The Fake Cell Tower in the Car Next to You
A false base station is a device that impersonates a mobile network's cell tower. Placed inside a car and driven around the streets, it convinces every phone within range that it is a genuine tower, so those phones connect to it. The operator can then push messages straight onto the handset.
The first question most people ask is whether they had to tap something wrong to be hit by this. The answer is that they had to do nothing at all.
"There is no button to consent to, because your phone is already choosing towers for you all day long."
The confusion comes from comparing this with WiFi. With WiFi you see a list of networks, you pick one yourself, you sometimes type a password, and you know what you are connected to. Mobile networks do not work that way. Your phone is constantly looking for towers belonging to your own operator and automatically latches onto whichever one has the best signal.
The system was designed this way from the start. Think of riding the Skytrain from Siam to Asok. Along the way your phone has to hand you from one tower to the next several times without you noticing a thing. If it asked for confirmation every time, you could not hold a phone call on the train.
Criminals exploit exactly this behaviour. They broadcast a signal stronger than the real tower nearby, so the phone chooses the fake one by itself. No window appears, no button is pressed, and the owner of the phone has done nothing wrong.
The next question is why the phone cannot tell that the tower is fake. The Canadian Centre for Cyber Security explains that the device broadcasts a stronger signal than the real tower to trick handsets into connecting, and once connected it forces the handset to downgrade to a 2G network, an older generation whose standards do not enforce authentication or encryption between the handset and the network.
Put simply, once the phone has been dragged down to 2G it has no way to check whether the tower it is attached to is genuine or counterfeit. That is why criminals have to get the handset onto 2G first, and only then send the message.
The consequence is that the attacker bypasses every protection and filter that mobile network operators put in place for their customers, so the links inside those messages are never analysed for legitimacy. This is what makes the device more dangerous than ordinary scam texting: the operator's filters cannot screen the message, because the message never reaches them.
Source: https://www.cyber.gc.ca/en/guidance/protect-your-devices-sms-blasters-itsap00104
Real Cases in Bangkok

In August 2025 Thai police arrested two Thai men with equipment in a car. Police described the kit as having four parts: a battery or portable power unit, a mobile tower simulator, a signal amplifier, and a mobile phone used to control the content of the messages.
The suspects said they were paid daily by a Chinese man who hired them for the work. Police stated that the device could send messages within a radius of 1 kilometre, and the suspects admitted driving around Bangkok broadcasting the signal, concentrating on the Sathorn, Rama 4, Sukhumvit and Phetchaburi areas, sending 20,000 messages a day.
Police laid six charges: jointly making, possessing, using, importing, exporting or trading transmitting equipment; jointly establishing a radio communication station; jointly using radio frequencies without authorisation; jointly attempting fraud; jointly intercepting signals; and jointly committing the offence of secret society membership.
Source: https://www.thaipbs.or.th/news/content/355225
The method is not new in Thailand. In May 2023 the authorities announced the dismantling of a gang that impersonated Kasikornbank to send scam SMS messages and drain accounts. Six offenders were arrested, along with four cars fitted with false base stations and five computer systems used to commit the offence.
The Equipment Is Illegal at the Border
The acting Secretary-General of the NBTC stated that telecommunications equipment of this type requires an import permit, and that in the case of false base stations the NBTC will categorically refuse permission to import, because it is treated as a serious danger to the public, in the same way as mobile signal jammers.
That means every device criminals are using is contraband brought in illegally, which requires vigilance from several agencies working together, the Customs Department in particular. In May 2023 the NBTC Office joined police officers in inspecting the sale of telecommunications equipment at MBK Center to prevent smuggled goods being sold there.
As for the offences, using this equipment breaches not only the Radiocommunications Act but also the law on fraud and the Computer Crime Act, which carry heavy criminal penalties.
Source: https://www.thairath.co.th/money/economics/thailand_econ/2697221
What Ordinary People Can Do
The Canadian Centre for Cyber Security gives four pieces of advice. The first is the one that strikes at the root: if your phone offers the option, turn off 2G network connections, because this attack has to drag the handset down to 2G first. If the handset never goes there, the attack cannot begin.
Second, use phishing-resistant multi-factor authentication, such as an authenticator app or a hardware security key, rather than receiving codes by SMS.
Third, do not click links or attachments in unsolicited messages. Fourth, if in doubt, contact the organisation through its own official channels, such as the number listed on its real website, rather than replying to the message.
What these cases teach in crime science terms is that when offenders meet one wall, they look for a way around it. As operators became better at filtering scam SMS, offenders began building their own towers so that no filtering would apply. Prevention therefore has to move upstream as well: intercepting the equipment at import, watching for abnormal signals from the operator side, and helping the public understand that a message arriving with a link may not have come from the network they pay for at all.
References
Canadian Centre for Cyber Security. (2026). Protect your devices from SMS blasters (ITSAP.00.104). https://www.cyber.gc.ca/en/guidance/protect-your-devices-sms-blasters-itsap00104
ไทยพีบีเอส. (2568, 10 สิงหาคม). รวบ 2 หนุ่มใช้เครื่องจำลองสถานีส่งสัญญาณ ส่ง SMS หลอกลวงประชาชน. https://www.thaipbs.or.th/news/content/355225
ไทยรัฐออนไลน์. (2566, 30 พฤษภาคม). กสทช. ยันไม่อนุญาตนำเข้าเครื่องจำลองสถานีฐานปลอมเด็ดขาด. https://www.thairath.co.th/money/economics/thailand_econ/2697221
Good knowledge should not stay in the library. It should be used to build a safer world.
Follow us at www.crimesci.com
Contact info@crimesci.com
#HubofKnowledge #CenterforCrimeScience #CrimeScienceWeekly
#วิทยาการอาชญากรรม #SMSBlaster #FalseBaseStation #อาชญากรรมออนไลน์







