31.8k unique visitors in the last 3 days

5 Aussie Telcos Breached Anti-Scam Rules; Millions of Impersonation Scam SMS Messages Sent

The Australian regulator issued orders to comply with the national anti-scam code but cannot levy fines for a first infringement.

The Australian Communications and Media Authority (ACMA) has ordered five telcos to comply with anti-scam rules after discovering they sent SMS messages that breached the national anti-scam code. Investigations into the telcos found they collectively sent 50 million SMS messages without performing mandatory checks. As a consequence, more than 2 million of the messages fraudulently impersonated legitimate organizations.

A single press release was issued to announce the action taken against the five telcos who breached the rules. The key figures for the scam SMS messages are reproduced below, with links to the full conclusions of the ACMA investigation in each case.

  • Message4U originated an estimated 36,124,237 SMS messages without proper SenderID validation between 12 July 2022 and 8 June 2023. Of these, at least 1,284,630 were used for scams.
  • SMS Broadcast originated an estimated 4,588,941 SMS messages without proper SenderID validation between 12 July 2022 and 8 June 2023. Of these, at least 1,240,548 were used for scams.
  • DirectSMS originated an estimated 1,630,012 SMS messages without proper SenderID validation between 12 July 2022 and 8 June 2023. Of these, at least 9,613 were used for scams.
  • Esendex originated an estimated 6,756,999 SMS messages without proper SenderID validation between 12 July 2022 and 8 June 2023. Of these, at least 99,000 were used for scams.
  • MessageBird originated 1,198,348 SMS messages without proper SenderID validation during early 2023. The extensive redactions applied to their investigation report suggest their case is more complicated, and makes it difficult to compare the extent of their failings to the other breaches listed in the ACMA’s press release.

There has been a recurring pattern of Aussie telcos originating SMS messages without properly confirming their customer is entitled to use the SenderID that was associated with the message. Not all of these messages are sent by fraudsters, but the failure to validate the use of the SenderID is a gap in anti-scam defenses that criminals will exploit whenever they can. But to be fair, this pattern may reflect the ACMA’s diligence in identifying and investigating potential breaches of its anti-scam rules. It seems unlikely that Australian telcos will be significantly worse than their peers in other countries, especially as the ACMA has been a world leader in adopting rules to protect consumers from scams.

I have simplified the description of the various rules that were breached by these telcos for the sake of brevity, but it is easy to generalize about their punishment. None of the telcos were fined. All five telcos received directions to comply with the national anti-scams code and with rules for updating entries in Australia’s Integrated Public Number Database. A direction to comply essentially means the telco has been told to obey rules they should have already been obeying. The ACMA’s press release perhaps contained a hint of frustration at the limits of the penalties they can impose on telcos that break the rules.

As a result of the breaches each of the telcos have been formally directed by the ACMA to comply with the Integrated Public Number Database and the Reducing Scam Calls and Scam SMs (sic) industry codes. This is the strongest enforcement outcome available to the ACMA for initial breaches of these codes.

The ACMA is doing excellent work and the data indicates their strategy for reducing voice and SMS scams is effective. However, I do not really understand why any country would tie the hands of a regulator by denying it the right to issue a fine whenever a telco fails to comply with anti-scam rules, even if it is the telco’s first non-compliance. The public is at risk. Telecoms scams are a bane on modern life. And some of the money made by scammers will be recycled into expanding and improving the scams they operate. The ACMA will be able to impose a fine of AUD250,000 (USD163,000) on any of these five telcos if they subsequently breach the new directions to comply they have just received. But the public interest would be better served by allowing the regulator to issue a fine of this severity on the first occasion when the rules are violated, instead of waiting for a second violation before a fine can be levied. The threat of an instant fine would signal the need to always guard against fraud, without any excuses.

Eric Priezkalns
Eric Priezkalnshttp://revenueprotect.com

During his career, Eric has been a Director of Risk Management for a national telco, the Chief Executive of the Risk & Assurance Group, a Chief Marketing Officer for a software business, a consultant, a public speaker and the publisher of Commsrisk since its launch in 2006. Look here for more about the history of Commsrisk and the role played by Eric.

The comms providers that Eric has worked for include Qatar Telecom, Cable & Wireless, T‑Mobile, Sky and Worldcom. In addition to his proficiency at speaking about the current scamdemic, Eric is also a qualified chartered accountant and a subject matter expert in consumer protection, enterprise risk management, fraud prevention, data integrity and billing accuracy. Eric was the lead author of Revenue Assurance: Expert Opinions for Communications Providers, published by CRC Press. He can be reached through the contact form on this website.

Related Articles

The Commsrisk Global Fraud Dashboard


Our Global Fraud Dashboard uses AI-powered search to collate, update and visualize data about scams and other network abuses from around the world. New charts are added each month. See it here.

Get Our Weekly Newsletter by Email