Thirteen Telstra customers lost more than $39,500 to fraud after the telco failed to act on warnings that they were at risk, prompting the regulator to hit the company with a $277,200 penalty.
The customers fell victim to unauthorised SIM swaps between January and October last year, with an Australian Communications and Media Authority (ACMA) investigation finding Telstra staff repeatedly failed to follow basic identity checks designed to stop criminals taking over mobile numbers.
In some cases, customers had already warned Telstra they were being targeted.
The telco nevertheless failed to put additional protections in place, leaving victims exposed to what ACMA described as “real harm” after fraudsters gained control of their services.
The regulator found 28 breaches of Australia’s mandatory customer authentication rules, including failures to use multi-factor authentication, verify dates of birth and make required outbound calls to numbers already associated with customer accounts.
In two cases, the failures went further. An “unknown actor” used social engineering to create a fraudulent duplicate customer account, then supplied their own details to pass Telstra’s multi-factor authentication process and make unauthorised changes.
ACMA identified 28 contraventions of section 101(1) of the Telecommunications Act 1997, which requires telcos to comply with mandatory customer authentication rules.
“In this case, Telstra’s frontline staff did not follow the provider’s own processes, leaving customers vulnerable to SIM swap scams and other types of mobile fraud,” ACMA member Samantha Yorke said.
Even after customers reported that they were being targeted, Telstra failed to provide adequate protections, she said, leaving them “exposed… to real harm” after they fell victim to fraud.
Telstra has been here before
The latest penalty is the seventh enforcement action by ACMA against a telco over failures to follow mandatory identity authentication rules during SIM swaps and password resets.
It is also Telstra’s second penalty for the same type of failure.
In 2024, ACMA fined Telstra $1.55 million after finding it had failed to use required identity authentication during 168,000 high-risk customer interactions, including more than 7,000 involving vulnerable customers.
The latest case adds to a growing list of telcos falling foul of the rules.
In May, ACMA fined SpinTel $59,400 and warned Yomojo over breaches of mobile number porting requirements. Exetel was fined $695,000 last year after similar failures enabled SIM-swapping fraud.
The enforcement action against Telstra carries a particularly high price per breach.
ACMA calculated the latest penalty at $19,800 for each contravention, almost twice the average $9,520 penalty imposed on Exetel.
The escalating penalties reflect a regulator increasingly unwilling to tolerate failures in basic anti-fraud controls.
“We are deeply concerned that so many telcos have had system vulnerabilities placing Australians at risk of preventable harm,” Yorke said in May, urging providers to ensure their systems are “tested and secure”.
SIM swapping remains a major threat
SIM swapping is particularly dangerous because taking control of a victim’s mobile number can give fraudsters a pathway into other accounts, including those protected by SMS-based authentication.
The threat is becoming harder to detect as criminals use synthetic identities, AI-powered impersonation and digitally manipulated documents to defeat traditional identity checks.
The scale of the broader account-takeover problem is also growing.
Australians lost $16.5 million to account takeover and identity theft scams in the first eight months of this year, according to Scamwatch — 32 per cent more than was lost across the whole of 2025.
ACMA has made mobile number fraud a major enforcement priority, alongside combating spam and telco scams and protecting vulnerable consumers.
During the 2025-26 financial year, the regulator finalised 12 investigations into mobile number fraud and issued $4.6 million in fines.
The crackdown appears to be having an impact.
Consumer reports of mobile number porting fraud fell 72 per cent compared with the previous financial year, ACMA said.
But the Telstra case shows the problem has not gone away — particularly when frontline staff fail to follow protections already in place.
Telstra put on notice
ACMA has imposed additional conditions on Telstra as part of a variation to the enforceable undertaking the telco signed after its previous penalty.
The telco now has three months to conduct a formal review of how it handles customer reports involving unsolicited verification codes, unauthorised SIM activity and vulnerable customers.
It must also strengthen training for customer-facing staff, including how to identify customers at risk of fraud and handle high-risk transactions.
Telstra will be required to regularly audit and document its quality-assurance processes, with a focus on whether staff correctly identify warning signs, complete mandatory authentication checks and escalate cases when necessary.
For ACMA, the message is clear: once a telco knows a customer is at risk, it cannot simply follow business as usual.
“When a telco becomes aware that a customer is at risk of fraud involving their service,” Yorke said, “it must offer protections that are additional or tailored to the situation.”