Telstra customers lost at least $39,500 to fraudsters who took over their mobile numbers after the company's frontline staff skipped identity checks the law requires, according to an Australian Communications and Media Authority investigation published on Thursday. Telstra has paid a $277,200 infringement notice, its second penalty under the same rules in two years.

Between January and October 2025, ACMA found, Telstra and its budget brand Belong completed 15 high-risk transactions, SIM swaps and changes to account security details, without the multi-factor authentication required under the customer identity rules in force since June 2022. In 13 further cases staff failed to apply extra fraud protections to customers who had already been identified as at risk, including customers who had reported receiving verification codes they never asked for.

The investigation report sets out how the checks were bypassed. In eight cases an agent completed the authentication by calling a number that was not listed on the account. In two, the agent went ahead without completing it. In two more, someone created a duplicate customer account, added their own contact details to it, and used those details to pass the check before talking an agent into the swap. Two failures happened in retail stores, and in one case a staff member verified a single government document where the rules require two.

A SIM swap moves a customer's number onto a device the attacker controls. Once it lands, the one-time codes that banks and email providers send by text arrive with the attacker, which is why the 2022 rules treat a swap as a high-risk transaction that must not proceed without multi-factor authentication.

In this case, Telstra's frontline staff did not follow the provider's own processes, leaving customers vulnerable to SIM swap scams and other types of mobile fraud," ACMA authority member Samantha Yorke said. "When a telco becomes aware that a customer is at risk of fraud involving their service, it must offer protections that are additional or tailored to the situation.

The penalty is the most the infringement notice could carry. ACMA found 28 contraventions but the notice covers 14 of them, those dated between 26 June and 30 October 2025, at 60 penalty units, or $19,800, each. The notice itself records that court penalties for the same conduct are significantly higher. ACMA did not go to court. It instead varied the court-enforceable undertaking Telstra gave in July 2024, when it paid $1,551,000 for skipping authentication on about 168,000 high-risk interactions between August 2022 and April 2023.

The varied undertaking runs for 12 months. Telstra must review its fraud-mitigation processes within three months, its staff training within four, and the decision thresholds its frontline staff work to within six, run quarterly internal audits, and report progress to ACMA by 26 February 2027. In the document Telstra "acknowledges the ACMA's findings". The company had not published a statement on the penalty by Thursday afternoon.

This is the seventh enforcement action under ACMA's mobile number fraud crackdown, and the regulator says telcos have now paid more than $5 million. Exetel paid $694,860 in August 2025, Southern Phone $2,500,560 in December and SpinTel $59,400 in May. In the Exetel and Southern Phone cases scammers got around the carriers' systems. ACMA's finding against Telstra is that the systems were there and staff did not follow them.

The investigation began on 7 November 2025, after ACMA monitored Telstra's compliance in the wake of the 2024 action. What Telstra has changed since October 2025 is not in the record. The first test is the process review due in three months, and the progress report ACMA will receive in February.