NewsBite

Telstra stung with $1.5m fine for failing to authenticate SIM card swaps

Telstra has been hit with a major fine from the communications watchdog which says the telco’s authentication practices put customers at risk.

Telstra has been fined $1.5m for failing to use a multi-factor authentication.
Telstra has been fined $1.5m for failing to use a multi-factor authentication.

Telstra has been fined $1.5m for failing to safely authenticate the identity of users who swapped SIM cards.

The communications watchdog has claimed that the nation’s largest telco left more than 100,000 people vulnerable to scams.

ACMA found Telstra had failed to authenticate customer IDs on 168,000 high-risk customer interactions including SIM-swap requests and password resets.

That included more than 7000 interactions by customers who had been identified as being in vulnerable circumstances.

ACMA member Samantha Yorke said the average victim of mobile fraud lost about $28,000.

“SIM-swap scams can be particularly devastating as victims can lose life savings as well as control of their phone number and other personal information,” she said.

A Telstra spokesman said the company supported the new rules introduced by ACMA in 2022 and acknowledged that it not implemented the new processes in time.

“The scope of changes driven by the new obligations were significant. We had to design and deploy multi-factor authentication processes across all our channels, while also maintaining our ability to service customer requests, including those customers who could not complete multi-factor authentication,” he said.

“We needed to take the time to get the implementation right for our customers, and while we made the changes as quickly as possible, we were not able to meet the initial commencement date for some aspects of the new rules.”

Telstra said it had informed ACMA that the telco was not able to meet the requirements and had taken steps “to minimise the risk to customers”.

The fine comes after ACMA released new authentication standards in 2022.

Read related topics:Telstra
Joseph Lam
Joseph LamReporter

Joseph Lam is a technology and property reporter at The Australian. He joined the national daily in 2019 after he cut his teeth as a freelancer across publications in Australia, Hong Kong and Thailand.

Add your comment to this story

To join the conversation, please Don't have an account? Register

Join the conversation, you are commenting as Logout

Original URL: https://www.theaustralian.com.au/business/technology/telstra-stung-with-15m-fine-for-failing-to-authenticate-sim-card-swaps/news-story/a330e363f589b445bd65cf592114a42e