If your business banking, email or accounting software sends a one-time code by SMS to confirm it's really you, that code is only as safe as your mobile number. Australia's telecommunications regulator, the ACMA, has confirmed it's investigating a rise in reports of mobile fraud after years of decline, and identity-recovery service IDCARE has recorded a sharp jump in Australians seeking help after their phone number was hijacked. The technique, called SIM-swapping or port-out fraud, lets a criminal take over your number without ever touching your phone — and once they have it, any account that relies on an SMS code to log in or approve a payment is exposed.
How the scam actually works
A SIM swap doesn't need your phone to be lost, stolen or hacked. A scammer who has gathered enough of your personal details — often from a prior data breach, a phishing email, or information scraped from social media and business directories — contacts your mobile carrier (or a rival carrier, since numbers can be ported between providers) and convinces them to move your number onto a SIM card the scammer controls. From that moment, every call and text meant for you, including the SMS codes your bank or email provider sends to verify a login, goes straight to the attacker instead.
IDCARE's data shows the majority of these attacks happen with no interaction from the victim at all — no suspicious call, no phishing link clicked, nothing to notice until the phone suddenly loses signal and won't send or receive anything. That loss of signal is often the first and only warning sign before an account is drained.
Why this matters more for a business than a personal phone
A personal mobile compromised this way is bad enough. A business mobile is worse, because it's frequently the single number tied to several high-value accounts at once: internet banking, the accounting platform, the domain registrar, cloud email admin, and any supplier portal using SMS as a "second factor" of login security. If that number is one call away from being handed to a criminal, all of those defences collapse together rather than one at a time.
It's also worth knowing the regulatory backdrop. Rules introduced in 2020 requiring telcos to run stronger identity checks before porting a number cut fraudulent porting by more than 90 percent at the time — proof the protection works when telcos apply it properly. The current rise suggests attackers are finding gaps in how consistently those checks are being followed, which is exactly why Telstra was fined over $1.5 million last year for failing to properly verify customers during high-risk interactions, SIM swaps among them. The rules exist; enforcement and follow-through are the weak point, and that's outside any individual business's control.
What you can control
You can't fix your telco's verification process, but you can reduce how much damage a successful SIM swap does to your business:
- Add a porting PIN or passcode to your business mobile accounts. Most Australian carriers let you set an extra password that must be provided before a number can be ported out or a SIM replaced. It's usually a two-minute call or app setting, and it's the single most direct block against this specific scam.
- Move critical accounts off SMS-based two-factor authentication. An authenticator app (like Microsoft Authenticator or Google Authenticator) or a physical security key generates codes on the device itself, not over the phone network, so a stolen number gives an attacker nothing. Prioritise business banking, your email admin console, and your domain registrar first.
- Watch for unexplained loss of mobile signal. If a phone that normally has reception suddenly shows "no service" or "emergency calls only" for no obvious reason, treat it as a possible SIM swap in progress and contact your carrier immediately, not as a network glitch to wait out.
- Separate business-critical logins from a single mobile number where you can. Where a platform allows it, use a landline, a shared admin email, or a hardware key as a backup verification method rather than relying solely on one person's mobile.
- Review who at your business could be a high-value target. Anyone with banking authority, admin access to your Microsoft 365 or Google Workspace tenant, or the ability to approve payments is worth prioritising for the changes above first.
The bigger pattern
SIM-swap fraud sits alongside payment redirection scams as another example of attackers going after the verification step itself rather than trying to guess a password outright. Both rely on exploiting a process that's supposed to add security — a bank transfer confirmation call, an SMS code — by compromising the channel it travels through. The fix in both cases is the same principle: don't let a single, easily intercepted channel be the only thing standing between a criminal and your money.
If you're not sure which of your business accounts still lean on SMS codes as their only second factor, that's a worthwhile audit to run this month rather than after an incident. Our IT security solutions include exactly this kind of review, tightening authentication across the accounts that matter most before an attacker finds the gap first. If you'd like a hand working through it, get in touch — we've been helping Perth businesses lock this kind of thing down since 1997.



