Telstra's $277,000 SIM-swap penalty shows exactly how your phone number gets stolen — and what the law says telcos owe you


Telstra's $277,000 SIM-swap penalty shows exactly how your phone number gets stolen

Your phone number is the recovery key to a large part of your digital life: banking apps, email, myGov, the second-factor codes that stand between an attacker and everything else. When someone else takes control of your number, they don't need your password manager — they need your SMS. That's the entire business model of SIM-swap fraud, and in September 2026 the Australian Communications and Media Authority (ACMA) put a fresh, very concrete price on what happens when telcos fail to stop it.

ACMA announced that Telstra had paid a $277,200 penalty after an investigation found that between January and October 2025 the carrier failed to use required identity authentication processes in 15 unauthorised SIM swaps, and that in 13 instances its agents failed to provide additional fraud protections to customers who had raised concerns or who were already flagged as being at risk of fraud. Customers affected reported combined financial losses of at least $39,500. The ACMA also accepted court-enforceable undertakings from Telstra to strengthen its fraud prevention processes and retrain customer-facing staff. As Mediaweek's coverage of the penalty noted, this was the seventh enforcement action under the regulator's mobile number fraud crackdown, which has now extracted more than $5 million in penalties from the sector.

ACMA Authority Member Samantha Yorke's statement on the case is worth quoting because it identifies the failure mode precisely: "Telstra's frontline staff did not follow the provider's own processes, leaving customers vulnerable to SIM swap scams and other types of mobile fraud." Not missing rules the company didn't have — skipping the rules the company had. And her second point sets out the positive duty: "When a telco becomes aware that a customer is at risk of fraud involving their service, it must offer protections that are additional or tailored to the situation."

How a SIM swap actually happens

The mechanics are social, not technical. A scammer contacts your carrier — by phone, in a store, through a reseller — claiming to be you. They present personal details, often bought from a prior data breach: name, date of birth, address, sometimes a driver's licence number. They report a lost phone or a "faulty SIM" and request the number be moved to a SIM card in their possession. Once the swap completes, your phone shows "no service", and every SMS verification code your bank sends goes to the attacker.

Australian security coverage has documented this pattern for years. In the most infamous earlier case, Medion Australia — which sells SIMs under the AldiMobile brand — paid a $260,000 penalty after an ACMA investigation found it had failed to complete required verification on more than 1,600 SIM-swap requests; nine customers had services illegally ported and five of them collectively lost more than $160,000. The scale difference between that case and Telstra's — thousands of unverified requests versus fifteen — is itself instructive: the harm concentrates in the handful of swaps where the fraudster gets through, not the volume of sloppy process overall.

What the law actually requires of telcos

The obligations aren't discretionary. Since 2022, the Telecommunications Service Provider (Customer Identity Authentication) Determination — the CID Determination — has required telcos to conduct multi-factor identity authentication before high-risk customer requests: account changes, disclosure of personal information, and above all SIM swaps and number porting. The Australian Telecommunications Alliance's 2026 submission to Treasury describes the CID Determination as the key fraud-protection regulation governing service cancellation and account operations, and notes that carriers must sometimes use alternative verification mechanisms — which may not be online — to protect consumers from malicious third-party cancellation attempts.

The Telstra case adds a second, less well-known layer: the duty to offer additional or tailored protections once a carrier knows a customer is at risk. A customer who calls and says "someone is trying to take over my number" is supposed to be escalated, not processed through the ordinary queue. That's the part of the determination that 13 of Telstra's failures touched, and it's the part most consumers don't know to demand.

The exposure that matters most: your second factor

Here is the uncomfortable arithmetic. SIM-swap fraud only pays because so much of Australia's financial and government authentication still falls back on SMS codes. Every bank, fund, or government account you protect primarily with an SMS code is one telco process failure away from compromise — and the Telstra case proves those failures happen at the largest carrier, not just at budget resellers. The ACMA has noted that SIM-swap rules are "very effective" when followed, but effectiveness at the carrier's end is not a guarantee you get to rely on.

So shift what you control:

  1. Move every account you can off SMS-based verification. Authenticator apps (TOTP) and hardware security keys don't transit the phone network and can't be intercepted by a SIM swap. Where a service offers passkeys, use them.
  2. Add a port-out PIN or carrier-level lock. All major Australian carriers now offer a way to require extra verification before a number is ported or a SIM is replaced. Ask for it explicitly — "I want additional protections on my account" — because the Telstra case shows staff don't always volunteer it.
  3. Set up carrier account security itself with MFA, and treat the telco account email as seriously as your banking email.
  4. Know the tell. Sudden "no service" on your phone with full battery, in an area with coverage, means someone may have just taken your number. Call your carrier from another line immediately, then your bank. Minutes matter: the gap between swap and detection is where the transfers happen.
  5. Audit your recovery paths. An attacker with your number can trigger "forgot password" flows. Accounts that allow email-based recovery to an address protected only by SMS are chaining two SIM-swappable links together.

There are hardware complements worth considering, especially if you've already been targeted or you work with sensitive data. If your threat model includes someone intercepting what your phone broadcasts, a faraday phone pouch blocks the radio entirely when the phone is inside — useful for anyone who wants their device dark in meetings, at borders, or overnight. If you've moved accounts onto hardware keys or want to protect the physical card layer of your financial life, an RFID card wallet shields contactless cards from skimming, which pairs sensibly with the SIM-swap story: both attacks monetise the gap between what a piece of plastic broadcasts and what its owner realises.

Where the enforcement is heading

ACMA's mobile number fraud crackdown has been one of the more consistent enforcement programs in Australian communications regulation: seven actions, more than $5 million in penalties, and a clear pattern of following up earlier undertakings with monitoring — the Telstra investigation followed monitoring after a previous enforcement action against the same carrier involving the same rules. That last detail is the signal for the whole sector: undertakings are not closure; ACMA checks whether the fixes stuck. Combined with the CID Determination's multi-factor authentication requirements and the growing pressure from banks for carriers to share fraud telemetry, the direction of travel is unmistakable — identity verification at the telco layer is becoming a legally policed control, not a customer-service nicety.

For consumers, the practical takeaway is shorter than this article: move your second factors off the phone network, put a lock on your own number, and if your phone goes dark unexpectedly, treat it as an incident, not an outage.

This article is general information, not legal advice.


← All posts