Summary
- Mobile number porting lets a customer keep the same number when moving to another provider. Because control of the number moves, the gaining carrier must verify that the requester is entitled to use it and has access to the associated device.
- The Australian Communications and Media Authority, or ACMA, said Southern Phone breached anti-scam requirements on 168 occasions over eight months between July 2024 and February 2025. Scammers could manipulate its systems and bypass the required checks.
- Twenty consumers reported combined losses of at least A$393,000 after scammers gained control of mobile-number services and accessed bank accounts. That figure is a reported minimum, not a complete valuation of every effect and not a claim that every one of the 168 occasions produced a bank loss.
- Southern Phone paid an A$2,500,560 infringement penalty. The undertaking began on 20 November 2025 with a 36-month base term, but ACMA varied it on 27 February 2026 after Southern Phone represented that it expected to transfer its Australian mobile customers and cease direct mobile service by December 2026. Current review, monitoring and training duties must therefore be read from the varied instrument.
- The lasting accountability lesson is operational: a policy is not a control until the running customer path resists realistic bypass attempts and produces evidence that supervisors can inspect.
What happened
Mobile number portability is meant to help competition and continuity. A customer can change provider without giving up the number through which people and services already reach them. The old carrier is commonly called the losing provider. The new carrier is the gaining provider. A port is the coordinated process that moves the number's service to that gaining provider.
The benefit is obvious. A person does not need to tell every contact, business and public service that their number has changed. The risk is equally important. If the requester is not the legitimate customer, the same continuity feature can transfer control to a fraudster while everyone else continues to trust the familiar number.
ACMA's public statement says Southern Phone breached the rules on 168 occasions during an eight-month period between July 2024 and February 2025. Scammers were able to manipulate the company's systems to bypass identity-verification processes required before a number transfer. They gained control of consumers' mobile-number services and accessed bank accounts. Twenty consumers reported combined losses of at least A$393,000.
The regulator's legal documents add detail about the control boundary. Southern Phone was acting as the gaining carriage service provider for the relevant ports. The applicable pre-port verification standard required it, before initiating a transfer, to use an additional identity-verification process to confirm that the requester was the person entitled to use the number, or an authorised representative, and had access to a device associated with it. The provider was not supposed to proceed without that additional verification.
Southern Phone had systems intended to prevent a port until the check succeeded. Yet the court-enforceable undertaking records that, shortly after ACMA began its investigation in March 2025, the company identified a vulnerability in the backend website process for one of its online channels. In plain language, the visible customer journey appeared to have a gate, but a weakness behind the page allowed an unauthorised user to get around it. The company said it fixed the issue on 26 March 2025 and had detected no further exploitation of that vulnerability since that date.
That distinction matters. This was not described as an absence of all rules or all verification design. It was a failure in the running path through which the rule was supposed to become reality.
Why it matters
People often hear “SIM swap” or “mobile port fraud” and imagine a problem limited to telephone service. The practical dependency is wider. Many organisations use possession of a phone number as one signal that the person on the other side is the expected customer. A one-time code sent by text may approve a login, reset a password or confirm a transaction. Calls and messages intended for the legitimate holder can also follow the number after the transfer.
Control of the number does not automatically prove control of every connected account. Different banks and online services use different controls, and ACMA's documents do not publish a full technical chain for each victim. It would therefore be wrong to claim that a port alone defeated every security measure or that every one of the 168 regulatory occasions caused a financial loss.
What ACMA did report is already serious and specific: scammers gained control of mobile-number services and accessed bank accounts; 20 consumers reported at least A$393,000 in combined losses. “At least” is important because it identifies a documented floor. It is not an estimate of the final total. The sources also describe substantial financial harm and stress, but they do not provide a complete account-by-account loss schedule in the public material.
The continuity harm begins even before a downstream account is touched. The legitimate holder may stop receiving calls and messages. They may struggle to contact providers while trying to reverse the transfer. The same number that makes a person easy to reach during normal life can make an unauthorised transfer unusually disruptive, because contacts continue using an identifier that has not visibly changed.
