HomeSecurityThree men convicted of operating a vishing-as-a-service business

Three men convicted of operating a vishing-as-a-service business

Three men have been sentenced at a London court after pleading guilty to running a vishing-as-a-service businessthat helped fraudsters log into users' bank and telecom accounts.

vishing-as-a-service

The three defendants are:

  • Callum Picari, 23 years old from Hornchurch
  • Vijayasidhurshan Vijayanathan, 21, from Aylesbury
  • Aza Siddeeque, 19 years old from Milton Keynes

All three had admitted to participating in a “conspiracy to manufacture and supply items for use in fraud.” Picari also pleaded guilty to money laundering.

See also: New phishing campaign targets mobile devices with malicious PDFs

At Snaresbrook Crown Court yesterday, Picari was sentenced to two years and eight months in prison , while Vijayanathan and Siddeeque were sentenced to 12 months' confinement and ordered to pay £760 costs each. They will also have to carry out 200 hours and 160 hours of community service respectively.

The three of them maintained a vishing-as-a-service site called www.OTP.Agency, which fraudsters could use, by paying a monthly subscription, to compromise accounts by bypassing multi-factor authentication (MFA).

For £30 a week, the fraudsters had access to a “call bot” designed to trick account holders into revealing genuine one-time passwords (OTPs).

For £380 a month, fraudsters could access a text-to-speech service, allowing for more personalised scams.

According to police, the scammers often posed as representatives from BT, Sky, Virgin Media, HMRC, Mastercard and Visa to scam users.

See also: Microsoft Teams: New phishing attacks from ransomware gangs

The NCA estimated that this malicious operation affected at least 12,500 users, between September 2019 and March 2021, when the website was shut down following the arrest of the three.

It is not yet clear how much the defendants made from their 3,000 subscribers. The NCA said the profits could have been around £90,000 if these fraudsters had bought the basic subscription, but could have reached up to £7.9 million if they had opted for the more expensive package.

Picari was described by the service as “owner, programmer and primary beneficiary” of the vishing-as-a-service platform. Siddeeque is said to have promoted the website and provided technical support on Telegram in exchange for unlimited use of the site for fraud. Finally, Vijayanathan also promoted the website and helped with management.

See also: Phishing: PNGPlug Loader distributes ValleyRAT malware

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Vijayasidhurshan Vijayanathan Callum Picari Aza Siddeeque
Three men convicted of operating a vishing-as-a-service business

What are the best practices for protecting against vishing attacks?

  • Education and awareness  are critical to protecting  against vishing attacks. Learn about common techniques used by attackers and the signs to look out for
  • Avoid giving out personal information over the phoneunless you are absolutely sure of the caller's identity. If you receive a call from someone claiming to be from a reputable company, hang up and call the company directly using a number you know to be valid.
  • Use technology to protect yourself. Install and keep software up to date security on your phone. Many apps can detect and block suspicious calls.
  • Be wary of calls that ask for immediate action or offer something that seems too good to be true. Attackers often use scare tactics or offers to convince you to give up information.
  • Report suspicious calls to the appropriate authorities. Many countries have helplines or websites where you can report vishing attacks, helping to protect others.
  • Use caller ID to filter out unknown or suspicious numbers. If you don't recognize the number, consider not answering and letting the caller leave a message.
  • Develop and follow policies security workplace. Educate your employees about the threats of vishing attacks and create procedures for verifying calls requesting sensitive information.

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS