TELSTRA HIT WITH $277K SIM SWAP PENALTY AS ID CHECK FAILURES EXPOSE CUSTOMERS TO FRAUD
Australia’s telecommunications giant Telstra has paid a $277,200 penalty after regulators found failures in mandatory identity verification and fraud protection controls that left customers exposed...
Australia’s telecommunications giant Telstra has paid a $277,200 penalty after regulators found failures in mandatory identity verification and fraud protection controls that left customers exposed to unauthorised SIM swaps and mobile number fraud.
The Australian Communications and Media Authority, ACMA, found that Telstra failed to apply required identity authentication processes in 15 unauthorised SIM swaps between January and October 2025. The investigation also uncovered 13 cases where frontline staff failed to provide additional fraud protections to customers who had either raised concerns or were known to be at risk.
The compliance failure had direct consequences. Customers affected by the fraud reported combined financial losses of at least $39,500, highlighting how weaknesses at the telecommunications layer can quickly become a banking and financial crime problem.
SIM swap fraud allows criminals to take control of a victim’s mobile number by obtaining a replacement SIM or eSIM. Once control of the number is compromised, fraudsters may be able to intercept authentication codes and exploit access to financial accounts and other services.
Australia introduced stronger customer identity authentication requirements for high-risk telecommunications transactions, including SIM swaps. The framework requires telcos to use multi factor authentication and other verification measures before carrying out transactions capable of compromising customer accounts.
The ACMA found that the problem at Telstra was not simply a technology gap. Frontline personnel failed to follow the provider’s own fraud prevention processes, creating a control weakness at the point where customer identity verification should have acted as the first line of defence.
In addition to the financial penalty, Telstra has entered into court enforceable undertakings requiring it to strengthen fraud prevention processes and improve training for customer facing employees. The action follows previous regulatory scrutiny of Telstra over customer identity and fraud controls.
The latest action is the seventh enforcement action announced under the ACMA’s crackdown on mobile number fraud, with telecommunications companies having paid more than $5 million in penalties under the campaign to date.
For financial institutions, the case carries a wider warning. Mobile identity has become deeply embedded in authentication ecosystems, meaning a weakness at a telecommunications provider can create downstream exposure for banks, fintechs and digital financial services.
The compliance challenge therefore extends beyond the telco. Banks and other financial institutions need to consider how reliance on mobile numbers, SMS authentication and customer contact details can create vulnerabilities within their own fraud controls.
Compliance takeaway
The Telstra penalty demonstrates that identity verification is only as strong as the control at the point of execution. Policies, procedures and authentication technology cannot adequately protect customers if frontline processes are bypassed or inconsistently applied.
Financial institutions should treat SIM swap exposure as part of their broader fraud and authentication risk framework, particularly where mobile numbers are used for account recovery, transaction authentication or customer verification.



No Comment! Be the first one.