A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support.
Social Engineering Examples·3 sources
Beginning around March 2023, Optus and TPG Telecom alerted the AFP-led Joint Policing Cybercrime Coordination Centre (JPC3) to a pattern of fraudulent high-end device orders being placed on customer accounts. Investigators established that a caller (or callers) impersonating a telecommunications company representative had been contacting customers, telling them their mobile service needed "maintenance" or offering a discount on a new device, then having a one-time SMS PIN sent to the victim "for authorisation," which the offender intercepted and used to complete a device purchase on the victim's own account (often using saved payment details) before rerouting delivery to another address.
Devices were allegedly then sent offshore for resale. The scheme was linked to more than 100 Australian victims. On 27 November 2024, AFP investigators arrested a 21-year-old Pakistani national at his home in Auburn, western Sydney, and executed a search warrant that allegedly turned up more than $1 million AUD in cash (hidden in suitcases and Louis Vuitton bags), over 500 SIM cards, and 21 electronic devices containing credit cards and financial documentation.
He was charged the next day (28 November 2024) and named in subsequent court reporting as Muhammad Akhtar. A Downing Centre Local Court hearing on 2 December 2024 heard that his phone (seized in August 2024) contained 111 credit reports generated on victims' identities without consent, and that the November search also turned up nine more mobile phones and 300 additional SIM cards, a figure that does not clearly reconcile with the AFP release's own count of 500+ SIM cards and 21 devices from the same search, possibly reflecting inconsistent reporting of the same haul rather than a separate additive tally; he was refused bail as a flight risk given Australia has no extradition treaty with Pakistan.
The offender (or accomplices) cold-called Optus and TPG Telecom customers, impersonating a telecommunications company representative. The pretext was either that the victim's mobile service was undergoing "maintenance" or that they were eligible for a discount/free upgrade on a new device. Once engaged, the caller told the victim to expect a one-time PIN (OTP) sent by SMS "for authorisation" of the upgrade, then intercepted that OTP and used it to complete a device purchase on the victim's own carrier account, frequently drawing on saved payment details already on file.
The order was rerouted to a delivery address controlled by the offender rather than the victim's address, and the devices were allegedly funneled offshore for resale. Victims typically discovered the fraud only when the "upgraded" device never arrived and they called their carrier, at which point the carrier's fraud team could trace many orders back to the same identity.
Investigators separately found the offender's seized phone held 111 credit reports generated on victims' identities without consent, pointing to a broader identity-data harvesting operation feeding the calls with victim-specific details that made the "your account" pretext convincing.
Lure: an inbound call from someone claiming to be from the victim's own telco (Optus or TPG), saying either that the mobile service needed "maintenance" or that the customer qualified for a discount/free upgrade on a new handset, playing on trust in a known, already-relied-upon brand plus the appeal of a free premium device. The tell victims should have caught: legitimate telcos do not call customers unprompted and then ask them to read back or otherwise share an incoming SMS one-time PIN; a real "authorisation" step never requires disclosing the OTP to the person on the phone.
The actual giveaway for the real victims here was passive rather than active: they only became suspicious after the promised new device never arrived, at which point they called their carrier directly and the fraud was traced.
Muhammad Akhtar, 21, a Pakistani national on a student visa (studying IT while working for Uber/Uber Eats), was arrested 27 November 2024 and charged the next day with (1) dishonestly obtaining/dealing in personal financial information (s480.4 Criminal Code 1995 Cth, max 5 years) and (2) dealing with money/property valued at $1,000,000+ believed to be proceeds of indictable crime (s400.3(1), max 25 years).
He appeared at Downing Centre Local Court and was refused bail on 2 December 2024; the judge called the alleged offending "high level, sophisticated, targeted (and) well-planned," and the defense barrister conceded the Crown had a strong case. Court heard that his phone (seized in August 2024) contained 111 credit reports generated on victims' identities without consent, and that the November search also turned up nine more mobile phones and 300 additional SIM cards, a figure reported in court (via AAP) that does not clearly reconcile with the AFP media release's statement that the same 27 November search recovered over 500 SIM cards and 21 electronic devices; the two accounts may describe the same haul reported inconsistently rather than as additive totals.
