Case Library / Vishing (Voice Phishing) / Optus/TPG Telecom OTP-Interception Mobile-Upgrade Vishing Fraud (Sydney, 2023-2024)

Optus/TPG Telecom OTP-Interception Mobile-Upgrade Vishing Fraud (Sydney, 2023-2024)

A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support, tricking 100+ Australians into receiving "maintenance"/upgrade-related SMS one-time PINs that he intercepted to fraudulently buy and reroute high-end phones for offshore resale, netting more than AUD $1 million in seized cash before his November 2024 arrest.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Beginning around March 2023, Optus and TPG Telecom alerted the AFP-led Joint Policing Cybercrime Coordination Centre (JPC3) to a pattern of fraudulent high-end device orders being placed on customer accounts. Investigators established that a caller (or callers) impersonating a telecommunications company representative had been contacting customers, telling them their mobile service needed "maintenance" or offering a discount on a new device, then having a one-time SMS PIN sent to the victim "for authorisation," which the offender intercepted and used to complete a device purchase on the victim's own account (often using saved payment details) before rerouting delivery to another address. Devices were allegedly then sent offshore for resale. The scheme was linked to more than 100 Australian victims. On 27 November 2024, AFP investigators arrested a 21-year-old Pakistani national at his home in Auburn, western Sydney, and executed a search warrant that allegedly turned up more than $1 million AUD in cash (hidden in suitcases and Louis Vuitton bags), over 500 SIM cards, and 21 electronic devices containing credit cards and financial documentation. He was charged the next day (28 November 2024) and named in subsequent court reporting as Muhammad Akhtar. A Downing Centre Local Court hearing on 2 December 2024 heard that his phone (seized in August 2024) contained 111 credit reports generated on victims' identities without consent, and that the November search also turned up nine more mobile phones and 300 additional SIM cards, a figure that does not clearly reconcile with the AFP release's own count of 500+ SIM cards and 21 devices from the same search, possibly reflecting inconsistent reporting of the same haul rather than a separate additive tally; he was refused bail as a flight risk given Australia has no extradition treaty with Pakistan.

How the Attack Worked

The offender (or accomplices) cold-called Optus and TPG Telecom customers, impersonating a telecommunications company representative. The pretext was either that the victim's mobile service was undergoing "maintenance" or that they were eligible for a discount/free upgrade on a new device. Once engaged, the caller told the victim to expect a one-time PIN (OTP) sent by SMS "for authorisation" of the upgrade, then intercepted that OTP and used it to complete a device purchase on the victim's own carrier account, frequently drawing on saved payment details already on file. The order was rerouted to a delivery address controlled by the offender rather than the victim's address, and the devices were allegedly funneled offshore for resale. Victims typically discovered the fraud only when the "upgraded" device never arrived and they called their carrier, at which point the carrier's fraud team could trace many orders back to the same identity. Investigators separately found the offender's seized phone held 111 credit reports generated on victims' identities without consent, pointing to a broader identity-data harvesting operation feeding the calls with victim-specific details that made the "your account" pretext convincing.

The Lure & the Tell

Lure: an inbound call from someone claiming to be from the victim's own telco (Optus or TPG), saying either that the mobile service needed "maintenance" or that the customer qualified for a discount/free upgrade on a new handset, playing on trust in a known, already-relied-upon brand plus the appeal of a free premium device. The tell victims should have caught: legitimate telcos do not call customers unprompted and then ask them to read back or otherwise share an incoming SMS one-time PIN; a real "authorisation" step never requires disclosing the OTP to the person on the phone. The actual giveaway for the real victims here was passive rather than active: they only became suspicious after the promised new device never arrived, at which point they called their carrier directly and the fraud was traced.

Outcome

Muhammad Akhtar, 21, a Pakistani national on a student visa (studying IT while working for Uber/Uber Eats), was arrested 27 November 2024 and charged the next day with (1) dishonestly obtaining/dealing in personal financial information (s480.4 Criminal Code 1995 Cth, max 5 years) and (2) dealing with money/property valued at $1,000,000+ believed to be proceeds of indictable crime (s400.3(1), max 25 years). He appeared at Downing Centre Local Court and was refused bail on 2 December 2024; the judge called the alleged offending "high level, sophisticated, targeted (and) well-planned," and the defense barrister conceded the Crown had a strong case. Court heard that his phone (seized in August 2024) contained 111 credit reports generated on victims' identities without consent, and that the November search also turned up nine more mobile phones and 300 additional SIM cards, a figure reported in court (via AAP) that does not clearly reconcile with the AFP media release's statement that the same 27 November search recovered over 500 SIM cards and 21 electronic devices; the two accounts may describe the same haul reported inconsistently rather than as additive totals. Court heard suggestions that Akhtar's brother-in-law and sister were also involved via scheme-related group chats, though as of the reporting reviewed, Akhtar was the only person charged and the AFP said further charges were expected. The matter was set to return to court 29 January 2025; no conviction or sentencing outcome was identified in the sources reviewed for this record, so the specific criminal allegations against Akhtar remain unproven pending trial even though the AFP-led investigation, arrest and seizures are confirmed by primary AFP reporting.

