Trust under pressure: Best infosec long reads 8/8/26
Inside a multimillion-dollar phone scam, How a fringe censorship theory reshaped policy, When AI learns to replicate itself, Iran's fractured information ecosystem, The unfinished fight over digital privacy

Happy Saturday to all!
Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.
8/8/26: This week's long reads explore the forces reshaping digital trust—from AI systems that can autonomously replicate themselves and the legal battle over digital privacy, to the inside story of a multimillion-dollar phone-scamming enterprise, the information war surrounding Iran's media ecosystem, and the migration of once-fringe censorship narratives into US technology and national security policy.
The Phone Scammers Next Door
Toronto Life's Malcom Johnston delivers a gripping investigative feature that traces how a picture-perfect, upwardly mobile Canadian couple allegedly operated a multimillion-dollar phone-scamming enterprise built on spoofing technology, exposing both the industrialization of voice fraud and the painstaking international effort required to bring it down.
The trail of clues that would lead the RCMP to Mansouri and Alouah’s front door began in London, England, in 2021. The Cyber Defence Alliance, a non-profit group of investigators who work on behalf of member banks, kept hearing the term “iSpoof” in criminal chatrooms and other dark-web networks. Many CDA investigators are ex–law enforcement, but the organization differs from police in a crucial way: whereas police deal with known criminality, the CDA roams the digital plains, scanning the horizon for future threats. Its investigators dug into iSpoof and were startled by what they discovered. The URL iSpoof.cc listed no ownership or contact information and accepted payment only in cryptocurrency. The site gave customers access to a service that enabled them to alter their caller IDs and phone numbers, making it appear as if they were calling from a bank, an insurance provider, a government agency or wherever else they liked. It was like *67, the caller ID–blocking feature, but on steroids. The service featured a user-friendly digital dashboard with custom hold music, fake call-centre background noise, PIN-capture technology and a “spy” mode setting. It also promised complete encryption and anonymity. The server logs, iSpoof assured prospective clients, were deleted at the end of every day.
The site was blatant fraud, yet iSpoof blithely mimicked the tone of any legitimate consumer service website. A cheerful video guided new users through the “spoofing” process, and a PDF with cute illustrations detailed each step toward a successful con. “Flexibility and freedom: they’ll never know it was you!” it read. “You can pick any number you want before you call. Your opposite will be thinking you’re someone else. It’s easy and works on every phone worldwide!” Customers could choose from an array of packages. The cheapest, for a flat fee of $170, allowed for 150 minutes of “spoof time.” The platinum bundle, for $850 a month, offered 2,500 minutes.
Step one for an iSpoof customer was to purchase names and numbers through a “smishing” campaign—text-based phishing—or from a dark-web provider like Briansclub, which sells real consumer information acquired from corruptible employees at banks and government agencies. The best targets were the elderly, many of whom could be convinced of just about anything. Some lists highlighted targets who had been successfully scammed before and were considered soft marks worth trying again.
Through the iSpoof dashboard, the fraudster would enter the real banking information of a target and dial their number. When the target answered, an automated voice would identify the call as coming from the customer’s bank and read out the target’s real name, number and address followed by a list of fictitious transactions. “If this wasn’t you,” it would say, “press 2.” The iSpoof user guide boasted that this step—the target actively participating—worked wonders: “The reason this feature works well is because it gives the feel that the target is calling in themselves which immediately brings ease to the target.” The automated voice would then prompt the target to key in their confidential client PIN, the resulting entry appearing on the fraudster’s dashboard, digit by digit. The call was then transferred to the “next available customer service rep,” which was really the fraudster, who had been listening on spy mode the entire time.
By this point, the target was in a panic. They believed that their accounts had been hacked and their funds were at risk. They were also convinced that the call was legitimate: the caller ID and number matched that of the bank; the caller had the correct name and address; and the provided PIN was accepted. The target had nibbled; now it was up to the fraudster to set the hook.
This is where Mansouri worked his magic. Hopping on the line, he would cheerily introduce himself as one of the bank’s customer service representatives and reassure the target that he would address the problem. First, to complete the verification process, he needed a few more identifying details: date of birth, most recent transactions and the like. Simultaneously, on a second line, Mansouri would dial the bank, using iSpoof to make it seem like the call was coming from the customer, and claim that he was having trouble logging into his account. He already knew most of the necessary information, but when the bank asked for a detail he didn’t have, he’d place the bank on hold, switch to the target and ask for it. Within minutes, he’d have reset the password. He’d tell the target that the problem had been successfully resolved and end the call, then log in to the account and drain it.