This is why number portability is an infrastructure accountability issue. The number is not merely a label printed on an invoice. It is a durable routing and identity reference whose service can move between operators. The transfer process must preserve continuity for the legitimate rights-of-use holder while rejecting an attacker who presents convincing but insufficient data.
The technical layer in plain language
The phrase “backend vulnerability” can sound remote. A simple model makes it concrete. Imagine an online form that asks a person to complete an extra check before moving a number. The screen may display the correct questions and the written procedure may require a successful result. But the system behind the screen must also make it impossible to call the next step, alter a request or follow an unexpected sequence that skips the decision.
A robust control does not rely on the customer interface alone. It creates a server-side state that says which number is being moved, who requested the move, which approved verification method was used, when it succeeded, which device or channel was involved, and whether the result is still valid for this transaction. The porting action should accept only that valid state. If any required element is absent, mismatched, expired or reused, the transfer should fail closed—that is, stop safely rather than continue.
Public ACMA material does not reveal the precise exploit steps, and it should not be read as a technical blueprint. It says scammers manipulated Southern Phone's systems to bypass required identity verification, and the undertaking refers to a vulnerability in the backend website process for one online channel. Those facts support scrutiny of the control chain, but not speculation about a particular software flaw, credential, endpoint or attacker technique.
The useful engineering question is broader: could the porting function be reached only through a verified state, or was verification treated as a nearby activity rather than a binding prerequisite? A control can appear in policy, user-interface design and training while remaining separable from the action it is meant to guard. Continuous tests are designed to discover that separation.
What the rule required
The Telecommunications (Mobile Number Pre-Porting Additional Identity Verification) Industry Standard 2020 is the central rule in ACMA's action. The legal wording matters because it identifies both the purpose and the owner of the decision.
Before initiating a mobile number port, the gaining carrier must use an additional identity-verification process to confirm two things: the requester is the rights-of-use holder for the number, or an authorised representative; and the requester has access to a mobile device associated with that number. The gaining carrier must not proceed unless an approved additional verification process has been used.
“Rights-of-use holder” is more precise than “owner.” Telephone numbers sit within an administered numbering system. Customers receive the right to use a number through service arrangements; they do not hold it like a piece of freehold land. The operational problem is therefore to preserve the legitimate person's continuing use while the service relationship moves.
“Gaining carrier” is also important. A transfer crosses organisational boundaries, but the provider accepting the number owns the pre-port gate described in the enforcement documents. That does not make every other participant irrelevant. It does make the accountability question concrete: what evidence did the gaining provider require before its systems allowed the transfer to proceed?
The rule is intentionally stronger than a generic account login. A person attempting a port may possess personal information obtained elsewhere. Additional verification is meant to test entitlement and access in the context of the number being transferred. Compliance therefore cannot be demonstrated solely by showing that a customer account existed, that some data fields matched or that an online session reached a confirmation page.
Reading the dates and numbers carefully
Several public documents describe the case at different levels. They should not be flattened into a single undifferentiated timeline.
ACMA's media release gives the clearest public summary: 168 occasions over an eight-month period between July 2024 and February 2025. The enforceable undertaking records ACMA's view that contraventions occurred between 16 July 2024 and 24 February 2025 and attributes them to the incident involving the online-channel vulnerability. The infringement notice describes specific alleged contraventions between 27 September 2024 and 3 February 2025. These formulations come from different instruments and may refer to different legal subsets or purposes.
The safest editorial treatment is to preserve each label. The article uses the regulator's 168-occasion, eight-month summary for the overall case. It does not infer that every legal document contains the identical population. It does not add separate date ranges together. It does not convert occasions into a count of unique individuals.
The same discipline applies to harm. ACMA says 20 consumers reported combined losses of at least A$393,000. Twenty consumers are not the same unit as 168 occasions. One number describes people who reported losses; the other describes regulatory breach occasions. The public evidence does not support dividing A$393,000 by 168 to create an “average loss per breach,” nor does it support assigning equal losses to the 20 consumers.
