Customer Identity Authentication and Fraud Protection

How the identity of a person requesting a high-risk change to an account is verified, what will never be requested of you, and how to report suspected fraud affecting a telecommunications service or account.

Customer Identity Authentication

This page sets out how VOCPhone verifies the identity of a person requesting a high-risk change to a customer account, and how to report suspected fraud. It is published in accordance with section 14 of the Telecommunications Service Provider (Customer Identity Authentication) Determination 2022.

Last updated
Summary

The identity of any person requesting a high-risk change to an account is verified before the change is made. High-risk changes include porting a number, altering account details, issuing a replacement SIM, adding or removing an authorised representative, and disclosing account information. Verification uses more than one factor. A notification is sent whenever a high-risk request is initiated, and no charge applies to those messages.

You may be asked to read back a one-time PIN sent to a trusted contact number already recorded on your account. You will never be asked for a code issued to you by your bank or any other organisation, to transfer funds to a safe account, or to install remote access software.

If you suspect fraud on your service or account, report it immediately to VOCPhone on 1300 663 222 and to your bank or financial institution.

Information We Are Required to Publish

Australian telecommunications providers operate under the Telecommunications Service Provider (Customer Identity Authentication) Determination 2022, made by the Australian Communications and Media Authority under subsection 99(1) of the Telecommunications Act 1997. It commenced on 30 June 2022.

Section 14 of the Determination requires every carriage service provider to publish two statements for the information of customers. They are set out below.

1. Identity authentication before high-risk transactions

To protect customers from unauthorised high-risk customer interactions, VOCPhone will use identity authentication processes to authenticate the identity of the person making a request, prior to undertaking a high-risk customer transaction. This applies to all customers on every occasion.

2. Reporting suspected fraud

If you suspect that your telecommunications service or account has been subject to fraud, you should immediately report the activity to both of the following.

i. Your carriage service providerVOCPhone, on 1300 663 222, or through our contact page.
ii. Your financial services providerYour bank, credit union or other financial institution.

Both should be contacted. Reporting to only one leaves part of the exposure unaddressed.

The remainder of this page explains how these obligations operate in practice, the circumstances in which you may be asked to verify your identity, and where further assistance can be obtained.

Why Telephone Accounts Are Targeted

A telephone number is frequently more than a means of contact. For many services it also functions as an account recovery method and as a second authentication factor. It is where a bank sends a one-time code, and where an email provider sends a verification message when a password reset is attempted.

Control of the number therefore confers a degree of control over other accounts. This is the objective of an unauthorised port, a SIM swap, or the reassignment of a virtual mobile number. The party responsible does not require the telephone service itself. They require the period immediately following the transfer, during which authentication codes are delivered to their device rather than to the customer.

The authentication requirements described on this page exist to interrupt that sequence. The Australian Communications and Media Authority has reported a substantial reduction in mobile number fraud since the Determination commenced.

Virtual Mobile Numbers and Services Without a SIM

Not every telephone number is delivered on a physical SIM. A virtual mobile number is an Australian mobile number that is held in the network and delivered over an internet connection to an application, a desk handset or a softphone. Numbers of this kind are supplied alongside geographic numbers and 1300 and 1800 numbers.

The protections described on this page apply to these services in full. The Determination applies to carriage service providers supplying a telecommunications service and draws no distinction between a number delivered on a SIM and one delivered over the internet.

What differs is the method by which a takeover would be attempted, and it is worth understanding because the warning signs are not identical.

Service typeHow a takeover is typically attempted
Number on a physical SIMA replacement SIM is requested, or the number is ported to another provider without authorisation.
Virtual mobile numberThere is no SIM to exchange, so the account itself is the target. Attempts involve obtaining account credentials, registering the number to a new device or application, altering the contact details held on the account, or porting the number away.

Each of the actions listed above is a high-risk customer transaction under the Determination, and each therefore requires identity authentication before it is carried out. Because a virtual service depends on account access rather than possession of a SIM, the security of your account credentials and of the contact details recorded against your account is correspondingly more important. Requests to change either are treated as high-risk transactions for that reason.

Transactions Classified as High-Risk

The Determination defines a high-risk customer transaction as one that may result in any of the outcomes set out below.

Outcome under the DeterminationExamples
Loss of access to the telecommunications servicePorting a number to another provider; transferring, suspending or cancelling a service; issuing a replacement SIM; reassigning a virtual mobile number, or changing the device, app or endpoint a number is delivered to.
A change to information held about the customerAltering personal information, business information, or account security information such as a password, PIN or recorded contact details.
Addition or removal of an authorised representativeGranting another person the ability to act on the account, or withdrawing that ability.
Disclosure of information to the requesting personReading out or sending personal information, business information or account security information held on the account.

Certain matters are expressly excluded so that routine service is not impeded. The definition does not extend to information already included in a bill or other correspondence with the customer, information that is mostly hidden or obscured when used to remind a customer of their own details, or notifications relating to the customer's use of the service.

How Identity Is Verified

A multi-factor process is used. Identity is confirmed using more than one independent piece of evidence, rather than a single detail that could be discovered, guessed or obtained from another source.

PrincipleApplication
More than one factorDepending on the contact method and the nature of the request, verification may combine information already held on the account, a one-time PIN sent to a trusted contact number recorded on the account, and identity documentation.
A single detail is not sufficientKnowledge of an address or date of birth does not authenticate a person. Information of that kind is routinely exposed in data breaches at other organisations.
Notification is sentWhen a high-risk interaction is initiated on an account, a notification is sent advising what has been requested and what to do if it was not authorised.
No charge appliesNo fee is charged for messages or notifications relating to identity authentication or to the initiation of a high-risk customer interaction, as required by section 15.
Verification is a preconditionWhere the process cannot be completed, the request does not proceed.
Records are retainedHigh-risk customer interactions are recorded, as required by the Determination, providing an auditable record if a transaction is subsequently disputed.
Requests to read back a one-time PIN

One of the methods used to confirm identity is to send a one-time PIN to a trusted contact number already recorded on the account and ask for it to be read back. A member of our team or our AI Phone Agent may do this. It is a recognised authentication method, because it demonstrates access to a contact point already held on the account.

Public guidance on fraud commonly advises that codes should never be disclosed to a caller. The distinction is set out below.

LegitimateFraudulent in all cases
A PIN issued by us, sent to a contact point already recorded on your account, used to verify the interaction taking place at that time. A request for a code issued to you by another organisation, such as your bank, your email provider or a delivery service.
The PIN is sent to the contact point already held on your account. A request that a contact number first be added or amended, followed by a request to read back a code sent to it.

A further safeguard applies in all circumstances. If you did not expect the contact, or if any aspect of it causes concern, end the call and telephone the number published on this page. Having placed the call yourself, you can be certain of the party you are speaking to. No member of our team will object to this course of action.

Customers in Vulnerable Circumstances

Some customers cannot complete a standard identity check through no fault of their own. The Determination requires that an alternative process be available. Customers to whom any of the following applies should advise us at the beginning of the conversation.

CircumstanceReason the standard process may be unavailable
Overseas, with a lost or stolen deviceA PIN sent to the contact number recorded on the account cannot be received.
Affected by an emergency or natural disasterDocuments and devices may be inaccessible or destroyed.
Experiencing domestic or family violenceThe account, the device or the recorded contact details may be under the control of another person. Matters raised on this basis are handled confidentially.
Otherwise unable to access a service, device or documentsAny personal circumstance giving rise to harm, detriment or disadvantage that prevents standard verification.

Where a staff member who has completed fraud mitigation training has reasonable grounds to believe that a customer is a person in vulnerable circumstances, an alternative identity authentication process appropriate to those circumstances may be applied. A customer will not be refused assistance solely because the standard method is unavailable to them.

Where a Transaction Was Not Authorised

Where a customer advises that an interaction on their account was not authorised, the following applies.

