The conviction of Ramzan Abubakarov exposed more than an individual fraudster operating through a messaging application. It revealed a digital supply chain in which stolen personal data, phishing tools, mobile numbers, criminal services and practical fraud guidance could be packaged, advertised and distributed to other offenders.
Abubakarov, from Hendon in north London, was sentenced to three years’ imprisonment at Croydon Crown Court in February 2023. He had been convicted of ten offences involving fraud by false representation, supplying articles for use in fraud and possessing articles intended for fraudulent activity.
Investigators attributed more than £1.9 million in victim losses to his activities. Devices seized from his home contained compromised personal and financial information relating to more than 30,000 people, customised phishing kits targeting financial institutions and a database of more than one million UK and international mobile telephone numbers.
For a FinCrime audience, the significance of the case lies in the operating model. Telegram was not merely used to communicate privately. It functioned as a distribution, marketing and networking layer connecting technical capability with criminals seeking ready-made tools, data and guidance.
The case anticipated a wider development now visible across cyber-enabled financial crime: specialist suppliers are industrialising fraud by lowering the technical barrier to entry and allowing less capable offenders to purchase the components of an attack as a service.
Key Takeaways
- Telegram Can Be Used as a Scalable Fraud Coordination Channel
- Investment Scams Often Begin Through Social Media Advertising
- Fraudsters Exploit Interest in Gold, Oil and Foreign Exchange Investments
- Fake Investment Accounts Can Create the Appearance of Legitimate Trading
- Fabricated Certificates and Bank Statements Can Reinforce Victim Trust
- Professional-Looking Documentation Does Not Prove Genuine Investment Activity
- Encrypted Messaging Can Help Criminals Move Victims Away From Visible Platforms
- Multiple Bank Accounts and Aliases Can Support Fraud Proceeds Laundering
- Investment Fraud Can Generate Multi-Million-Pound Losses
- Fraud and Money Laundering Frequently Operate as a Single Criminal Process
- Social Media, Messaging Apps and Banking Channels Form One Fraud Journey
- Law Enforcement Financial Analysis Can Expose Hidden Account Networks
- Fraud Detection Must Look Beyond the Initial Customer Payment
- Criminal Proceeds Recovery Is an Important Part of Fraud Disruption
Listen the podcast
Watch the video
Why Telegram matters to the fraud ecosystem
Telegram is a legitimate communications platform used by individuals, businesses, media organisations and public bodies. The use of the application is not itself evidence of criminality.
However, several features that support legitimate communities can also be attractive to offenders. Public channels can broadcast content to very large audiences, usernames can be used without publicly exposing a telephone number, links can be shared outside the application and bots can automate interactions or distribute information.
Criminal actors can use these functions to advertise stolen credentials, phishing kits, account-access services, counterfeit documents, money-mule opportunities and tutorials explaining how to exploit financial systems.
The National Crime Agency’s 2026 strategic assessment identified the audience reach, accessibility and perceived anonymity of popular communication platforms as important criminal enablers. It specifically noted that advertisements for fraud-enabling products are increasingly being identified on Telegram channels.
This reflects a wider migration from specialist dark-web forums toward accessible clear-web platforms. A new offender no longer needs advanced technical knowledge, knowledge of hidden services or an invitation to a closed criminal forum. A link shared through social media can lead directly to a channel offering tools, data and technical support.
The Abubakarov operation
Abubakarov operated under multiple online identities and used a Telegram channel to coordinate activity and communicate with thousands of other cybercriminals. At one stage, investigators described it as one of the largest Telegram channels targeting a British criminal audience.
The channel was used to advertise tools, display evidence of successful offending and promote access to compromised data. Abubakarov reportedly showcased victim lists and publicised his involvement in fraudulent government-backed loan applications, false tax-refund claims and unauthorised access to personal bank accounts.
This visibility served a commercial purpose. Criminal marketplaces depend on trust, even where every participant is acting illegally. Prospective buyers need to believe that stolen credentials are current, phishing pages work and the seller will provide the promised service.
