  • Attack channels: vishing.
  • Impersonated: A trusted organization (e.g., a financial institution).

Red flags to watch for

  • Caller ID appears trusted, but that can be spoofed
  • Pressure to move money quickly to a new/different account
  • Unsolicited call claiming fraud and requesting financial action
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What was the Russian Coms platform?

It was a vishing platform used by fraudsters to spoof caller ID and hide their identity, marketed as a cybercrime-as-a-service package with features like voice-changing and encrypted calls.

How did the scam typically work?

Callers impersonated banks, telecom providers, or law enforcement, claimed the victim's account had fraudulent activity, then persuaded the victim to transfer funds to another account to safeguard them.

How can I tell if a fraud alert call is real?

Treat caller ID as untrusted since it can be spoofed, and independently verify any unexpected call by contacting the organization through a known, official number rather than acting on the call itself.

Why did this scam succeed against victims?

The platform offered professional features like hold music, 24/7 support, and voice-changing tools that made fraudulent calls sound legitimate and trustworthy.

Read the video transcript

Your phone rings, it says your actual bank’s name. The voice says, “I’m calling because your account is subject to fraudulent activity.” Behind that call could be “Russian Coms”, a vishing platform that lets fraudsters spoof banks, telecoms, even law enforcement, with hold music, voice-changing, and encrypted calls. Their script is simple: “We see fraud on your account. To safeguard your money, you must immediately transfer it to a safe account we provide.” If you follow that, you’ve just sent money straight to them. Here’s the rule: if an inbound call ever asks you to move money to a “safe account,” hang up, then call your bank back on the official number from their website or our internal directory.

Similar attacks

FaceTime Spoof Calls Steal Codes and Money

FaceTime Spoof Calls Steal Codes and Money

Apple warns that scammers are using FaceTime calls, often with spoofed caller ID, to impersonate Apple or banks and pressure people into sharing passwords,…

July 17, 2026
Fake iPhone Crypto Wallet Stole $1.8M

Fake iPhone Crypto Wallet Stole $1.8M

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users…

July 29, 2026