'Hey mum, I dropped my phone down the toilet': Investigating Hi Mum and Dad SMS Scams in the United Kingdom

Sharad Agarwal (PhD candidate · UCL)

34th USENIX Security Symposium (USENIX Security '25) · Day 2 · Fraud, Malware, Spam

Overview

This talk, presented by Sharad Agarwal, a final-year PhD candidate at UCL, delves into the pervasive and financially devastating "Hi Mum, I dropped my phone down the toilet" SMS scams prevalent in the United Kingdom. Collaborating with Stop Scams UK, MDI Networks, and UCL, Agarwal’s research sheds light on a sophisticated form of online financial fraud that deviates from traditional SMS phishing. Instead of generic links or requests, these scams leverage emotional manipulation, with fraudsters posing as a child in distress, addressing recipients as "mom" or "dad," and fabricating urgent financial predicaments.

Watch on YouTube · Slides

Visual summary for 'Hey mum, I dropped my phone down the toilet': Investigating Hi Mum and Dad SMS Scams in the United Kingdom by Sharad Agarwal
Visual summary for 'Hey mum, I dropped my phone down the toilet': Investigating Hi Mum and Dad SMS Scams in the United Kingdom by Sharad Agarwal

Key moments

  1. 0:00 Introduction to Hi Mum/Dad SMS scams
  2. 1:45 Scammer interaction flow to request money
  3. 2:45 Overview of research methodology and data sources
  4. 3:45 Scammer preferences: platforms, targets, and excuses
  5. 6:00 Identifying scammer's psychological lures and deception tactics
  6. 7:50 Peak operational hours for Hi Mum/Dad scammers
  7. 9:00 Analysis of mobile network operators used by scammers

'Hey mum, I dropped my phone down the toilet': Investigating Hi Mum and Dad SMS Scams in the United Kingdom

Speakers: Sharad Agarwal, PhD Candidate, UCL

Conference: USENIX Security

YouTube: https://www.youtube.com/watch?v=XAgzRi4Y_40

Overview

This talk, presented by Sharad Agarwal, a final-year PhD candidate at UCL, delves into the pervasive and financially devastating "Hi Mum, I dropped my phone down the toilet" SMS scams prevalent in the United Kingdom. Collaborating with Stop Scams UK, MDI Networks, and UCL, Agarwal’s research sheds light on a sophisticated form of online financial fraud that deviates from traditional SMS phishing. Instead of generic links or requests, these scams leverage emotional manipulation, with fraudsters posing as a child in distress, addressing recipients as "mom" or "dad," and fabricating urgent financial predicaments.

The significance of this research lies in its comprehensive, multi-faceted approach to understanding the entire lifecycle of these scams—from initial contact to money transfer. By engaging directly with scammers, analyzing mobile network data, and scrutinizing financial transactions, the study uncovers critical operational patterns, preferred communication channels, the longevity of scammer infrastructure, and the financial institutions most exploited. This granular insight is crucial for developing targeted defensive strategies, informing public awareness campaigns, and shaping policy to combat this evolving threat.

The article explores the mechanics of these interaction scams, the social engineering tactics employed, and the infrastructure supporting them. It provides a detailed breakdown of the research methodology, key findings regarding scammer behavior and financial flows, and actionable defensive implications for individuals, mobile network operators, financial institutions, and law enforcement agencies. Ultimately, this work offers a vital contribution to the fight against online financial fraud, demonstrating how academic research can directly inform and influence real-world security measures.

Background

▶ Watch: Introduction to Hi Mum/Dad SMS scams (0:00)

The landscape of online financial fraud has seen a significant shift beyond rudimentary phishing attempts. Historically, SMS phishing (smishing) often involved sending malicious links or impersonating legitimate organizations to trick users into revealing credentials. However, the "Hi Mum, I dropped my phone down the toilet" scam represents an evolution into interaction scams, where the fraudster engages in a conversational exchange designed to exploit emotional bonds and a sense of urgency. This particular variant preys on the innate parental instinct to help a child in distress, making it particularly potent and difficult for victims to identify as fraudulent in the initial stages.