Screenshots, victim lists, transaction evidence and claims of successful fraud operate as criminal marketing material. They create reputation, attract buyers and distinguish one supplier from competitors.
The Telegram channel therefore performed several functions simultaneously: storefront, customer-support desk, advertising service, professional network and status platform.
iChop and the market for compromised data
Abubakarov was also responsible for creating iChop.it, a web service through which cybercriminals could buy and sell compromised personal and financial information.
The value of such a service extends beyond the direct sale of card or banking details. A complete victim profile may include a name, address, date of birth, telephone number, email address, account information and security data.
Different offenders can reuse those records for different crimes. One buyer may attempt account takeover. Another may apply for credit or government support using a stolen identity. A third may use the information to make an impersonation call more convincing.
Data can also be combined. Credentials from one breach may be matched with telephone numbers from another dataset and financial information obtained through phishing. Each additional attribute increases the credibility and potential value of the resulting victim profile.
The discovery of more than one million mobile numbers illustrates the importance of scale. Even where only a small proportion of recipients respond to a phishing message or fraudulent call, mass targeting can produce substantial returns.
The underlying asset is not only the stolen data. It is the ability to organise, search, segment and distribute that data to other criminals.
Phishing kits as crime-as-a-service
A phishing kit is a prepared collection of webpages, scripts and instructions designed to imitate a legitimate organisation and capture information entered by victims.
Instead of building a fraudulent banking website from the beginning, an offender can purchase a ready-made package, deploy it on a domain and begin distributing links. More advanced kits may include administrative panels, real-time notifications, victim-management tools and mechanisms for capturing authentication codes.
The supplier may provide updates when a bank changes its website, troubleshoot installation problems and modify the kit to target another institution. This turns phishing into a service relationship rather than a one-time software sale.
The Abubakarov case is an early example of this commercialisation. Investigators recovered customised kits designed to imitate UK and international financial institutions.
The model has continued to develop. In 2025, a separate UK offender was sentenced to seven years after creating and supplying more than 1,000 phishing kits targeting dozens of institutions across multiple countries. Those kits were distributed through Telegram, where the supplier also provided advice, maintenance and technical support.
The important FinCrime lesson is that the person who steals the money may be several steps removed from the person who created the infrastructure. One actor develops the phishing page, another supplies victim data, another distributes messages, another conducts social-engineering calls and a separate network receives and launders the proceeds.
From stolen data to account compromise
A successful phishing page does not automatically create a financial loss. The captured information must be converted into account access, fraudulent credit, an unauthorised card transaction or a manipulated payment.
Stolen credentials may be tested against online banking, email, retail and payment accounts. Where a victim has reused passwords, access to one service can enable compromise elsewhere.
Email accounts are particularly valuable because they may contain financial correspondence and provide a route for resetting other passwords. An attacker who controls the victim’s email may suppress security notifications, collect account statements and identify organisations with which the victim has an existing relationship.
Criminals can then use the stolen data in live social-engineering attacks. A caller who knows the victim’s name, bank, address and recent account information can appear far more credible than an unknown fraudster making a generic approach.
The data marketplace, phishing operation and impersonation scam are therefore not separate threats. They form stages within the same criminal value chain.
Exploiting public financial support
Abubakarov also advertised involvement in fraudulent applications under the UK’s Bounce Back Loan Scheme and in false tax-return claims.
Public support programmes are attractive to organised fraud because they often need to distribute funds rapidly, process high application volumes and rely on information supplied electronically.
Criminals can use stolen or synthetic identities, dormant companies, false trading records and recruited account holders to submit applications. Fraud-enabling marketplaces support this activity by providing identity records, company information, forged documents and instructions for navigating application processes.
Once funds are released, they can be transferred through business and personal accounts, withdrawn as cash, spent on assets or moved through cryptoassets.
The case demonstrates why cybercrime, fraud and money laundering cannot be investigated in isolation. The phishing kit captures the identity, the false application monetises it and the mule network obscures the proceeds.
