Case Library / Vishing (Voice Phishing) / Optus/TPG Telecom OTP-Interception Mobile-Upgrade Vishing Fraud (Sydney, 2023-2024)

Optus/TPG Telecom OTP-Interception Mobile-Upgrade Vishing Fraud (Sydney, 2023-2024)

A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support.

Share:

Social Engineering Examples·3 sources

What Happened

Beginning around March 2023, Optus and TPG Telecom alerted the AFP-led Joint Policing Cybercrime Coordination Centre (JPC3) to a pattern of fraudulent high-end device orders being placed on customer accounts. Investigators established that a caller (or callers) impersonating a telecommunications company representative had been contacting customers, telling them their mobile service needed "maintenance" or offering a discount on a new device, then having a one-time SMS PIN sent to the victim "for authorisation," which the offender intercepted and used to complete a device purchase on the victim's own account (often using saved payment details) before rerouting delivery to another address.

Devices were allegedly then sent offshore for resale. The scheme was linked to more than 100 Australian victims. On 27 November 2024, AFP investigators arrested a 21-year-old Pakistani national at his home in Auburn, western Sydney, and executed a search warrant that allegedly turned up more than $1 million AUD in cash (hidden in suitcases and Louis Vuitton bags), over 500 SIM cards, and 21 electronic devices containing credit cards and financial documentation.

He was charged the next day (28 November 2024) and named in subsequent court reporting as Muhammad Akhtar. A Downing Centre Local Court hearing on 2 December 2024 heard that his phone (seized in August 2024) contained 111 credit reports generated on victims' identities without consent, and that the November search also turned up nine more mobile phones and 300 additional SIM cards, a figure that does not clearly reconcile with the AFP release's own count of 500+ SIM cards and 21 devices from the same search, possibly reflecting inconsistent reporting of the same haul rather than a separate additive tally; he was refused bail as a flight risk given Australia has no extradition treaty with Pakistan.

How the Attack Worked

The offender (or accomplices) cold-called Optus and TPG Telecom customers, impersonating a telecommunications company representative. The pretext was either that the victim's mobile service was undergoing "maintenance" or that they were eligible for a discount/free upgrade on a new device. Once engaged, the caller told the victim to expect a one-time PIN (OTP) sent by SMS "for authorisation" of the upgrade, then intercepted that OTP and used it to complete a device purchase on the victim's own carrier account, frequently drawing on saved payment details already on file.

The order was rerouted to a delivery address controlled by the offender rather than the victim's address, and the devices were allegedly funneled offshore for resale. Victims typically discovered the fraud only when the "upgraded" device never arrived and they called their carrier, at which point the carrier's fraud team could trace many orders back to the same identity.

Investigators separately found the offender's seized phone held 111 credit reports generated on victims' identities without consent, pointing to a broader identity-data harvesting operation feeding the calls with victim-specific details that made the "your account" pretext convincing.

The Lure & the Tell

Lure: an inbound call from someone claiming to be from the victim's own telco (Optus or TPG), saying either that the mobile service needed "maintenance" or that the customer qualified for a discount/free upgrade on a new handset, playing on trust in a known, already-relied-upon brand plus the appeal of a free premium device. The tell victims should have caught: legitimate telcos do not call customers unprompted and then ask them to read back or otherwise share an incoming SMS one-time PIN; a real "authorisation" step never requires disclosing the OTP to the person on the phone.

The actual giveaway for the real victims here was passive rather than active: they only became suspicious after the promised new device never arrived, at which point they called their carrier directly and the fraud was traced.

Outcome

Muhammad Akhtar, 21, a Pakistani national on a student visa (studying IT while working for Uber/Uber Eats), was arrested 27 November 2024 and charged the next day with (1) dishonestly obtaining/dealing in personal financial information (s480.4 Criminal Code 1995 Cth, max 5 years) and (2) dealing with money/property valued at $1,000,000+ believed to be proceeds of indictable crime (s400.3(1), max 25 years).