The problem's existence is rooted in a blend of human psychology and the relative anonymity offered by modern communication technologies. Scammers exploit the immediate concern a parent would feel upon receiving a message from their "child" using an unfamiliar number, often with a plausible (albeit fabricated) explanation like a broken or lost phone. This creates a cognitive bypass, where the emotional response overrides critical thinking and verification steps. The ultimate goal of these scams is to coerce victims into making direct financial payments to accounts controlled by the scammers, often facilitated by money mules.

Money mules are individuals or entities that receive stolen money from victims and forward it to scammers. These mules can be either witting, meaning they are fully complicit in the fraudulent scheme, or unwitting, unaware that they are participating in illegal money laundering activities. The use of money mules adds a layer of obfuscation, making it harder for law enforcement to trace funds directly back to the primary orchestrators of the scam. Prior work, such as that by Stanau and Wilson on understanding scam victims, has categorized various scam lures. This research builds upon such frameworks by specifically identifying which lures are most effective in the context of "Hi Mum, Dad" scams, providing crucial context for understanding why these scams succeed. The reliance on emotional manipulation, combined with the logistical challenge of identifying and tracking transient mobile numbers and bank accounts, underscores the complex nature of this pervasive financial threat.

Key Findings

▶ Watch: Overview of research methodology and data sources (2:45)

The research presented by Sharad Agarwal unveiled a multitude of critical insights into the operational mechanics and impact of "Hi Mum, Dad" SMS scams. The study's robust methodology involved analyzing a substantial dataset: 3,420 initial scam texts leading to 711 engaged scammer conversations. This engagement allowed researchers to collect data on 1,184 scammer mobile numbers, 486 originating sender ID numbers, and crucially, 582 unique suspect mule accounts.

Analysis of the initial scam texts revealed several strategic preferences by the scammers. They predominantly favored online encrypted messaging platforms like WhatsApp, as indicated by a word cloud analysis. The targeted individuals were explicitly addressed as "mom" or "dad," with a notable preference for female targets over male targets, suggesting an exploitation of perceived maternal instincts. Common reasons provided for contacting from a new number included familiar scenarios such as "phone dropped," "smashed," or "fell down the toilet," designed to evoke immediate empathy and urgency.

The interaction success rates with scammers showed only slight variations across different mediums and identities, although pretending to be "mom" yielded a marginally higher response rate. Further en-gram analysis (unigram and bi-gram) of scammer responses uncovered a clear, three-stage conversational progression:

  1. First Response: Scammers primarily expressed emotions like stress and provided distracting reasons for their new number (e.g., lost phone, locked account).
  2. Second Response: They continued to leverage emotional appeals while subtly shifting the conversation towards financial difficulties, mentioning inability to access banking and outstanding bills.
  3. Third Response: Emotional language largely ceased, and the conversation became purely financial, focusing on how money could be paid and offering reassurances of repayment.

The study confirmed that scammers predominantly utilized three specific scam lures identified in existing literature: Distraction lure (confusing victims with unrelated details), the Kindness principle (leveraging victims' willingness to help), and the Time or urgency lure (pressurizing victims into irrational, quick decisions). These lures were strategically deployed to manipulate victims effectively.

Regarding scammer activity patterns, the research identified a clear operational window: most scammers were active between 10:00 AM and 3:00 PM UK time on weekdays. While some messages were received over weekends, active engagement ceased during these periods.

Mobile network analysis, utilizing HLR lookup results, provided insights into the infrastructure. The M1 mobile virtual network operator (MVNO) was identified as the most abused network. Survival analysis revealed significant differences in the median lifetime of numbers: originating sender IDs had a median lifetime of just 14 days, while scammer mobile numbers remained active for a median of 46 days, indicating a more sustained use of the latter.

Financially, the requested transaction amounts were substantial, totaling over £577,000 from 270 unique scammer mobile numbers. These requests led to 582 unique suspect mule accounts across more than 30 financial institutions. A comparison between SMS and online messaging showed slightly higher requested amounts via encrypted online platforms. Categorization of these mule accounts, guided by the Financial Conduct Authority (FCA) handbook, highlighted that Electronic Money Institutions (EMIs) and High Street Banks were the most abused types of financial institutions. Scammers demonstrated an awareness of detection thresholds, with EMIs having only eight requests above £2500 compared to 29 requests above £2500 for High Street Banks, suggesting an effort to evade transaction monitoring alerts.

