Arrests made and thousands of victims contacted after scammer site taken offline

18 April 2024, 12:34

A screengrab of an arrest in connection with the LabHost website
LabHost scammer site. Picture: PA

Law enforcement agencies have arrested 37 suspects across the UK and around the world

A UK-founded website used to defraud victims on an industrial scale has been infiltrated – leading to scores of arrests around the world, the Metropolitan Police has said.

As many as 70,000 UK victims were tricked by the site’s scams, which obtained 480,000 card numbers and 64,000 PINs globally.

Law enforcement agencies have arrested 37 suspects across the UK and around the world, including at Manchester and Luton airports, as well as in Essex and London.

LabHost, a scammer site set up in 2021 by a criminal network, enabled users to set up phishing websites designed to trick victims into revealing personal information such as email addresses, passwords, and bank details.

Phishing is a form of scam where attackers deceive people into revealing sensitive information by masquerading as a legitimate person.

Criminal subscribers were able to log on and choose from existing sites or request bespoke pages replicating those of trusted brands including banks, healthcare agencies and postal services.

LabHost even provided templates and an easy to follow tutorial allowing would-be fraudsters with limited IT knowledge to use the service.

At the end of the tutorial, a robotic voice told fraudsters: “Stay safe and good spamming.”

By the beginning of 2024, more than 40,000 fraudulent sites had been created and 2,000 users were registered and paying a monthly subscription fee.

LabHost provided its subscribers with fake profiles for 170 companies to trick victims, including 47 based in the UK.

A website seizure notice on LabHost (Metropolitan Police/PA)
A website seizure notice on LabHost (Metropolitan Police/PA)

Those subscribing to the “worldwide membership”, meaning they could target victims internationally, paid between £200 and £300 a month.

Since creation, the site has received just under £1 million in payments from criminal users.

Shortly after the platform was seized and disrupted, 800 users received a message telling them that police “know who they are and what they’ve been doing”.

Police hope they can dissuade former LabHost subscribers from further offending by creating the same level of fear about their information as their victims.

As part of Operation Stargrew, detectives have contacted up to 25,000 victims in the UK to tell them their data has been compromised.

Work began in June 2022 after detectives received crucial intelligence about LabHost’s activity from the Cyber Defence Alliance – a group of British-based banks and law enforcement agencies which work together to share intelligence.

LabHost scammer site
Some of the equipment seized (Metropolitan Police/PA)

In November 2022, the Met arrested more than 130 suspects as part of Operation Elaborate. An estimated 200,000 victims were targeted by a scam stealing millions from the public via fake bank phone calls.

Dame Lynne Owens, deputy commissioner of the Metropolitan Police Service, said: “You are more likely to be a victim of fraud than any other crime.

“In addition to the financial impact, it undermines the public’s confidence in the tools and technology they need to use in daily life. Our collective approach should ensure suspects feel that same level of distrust in their own criminal environment.

“Online fraudsters think they can act with impunity. They believe they can hide behind digital identities and platforms such as LabHost and have absolute confidence these sites are impenetrable by policing.

“But this operation and others over the last year show how law enforcement worldwide can, and will, come together with one another and private sector partners to dismantle international fraud networks at source.

“Our approach is to be more precise and targeted with a clear focus on those enabling online fraud to be carried out on an international scale.”

A screengrab from the subscription page
A screengrab from the subscription page (Metropolitan Police/PA)

Adrian Searle, director of the National Economic Crime Centre in the NCA, said: “Fraud is a terrible crime that impacts victims both financially and psychologically, undermining our collective trust in others and the online services on which we all rely.

“Together with cyber crime, it makes up around 50% of all crime in England and Wales. Recognising the scale and nature of the threat, law enforcement are working evermore closely together, both here and overseas, to target the fraudsters and the technology they are exploiting.

“This operation again demonstrates that UK law enforcement has the capability and intent to identify, disrupt and completely compromise criminal services that are targeting the UK on an industrial scale.”

By Press Association

More Technology News

See more More Technology News

X logo

Irish watchdog ‘surprised’ over X move on user data

A sign reminding people of new UK customs rules (PA)

Global trade to go digital as UK and 90 other countries agree paperless switch

A broadband router

Now most complained-about broadband and landline provider – latest Ofcom figures

Tasty Spoon

High-tech spoon developed to enrich lives of dementia patients

The NCSC said the Andariel group has been compromising organisations around the world (PA)

North Korea-backed cyber group sought to steal nuclear secrets, NCSC says

Tanaiste Micheal Martin speaks to the media

Tanaiste: Fake ads about me originated in Russia

Revolut card on a table

Revolut secures UK banking licence after three-year wait

IT outages

CrowdStrike faces backlash over 10 dollar apology vouchers for IT outage

Charlie Nunn, the boss of Lloyds, wearing a suit and tie outisde a building

Lloyds boss says tech outages a ‘really important issue’ for bank

A woman using a mobile

Accessing GP services online could pose risk to patient safety, probe finds

Overhead view of a man using a laptop computer

AI could help two-thirds of workers with daily tasks, says study

A TikTok logo on a mobile phone screen alongside logos for other apps

TikTok fined £1.8m over failure to provide accurate information to Ofcom

A hand pressing on laptop keys

UK competition regulator signs AI agreement with EU and US counterparts

A woman using a mobile phone

Third of UK adults use mobile contactless payments at least every month

Businessman hand touching password login device screen, cyber security concept

Lawlessness ‘characterises’ pornography online, says MP in plea to reform laws

Hands on a computer keyboard

State threat law watchdog calls for greater transparency from tech giants