The A$2,500,560 figure is the infringement penalty Southern Phone paid. It is not compensation distributed to the 20 reporting consumers and should not be compared as if both numbers measured the same thing. ACMA described it as the highest penalty it had imposed for breaches of this kind at the time of the announcement.
Finally, the statement that vulnerabilities went undetected for over a year should not be confused with the eight-month breach period. One describes how long a weakness was not identified; the other describes ACMA's summary of the breach occasions. Public evidence does not permit an exact day-by-day reconstruction of when the vulnerability first existed, when every attacker learned of it or when each consumer loss occurred.
The control failed in operation, not just on paper
Southern Phone's undertaking says it had systems for its online and agent-assisted channels intended to stop mobile ports until additional verification succeeded. This is a critical piece of the accountability story. It shows why the existence of a documented workflow is not enough.
A policy states what should happen. A design maps that requirement into a customer and staff journey. Running code decides what can actually happen. When those layers diverge, dashboards and procedure documents can give false reassurance.
There are several common ways that divergence can appear, although ACMA's public record does not say which of them applied here. A new online route may bypass an older control. A verification result may not be bound tightly to the exact port request. An error-handling path may continue after a failed check. A backend interface may trust a signal that a browser or another service can supply without proof. A security test may cover the expected customer sequence but not an intentionally disordered one.
These are examples of what operators should test, not claims about Southern Phone's undisclosed implementation. The verified fact is narrower: a backend website vulnerability in one online channel allowed unauthorised users to proceed without completing required pre-port verification, and third-party bad actors exploited it on numerous occasions.
For leaders, the distinction between design and operation changes the evidence they should request. A screenshot of the verification screen shows that a step was presented. A policy attestation shows that a rule was written. Neither proves that every successful port carried a valid, transaction-bound verification result through the backend. That proof must come from system records and adversarial testing.
Who was affected
The most direct affected group was the consumers whose mobile services were taken over. ACMA reports that 20 consumers identified combined losses of at least A$393,000. The sources do not publish their identities, individual losses or complete recovery outcomes, and those gaps should remain protected rather than filled with speculation.
The case also affects ordinary Southern Phone customers who were not part of the 20. It gives them a legitimate question about how port requests are verified now. It does not prove that every customer was exposed, that all channels were vulnerable in the same way or that every past transfer was unauthorised.
Banks and other services that use a telephone number as one factor in customer access are part of the dependency chain. They remain responsible for their own authentication and fraud controls. The telecom failure does not erase that responsibility, and the public record does not allocate precise causal shares among carriers, financial institutions, customers or attackers. The lesson is that a phone number is a shared dependency; no participant should treat it as an unchallengeable proof of identity by itself.
Staff and service partners are affected operationally because a secure porting process changes how exceptions are handled. Fraud teams, service-delivery teams, complaints staff, specialist telco agents and their managers are among the groups named in the undertaking's training requirements. A sound process should help them stop suspicious transfers without creating an informal workaround that becomes the next bypass.
The regulator and the wider industry are affected because repeated exploitation across providers can weaken confidence in portability itself. ACMA described Southern Phone as the third enforcement action that year involving scammers exploiting a vulnerability in a telco's number-porting process. That contextual statement does not make the cases identical. It does show why carrier-by-carrier compliance has a system-wide trust dimension.
What Southern Phone said it changed
The enforceable undertaking records several remedial actions after the vulnerability was identified. Southern Phone said it implemented a fix in late March 2025. It strengthened monitoring and alerts so suspicious activity could be identified promptly. It carried out internal and external penetration testing, meaning controlled attempts to find ways through or around security controls. It also strengthened potential-fraud monitoring to improve detection and response.
Those actions address different parts of the failure chain. The fix removes the known route. Monitoring looks for abnormal use and possible recurrence. Penetration testing challenges assumptions before an attacker does. Fraud monitoring connects technical activity with consumer and behavioural signals.