Geographical analysis of High Street Bank mule accounts, overlaid with UK Office for National Statistics data, revealed a correlation between the location of these mules and areas of higher unemployment rates and population density. This finding offers a valuable insight for targeted public awareness campaigns. Finally, the study identified six communities of four or more scammer mobile numbers and three additional communities where just two or three numbers collectively requested over £10,000, demonstrating that significant financial impact can be achieved even with smaller, coordinated groups. One enlarged group (Group 1) involved eight phone numbers providing 31 mule accounts across eight financial institutions, requesting over £41,000. These findings were directly submitted to Ofcom and impacted new legislation in Spain to tackle SMS scams, underscoring the real-world relevance of the research.

Technical Deep Dive

▶ Watch: Scammer preferences: platforms, targets, and excuses (3:45)

The technical rigor of this research stemmed from its multi-pronged analytical approach, combining textual, mobile network, and financial data analysis to construct a holistic view of the "Hi Mum, Dad" scam ecosystem.

The data collection methodology was a cornerstone of the study. Researchers collaborated with Stop Scams UK and a major UK mobile network operator to access real-world initial scam texts. Subsequently, they systematically engaged with scammers using ten different mobile numbers, pretending to be "mom" (or "dad," or unlabeled) to observe and record scammer interaction success rates and conversational patterns. This active engagement allowed for the collection of rich, first-hand data on scammer responses, preferred communication channels (SMS vs. online messaging), and crucially, the suspect mule account details provided by the scammers.

Textual analysis was performed on the engaged scammer conversations. This involved en-gram analysis, specifically unigram (single-word frequency) and bi-gram (two-word sequence frequency) analysis. Unigram analysis of the first scammer responses highlighted the prevalence of emotional words and phrases related to distress and phone issues ("lost," "stressed," "locked"). As conversations progressed, bi-gram analysis helped track the shift in scammer language, demonstrating the transition from emotional manipulation to direct financial requests. This method provided quantitative evidence for the three-stage conversational flow identified, confirming the strategic deployment of the Distraction, Kindness, and Time/Urgency lures.

For mobile network analysis, the researchers employed Home Location Register (HLR) lookup services. An HLR lookup is a critical telecommunications tool that queries a database containing subscriber information. For a given mobile number, it can determine:

  • Its validity and current availability status.
  • The actual network operator it is currently registered on.
  • Whether the number has been ported from its original network to another.
  • If the number is currently roaming outside its home network.

This information allowed the categorization of numbers into physical operators (issuing physical SIM cards), Mobile Virtual Network Operators (MVNOs) (issuing SIMs but running on another physical operator's infrastructure), and virtual numbers (service-based, no physical SIM). The identification of M1 as the most abused MVNO was a direct result of this detailed analysis.

Furthermore, survival analysis was applied to the mobile number data. This statistical technique, commonly used in fields like medicine and engineering, was adapted here to model the "lifetime" of scammer-controlled numbers. It helps determine the probability of a number remaining active over time and calculates metrics like median lifetime. The finding that originating sender IDs had a median lifetime of 14 days compared to 46 days for scammer mobile numbers highlights the transient nature of initial contact points versus the more sustained operational infrastructure.

The financial analysis involved categorizing the collected suspect mule accounts. Using the Financial Conduct Authority (FCA) handbook, financial institutions were classified into types such as Electronic Money Institutions (EMIs), High Street Banks, Authorized Payment Institutions (APIs), and Small Electronic Money Institutions (SEIs). This allowed for a comparative analysis of how different institutional types were exploited. The distribution of requested amounts was meticulously examined, particularly the observation that EMIs received fewer requests above £2500 than High Street Banks. This suggests a calculated strategy by scammers to keep transaction values below thresholds that might trigger automated fraud detection systems at EMIs, which often have different risk appetites and monitoring capabilities compared to larger High Street Banks.

