UK authorities have charged five people following a National Crime Agency investigation into Russian Coms, a fraud-enablement platform accused of powering large-scale scam calling campaigns. Investigators said the service, launched in 2020, allowed criminals to spoof trusted caller IDs and impersonate banks, telecommunications providers, and law enforcement agencies to steal money and personal information. The defendants face allegations including conspiracy to supply articles for use in connection with fraud, along with multiple money-laundering-related offenses tied to proceeds allegedly generated by selling the platform’s devices and applications.
The NCA said Russian Coms was linked to more than 1.8 million scam calls, roughly 170,000 victims, and tens of millions in losses. The platform was promoted through Telegram, Snapchat, and Instagram, accepted cryptocurrency payments, and offered handset and web-based tools with features including encrypted calls, no-logs functionality, voice changing, and instant handset wipes. Authorities previously disrupted the service in March 2024 as part of Operation Henhouse, a wider anti-fraud campaign that led to 290 arrests across the UK, and the five defendants are due to appear at Westminster Magistrates’ Court.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
In March 2024, the UK National Crime Agency disrupted Russian Coms as part of Operation Henhouse, a broader anti-fraud effort. The platform was linked to more than 1.8 million scam calls, roughly 170,000 victims, and tens of millions in losses.
The five defendants are scheduled to appear at Westminster Magistrates’ Court on 14 August following the charges announced in the Russian Coms investigation.
The UK National Crime Agency announced charges against five individuals in connection with its investigation into Russian Coms, including conspiracy to supply articles for use in connection with fraud and multiple money-laundering-related offenses.
The Russian Coms caller ID spoofing platform was established in 2020, initially as a handset product before later evolving into a web-based application used to facilitate scam calls.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourcenationalcrimeagency.gov.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.