He appeared at Downing Centre Local Court and was refused bail on 2 December 2024; the judge called the alleged offending "high level, sophisticated, targeted (and) well-planned," and the defense barrister conceded the Crown had a strong case. Court heard that his phone (seized in August 2024) contained 111 credit reports generated on victims' identities without consent, and that the November search also turned up nine more mobile phones and 300 additional SIM cards, a figure reported in court (via AAP) that does not clearly reconcile with the AFP media release's statement that the same 27 November search recovered over 500 SIM cards and 21 electronic devices; the two accounts may describe the same haul reported inconsistently rather than as additive totals.

Court heard suggestions that Akhtar's brother-in-law and sister were also involved via scheme-related group chats, though as of the reporting reviewed, Akhtar was the only person charged and the AFP said further charges were expected. The matter was set to return to court 29 January 2025; no conviction or sentencing outcome was identified in the sources reviewed for this record, so the specific criminal allegations against Akhtar remain unproven pending trial even though the AFP-led investigation, arrest and seizures are confirmed by primary AFP reporting.

Why It Matters

This case shows how a routine, high-trust customer-service interaction (an inbound "your telco" call about maintenance or a device upgrade) can be weaponized into a full-blown OTP-interception fraud pipeline at scale (100+ victims over ~20 months) without any exotic technical exploit: the entire compromise rode on the victim being talked into treating an SMS one-time PIN as something to share or act on for a caller-initiated "authorisation," rather than a secret the victim alone should complete.

It also illustrates the value of cross-carrier and law-enforcement collaboration (Optus + TPG + AFP/JPC3) in spotting a single offender's fingerprint across two competing telcos' customer bases, and how identity-data harvesting (unauthorized credit-report pulls) can feed the pretext used in the calls, making a generic-sounding vishing script far more convincing to each specific victim.

Defenses

Optus and TPG Telecom flagged the anomalous device-upgrade/OTP pattern to the AFP-led JPC3 (Joint Policing Cybercrime Coordination Centre) rather than treating individual cases in isolation, which let investigators link one offender to 100+ victims over ~20 months. AFP's public guidance after the case: never trust an inbound caller claiming to be your telco; hang up and call the company back only via the number on its official website/app; never read out or forward an SMS one-time PIN to anyone, including someone who says they are "verifying" you; watch for signs of account tampering (unexpected "maintenance" claims, unsolicited discount/upgrade offers, an OTP arriving that you did not request); if an expected new/replacement device does not arrive, contact the carrier immediately rather than assuming courier delay.

Carrier-side controls implicated: delivery-address changes and high-value device purchases authorized by a single SMS OTP were exploitable step-up authentication for account changes/shipping-address changes, and monitoring for bulk SIM/credit-report anomalies tied to one identity.

Sources
  • Pakistan man charged for dealing with more than $1 million derived from scams. Australian Federal Police (joint release with Optus and TPG Telecom) Primary. Verified by direct fetch on 2026-07-29: loads correctly and confirms investigation timeline (opened Mar 2023), method description, 27 Nov 2024 arrest, 28 Nov 2024 charges, seizure figures (>$1M cash, 500+ SIM cards, 21 devices), and AFP/Optus/TPG statements including the ScamWatch ~34,000-reports/~$71M figures.
  • Accused scammer found with $1m cash, Louis Vuitton bags. AAP News (Australian Associated Press) Secondary. Verified by direct fetch on 2026-07-29: loads correctly and confirms Downing Centre Local Court reporting (2 Dec 2024), names the accused (Muhammad Akhtar, 21), bail refusal, Judge Michael Allen's and prosecutor Edward Jude's remarks, no-extradition-treaty point, and additional seizure details (111 credit reports, 9 more phones, 300 SIM cards).
  • Pakistan Man Charged in $1M Scam Scheme. Mirage News Secondary. Verified by direct fetch on 2026-07-29: loads correctly and is a near-verbatim republication of the AFP release, independently corroborating the same timeline and figures.
Cite this case

