From the FinCrime Agent course
Want to do this for a living?
This is the kind of story financial-crime professionals act on every day. Learn the craft in Marco’s AML & Financial Crime course.
Five charged over Russian Coms, the spoofing platform sold as a fraud product
The NCA has charged five London residents over Russian Coms, a caller ID spoofing service sold to criminals as both a handset and a web application.
What happened
The UK National Crime Agency (NCA) announced on 13 July 2026 that five people have been charged as part of its investigation into Russian Coms, which the NCA describes as “a group which made products used by criminals to defraud victims all over the world.”
The NCA says the platform was established in 2020, “started as a handset and then moved to a web-based application, with both products being marketed and sold.” Those products “allowed criminals to hide their identity by appearing to call from pre-selected numbers.” Those numbers, the NCA says, “would often be of financial institutions, telecommunications companies and law enforcement agencies with the aim of stealing funds and personal details from victims.”
The five have been charged “in relation to supplying Russian Coms devices and apps and offences relating to money made from allegedly selling the devices.” They are Ayoub Sehailia, 28; Zakkaria Sehailia, 30; Usman Din, 30; Denis Ozmus, 29; and Fadila Salem, 53, all of London.
The charges differ by individual. Four face conspiracy to supply articles for use in connection with fraud, and the property offences are split across the group: transferring, converting, and in one case acquiring criminal property. Zakkaria Sehailia also faces a charge of failing to comply with a notice relating to not providing phone passcodes. All five will appear at Westminster Magistrates’ Court on Friday, 14 August. No one has been convicted.
The 13 July release does not quantify the harm. Reporting the same week by Help Net Security, drawing on the NCA’s earlier disclosure, put the scale at over 1.3 million scam calls to around half a million UK phone numbers, roughly 170,000 victims, and an average reported loss above GBP 9,400. Help Net Security also reported subscription pricing of GBP 1,200 to GBP 1,400 for a six-month handset contract, or GBP 350 a month for the web app, paid in cryptocurrency.
Why it matters
Read the NCA’s own description carefully and the analytical point is hard to miss: this is not a gang, it is a product. Built, versioned from hardware to web, and in the NCA’s words marketed and sold. Treating it as an organised crime group misreads what customers were actually exposed to. They were exposed to infrastructure that anyone could rent.
The control implication follows from the spoofing itself. When an inbound call appears to come from a bank’s own published number, it defeats the trust signal the bank created and spent years teaching customers to rely on. Caller ID is not an authentication factor, and this case is a useful reminder that it never was.
The money laundering angle deserves naming for an anti-money laundering (AML) audience. The property offences sit alongside the supply charges, which reflects how these cases now run: the enabling service and the proceeds are pursued together, not sequentially.
Practitioner angle
- Name safe-account transfers as an explicit typology in your fraud rules, not just as a training slide. Rules should look for a first-time payee, a full or near-full balance sweep, and a customer-stated reason of account security, in combination.
- Check what your contact centre can confirm and how fast. If a customer calls back asking whether you rang them ten minutes ago, an agent should answer from outbound call records within the call, not the next working day.
- Pressure-test your out-of-band verification. Any process where a customer verifies an inbound call using a channel the caller controls or suggests should be redesigned.
- Say plainly in your scam warning copy that your own number can be spoofed. Customers who treat caller ID as proof of identity are the exposed population.
- Feed the typology into transaction monitoring, not just the fraud team. Onward movement of proceeds is the AML side of the same event.
Start with the contact centre callback test. It is cheap, and it tells you whether your first line can break the spoof at the moment it matters.
Want to do this for a living?
Turn this weekly intelligence into a career. Marco’s AML & Financial Crime course takes you from curious to hireable.
AML & Financial Crime course →