Court heard suggestions that Akhtar's brother-in-law and sister were also involved via scheme-related group chats, though as of the reporting reviewed, Akhtar was the only person charged and the AFP said further charges were expected. The matter was set to return to court 29 January 2025; no conviction or sentencing outcome was identified in the sources reviewed for this record, so the specific criminal allegations against Akhtar remain unproven pending trial even though the AFP-led investigation, arrest and seizures are confirmed by primary AFP reporting.
This case shows how a routine, high-trust customer-service interaction (an inbound "your telco" call about maintenance or a device upgrade) can be weaponized into a full-blown OTP-interception fraud pipeline at scale (100+ victims over ~20 months) without any exotic technical exploit: the entire compromise rode on the victim being talked into treating an SMS one-time PIN as something to share or act on for a caller-initiated "authorisation," rather than a secret the victim alone should complete.
It also illustrates the value of cross-carrier and law-enforcement collaboration (Optus + TPG + AFP/JPC3) in spotting a single offender's fingerprint across two competing telcos' customer bases, and how identity-data harvesting (unauthorized credit-report pulls) can feed the pretext used in the calls, making a generic-sounding vishing script far more convincing to each specific victim.
Optus and TPG Telecom flagged the anomalous device-upgrade/OTP pattern to the AFP-led JPC3 (Joint Policing Cybercrime Coordination Centre) rather than treating individual cases in isolation, which let investigators link one offender to 100+ victims over ~20 months. AFP's public guidance after the case: never trust an inbound caller claiming to be your telco; hang up and call the company back only via the number on its official website/app; never read out or forward an SMS one-time PIN to anyone, including someone who says they are "verifying" you; watch for signs of account tampering (unexpected "maintenance" claims, unsolicited discount/upgrade offers, an OTP arriving that you did not request); if an expected new/replacement device does not arrive, contact the carrier immediately rather than assuming courier delay.
Carrier-side controls implicated: delivery-address changes and high-value device purchases authorized by a single SMS OTP were exploitable step-up authentication for account changes/shipping-address changes, and monitoring for bulk SIM/credit-report anomalies tied to one identity.
Social Engineering Examples. “Optus/TPG Telecom OTP-Interception Mobile-Upgrade Vishing Fraud (Sydney, 2023-2024)”. Accessed 19 September 2026. https://socialengineeringexamples.com/optus-tpg-otp-interception-vishing-2024
Court reporting on the offender's seized phone found 111 credit reports generated on victims' identities without their consent, consistent with using unauthorized credit-report pulls and other harvested personal data to build a profile of a real customer's name, phone number, and telco billing details before making contact, the kind of preparatory identity-data gathering that let each call sound tailored to that specific victim's account.
Consumers cannot easily prevent someone from pulling an unauthorized credit report in their name, but credit bureaus and lenders can add anomaly detection for repeated report requests tied to one requester, and individuals can use free credit-monitoring or credit-freeze services that alert them whenever a new report is generated in their name, catching this stage after the fact rather than blocking it outright.
Victims were current Optus or TPG Telecom customers, so the offender likely needed to establish which telco a given phone number or identity was actually subscribed to before calling, whether through the harvested account data itself or simply by having each call open with confirming the victim's provider.
This step rides on data already exposed in Stage 1, so the more effective control is the same one that limits how much account-specific detail an attacker can bring to the call in Stage 3, rather than a control aimed at carrier identification itself.
The offender or an associate cold-called victims, impersonating a representative of the victim's own telecommunications provider (Optus or TPG Telecom), opening with a pretext that the mobile service needed "maintenance" or that the customer qualified for a free or discounted device upgrade, exploiting the built-in trust of what appeared to be an inbound call from the victim's own carrier.