Social Engineering Examples. “Optus/TPG Telecom OTP-Interception Mobile-Upgrade Vishing Fraud (Sydney, 2023-2024)”. Accessed 19 September 2026. https://socialengineeringexamples.com/optus-tpg-otp-interception-vishing-2024

Attack Chain & Defense
1Reconnaissance and identity-data sourcing
What happened

Court reporting on the offender's seized phone found 111 credit reports generated on victims' identities without their consent, consistent with using unauthorized credit-report pulls and other harvested personal data to build a profile of a real customer's name, phone number, and telco billing details before making contact, the kind of preparatory identity-data gathering that let each call sound tailored to that specific victim's account.

The control that would have stopped it

Consumers cannot easily prevent someone from pulling an unauthorized credit report in their name, but credit bureaus and lenders can add anomaly detection for repeated report requests tied to one requester, and individuals can use free credit-monitoring or credit-freeze services that alert them whenever a new report is generated in their name, catching this stage after the fact rather than blocking it outright.

2Target and carrier identification
What happened

Victims were current Optus or TPG Telecom customers, so the offender likely needed to establish which telco a given phone number or identity was actually subscribed to before calling, whether through the harvested account data itself or simply by having each call open with confirming the victim's provider.

The control that would have stopped it

This step rides on data already exposed in Stage 1, so the more effective control is the same one that limits how much account-specific detail an attacker can bring to the call in Stage 3, rather than a control aimed at carrier identification itself.

3Initial contact vishing
What happened

The offender or an associate cold-called victims, impersonating a representative of the victim's own telecommunications provider (Optus or TPG Telecom), opening with a pretext that the mobile service needed "maintenance" or that the customer qualified for a free or discounted device upgrade, exploiting the built-in trust of what appeared to be an inbound call from the victim's own carrier.

The control that would have stopped it

Consumer-facing guidance, reinforced by AFP's own post-case advice, that a legitimate telco does not cold-call customers about unscheduled "maintenance" or unprompted device upgrades, and that any such call should be ended so the customer can call back only via the number on the provider's official app or website, closes off the initial pretext before it can progress.

4OTP solicitation and interception
What happened

Having primed the victim to expect a one-time SMS PIN "for authorisation" of the fake upgrade, the offender obtained that PIN once it arrived. AFP and court reporting describe it as "intercepted" without detailing the precise mechanism, consistent with real-time social engineering during the call, such as talking the victim into reading it back, rather than a SIM-swap or network-level interception.

The control that would have stopped it

The single highest-leverage control in this case: never read out, forward, or otherwise share an incoming SMS one-time PIN with anyone who calls or messages you, since a genuine "authorisation" step never requires disclosing the OTP to another person; this one behavior change would have stopped the fraud regardless of how convincing the earlier pretext was.

5Fraudulent purchase and delivery rerouting
What happened

Using the OTP, the offender authorized a high-end mobile device or tablet purchase on the victim's own carrier account, frequently drawing on payment details already saved to that account, then had the order shipped to a delivery address he controlled instead of the victim's actual address.

The control that would have stopped it

Carrier-side step-up authentication for high-value device purchases and shipping-address changes, such as requiring a second verification factor beyond a single SMS OTP, a mandatory hold period, or an outbound confirmation call before a new delivery address is accepted on an existing account, would have blocked the fraudulent order even after the OTP was compromised.

6Reshipping and offshore resale
What happened

The fraudulently obtained devices were allegedly sent offshore for resale, moving the stolen goods outside domestic retail and secondhand channels where a carrier or law enforcement would be more likely to trace them back to a victim's account.

The control that would have stopped it

Monitoring high-end device IMEIs for bulk resale or export shortly after purchase, and cooperation between carriers, retailers, and customs or freight-export screening to flag newly purchased or unactivated devices being shipped offshore in volume, can disrupt the resale channel that turns stolen phones into cash.