StepAction
1. Transaction stoppedThe transaction does not proceed.
2. ReversalWhere the transaction has already been carried out, steps are taken to reverse it.
3. NotificationThe customer is advised of the steps taken and of the measures available to protect the account.
4. Additional protectionsFraud mitigation protections may be applied to the account to prevent recurrence.

Your financial institution should be contacted at the same time. Where an attempt has been made to obtain control of a telephone number, the objective is frequently access to financial accounts, and action can be taken by both parties concurrently.

Fraud Mitigation Protections

Section 13 of the Determination requires providers to maintain systems that identify customers at risk of fraud and to provide those customers with fraud mitigation protections. It further requires that such protections be offered in response to a reasonable request from a customer who believes they are at risk. Customers may request these protections directly, and no charge applies.

Fraud mitigation protections are additional or tailored measures designed to prevent fraud in relation to a customer's telecommunications service. They may include notification of suspected fraudulent activity, flagging of the account for heightened scrutiny, and the application of further verification requirements before any high-risk transaction is carried out.

A request may be appropriate where a customer has been affected by a data breach at another organisation, has previously been targeted by fraud, holds a public profile, or is experiencing domestic or family violence.

Authorised Representatives

A customer may nominate another person to deal with us on their behalf. This is common for business accounts, for family members managing an account, and for professional advisers.

Two matters should be noted. First, the addition or removal of an authorised representative is itself a high-risk customer transaction and therefore requires identity authentication. This is deliberate, as the addition of an authorised representative is a recognised method of account takeover. Second, where a person contacts us asserting authority to act on an account without being recorded as an authorised representative, a separate process applies under section 12 of the Determination. A record is kept of the basis on which the provider was satisfied as to that person's authority, together with any supporting evidence provided, and a notification is sent once the transaction has been completed.

Customers are encouraged to keep their list of authorised representatives current. Removing a person who no longer requires access, such as a former employee or former partner, is among the most effective account security measures available.

Requests That Are Never Made

The following will never be requested by VOCPhone. Familiarity with this list allows a contact to be assessed against a fixed standard, rather than on the apparent credibility of the person making it.

Never requestedExplanation
A code issued by another organisationYou may be asked to read back a PIN issued by us and sent to a contact point recorded on your account. You will never be asked for a code sent to you by your bank, your email provider or any other organisation.
Transfer of funds to a safe accountNo legitimate organisation makes this request. It is among the most damaging frauds currently operating in Australia.
Installation of remote access softwareYou will not be asked to install software granting access to your computer or mobile device.
Payment by unusual methodPayment is never requested by gift card, cryptocurrency, or transfer to a personal account.
Immediate action without opportunity to verifyUrgency is a common feature of fraudulent contact, because it discourages verification. You will never be discouraged from ending a call and telephoning the published number.
Reliance on calling line identificationCalling line identification can be falsified. Where there is any doubt, end the call and dial 1300 663 222.
General principle

Do not verify an incoming contact using information supplied by the person making it. End the contact and telephone a number obtained independently: from a bill, from your own records, or from this page. This measure does not depend on the recipient detecting anything, and is therefore effective irrespective of how the contact was presented.

Reporting Suspected Fraud

Where fraud is suspected in relation to a telecommunications service or account, it should be reported immediately. The period during which an unauthorised port, SIM swap or virtual mobile number reassignment can be reversed is limited.

OrganisationContactPurpose
1. VOCPhone1300 663 222
Contact page
To stop or reverse the transaction, secure the account, and apply fraud mitigation protections.
2. Your financial institutionThe number shown on your card or statementRequired under section 14 of the Determination, and a priority where account takeover is suspected.
IDCARE1800 595 160
idcare.org
Australia's national identity and cyber support service. Assistance is provided without charge.
Scamwatchscamwatch.gov.auReporting contributes to national scam intelligence and public warnings.
ReportCybercyber.gov.au/reportThe Australian Government reporting channel for cybercrime.
Telecommunications Industry Ombudsman1800 062 058
tio.com.au
Available where a complaint has not been resolved to your satisfaction.
Indicators that a service may have been compromised

A mobile or virtual mobile service ceases to function unexpectedly and does not resume. Calls or messages stop arriving in your app or on your handset. Expected calls or messages are no longer received. A notification is received regarding a port, SIM replacement, number reassignment, a new device or app registration, or an account change that was not requested. Access to an online account is lost, or password reset messages are received that were not initiated by the customer. Any of these warrants immediate contact with us and with your financial institution, using an alternative telephone if the affected service is unavailable.