The measures are necessary, but a public observer cannot declare them permanently effective from their names alone. A penetration test is a dated assessment, not a perpetual guarantee. An alert is useful only if it covers the right events, reaches a capable responder and leads to a timely decision. A software fix can be weakened by a later release or by a parallel customer channel that develops different logic.
That is why ACMA's response extended beyond a penalty and a one-time patch. The original undertaking created a sequence of independent review, implementation, monitoring, reporting, training and record-keeping within a 36-month base term. A February 2026 variation changed how several duties apply during Southern Phone's proposed customer migration and cessation, so the current instrument—not the original summary—governs the evidence obligation.
How the 36-month base term changed in 2026
The original court-enforceable undertaking commenced on 20 November 2025 with a 36-month base term. It set out an ACMA-approved independent consultant, a review of systems and practices, an implementation plan, monthly operational monitoring, Risk Committee oversight, periodic reports, training and record-keeping.
ACMA consented to a variation on 27 February 2026. Southern Phone represented that it expected to transfer its then-current Australian mobile customer base to an unrelated Australian mobile carriage service provider and cease supplying mobile services in Australia by December 2026. As of the evidence freeze on 6 August 2026, that was a company expectation, not proof that migration or cessation had been completed. The unrelated successor must not be guessed or named.
The variation preserved the base term but made the independent-review and implementation-plan regime in the relevant clauses conditional on Southern Phone recommencing the supply of mobile services after the notification date. If that condition arises, the independent reviewer is meant to test current systems and recommend changes; Southern Phone then has to translate recommendations into an approved, dated implementation plan.
Monitoring and reporting also have transitional application tied to the customer migration and cessation. The original measurement set remains a useful description of the evidence at issue: ported-in numbers by channel and outcome, withdrawn requests, reversals, termination requests by rights-of-use holders, non-compliant ports, complaints, fraud indications and remediation. But the article does not claim that every original reporting duty operates unconditionally for the full 36 months.
The varied training and record-keeping provisions apply through the later of 30 November 2026 or the migration of the last relevant user, with recommencement conditions thereafter. That transition protects evidence while customers and service responsibility move. It does not prove that the proposed migration had already occurred by August 2026.
This combination matters. Technical controls without governance can drift. Governance without transaction evidence can become ceremony. Training without fail-closed code asks staff to compensate for a system that still permits unsafe state. The varied instrument makes accurate transition records and clear control ownership as important as the original remediation design.
Why continuous testing is the central lesson
The title of this article does not claim that testing alone prevents every fraud. It says a number-transfer control needs continuous testing because its effectiveness depends on a changing system.
Online channels change. Customer interfaces are redesigned. Identity services are replaced. Teams add promotional flows and exception handling. Mobile applications and websites call new backend services. Attackers observe which checks are enforced and search for paths that behave differently. A control that passed an assessment in January may be bypassable after a release in April.
Continuous testing does not mean attacking production without restraint. It means maintaining a planned assurance program that covers the control as it actually runs. Unit tests can verify individual decisions in code. Integration tests can confirm that verification state travels correctly between systems. Negative tests can prove that missing, expired, reused and mismatched evidence stops a port. Penetration tests can examine unexpected sequences and trust boundaries. Monitoring can then confirm that real transactions continue to match those expectations.
The most valuable test is often the one that asks whether the protected action can occur without the control evidence. Start at the successful port and trace backwards. Is there a unique verification event for this number, this requester, this channel and this time window? Was the approved method completed? Can the evidence be replayed? Could an administrator or service call force the next state without generating the expected record?
This approach gives “running-code primacy” a practical meaning. The organisation does not dismiss policies or legal rules. It asks the software and records to demonstrate that the rule governed every real transfer. A green design review cannot override contradictory transaction evidence.
A number-resource accountability view
The relevant accountability surface is operator continuity and portability, closely linked to number resources. Registries and transfer records are ledgers of operational reality; they do not create legitimate authority by themselves. In this case, the portability process records and executes a change in which provider serves a number while the legitimate user's continuity is meant to remain intact.
