Full Report
Canadian authorities have arrested three men for operating an "SMS blaster" device that pretends to be a cellular tower to send phishing texts to nearby phones. [...]
Analysis Summary
# Incident Report: Project Lighthouse - Rogue Cellular Base Station (SMS Blaster) Operations
## Executive Summary
Canadian authorities dismantled a coordinated phishing operation utilizing "SMS Blaster" technology (IMSI catchers) to bypass traditional telecom security. The attackers used vehicle-mounted devices to mimic legitimate cell towers, forcing nearby mobile devices to connect and receive fraudulent SMS messages. The operation resulted in three arrests and highlighted a significant public safety risk due to the disruption of emergency services.
## Incident Details
- **Discovery Date:** November 2025
- **Incident Date:** November 2025 – April 2026
- **Affected Organization:** General Public (Greater Toronto Area)
- **Sector:** Telecommunications / Public Safety
- **Geography:** Toronto, Markham, and Hamilton, Ontario (Canada)
## Timeline of Events
### Initial Access
- **Date/Time:** November 2025
- **Vector:** Radio Frequency (RF) Signal Manipulation
- **Details:** Attackers deployed rogue cellular base stations from moving vehicles. These devices emitted high-power signals that mimicked legitimate service providers, forcing nearby phones to "handover" from real towers to the rogue device.
### Lateral Movement
- **Details:** N/A. The attack focused on broad-spectrum broadcast (SMS blasting) rather than moving through a specific corporate network.
### Data Exfiltration/Impact
- **Details:** The primary goal was the theft of personal information, banking credentials, and passwords via phishing links sent in SMS messages. Additionally, 13 million instances of mobile network entrapment were recorded, where devices were forcibly disconnected from legitimate networks.
### Detection & Response
- **How it was discovered:** Toronto Police received tips regarding suspicious activity in downtown Toronto, leading to the launch of "Project Lighthouse."
- **Response actions taken:** Surveillance of moving vehicles; coordinated raids in Markham and Hamilton on March 31; seizure of multiple SMS blaster units; arrest of three suspects.
## Attack Methodology
- **Initial Access:** Forced cellular connection via signal mimicry (Man-in-the-Middle).
- **Persistence:** Mobility (vehicle-mounted) allowed the attackers to evade static signal detection.
- **Defense Evasion:** Use of roving vehicles to prevent localization; exploitation of mobile device "auto-connect" protocols to legitimate-looking signals.
- **Collection:** Harvested PII and banking credentials through spoofed websites hosted on phishing links.
- **Impact:** Service disruption (denial of service for emergency calls) and large-scale financial fraud.
## Impact Assessment
- **Financial:** Massive potential for fraud; specific dollar amounts not disclosed.
- **Data Breach:** Attempted theft of banking credentials and passwords from millions of potential targets.
- **Operational:** 13 million cases of mobile network entrapment; disruption of legitimate cellular traffic.
- **Reputational:** Public concern regarding the security of SMS-based communications from trusted entities (banks/government).
## Indicators of Compromise
- **Network indicators:**
- Deployment of rogue GSM/LTE signals.
- Unexpected "downgrading" of cellular service (e.g., jumping from 5G to 2G/LTE unexpectedly).
- **Behavioral indicators:**
- Receipt of unsolicited "urgent" SMS from banks/government without a known trigger.
- Temporary loss of cellular data or inability to make calls while in specific high-traffic areas.
## Response Actions
- **Containment measures:** Physical seizure of the broadcasting hardware to stop the transmission of fraudulent signals.
- **Eradication steps:** Arrest of the operators (3 individuals) and seizure of electronic support devices.
- **Recovery actions:** Public awareness campaign advising citizens to ignore suspicious links.
## Lessons Learned
- **Key takeaways:** This was the first recorded use of SMS Blasters in Canada, indicating an evolution in local cyber-crime tactics.
- **Vulnerabilities:** Mobile devices are designed to favor the strongest signal, a protocol that can be easily exploited by high-power rogue hardware. Traditional SMS is inherently insecure as a delivery method for sensitive links.
## Recommendations
- **Technical Prevention:** Android users should enable "Disable 2G" in SIM settings to prevent downgrading attacks.
- **Organizational Policy:** Financial and government institutions should transition away from SMS-based link delivery for sensitive communications.
- **Public Awareness:** Educate the public that SMS "Sender IDs" (e.g., "CRA" or "Bank") can be easily spoofed by rogue towers without needing the user's phone number.