7Proceeds retention (objective completion)
What happened

Sale proceeds were converted into and held largely as physical cash; more than $1 million AUD was found hidden in suitcases and Louis Vuitton bags at the offender's home rather than banked, consistent with an attempt to keep large scam proceeds outside routine financial-system monitoring until AFP's search and seizure.

The control that would have stopped it

Anti-money-laundering reporting on large undeclared cash holdings and financial-intelligence sharing between banks and law enforcement are the realistic backstop once proceeds have already been converted to physical currency; in this case it was AFP's own search-warrant seizure, prompted by the cross-carrier fraud pattern identified in earlier stages, that ultimately recovered the cash and supported the proceeds-of-crime charge.

Quick Facts
Victim
More than 100 Australian mobile customers of Optus
and TPG Telecom, defrauded of high-end mobile devices via their own carrier accounts.
Location
Sydney (Auburn, western Sydney, New South Wales), Australia; victims located across Australia
Date
Mar 2023
(investigation opened) to 27 Nov 2024 (arrest); charged 28 Nov 2024; bail refused 2 Dec 2024; next court date 29 Jan 2025 (case status: on remand, allegations not yet tried at time of research)
Impact
More than AUD $1,000,000 in cash found hidden in suitcases and Louis Vuitton bags at the offender's Auburn home, seized by AFP during the 27 Nov 2024 search.
The AFP media release states this same search also recovered over 500 SIM cards and 21 electronic devices (laptops, phones) containing credit cards and financial documents; separately, the AAP court report of the 2 Dec 2024 bail hearing states the November search additionally turned up nine more mobile phones and 300 SIM cards (on top of 111 unauthorized credit reports found on a phone seized in August 2024). These two sets of figures are not clearly reconciled in the sources reviewed; they may describe the same search reported inconsistently by AFP comms versus the Crown prosecutor in court, rather than strictly additive totals. He was separately charged with dealing in proceeds of crime valued at $1,000,000+ under s400.3(1) of the Criminal Code. No aggregate victim-loss total (retail value of the "hundreds" of fraudulently obtained high-end mobile devices) was disclosed by AFP; ScamWatch data cited in the same release recorded ~34,000 phone-scam reports and ~$71 million in total 2024 losses to the Australian economy (not specific to this case).
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Telecommunications
Threat Actor
Organized Crime
Explore more

Related Cases

Browse by what this case has in common with others in the library.

iSpoof Caller-ID Spoofing-as-a-Service Platform (Tejay Fletcher)

Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank.

Incident 2020Read →

Bank Fraud-Team Impersonation Vishing Drains Scottish Small Businesses: Perth (£31,000, 2019) and Handmade Craft House, Dumfries (£5,000+, 2026)

Two Scottish small businesses lost £31,000 and over £5,000 after callers impersonating bank fraud-team staff talked owners into wiring money.

Incident 2019Read →

Arup Hong Kong Deepfake CFO Video-Call Fraud (HK$200M / US$25.6M)

A finance employee in Arup's Hong Kong office wired HK$200M (~US$25.6M) after a video conference in which the CFO and…

Incident 2024Read →

Doorstep Dispensaree: Unsecured Patient Records Found in a Pharmacy's Back Yard Trigger the ICO's First GDPR Fine (2019)

An unrelated MHRA search warrant found care-home patient prescription and NHS records rotting in unlocked crates and bin bags at…

Incident 2018Read →

Robertson, Smith & Kempson Estate Agent Refuse Sack Data Exposure (2013-2014)

A Metropolitan Police officer spotted customers' passports and tax-credit paperwork clearly visible through transparent bin bags left on the street.

Incident 2013Read →

UK Council Car Park QR Code ("Quishing") Scams - Cheltenham, Swindon & Somerset

Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.

Incident 2024Read →