Telegram is an enabler, not the complete offence
Descriptions of Telegram as an “encrypted platform” require precision. Telegram’s Secret Chats use end-to-end encryption, but ordinary cloud chats, groups and channels use client-to-server and server-to-client encryption rather than end-to-end encryption by default.
The criminal value of the platform is not limited to encryption. Reach, persistent channels, public links, file sharing, usernames, automation and the ability to rebuild audiences all contribute to its attractiveness.
The distinction matters because platform risk should be assessed through functionality and behaviour rather than simplified labels. Criminals may use public channels for advertising, private groups for customer support, external websites for transactions and cryptocurrency for settlement.
Removing one channel may interrupt activity without dismantling the wider network. Administrators can create replacement channels, direct users to alternative accounts or migrate audiences to another platform.
Effective disruption must therefore target the identities, payment routes, domains, devices and criminal relationships supporting the channel—not only the visible content.
Following the cryptocurrency trail
The investigation began after the Cyber Defence Alliance identified Abubakarov in November 2020 and passed intelligence to the Metropolitan Police’s cybercrime team.
Investigators used cryptocurrency tracing, communications-data analysis and cooperation with banks and HM Revenue and Customs to identify and build the case against him. He was arrested in November 2021, after which laptops and mobile devices were seized for forensic examination.
This investigative approach is important because online aliases can create separation between a physical person and a digital criminal identity. Cryptocurrency is also frequently used to pay for illicit services because it can move internationally without relying on traditional card acquiring.
Cryptoassets are not inherently anonymous. Transactions recorded on public blockchains can provide a durable history of movement between addresses. When those records are combined with exchange information, seized devices, communications and banking data, investigators may be able to connect online activity to identifiable individuals.
The Abubakarov investigation demonstrates the value of combining private-sector intelligence with financial and digital evidence. No participant held the full picture independently. The case emerged through collaboration between banks, the Cyber Defence Alliance, police and HMRC.
The laundering infrastructure behind platform-enabled fraud
Selling a phishing kit or stolen dataset is only one source of criminal revenue. The larger financial harm occurs when those tools are used to take money from victims or obtain fraudulent loans and refunds.
The proceeds must then be received and moved. Criminals may use accounts held by recruited money mules, businesses under their control, compromised customers or synthetic identities.
Funds can be dispersed across multiple accounts, withdrawn through cash machines, spent through payment cards or converted into cryptoassets. Rapid movement makes recovery more difficult and separates the organiser from the original offence.
Financial institutions should therefore look beyond the victim’s compromised account. Recipient-side analysis can reveal clusters of accounts receiving payments from unrelated people, rapid pass-through behaviour, common devices, shared addresses and links to cryptocurrency services.
A Telegram channel may facilitate the initial criminal relationship, but the banking system remains a critical conversion point between stolen information and usable proceeds.
What a resilient control stack looks like
Financial institutions need controls that connect cyber intelligence, fraud monitoring and AML investigation.
Phishing intelligence should feed into account-protection systems. Where credentials associated with a customer appear in a recovered dataset, the institution may need to reset access, revoke sessions or apply enhanced authentication.
Device and behavioural analytics can identify account access inconsistent with the customer’s normal profile. Relevant signals include new devices, unusual locations, automated navigation, rapid credential testing and changes to contact details followed by payments.
Recipient-account monitoring should identify mule behaviour, including sudden inflows from multiple unrelated parties, rapid onward transfers and activity inconsistent with the stated purpose of the account.
Institutions should also monitor criminal-market intelligence for references to their brands, phishing templates and compromised customer data. That intelligence becomes more valuable when it is linked to domain takedowns, customer protection and active transaction controls.
Investigators require clear escalation routes between cybersecurity, fraud, AML, legal and law-enforcement liaison teams. A phishing kit targeting a bank is simultaneously a brand-abuse incident, a cyber threat, a fraud precursor and a potential source of laundering risk.
