Telstra fined $1.55m by ACMA for failings in thwarting SIM-swap scams

Telstra fined $1.55m by ACMA for failings in thwarting SIM-swap scams

Photo: Priscilla du Preez via Unsplash

A failure by Telstra to implement customer ID authentication processes to protect customers from SIM-swap scams has cost the Australian telco a $1.55 million penalty from the industry regulator.

The Australian Communications and Media Authority (ACMA) found that between August 2022 and April 2023 Telstra neglected to use the required ID authentication measures for 168,000 high-risk customer interactions, including SIM-swap requests and password resets.

The regulator found that this oversight by the telco giant affected more than 7,000 interactions involving customers identified as being in “vulnerable circumstances”.

"When the ACMA established these rules in mid-2022, we identified that victims of mobile fraud typically lose $28,000 on average," says ACMA member Samantha.

"While there is no direct evidence of financial losses due to these breaches, customers must trust that their telcos are safeguarding their accounts from fraud."

ACMA says that SIM-swap scams can have devastating consequences leading to victims potentially losing their life savings and control over their phone numbers and personal information.

These scams typically occur when someone requests a replacement SIM card or eSIM from their telco due to a lost or damaged SIM.

Yorke says the customer ID authentication rules introduced in 2022 have been highly effective in reducing SIM-swap fraud, with the mandating telcos to use multi-factor authentication, such as verifying one-time codes sent to consumers, before allowing transactions that could compromise an account.

"It is unacceptable that Telstra did not have proper systems in place when the rules came into force," she says.

On top of the $1.55 million fine, ACMA has secured a two-year court-enforceable undertaking from Telstra that requires the appointment of an independent consultant to review Telstra's compliance with customer ID rules and to recommend necessary improvements.

ACMA says the breach “underscores the importance of rigorous ID verification processes to protect consumers from the growing threat of mobile fraud”.

“As Australia's leading telecommunications provider, Telstra's compliance with these standards is critical to maintaining customer trust and security in an increasingly digital world,” says the authority.

Business News Australia

Australia's business news.
Free. Always.

Join thousands of founders, investors and executives
who read Business News Australia every morning.

Free Access

You're on a roll.
Keep reading — it's free.

Create a free account to keep reading
Business News Australia. No restrictions, ever.

of articles read

You've read articles.
The rest are free too.

Create a free account to keep reading
Business News Australia. No restrictions, ever.

Join Free

No paid subscriptions, just free. Unsubscribe anytime.

The financial case for knockdown rebuild on established Australian land
Partner Content
For most Australian homeowners, the house gets the attention and the land gets taken fo...
Ventures & Visionaries
Advertisement

More News