Finally, geographical analysis involved mapping the postcodes associated with physically branched High Street Bank mule accounts. This data was then overlaid with publicly available UK Office for National Statistics (ONS) data on population density and unemployment rates for individuals aged 16 and above. The observed correlation between mule account locations and areas of higher unemployment and population density provides a socio-economic dimension to the scam, suggesting potential recruitment grounds for unwitting money mules or areas where individuals are more susceptible to becoming mules. The creation of network diagrams further elucidated the connections between scammer mobile numbers and the mule accounts they provided, revealing "communities" of scammers and the collective financial impact of these groups. This systematic technical approach provided the empirical evidence necessary to dissect the scam's operation and inform robust countermeasures.

Demo / Proof of Concept

▶ Watch: Peak operational hours for Hi Mum/Dad scammers (7:50)

While the talk did not feature a traditional software or tool demonstration, the core of the research inherently involved a systematic proof of concept for the scam's operational effectiveness and the researchers' ability to intercept and analyze its flow. The entire research methodology, particularly the active engagement with scammers, served as a live demonstration of how these scams unfold and how their components can be observed and collected.

The researchers effectively "simulated" the victim experience by using 10 different mobile numbers to respond to initial scam texts. They adopted personas, specifically pretending to be "mom" (or "dad," or an unlabeled contact), to initiate and sustain conversations with the scammers. This process was a controlled experiment to understand the scam's progression: from the initial emotional plea ("lost my phone") to the gradual shift towards financial requests ("need to pay a bill") and ultimately, the provision of suspect mule account details. By meticulously recording these interactions, the researchers demonstrated the scam's step-by-step social engineering process and its reliance on specific lures like distraction, kindness, and urgency.

This active engagement allowed the team to collect vital, real-world data that would otherwise be inaccessible, including the specific mobile numbers used by scammers, the financial institutions they exploited, and the exact amounts requested. The success rates of these interactions, where scammers consistently responded and provided financial details, served as a stark demonstration of the scam's persuasive power and the relative ease with which fraudsters can elicit payment information. Thus, the research itself, through its direct interaction and data collection strategy, functioned as a powerful, albeit ethical, "proof of concept" detailing the live operation of these sophisticated social engineering attacks.

Defensive Implications

▶ Watch: Analysis of mobile network operators used by scammers (9:00)

The detailed insights uncovered by this research offer critical implications for various stakeholders involved in combating financial fraud. Effective defense against "Hi Mum, Dad" scams requires a multi-faceted approach, addressing vulnerabilities at the individual, telecommunications, financial, and policy levels.

For Individuals:

  • Enhanced Awareness and Verification: The most crucial defense is public education. Individuals, especially parents, must be made aware of the specific lures used (distraction, kindness, urgency) and the common narrative elements (lost phone, new number, urgent bill). The primary takeaway should be to always verify the identity of the sender through a known, trusted contact method (e.g., calling the child on their original number or a family member). Never rely solely on the new number provided by the suspicious text.
  • Recognizing Scammer Progression: Understanding the three-stage conversational flow (emotions, shift to finance, direct financial request) can help potential victims identify a scam before monetary loss occurs. The sudden cessation of emotional language and immediate focus on payment should be a red flag.

For Mobile Network Operators (MNOs) and MVNOs:

  • Proactive Monitoring and Disruption: Given that M1 MVNO was identified as highly abused, MNOs need to enhance monitoring of their MVNO partners for suspicious number acquisition and usage patterns.
  • Leveraging HLR Lookup: MNOs should utilize HLR lookup results more effectively to identify and flag transient or unusual number activity. Numbers with very short median lifespans, especially originating sender IDs (median 14 days), should trigger automated alerts for potential scam activity.
  • Faster Number Deactivation: The longer median lifetime of scammer mobile numbers (46 days) compared to sender IDs indicates a window of opportunity for disruption. MNOs need faster mechanisms to identify and deactivate numbers reported or detected as being involved in scams, limiting their operational lifespan.
  • Collaboration with Law Enforcement: MNOs must improve data sharing and collaboration with law enforcement agencies to track and shut down scammer infrastructure more efficiently.