The number does not become legitimate because a database accepted a transaction. The transaction should be accepted because the running process obtained reliable evidence from the legitimate rights-of-use holder. That order is important. If the ledger changes after a bypass, formal state and legitimate authority diverge.
This is not an argument against portability. Portability reduces switching friction and helps users preserve reachability. The reality-layer question is how the industry maintains uniqueness, accurate transfer records, security metadata and operational continuity without turning a convenient transfer into an attacker-controlled reassignment.
Nor is this a call for permission theatre—more forms, more approvals and more customer friction that do not bind to the actual transfer. A control has legitimacy when it changes what the system will allow and leaves evidence that the decision can be tested. Extra steps that can be bypassed or that exist only in procedure create cost without protection.
The operator therefore needs two linked truths. The rights-of-use truth asks whether the requester is authorised to move the number. The running-service truth asks which network currently serves it and whether that state resulted from a valid process. Accountable portability keeps those truths aligned before, during and after the handoff.
A practical control model
A carrier can turn the lessons into an evidence chain. The following model is not a description of Southern Phone's undisclosed architecture. It is a control pattern derived from the public failure and remedy.
- Create a unique port-request identifier before collecting verification.
- Bind the identifier to the number, gaining provider, customer context, channel and a short validity window.
- Complete an approved additional verification method and record the result server-side.
- Require the porting service—not merely the web page—to validate that exact result.
- Reject missing, expired, reused or mismatched verification evidence.
- Record the reason for every withdrawal, rejection, manual exception and reversal.
- Alert on unusual sequences, repeated attempts, high-risk channel patterns and any successful port lacking complete evidence.
- Reconcile successful ports against verification events each day, with zero unexplained successes as the control objective.
- Test expected and adversarial paths after every material change.
- Give an accountable governance group the exceptions, oldest unresolved items, test results and remediation status.
The sequence makes evidence inseparable from action. A port is not “verified” because a process owner believes the check normally happens. It is verified when the successful transfer can be traced to a valid, approved, transaction-bound result.
Manual exceptions deserve special attention. Customer service sometimes faces legitimate edge cases: a damaged device, accessibility needs, account transitions or inconsistent records. A secure system needs ways to help real customers, but those ways must not become an unobserved alternate porting channel. Every exception should have an explicit authority, reason, second-person review where appropriate, expiry and retrospective testing.
Measures that reveal the real condition
Boards rarely need raw security logs. They do need measures that distinguish control operation from control activity.
“Verification attempts completed” is an activity measure. “Successful ports with valid, transaction-bound verification evidence” is an outcome measure. “Penetration tests performed” is an activity. “Known bypass paths closed and regression-tested across every channel” is closer to an outcome.
The undertaking's monthly categories provide a strong base: ported-in numbers by channel and outcome, reversal requests, termination requests from rights-of-use holders, non-compliant ports, complaints, fraud indications and remediation. Operators can add control-specific measures without publishing sensitive details.
Useful indicators include the share of successful ports with complete evidence; the number of impossible or missing state transitions; time from suspicious activity to containment; age of open control defects; tests passed after code changes; and the difference between channel-level port totals and central transaction records. The target for successful ports without valid evidence should be zero.
Ratios should retain their underlying counts. A 100 per cent pass rate over a small or incomplete population can mislead. Leaders should know the denominator, which channels were included, which exceptions were excluded and whether independent testers could reproduce management's result.
Consumer reports are a detection input, not the only detection system. If the first reliable signal arrives when a person loses service or money, the operator is learning too late. Backend state, unusual request patterns, failed verification and reversals can provide earlier warning when they are connected and reviewed.
What the enforcement result proves—and what it does not
The public record supports several firm conclusions. Southern Phone paid the stated infringement penalty. ACMA found anti-scam rule breaches on 168 occasions over the stated period. Scammers manipulated systems to bypass required identity verification. Twenty consumers reported combined losses of at least A$393,000. The undertaking originally carried a 36-month base term, but the 27 February 2026 variation made independent-review and implementation obligations conditional on recommencement of direct Australian mobile service, while monitoring and training have transitional application.
