A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support, tricking 100+ Australians into receiving "maintenance"/upgrade-related SMS one-time PINs that he intercepted to fraudulently buy and reroute high-end phones for offshore resale, netting more than AUD $1 million in seized cash before his November 2024 arrest.
Reviewed by the Social Engineering Examples team.
Beginning around March 2023, Optus and TPG Telecom alerted the AFP-led Joint Policing Cybercrime Coordination Centre (JPC3) to a pattern of fraudulent high-end device orders being placed on customer accounts. Investigators established that a caller (or callers) impersonating a telecommunications company representative had been contacting customers, telling them their mobile service needed "maintenance" or offering a discount on a new device, then having a one-time SMS PIN sent to the victim "for authorisation," which the offender intercepted and used to complete a device purchase on the victim's own account (often using saved payment details) before rerouting delivery to another address. Devices were allegedly then sent offshore for resale. The scheme was linked to more than 100 Australian victims. On 27 November 2024, AFP investigators arrested a 21-year-old Pakistani national at his home in Auburn, western Sydney, and executed a search warrant that allegedly turned up more than $1 million AUD in cash (hidden in suitcases and Louis Vuitton bags), over 500 SIM cards, and 21 electronic devices containing credit cards and financial documentation. He was charged the next day (28 November 2024) and named in subsequent court reporting as Muhammad Akhtar. A Downing Centre Local Court hearing on 2 December 2024 heard that his phone (seized in August 2024) contained 111 credit reports generated on victims' identities without consent, and that the November search also turned up nine more mobile phones and 300 additional SIM cards, a figure that does not clearly reconcile with the AFP release's own count of 500+ SIM cards and 21 devices from the same search, possibly reflecting inconsistent reporting of the same haul rather than a separate additive tally; he was refused bail as a flight risk given Australia has no extradition treaty with Pakistan.
The offender (or accomplices) cold-called Optus and TPG Telecom customers, impersonating a telecommunications company representative. The pretext was either that the victim's mobile service was undergoing "maintenance" or that they were eligible for a discount/free upgrade on a new device. Once engaged, the caller told the victim to expect a one-time PIN (OTP) sent by SMS "for authorisation" of the upgrade, then intercepted that OTP and used it to complete a device purchase on the victim's own carrier account, frequently drawing on saved payment details already on file. The order was rerouted to a delivery address controlled by the offender rather than the victim's address, and the devices were allegedly funneled offshore for resale. Victims typically discovered the fraud only when the "upgraded" device never arrived and they called their carrier, at which point the carrier's fraud team could trace many orders back to the same identity. Investigators separately found the offender's seized phone held 111 credit reports generated on victims' identities without consent, pointing to a broader identity-data harvesting operation feeding the calls with victim-specific details that made the "your account" pretext convincing.
Lure: an inbound call from someone claiming to be from the victim's own telco (Optus or TPG), saying either that the mobile service needed "maintenance" or that the customer qualified for a discount/free upgrade on a new handset, playing on trust in a known, already-relied-upon brand plus the appeal of a free premium device. The tell victims should have caught: legitimate telcos do not call customers unprompted and then ask them to read back or otherwise share an incoming SMS one-time PIN; a real "authorisation" step never requires disclosing the OTP to the person on the phone. The actual giveaway for the real victims here was passive rather than active: they only became suspicious after the promised new device never arrived, at which point they called their carrier directly and the fraud was traced.
Muhammad Akhtar, 21, a Pakistani national on a student visa (studying IT while working for Uber/Uber Eats), was arrested 27 November 2024 and charged the next day with (1) dishonestly obtaining/dealing in personal financial information (s480.4 Criminal Code 1995 Cth, max 5 years) and (2) dealing with money/property valued at $1,000,000+ believed to be proceeds of indictable crime (s400.3(1), max 25 years). He appeared at Downing Centre Local Court and was refused bail on 2 December 2024; the judge called the alleged offending "high level, sophisticated, targeted (and) well-planned," and the defense barrister conceded the Crown had a strong case. Court heard that his phone (seized in August 2024) contained 111 credit reports generated on victims' identities without consent, and that the November search also turned up nine more mobile phones and 300 additional SIM cards, a figure reported in court (via AAP) that does not clearly reconcile with the AFP media release's statement that the same 27 November search recovered over 500 SIM cards and 21 electronic devices; the two accounts may describe the same haul reported inconsistently rather than as additive totals. Court heard suggestions that Akhtar's brother-in-law and sister were also involved via scheme-related group chats, though as of the reporting reviewed, Akhtar was the only person charged and the AFP said further charges were expected. The matter was set to return to court 29 January 2025; no conviction or sentencing outcome was identified in the sources reviewed for this record, so the specific criminal allegations against Akhtar remain unproven pending trial even though the AFP-led investigation, arrest and seizures are confirmed by primary AFP reporting.
This case shows how a routine, high-trust customer-service interaction (an inbound "your telco" call about maintenance or a device upgrade) can be weaponized into a full-blown OTP-interception fraud pipeline at scale (100+ victims over ~20 months) without any exotic technical exploit: the entire compromise rode on the victim being talked into treating an SMS one-time PIN as something to share or act on for a caller-initiated "authorisation," rather than a secret the victim alone should complete. It also illustrates the value of cross-carrier and law-enforcement collaboration (Optus + TPG + AFP/JPC3) in spotting a single offender's fingerprint across two competing telcos' customer bases, and how identity-data harvesting (unauthorized credit-report pulls) can feed the pretext used in the calls, making a generic-sounding vishing script far more convincing to each specific victim.
Optus and TPG Telecom flagged the anomalous device-upgrade/OTP pattern to the AFP-led JPC3 (Joint Policing Cybercrime Coordination Centre) rather than treating individual cases in isolation, which let investigators link one offender to 100+ victims over ~20 months. AFP's public guidance after the case: never trust an inbound caller claiming to be your telco; hang up and call the company back only via the number on its official website/app; never read out or forward an SMS one-time PIN to anyone, including someone who says they are "verifying" you; watch for signs of account tampering (unexpected "maintenance" claims, unsolicited discount/upgrade offers, an OTP arriving that you did not request); if an expected new/replacement device does not arrive, contact the carrier immediately rather than assuming courier delay. Carrier-side controls implicated: delivery-address changes and high-value device purchases authorized by a single SMS OTP were exploitable step-up authentication for account changes/shipping-address changes, and monitoring for bulk SIM/credit-report anomalies tied to one identity.
SABRIC's own Annual Crime Statistics reports document a sustained, industry-wide surge in vishing- and SIM-swap-driven digital banking fraud across South…
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
A roughly ten-minute phone call impersonating an MGM employee to the IT help desk let Scattered Spider reset MFA, seize…