What platforms and authorities need to disrupt
Messaging and social-media platforms can reduce harm through proactive detection of channels advertising stolen data, phishing tools and criminal services.
Useful signals may include repeated sharing of known malicious domains, payment addresses linked to illicit markets, migration between previously removed channels and the mass distribution of credential-harvesting files.
Platform action must be supported by information sharing. Banks may recognise the impersonated brand, hosting companies may hold domain-registration data, cryptoasset providers may identify payment flows and law enforcement may connect administrators to wider organised-crime investigations.
Takedowns should also be designed around resilience. Removing visible content without preserving evidence or identifying administrators may simply displace activity.
The objective should be to disrupt the criminal business model: its reputation, customer base, payment channels, infrastructure and ability to reconstitute.

What this means for financial crime leaders
The Abubakarov case was not simply an example of a fraudster using Telegram. It was an example of fraud becoming organised as a digital marketplace.
The operation brought together stolen data, phishing software, criminal advertising, technical support and access to other offenders. It allowed specialised capability to be reused across bank-account compromise, false tax claims and government-loan fraud.
That model has become increasingly relevant. UK payment providers reported almost £1.3 billion in fraud losses during 2025, while two-thirds of authorised push payment cases originated online. Criminal platforms and channels form part of the infrastructure that makes such activity scalable.
For FinCrime leaders, the strategic implication is clear. Fraud prevention cannot focus exclusively on the final transaction. Institutions must understand the upstream ecosystem in which victim data is acquired, tools are developed, services are marketed and offenders are recruited.
The strongest response combines criminal-market intelligence, brand monitoring, customer protection, device analytics, mule-account detection and financial investigation.
A messaging channel may look like the edge of the financial system, but it can function as the commercial centre of a fraud network. Disrupting that network requires institutions to follow the full chain—from the advertised phishing kit and stolen identity to the compromised account, criminal payment and laundering destination.
What Financial Institutions Should Consider
- Strengthen Investment Scam Detection
- Monitor Payments to Unregulated Investment Recipients
- Identify Customers Making Repeated Payments Following Social Media Contact
- Detect Payments to Personal Accounts Presented as Investment Businesses
- Monitor Sudden Transfers for Gold, Forex and Commodity Investments
- Apply Behavioural Analytics to Unusual Investment Activity
- Strengthen New-Beneficiary Risk Controls
- Detect Multiple Victims Paying Common Beneficiaries
- Identify Rapid Movement of Scam Proceeds
- Strengthen Money Mule and Recipient-Account Detection
- Apply Network Analytics Across Connected Accounts
- Monitor Accounts Operating Under Multiple Identities or Aliases
- Integrate Fraud and AML Intelligence
- Capture Telegram and Other Messaging Platforms as Scam Origination Channels
- Conduct Retrospective Reviews Following Confirmed Investment Fraud
- Strengthen Rapid Freezing and Recovery Processes
- Share Fraud Intelligence Across Financial Institutions
- Treat Investment Fraud Proceeds as Potential Money Laundering Activity




The Abubakarov case demonstrates that Telegram was not simply a communications tool used by an individual fraudster. It became part of a wider commercial infrastructure through which stolen data, phishing software, technical guidance and access to other criminals could be marketed and distributed at scale.
This operating model lowers the barrier to entry for fraud. Offenders no longer need to develop every capability themselves. They can purchase victim data, deploy ready-made phishing kits, recruit money mules and obtain support from specialist suppliers operating across interconnected platforms and marketplaces.
For financial institutions, the case shows why controls cannot focus only on the final fraudulent transaction. Effective prevention requires intelligence on criminal marketplaces, compromised credentials, malicious domains, suspicious devices and recipient accounts used to receive and launder the proceeds.
Ultimately, disrupting platform-enabled fraud means targeting the entire supply chain—from the seller of stolen identities and phishing tools to the compromised account, mule network and laundering destination. Fraud becomes industrialised when specialist criminal services are allowed to connect; financial-crime defences must become equally integrated.