The record does not reveal the full exploit procedure. It does not provide the identities or complete outcomes of affected consumers. It does not establish that every one of the 168 occasions caused a bank loss. It does not state that every Southern Phone channel had the same weakness. It does not prove that a fix and undertaking have eliminated every future porting risk.
The infringement notice also uses the language of reasonable grounds and alleged contraventions within its particular legal instrument. Southern Phone's undertaking says the company accepted ACMA's findings and acknowledged that it did not have sufficient systems at the time to prevent the contraventions. Accurate reporting should preserve those formulations instead of turning every procedural statement into a broader admission.
This boundary is part of accountability. Exaggeration does not strengthen the case. It makes it harder to distinguish documented harm, regulator findings, company acknowledgements and recommendations for future control.
What to watch next
The first question is whether independent review tests all relevant online paths as they now operate, including attempts to skip or replay verification rather than only the expected customer journey. A confidential report may limit what the public sees, but ACMA's undertaking gives the regulator and company governance bodies a basis for checking completion.
The second question is whether the implementation plan translates recommendations into dated, testable changes. A list of projects is weaker than acceptance criteria. Each action should identify the unsafe state it prevents, the evidence it produces and the regression test that will remain after the project closes.
The third question is whether monthly reporting detects weak signals before losses accumulate. Reversals, complaints and termination requests may indicate a transfer the legitimate user did not request. They should be examined alongside verification and channel data, not managed as unrelated customer-service categories.
The fourth question is how business changes affect continuity. The publication page later noted a variation to the undertaking in 2026. Any transfer of customers, systems or service responsibilities can change control ownership. The core obligation remains evidential: the organisation operating a porting path must know which controls run, which records survive migration and who responds when they fail.
The final question is whether the industry learns across cases. ACMA said this was its third 2025 enforcement action involving exploitation of a telco porting-process vulnerability. Providers should not need the same failure in their own environment before testing for the class of problem. Cross-industry alerts can reduce harm only when each operator converts them into specific checks of its running systems.
The durable lesson
Mobile number portability preserves a useful identity and communications link while a customer changes provider. The same continuity makes an unauthorised transfer dangerous. The operator accepting the number must prove that the requester has the right and the associated access required by the rules.
Southern Phone's case shows the gap between intended control and effective control. The company had processes designed to require verification, but a backend vulnerability allowed unauthorised users to bypass it. The public outcome—168 breach occasions, reported losses of at least A$393,000 among 20 consumers, an A$2,500,560 penalty and a 36-month undertaking—shows why that gap cannot be treated as a minor technical defect.
The answer is not a larger stack of untested policy. It is a closed evidence loop: bind verification to the exact transfer, make the backend fail safely, test the live path adversarially, monitor every channel, reconcile successful ports, investigate exceptions and report results to accountable leaders.
A number registry or porting ledger is valuable because it records a legitimate operational handoff accurately. It cannot make an illegitimate handoff legitimate merely by accepting it. In number-resource governance, reality comes first. The control must protect the legitimate user's continuity in running systems, and the record must prove that it did.
Sources
- ACMA media release — Southern Phone penalised A$2.5M for anti-scam breaches
- ACMA publication page — investigation report, infringement notice and enforceable undertaking for Southern Phone Company Limited
- ACMA investigation report — Southern Phone Company Limited
- ACMA infringement notice — Southern Phone Company Limited
- ACMA court-enforceable undertaking — Southern Phone Company Limited
- ACMA varied undertaking — Southern Phone Company Limited, 27 February 2026
- ACMA current register — investigations into telco providers
- ACMA compliance and enforcement policy
- Federal Register — authorised text of the pre-port verification standard
- Federal Register — current instrument details
- ACCC consumer guidance — unauthorised transfer of phone or internet services
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
