The CyberSignal
  • Latest
  • Trending
  • Cyber Attacks
  • Data Breaches
  • Threat Intelligence
  • Critical Infrastructure
  • Policy & Government
  • Cybersecurity 101
  • Vulnerabilities
  • About Us
  • Weekly Briefing
  • Topics
Cyber Attacks

Mobile SMS Blasters Prowled Canadian Streets, Blocking 911 Calls and Stealing Phone Data

Nicholas Robert

Nicholas Robert

26 Apr 2026 — 3 min read
Share
Minimalist white line art on a purple background showing a stylized car silhouette with a signal tower emerging from its roof, symbolizing mobile telecom-hijacking equipment.

A “mobile SMS blaster” deployed from vehicles in Toronto mimicked cell towers, hijacked tens of thousands of phones, and caused 13 million network disruptions—temporarily blocking 911 access while sending massive volumes of fraudulent texts under Project Lighthouse.

TORONTO, ONTARIO — In a first-of-its-kind cybercrime investigation in Canada, the Toronto Police Service has dismantled a sophisticated "drive-by" smishing operation that turned city streets into a digital battlefield. Known as Project Lighthouse, the probe revealed that suspects used vehicle-mounted "SMS blasters" to hijack mobile connections, causing millions of network disruptions and potentially endangering public safety by impairing access to 911 services.

The operation involved vehicles cruising through downtown Toronto and the Greater Toronto Area (GTA). These cars were equipped with custom-built radio equipment designed to mimic legitimate cellular towers, tricking nearby mobile devices into disconnecting from the secure carrier network and "latching" onto the rogue pirate site.

Project Lighthouse Incident Profile
Metric Detail
Investigation Name Project Lighthouse (Toronto Police)
Device Type Vehicle-Mounted "SMS Blaster" (IMSI-Catcher)
Network Disruptions 13 Million events recorded
Critical Impact Temporary impairment of 911 access

The Mechanics of a "Mobile Blaster"

Technically, the devices seized by police function similarly to IMSI-catchers — often called "Stingrays" — but are specialized for high-volume smishing and SMS fraud. By projecting a signal stronger than actual cell towers in a localized area, the blaster forces phones to perform a "handover" to the attacker's hardware.

Once a phone is connected to the blaster, the attackers gain significant control:

  • Mass Smishing: The device sends fraudulent text messages directly to every phone in the vicinity. These messages posed as trusted entities like Canada Post, major banks, and government agencies.
  • Network Hijacking: Because the device is not connected to the actual cellular backbone, the "tens of thousands" of hijacked phones lose their ability to send or receive legitimate traffic.
  • 13 Million Disruptions: Investigators recorded a staggering 13 million instances where devices were knocked off their legitimate carrier networks, a pattern that points to a persistent, repetitive operation across the city.

A Public Safety Incident: The 911 Risk

The most alarming aspect of Project Lighthouse is the impact on emergency services. While the perpetrators were targeting financial credentials, their equipment created a "dead zone" for legitimate cellular communication.

According to reporting from Tom's Hardware and Global News, police warned that during these hijacked windows, a victim's ability to reach 911 could have been impaired. Because the phone believes it is connected to a tower, it may fail to seek an alternative emergency network, effectively silencing the device during a critical moment. This transition from "fraud" to "public safety threat" marks a dangerous shift in the telecom-security landscape.

Defender Angle: Detecting the Drive-By

For residents, this incident serves as a stark reminder that mobile-security is not just a software issue; it is an RF (Radio Frequency) issue.

Red Flags for Users:

  • Sudden Signal Drops: If your phone suddenly loses LTE/5G bars in a high-coverage urban area or switches to an older protocol (like 2G), it may be a sign of a nearby IMSI-catcher or blaster.
  • Unsolicited High-Pressure Texts: Messages that arrive precisely when your signal flickers, claiming an "urgent delivery failure" or "bank account freeze," should be treated with extreme skepticism.

For law enforcement and telecom providers, the "Project Lighthouse" case demonstrates the need for advanced RF monitoring in urban centers to identify mobile anomalies that move through traffic.


The CyberSignal Analysis: Strategic Signals

Signal 01 — The Physicality of Phishing

Phishing is no longer just a "link in an email." By using vehicles, attackers have created a mobile attack surface that exploits the physical geography of a city. This "city-as-a-lab" approach allows criminals to harvest thousands of victims in a single afternoon commute.

Signal 02 — Criminalization of Nation-State Tools

The "SMS blaster" is a specialized derivative of IMSI-catcher technology once reserved for intelligence agencies. Its appearance in the hands of three suspects in Toronto suggests a rapid commodification of high-end radio-hacking hardware.

Signal 03 — The 911 "Collateral Damage"

Attackers are becoming increasingly indifferent to the collateral damage of their operations. By prioritizing smishing volume over network stability, the Project Lighthouse actors demonstrated that the disruption of emergency services is now an acceptable "overhead" for cyber-criminal enterprises.


Sources

Type Source
Technical Tom's Hardware: SMS Blasters in Canada
Official Global News: Project Lighthouse Arrests
Public Alert Toronto Police: Project Lighthouse Briefing

Read more

Flat white line-art of an Android TV box disguised as a phone clicking an ad, the payout looping to a company, on a saturated background with one red dot.

Fuyao: The Android TV Ad-Fraud Botnet Now Has a Name and an Operator

The cheap Android TV boxes that pose as phones to click ads now have a name — Fuyao — and an attributed operator, Zhejiang Fengwo IoT. Bitsight's forensic trail, the machine-vision fraud engine, and why the headline device counts are softer than they look.

31 Jul 2026
Flat white line-art of a build agent and a server exchanging a polling signal, with one flat red dot, on a solid background — TeamCity CVE-2026-63077.

TeamCity CVE-2026-63077: The Agent Polling Protocol Is the Way In

A follow-up on CVE-2026-63077: JetBrains ties the CVSS 9.8 unauthenticated TeamCity RCE to insecure deserialization in the agent polling protocol — the build-agent-to-server channel. What that mechanism detail changes for your exposure check and interim mitigation.

31 Jul 2026
Diagram of a mobile core network showing session hijacking and denial-of-service risks in the 4G and 5G signaling core.

84 Flaws Found in 4G and 5G Core Networks, Including Live Session Hijacking

An NTU study disclosed a widespread class of 84 vulnerabilities in the signaling core of 4G and 5G networks — not the radio — including one that lets an attacker hijack a user's live session. The shared root cause is implicit trust between core network functions. Here is what operators should do.

31 Jul 2026
Flat white line-art of a chain of four npm package boxes linked to a single location pin, on a warm background — AWS North Korea axios npm attribution.

AWS Links the axios npm Hijack Chain to One North Korean Operator

One operator, four poisoned npm packages, over a billion combined weekly downloads. AWS's own report links axios, debug, chalk and typo-crypto to North Korea's Sapphire Sleet at medium confidence — and lays out how the group's tradecraft is shifting into the generative-AI era.

31 Jul 2026
The CyberSignal
  • Daily Briefing
  • Weekly Briefing
  • Corrections
  • Privacy Policy
Powered by Ghost