Consumer-facing guidance, reinforced by AFP's own post-case advice, that a legitimate telco does not cold-call customers about unscheduled "maintenance" or unprompted device upgrades, and that any such call should be ended so the customer can call back only via the number on the provider's official app or website, closes off the initial pretext before it can progress.
Having primed the victim to expect a one-time SMS PIN "for authorisation" of the fake upgrade, the offender obtained that PIN once it arrived. AFP and court reporting describe it as "intercepted" without detailing the precise mechanism, consistent with real-time social engineering during the call, such as talking the victim into reading it back, rather than a SIM-swap or network-level interception.
The single highest-leverage control in this case: never read out, forward, or otherwise share an incoming SMS one-time PIN with anyone who calls or messages you, since a genuine "authorisation" step never requires disclosing the OTP to another person; this one behavior change would have stopped the fraud regardless of how convincing the earlier pretext was.
Using the OTP, the offender authorized a high-end mobile device or tablet purchase on the victim's own carrier account, frequently drawing on payment details already saved to that account, then had the order shipped to a delivery address he controlled instead of the victim's actual address.
Carrier-side step-up authentication for high-value device purchases and shipping-address changes, such as requiring a second verification factor beyond a single SMS OTP, a mandatory hold period, or an outbound confirmation call before a new delivery address is accepted on an existing account, would have blocked the fraudulent order even after the OTP was compromised.
The fraudulently obtained devices were allegedly sent offshore for resale, moving the stolen goods outside domestic retail and secondhand channels where a carrier or law enforcement would be more likely to trace them back to a victim's account.
Monitoring high-end device IMEIs for bulk resale or export shortly after purchase, and cooperation between carriers, retailers, and customs or freight-export screening to flag newly purchased or unactivated devices being shipped offshore in volume, can disrupt the resale channel that turns stolen phones into cash.
Sale proceeds were converted into and held largely as physical cash; more than $1 million AUD was found hidden in suitcases and Louis Vuitton bags at the offender's home rather than banked, consistent with an attempt to keep large scam proceeds outside routine financial-system monitoring until AFP's search and seizure.
Anti-money-laundering reporting on large undeclared cash holdings and financial-intelligence sharing between banks and law enforcement are the realistic backstop once proceeds have already been converted to physical currency; in this case it was AFP's own search-warrant seizure, prompted by the cross-carrier fraud pattern identified in earlier stages, that ultimately recovered the cash and supported the proceeds-of-crime charge.
Browse by what this case has in common with others in the library.
SABRIC's own Annual Crime Statistics reports document a sustained, industry-wide surge in vishing- and SIM-swap-driven digital banking fraud across South.
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
Scattered Spider's ten-minute vishing call to MGM's help desk reset MFA and seized identity systems, an incident Moody's called credit-negative.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
In June 2025 the DOJ filed a civil forfeiture complaint against more than $225.3M in Tether (USDT) traced to a…
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…
An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims.
The FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters…
A scammer posing as GCI's CFO emailed payroll and, after the employee's initial pushback, persuaded them to hand over 2015…
A Taiwan-linked money courier was caught in an Austin bank sting while collecting part of the $1.4 million a victim…
Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank.
Two Scottish small businesses lost £31,000 and over £5,000 after callers impersonating bank fraud-team staff talked owners into wiring money.
A finance employee in Arup's Hong Kong office wired HK$200M (~US$25.6M) after a video conference in which the CFO and…
An unrelated MHRA search warrant found care-home patient prescription and NHS records rotting in unlocked crates and bin bags at…
A Metropolitan Police officer spotted customers' passports and tax-credit paperwork clearly visible through transparent bin bags left on the street.
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
Fraudsters posing as RBS fraud-team staff talked Hamilton Academical FC's banking employee into moving nearly £1 million to fake accounts.
A Singaporean finance professional in her 50s lost S$1.2 million.
A revived Lampion banking-trojan campaign spoofed Portugal's tax authority site to trick victims into pasting a PowerShell command into the…
Scattered Spider's ten-minute vishing call to MGM's help desk reset MFA and seized identity systems, an incident Moody's called credit-negative.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.