Insights › Passwords & MFA

SIM Swap Fraud: Protecting Your Business Numbers

SecurityScore article cover reading SIM Swap Fraud, Protecting Your Business Numbers, in the Passwords and MFA category

Most Australian businesses now rely on a mobile number for far more than phone calls. It is the number that receives your one-time login codes, resets your passwords, and verifies transactions with your bank. That makes it a prize worth stealing, and a growing number of scammers are doing exactly that through SIM swap and mobile porting fraud.

The good news is that this attack is preventable once you understand how it works. This guide explains SIM swapping in plain English, walks through the warning signs, and sets out the practical steps that keep your business numbers, and the accounts tied to them, out of a scammer’s hands.

What is SIM swap fraud?

SIM swap fraud is when a criminal takes control of your mobile number so that your calls and text messages start arriving on their device instead of yours. There are two common versions.

The first is a SIM swap. The scammer contacts your existing mobile provider, pretends to be you, and asks for your number to be moved to a new SIM card that they control. The second is mobile porting fraud, where the scammer transfers your number to a different provider altogether. The Australian Competition and Consumer Commission describes both as an unauthorised transfer of your phone service, and the effect is the same: your number, and everything connected to it, is now in someone else’s pocket.

Once the transfer goes through, your own phone loses signal. The scammer starts receiving the text messages and calls meant for you, including the security codes that protect your logins.

Why your business number is a target

Your mobile number is not just a way to reach you. It is often the key that unlocks the rest of your business.

Think about how many accounts send a code by text message when you log in or reset a password: your bank, your accounting software, your email, your domain registrar, even your payroll system. If a scammer controls your number, they can request those codes, intercept them, and work their way into account after account. From there they can drain a bank balance, send fake invoices to your customers, or lock you out entirely.

This is why SIM swapping is so damaging for small business. It does not rely on malware or a clever piece of code. It exploits a weak link that most of us set up years ago without a second thought: the text message as a second factor. If you want a refresher on why a second factor matters at all, our guide to multi-factor authentication is a good place to start.

How scammers take over your number

A SIM swap almost never begins with the phone company. It begins with information about you.

Scammers gather personal details from data breaches, social media, public records and earlier phishing emails. Armed with your name, date of birth, address and perhaps a recent bill, they contact your telco and impersonate you convincingly enough to request a new SIM or a port to another carrier. In some cases they target the telco’s staff or systems directly.

This is often the final step in a longer con. A hijacked number is one of the most common paths into a business, sitting alongside the other entry points we cover in how small businesses get hacked. Once the number is theirs, the scammer moves fast, resetting passwords and approving logins before you notice anything is wrong.

What the rules require of telcos

Australia has tightened the rules in recent years, and it helps to know what protection you are entitled to.

In early 2020 the Australian Communications and Media Authority (ACMA) introduced rules to reduce mobile porting fraud, requiring providers to verify your identity before moving your number to another telco. In 2022 the ACMA went further with the Telecommunications Service Provider (Customer Identity Authentication) Determination, which took effect on 30 June 2022. It requires telcos to use stronger, multi-factor identity checks before carrying out high-risk transactions such as a SIM swap or a major account change. Providers that fail to comply can face enforcement action.

These rules make the attack harder, but they do not make it impossible. Your own habits and account settings still matter, which is where the next section comes in.

Warning signs your number has been hijacked

A SIM swap can happen in minutes, so the sooner you spot it the better. Watch for these signs:

Any one of these on its own might be harmless. Two or three together, especially a dead phone paired with account alerts, should be treated as an emergency.

How to protect your business

You cannot control every telco’s systems, but you can make your number, and the accounts behind it, much harder to hijack. The single most important step is to stop relying on text messages as your main second factor.

Roll these out for every person who holds the keys to money or data, not just the business owner.

What to do if it happens

If you believe your number has been taken over, act quickly and in this order.

Deal with the phone number and the bank first. Every minute the scammer holds your number is a minute they can use to reset another account.

Find out where you stand

SIM swap fraud works by slipping through a gap you did not know you had, usually an important account still protected by a text message code. The best defence is knowing where those gaps are before a scammer finds them.

SecurityScore is a free self-assessment built for Australian businesses. It takes about 5 to 10 minutes, asks 27 plain-English questions, and gives you an instant PDF report mapped to the ACSC Essential Eight, ISO 27001 and SOC 2. You will see exactly where your logins, accounts and recovery options are strong, and where they need work.

Take the free assessment and find out where your business stands.

Discover more from Security Score

Subscribe now to keep reading and get access to the full archive.

Continue reading