Why It Matters

This case shows how a routine, high-trust customer-service interaction (an inbound "your telco" call about maintenance or a device upgrade) can be weaponized into a full-blown OTP-interception fraud pipeline at scale (100+ victims over ~20 months) without any exotic technical exploit: the entire compromise rode on the victim being talked into treating an SMS one-time PIN as something to share or act on for a caller-initiated "authorisation," rather than a secret the victim alone should complete. It also illustrates the value of cross-carrier and law-enforcement collaboration (Optus + TPG + AFP/JPC3) in spotting a single offender's fingerprint across two competing telcos' customer bases, and how identity-data harvesting (unauthorized credit-report pulls) can feed the pretext used in the calls, making a generic-sounding vishing script far more convincing to each specific victim.

Defenses

Optus and TPG Telecom flagged the anomalous device-upgrade/OTP pattern to the AFP-led JPC3 (Joint Policing Cybercrime Coordination Centre) rather than treating individual cases in isolation, which let investigators link one offender to 100+ victims over ~20 months. AFP's public guidance after the case: never trust an inbound caller claiming to be your telco; hang up and call the company back only via the number on its official website/app; never read out or forward an SMS one-time PIN to anyone, including someone who says they are "verifying" you; watch for signs of account tampering (unexpected "maintenance" claims, unsolicited discount/upgrade offers, an OTP arriving that you did not request); if an expected new/replacement device does not arrive, contact the carrier immediately rather than assuming courier delay. Carrier-side controls implicated: delivery-address changes and high-value device purchases authorized by a single SMS OTP were exploitable step-up authentication for account changes/shipping-address changes, and monitoring for bulk SIM/credit-report anomalies tied to one identity.

