Telstra has paid a $277,200 penalty after an Australian regulator found failures in the company’s checks designed to protect customers from mobile number fraud. The case involved unauthorized SIM swaps and customers who later reported at least $39,500 in combined financial losses.
What happened with Telstra customers
The Australian Communications and Media Authority found that Telstra failed to use required identity checks in 15 unauthorized SIM swaps between January and October 2025. A SIM swap happens when a mobile number is moved to a different SIM card without the real customer’s permission.
Once criminals gain control of a mobile number, they may be able to receive calls and text messages meant for the victim. This can create a risk of further fraud, especially when a phone number is used to help protect online accounts.
The regulator also found 13 cases where Telstra agents did not provide extra fraud protection to customers who had either raised concerns or were already known to be at risk.
Customers suffered real financial losses
The investigation found that the security failures were not simply technical or paperwork issues. Customers affected by the fraud reported combined financial losses of at least $39,500.
The $277,200 payment made by Telstra is a penalty imposed over the company’s compliance failures. It is separate from the amount customers reported losing through the fraud.
| Item | Latest confirmed detail |
|---|---|
| Telstra penalty | $277,200 |
| Unauthorized SIM swaps found | 15 |
| Other cases involving missed fraud protections | 13 |
| Customer financial losses reported | At least $39,500 combined |
| Period covered by the investigation | January to October 2025 |
| Regulatory body | Australian Communications and Media Authority |
The regulator said the case showed the importance of following identity checks and using extra protections when a customer may be at risk.
Why SIM swap fraud is dangerous
SIM swap fraud can give criminals control over a victim’s mobile number. That can make it easier for them to intercept calls and text messages, including messages that may be used for account security.
For this reason, mobile providers are required to follow identity verification rules when handling certain changes involving mobile numbers. They also have duties to offer extra protections when they know a customer may be at risk.
In the Telstra case, the regulator said frontline staff did not always follow the required processes or Telstra’s own procedures.
Telstra must strengthen its fraud controls
Along with the financial penalty, the regulator accepted legally enforceable commitments from Telstra. The company has agreed to strengthen its fraud prevention processes and improve training for staff who deal directly with customers.
The regulator’s investigation followed earlier monitoring of Telstra’s compliance with the same rules. This is significant because it means the latest action was not the first regulatory concern involving these requirements.
The case is also part of a wider crackdown on mobile number fraud. The regulator said it was the seventh enforcement action announced under this effort, with telecommunications companies paying more than $5 million in penalties so far.
What customers should do if they suspect fraud
Customers who suddenly lose mobile service without a clear reason, receive unexpected messages about a SIM change, or notice suspicious activity on their accounts should act quickly. A suspected SIM takeover can affect more than the phone itself because the number may be connected to banking, email and other accounts.
If you believe your mobile number has been taken over or used in a scam, the key steps are:
- Contact your mobile provider immediately and report the suspected fraud.
- Contact your bank or financial institution if money or financial accounts may be involved.
- Check important online accounts for unexpected password or security changes.
- Change affected passwords and review account security as soon as possible.
The regulator also advises people who believe they have been affected by a phone scam to contact their telecommunications provider and financial institution immediately.
What the latest Telstra penalty means
The latest action puts attention on a basic part of mobile security: making sure the person requesting changes to a mobile account is really the account holder. It also shows that extra safeguards may be needed when a provider already knows a customer could be at risk.
For Telstra, the immediate requirements go beyond paying the $277,200 penalty. The company must strengthen its fraud prevention work and improve staff training under the commitments accepted by the regulator.
For customers, the case is a reminder that control of a mobile number can be closely tied to the security of other accounts. Quick action after a suspected SIM swap can help limit further damage.
The regulator’s announcement was made on September 3, 2026, and the investigation covered incidents from January through October 2025. The penalty and new commitments mark the latest regulatory response to failures in preventing mobile number fraud in Australia.