For Financial Institutions (FIs):

  • Enhanced Transaction Monitoring: FIs, particularly Electronic Money Institutions (EMIs) and High Street Banks, must refine their fraud detection systems. The finding that scammers keep EMI transaction requests below £2500 to evade detection highlights a specific vulnerability. Monitoring systems need to be more sensitive to patterns of smaller, frequent transactions, especially from newly opened accounts or accounts linked to suspicious mobile numbers.
  • Improved Mule Account Detection: FIs need to invest in more sophisticated algorithms and data analytics to identify and freeze money mule accounts faster. This includes analyzing account activity, source of funds, destination of funds, and geographical patterns (as correlated with unemployment rates).
  • Customer Education: Banks should actively educate their customers about these scams, including how to verify requests and the risks associated with acting as a money mule, wittingly or unwittingly.
  • Cross-Institutional Collaboration: FIs should improve information sharing regarding identified mule accounts and scammer tactics to create a more robust, collective defense.

For Law Enforcement and Policy Makers:

  • Targeted Awareness Campaigns: The geographical correlation of mule accounts with areas of high unemployment and population density provides a clear target for localized public awareness and anti-mule recruitment campaigns.
  • Legislative and Regulatory Action: The research's impact on Ofcom consultations and new legislation in Spain demonstrates the power of data-driven policy. Regulators should consider mandating stricter identity verification for new mobile numbers and financial accounts, particularly for MVNOs and EMIs, to make it harder for scammers to acquire and use infrastructure.
  • International Cooperation: Since scams often originate from outside the UK, international collaboration between law enforcement agencies is crucial for disrupting cross-border criminal networks.

By implementing these defensive strategies, individuals can be better protected, and the operational environment for "Hi Mum, Dad" scammers can become significantly more hostile, ultimately reducing their success rate and financial impact.

Key Takeaways

  • Emotional Exploitation is Key: "Hi Mum, Dad" scams are sophisticated social engineering attacks that leverage emotional manipulation (distraction, kindness, urgency) by impersonating a child in distress to elicit urgent financial transfers.
  • Structured Scammer Interaction: Scammers follow a predictable three-stage conversational flow: initial emotional distress, a gradual shift to financial problems, and then a direct request for funds, often reassuring victims of repayment.
  • Transient but Persistent Infrastructure: While originating sender IDs are highly transient (median 14 days), scammer mobile numbers have a longer operational life (median 46 days), indicating a more stable, albeit still disposable, infrastructure. M1 MVNO was identified as the most abused network.
  • Mule Accounts are Critical and Detectable: Scammers heavily rely on money mules across various financial institutions, particularly Electronic Money Institutions (EMIs) and High Street Banks. Scammers often tailor transaction amounts (e.g., below £2500 for EMIs) to evade fraud detection systems.
  • Geographical and Network Patterns Exist: Mule accounts show geographical correlations with areas of higher unemployment and population density, and scammers operate in identifiable networks, even small ones, capable of significant financial impact.
  • Multi-Sectoral Defense is Essential: Combating these scams requires coordinated efforts from individuals (awareness, verification), MNOs (monitoring, faster deactivation), financial institutions (enhanced transaction monitoring, mule detection), and law enforcement/policy makers (targeted campaigns, legislative action).

About the Speaker(s)

Sharad Agarwal is a final-year PhD candidate at UCL (University College London), where his research is focused on the critical area of online financial fraud. His work on "Hi Mum, I dropped my phone down the toilet" SMS scams in the United Kingdom was conducted in collaboration with colleagues from Stop Scams UK, MDI Networks, and UCL, demonstrating a strong interdisciplinary approach to tackling real-world security challenges. His academic background and ongoing doctoral research position him as an emerging expert in understanding and combating contemporary forms of digital financial deception.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent, methodologically grounded academic work on a financially damaging but technically shallow threat. The empirical rigor — live scammer engagement, HLR analysis, survival analysis on number lifetimes, FCA-categorized mule account mapping — elevates this above a typical awareness talk, but the attack surface here is human psychology and payment rails, not systems. The findings are useful for fraud teams and telecom operators; they won't move the needle for most security researchers.

Heather Calloway (CISO) — SOLID

Rigorous academic work on a real and growing fraud vector, with genuine policy impact and usable findings for financial institutions and telecom operators. The research is credible and the methodology is sound, but the talk never quite crosses from 'interesting study' to 'here is what your organization must change and why.'

→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)

All talks from 34th USENIX Security Symposium (USENIX Security '25)