
FaceTime Spoof Calls Steal Codes and Money
Apple warns that scammers are using FaceTime calls, often with spoofed caller ID, to impersonate Apple or banks and pressure people into sharing passwords,…
UK authorities charged five people linked to “Russian Coms,” a vishing (phone-scam) platform used to make large volumes of spoofed calls that appeared to come from trusted organizations. Victims were told their accounts were under fraud and were pressured to move money to “safe” accounts controlled by criminals.
UK authorities charged five people connected to a vishing platform known as "Russian Coms." The platform allowed fraudsters to spoof caller ID so that outbound calls appeared to come from pre-selected, trusted numbers. Victims received calls that seemed to originate from banks, telecommunications companies, or law enforcement agencies, immediately establishing a false sense of legitimacy before any request was made.
Once the caller had the victim's attention, the scam followed a consistent script: claim the victim's account showed fraudulent activity, then pressure the victim to transfer funds to a different account described as a way to "safeguard" their money. This combination of urgency and a false sense of protection was the core mechanism used to extract funds.
The platform was reportedly marketed through Snapchat, Instagram, and Telegram as a cybercrime-as-a-service offering. It included features designed to make scam calls sound and feel professional, such as hold music, encrypted calls, voice-changing services, instant handset wipe, and 24/7 support. This level of polish helped fraudsters sound convincing to targets who had no reason to doubt the call's origin.
Because the spoofed caller ID displayed a trusted-looking number, victims had little immediate way to distinguish a fraudulent call from a genuine one. The pressure to act quickly, combined with the appearance of institutional authority, reduced the likelihood that a victim would pause to verify the request independently.
Organizations and individuals can reduce exposure to this type of scam by treating inbound caller ID as unverified information rather than proof of identity. Any call requesting a fund transfer or account action, especially one framed as urgent fraud protection, should be independently verified by contacting the organization through a known official number rather than any number or process suggested during the call itself.
Finance and accounts payable teams, executives, and customer-facing staff are useful audiences for reinforcing this behavior, since they are more likely to be targeted with pretexts involving account activity or fund movement. Awareness that criminals increasingly rely on professional-grade tooling, voice changing, hold music, and dedicated support, to make scam calls sound legitimate can help staff maintain healthy skepticism even when a call sounds polished and credible.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It was a vishing platform used by fraudsters to spoof caller ID and hide their identity, marketed as a cybercrime-as-a-service package with features like voice-changing and encrypted calls.
Callers impersonated banks, telecom providers, or law enforcement, claimed the victim's account had fraudulent activity, then persuaded the victim to transfer funds to another account to safeguard them.
Treat caller ID as untrusted since it can be spoofed, and independently verify any unexpected call by contacting the organization through a known, official number rather than acting on the call itself.
The platform offered professional features like hold music, 24/7 support, and voice-changing tools that made fraudulent calls sound legitimate and trustworthy.
Your phone rings, it says your actual bank’s name. The voice says, “I’m calling because your account is subject to fraudulent activity.” Behind that call could be “Russian Coms”, a vishing platform that lets fraudsters spoof banks, telecoms, even law enforcement, with hold music, voice-changing, and encrypted calls. Their script is simple: “We see fraud on your account. To safeguard your money, you must immediately transfer it to a safe account we provide.” If you follow that, you’ve just sent money straight to them. Here’s the rule: if an inbound call ever asks you to move money to a “safe account,” hang up, then call your bank back on the official number from their website or our internal directory.

Apple warns that scammers are using FaceTime calls, often with spoofed caller ID, to impersonate Apple or banks and pressure people into sharing passwords,…

Microsoft reports billions of phishing attempts in Q2 2026, with attackers increasingly using attachments (PDF/DOC/HTML) and new formats like calendar invites…

UK authorities said two Scattered Spider members accessed Transport for London (TfL) by buying partial employee credentials and then tricking TfL’s helpdesk…

The article highlights how attackers can quickly build convincing executive “profiles” from public information and use them to manipulate employees. It cites…

Three crypto investors sued Apple after allegedly losing about $1.8 million in Bitcoin to an iPhone app that impersonated the legitimate (desktop-only) Sparrow…

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users…