Sources
  • Pakistan man charged for dealing with more than $1 million derived from scams. Australian Federal Police (joint release with Optus and TPG Telecom) Primary. Verified by direct fetch on 2026-07-29: loads correctly and confirms investigation timeline (opened Mar 2023), method description, 27 Nov 2024 arrest, 28 Nov 2024 charges, seizure figures (>$1M cash, 500+ SIM cards, 21 devices), and AFP/Optus/TPG statements including the ScamWatch ~34,000-reports/~$71M figures.
  • Accused scammer found with $1m cash, Louis Vuitton bags. AAP News (Australian Associated Press) Secondary. Verified by direct fetch on 2026-07-29: loads correctly and confirms Downing Centre Local Court reporting (2 Dec 2024), names the accused (Muhammad Akhtar, 21), bail refusal, Judge Michael Allen's and prosecutor Edward Jude's remarks, no-extradition-treaty point, and additional seizure details (111 credit reports, 9 more phones, 300 SIM cards).
  • Pakistan Man Charged in $1M Scam Scheme. Mirage News Secondary. Verified by direct fetch on 2026-07-29: loads correctly and is a near-verbatim republication of the AFP release, independently corroborating the same timeline and figures.
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and identity-data sourcing: Court reporting on the offender's seized phone found 111 credit reports generated on victims' identities without their consent, consistent with using unauthorized credit-report pulls and other harvested personal data to build a profile of a real customer's name, phone number, and telco billing details before making contact, the kind of preparatory identity-data gathering that let each call sound tailored to that specific victim's account.
Countering Stage 1: Consumers cannot easily prevent someone from pulling an unauthorized credit report in their name, but credit bureaus and lenders can add anomaly detection for repeated report requests tied to one requester, and individuals can use free credit-monitoring or credit-freeze services that alert them whenever a new report is generated in their name, catching this stage after the fact rather than blocking it outright.
2
Target and carrier identification: Victims were current Optus or TPG Telecom customers, so the offender likely needed to establish which telco a given phone number or identity was actually subscribed to before calling, whether through the harvested account data itself or simply by having each call open with confirming the victim's provider.
Countering Stage 2: This step rides on data already exposed in Stage 1, so the more effective control is the same one that limits how much account-specific detail an attacker can bring to the call in Stage 3, rather than a control aimed at carrier identification itself.
3
Initial contact vishing: The offender or an associate cold-called victims, impersonating a representative of the victim's own telecommunications provider (Optus or TPG Telecom), opening with a pretext that the mobile service needed "maintenance" or that the customer qualified for a free or discounted device upgrade, exploiting the built-in trust of what appeared to be an inbound call from the victim's own carrier.
Countering Stage 3: Consumer-facing guidance, reinforced by AFP's own post-case advice, that a legitimate telco does not cold-call customers about unscheduled "maintenance" or unprompted device upgrades, and that any such call should be ended so the customer can call back only via the number on the provider's official app or website, closes off the initial pretext before it can progress.
4
OTP solicitation and interception: Having primed the victim to expect a one-time SMS PIN "for authorisation" of the fake upgrade, the offender obtained that PIN once it arrived. AFP and court reporting describe it as "intercepted" without detailing the precise mechanism, consistent with real-time social engineering during the call, such as talking the victim into reading it back, rather than a SIM-swap or network-level interception.
Countering Stage 4: The single highest-leverage control in this case: never read out, forward, or otherwise share an incoming SMS one-time PIN with anyone who calls or messages you, since a genuine "authorisation" step never requires disclosing the OTP to another person; this one behavior change would have stopped the fraud regardless of how convincing the earlier pretext was.
5
Fraudulent purchase and delivery rerouting: Using the OTP, the offender authorized a high-end mobile device or tablet purchase on the victim's own carrier account, frequently drawing on payment details already saved to that account, then had the order shipped to a delivery address he controlled instead of the victim's actual address.
Countering Stage 5: Carrier-side step-up authentication for high-value device purchases and shipping-address changes, such as requiring a second verification factor beyond a single SMS OTP, a mandatory hold period, or an outbound confirmation call before a new delivery address is accepted on an existing account, would have blocked the fraudulent order even after the OTP was compromised.
6
Reshipping and offshore resale: The fraudulently obtained devices were allegedly sent offshore for resale, moving the stolen goods outside domestic retail and secondhand channels where a carrier or law enforcement would be more likely to trace them back to a victim's account.
Countering Stage 6: Monitoring high-end device IMEIs for bulk resale or export shortly after purchase, and cooperation between carriers, retailers, and customs or freight-export screening to flag newly purchased or unactivated devices being shipped offshore in volume, can disrupt the resale channel that turns stolen phones into cash.
7
Proceeds retention (objective completion): Sale proceeds were converted into and held largely as physical cash; more than $1 million AUD was found hidden in suitcases and Louis Vuitton bags at the offender's home rather than banked, consistent with an attempt to keep large scam proceeds outside routine financial-system monitoring until AFP's search and seizure.
Countering Stage 7: Anti-money-laundering reporting on large undeclared cash holdings and financial-intelligence sharing between banks and law enforcement are the realistic backstop once proceeds have already been converted to physical currency; in this case it was AFP's own search-warrant seizure, prompted by the cross-carrier fraud pattern identified in earlier stages, that ultimately recovered the cash and supported the proceeds-of-crime charge.
Quick Facts
Victim
More than 100 Australian mobile customers of Optus and TPG Telecom, defrauded of high-end mobile devices via their own carrier accounts.
Location
Sydney (Auburn, western Sydney, New South Wales), Australia; victims located across Australia
Date
Mar 2023 (investigation opened) to 27 Nov 2024 (arrest); charged 28 Nov 2024; bail refused 2 Dec 2024; next court date 29 Jan 2025 (case status: on remand, allegations not yet tried at time of research)
Impact
More than AUD $1,000,000 in cash found hidden in suitcases and Louis Vuitton bags at the offender's Auburn home, seized by AFP during the 27 Nov 2024 search. The AFP media release states this same search also recovered over 500 SIM cards and 21 electronic devices (laptops, phones) containing credit cards and financial documents; separately, the AAP court report of the 2 Dec 2024 bail hearing states the November search additionally turned up nine more mobile phones and 300 SIM cards (on top of 111 unauthorized credit reports found on a phone seized in August 2024). These two sets of figures are not clearly reconciled in the sources reviewed; they may describe the same search reported inconsistently by AFP comms versus the Crown prosecutor in court, rather than strictly additive totals. He was separately charged with dealing in proceeds of crime valued at $1,000,000+ under s400.3(1) of the Criminal Code. No aggregate victim-loss total (retail value of the "hundreds" of fraudulently obtained high-end mobile devices) was disclosed by AFP; ScamWatch data cited in the same release recorded ~34,000 phone-scam reports and ~$71 million in total 2024 losses to the Australian economy (not specific to this case).
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Telecommunications
Threat Actor
Organized Crime
Related

Related Cases

SABRIC-Documented Vishing and SIM-Swap Fraud Surge Against South African Bank Customers (2023-2025)

SABRIC's own Annual Crime Statistics reports document a sustained, industry-wide surge in vishing- and SIM-swap-driven digital banking fraud across South…

Incident 2023Read →

Retool smishing + deepfake vishing breach (2023)

A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…

Incident 2023Read →

MGM Resorts Help-Desk Vishing Breach (Scattered Spider, 2023)

A roughly ten-minute phone call impersonating an MGM employee to the IT help desk let Scattered Spider reset MFA, seize…

Incident 2023Read →