HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

UK Charges Five Individuals Over Russian Coms Call‑Spoofing Platform Used in 1.8 M Scam Calls

UK authorities have charged five people for operating Russian Coms, a spoofing service that enabled over 1.8 million fraudulent calls worldwide. The incident highlights the need for robust caller‑ID verification and security‑awareness training to satisfy SOC 2 access‑control requirements.

LiveThreat™ Intelligence · 📅 July 13, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
2 recommended
📰
Source
bleepingcomputer.com

UK Charges Five Individuals Over Russian Coms Call‑Spoofing Platform Used in 1.8 M Scam Calls

What Happened – The UK National Crime Agency (NCA) has charged five people for operating and selling “Russian Coms,” a caller‑ID spoofing service that enabled more than 1.8 million fraudulent calls to victims in 107 countries. The platform offered encrypted handsets, web‑phone apps, voice‑changing, and “no‑logs” features, and was marketed on Telegram, Snapchat and Instagram.

Why It Matters for Compliance & Audit Readiness

  • The scenario exemplifies a classic social‑engineering attack that SOC 2 access‑control policies must address: verifying caller identity and restricting privileged communications.
  • Continuous security‑awareness training and documented verification procedures provide the audit evidence needed to demonstrate compliance with the SOC 2 CC6 (Logical Access) and CC7 (System Operations) criteria.
  • The NCA’s takedown underscores the importance of monitoring third‑party communication tools for misuse, a control gap often highlighted in readiness assessments.

Who Is Affected – Financial services, telecommunications, law‑enforcement agencies, and any organization that relies on voice channels for customer interaction.

Recommended Actions

  • Review and tighten caller‑ID verification policies; require multi‑factor authentication for any outbound voice request involving sensitive data or fund transfers.
  • Incorporate call‑spoofing scenarios into your security‑awareness curriculum and test staff response with simulated phishing‑by‑phone drills.
  • Capture evidence of training completion, policy updates, and incident‑response logs as part of your continuous SOC 2 audit trail.

Technical Notes – The platform operated as both a hardware handset and a web‑based application, sold via cryptocurrency contracts (£1.2k‑£1.4k for six‑month access). Attackers spoofed numbers belonging to banks, telecoms and law‑enforcement agencies to harvest personal details and illicitly move funds. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/uk-charges-suspects-linked-to-russian-coms-call-spoofing-platform/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →