SIM-Swap Fraud Is Rising Again: What It Means for Your Perth Business Accounts

Reports of SIM-swap and phone port-out fraud are climbing in Australia, and the target is usually the SMS codes protecting your business banking and email. From Computer Mechanics, Perth IT specialists since 1997.

Garry BloomGarry Bloom · Founder & CEO
4 September 2026
5 min read
Cybersecurity
Scams
Mobile Security
Perth Business
Scammer taking over a mobile phone number to intercept business security codes

If your business banking, email or accounting software sends a one-time code by SMS to confirm it's really you, that code is only as safe as your mobile number. Australia's telecommunications regulator, the ACMA, has confirmed it's investigating a rise in reports of mobile fraud after years of decline, and identity-recovery service IDCARE has recorded a sharp jump in Australians seeking help after their phone number was hijacked. The technique, called SIM-swapping or port-out fraud, lets a criminal take over your number without ever touching your phone — and once they have it, any account that relies on an SMS code to log in or approve a payment is exposed.

How the scam actually works

A SIM swap doesn't need your phone to be lost, stolen or hacked. A scammer who has gathered enough of your personal details — often from a prior data breach, a phishing email, or information scraped from social media and business directories — contacts your mobile carrier (or a rival carrier, since numbers can be ported between providers) and convinces them to move your number onto a SIM card the scammer controls. From that moment, every call and text meant for you, including the SMS codes your bank or email provider sends to verify a login, goes straight to the attacker instead.

IDCARE's data shows the majority of these attacks happen with no interaction from the victim at all — no suspicious call, no phishing link clicked, nothing to notice until the phone suddenly loses signal and won't send or receive anything. That loss of signal is often the first and only warning sign before an account is drained.

Why this matters more for a business than a personal phone

A personal mobile compromised this way is bad enough. A business mobile is worse, because it's frequently the single number tied to several high-value accounts at once: internet banking, the accounting platform, the domain registrar, cloud email admin, and any supplier portal using SMS as a "second factor" of login security. If that number is one call away from being handed to a criminal, all of those defences collapse together rather than one at a time.

It's also worth knowing the regulatory backdrop. Rules introduced in 2020 requiring telcos to run stronger identity checks before porting a number cut fraudulent porting by more than 90 percent at the time — proof the protection works when telcos apply it properly. The current rise suggests attackers are finding gaps in how consistently those checks are being followed, which is exactly why Telstra was fined over $1.5 million last year for failing to properly verify customers during high-risk interactions, SIM swaps among them. The rules exist; enforcement and follow-through are the weak point, and that's outside any individual business's control.

What you can control

You can't fix your telco's verification process, but you can reduce how much damage a successful SIM swap does to your business:

  • Add a porting PIN or passcode to your business mobile accounts. Most Australian carriers let you set an extra password that must be provided before a number can be ported out or a SIM replaced. It's usually a two-minute call or app setting, and it's the single most direct block against this specific scam.
  • Move critical accounts off SMS-based two-factor authentication. An authenticator app (like Microsoft Authenticator or Google Authenticator) or a physical security key generates codes on the device itself, not over the phone network, so a stolen number gives an attacker nothing. Prioritise business banking, your email admin console, and your domain registrar first.
  • Watch for unexplained loss of mobile signal. If a phone that normally has reception suddenly shows "no service" or "emergency calls only" for no obvious reason, treat it as a possible SIM swap in progress and contact your carrier immediately, not as a network glitch to wait out.
  • Separate business-critical logins from a single mobile number where you can. Where a platform allows it, use a landline, a shared admin email, or a hardware key as a backup verification method rather than relying solely on one person's mobile.
  • Review who at your business could be a high-value target. Anyone with banking authority, admin access to your Microsoft 365 or Google Workspace tenant, or the ability to approve payments is worth prioritising for the changes above first.

The bigger pattern

SIM-swap fraud sits alongside payment redirection scams as another example of attackers going after the verification step itself rather than trying to guess a password outright. Both rely on exploiting a process that's supposed to add security — a bank transfer confirmation call, an SMS code — by compromising the channel it travels through. The fix in both cases is the same principle: don't let a single, easily intercepted channel be the only thing standing between a criminal and your money.

If you're not sure which of your business accounts still lean on SMS codes as their only second factor, that's a worthwhile audit to run this month rather than after an incident. Our IT security solutions include exactly this kind of review, tightening authentication across the accounts that matter most before an attacker finds the gap first. If you'd like a hand working through it, get in touch — we've been helping Perth businesses lock this kind of thing down since 1997.

Garry Bloom
Written by
Garry Bloom
Founder & CEO · 25+ years in IT

Garry founded Computer Mechanics — the business behind IT Support Perth — in 1997. With more than 25 years in IT management and support across internal and external service environments, he leads the team's technical direction and its cybersecurity and managed-IT strategy for Perth businesses.

Meet the IT Support Perth team →
Garry Bloom
4 September 2026
5 min read
Cybersecurity
Scams
Mobile Security
Perth Business

Stay Updated with IT Insights

Get the latest cybersecurity tips and technology insights delivered to your inbox

Related Articles

Microsoft 365 Prices Went Up: What to Check Before Your Perth Business Renews

Microsoft 365 Business Standard is now $21/user/month in Australia, up 12%, while Business Premium is unchanged. Here's what Perth businesses should check before renewal. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

The SMS Sender ID Register Is Mandatory: What Perth Businesses Need to Do

Australia's SMS Sender ID Register became mandatory on 1 July 2026. Here's what Perth businesses that send appointment reminders, invoices or marketing texts need to check now. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Critical Windows VPN Flaw Under Active Attack: What Perth Businesses Need to Check

CISA confirms hackers are actively exploiting a critical Windows VPN flaw, CVE-2026-33824, to break into business networks with no login required. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Need Expert IT Support?

Get personalized advice from our Perth IT experts. Free consultation available.

Related Content

Continue Reading

Explore more insights and expert advice on IT support, cybersecurity, and digital transformation

The SMS Sender ID Register Is Mandatory: What Perth Businesses Need to Do
SMS Scams
Compliance

The SMS Sender ID Register Is Mandatory: What Perth Businesses Need to Do

Australia's SMS Sender ID Register became mandatory on 1 July 2026. Here's what Perth businesses that send appointment reminders, invoices or marketing texts need to check now. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
9/2/2026
Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.
CyberSecurity
ITSupportPerth

Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.

Most small business owners believe end-to-end encryption means their messages are completely private. A recent FBI case proves that assumption is dangerously incomplete.

5 min read
4/15/2026
What’s new in SMB1001:2026?
SMB1001
SMB10012026

What’s new in SMB1001:2026?

SMB1001:2026 updates for Perth SMBs: Mandatory DMARC from Silver tier, 5 maturity levels, Essential Eight alignment. Get certified, cut insurance costs, win tenders—start your roadmap today!

5 min read
2/25/2026
Call us