Frequently Asked Questions

Why must my identity be verified before changes are made to my account?
Because the law requires it, and because it is the most effective protection available against another person taking control of your service. Under the Telecommunications Service Provider (Customer Identity Authentication) Determination 2022, every Australian carriage service provider must authenticate the identity of the person making a request before carrying out a high-risk customer transaction. A high-risk transaction is one that could cause you to lose access to your service, change the personal or account information held about you, add or remove an authorised representative, or disclose your information to the person making the request. Those are the steps required to take over a telephone number. Once a number is controlled by another party, one-time codes protecting banking and email accounts can often be intercepted. Verification applies to every customer on every occasion, including long-standing customers and those we speak with regularly, because a person impersonating you will present confidently and may already hold some of your details.
What is a high-risk customer transaction?
The Determination defines it as a transaction that may result in any of the following: the customer losing access to their telecommunications service; a change to the personal information, business information or account security information held by the provider; a person being added to or removed from the account as an authorised representative; or the disclosure of personal information, business information or account security information to the person making the request. In practical terms this covers porting a number to another provider, transferring or cancelling a service, changing contact details or account credentials, issuing a replacement SIM, reassigning or re-provisioning a virtual mobile number, changing the device or app registration a number is delivered to, adding or removing an authorised representative, and requesting that account information be read back or sent. The definition excludes information already contained in a bill or other correspondence, information that is mostly hidden or masked when used to remind a customer of their own details, and notifications relating to service usage.
I have a virtual mobile number rather than a SIM. Do these protections apply?
Yes, in full. The Determination applies to carriage service providers supplying a telecommunications service, and it does not distinguish between a number delivered on a physical SIM and a virtual mobile number delivered over the internet to an application or handset. The same identity authentication requirements, the same notification obligations and the same fraud mitigation protections apply. The practical difference is in how a takeover would be attempted rather than in whether you are protected. A service on a physical SIM is typically attacked by requesting a replacement SIM or an unauthorised port. A virtual mobile number has no SIM to swap, so the equivalent attack is directed at the account itself: obtaining access to account credentials, registering the number to a new device or application, altering the contact details held on the account, or porting the number away. Each of those is a high-risk customer transaction and each therefore requires identity authentication before it will be carried out.
How is identity verified?
Through a multi-factor process, meaning identity is confirmed using more than one independent piece of evidence rather than a single detail that could be discovered or guessed. Depending on the contact method and the nature of the request, this may involve confirming information already held on the account, sending a one-time PIN to a trusted contact number recorded on the account and asking for it to be read back, or requesting identity documentation. Knowledge of a single item such as an address or date of birth is not accepted as sufficient on its own, because information of that kind is frequently exposed in data breaches at other organisations. Where the process cannot be completed, the request does not proceed. This may cause a delay to a genuine request, which is accepted as preferable to the alternative.
Will I ever be asked to read out a PIN or code?
Yes, in one specific and limited circumstance. As part of verifying identity, a member of our team or our AI Phone Agent may send a one-time PIN to a trusted contact number already recorded on your account and ask you to read it back. This is a recognised authentication method, because it demonstrates that you have access to a contact point already held on the account, which a person impersonating you would not. What will never occur is a request for a code or PIN issued to you by another organisation, such as your bank, your email provider or a delivery service. Those codes are never ours to request, and any such request is fraudulent. Two further points distinguish a genuine request. The PIN is sent to a contact point already recorded on your account, never to a number supplied during the call. And if you did not expect the contact, you may end the call and telephone us on our published number, at which point you can be certain of the party you are speaking to.
What happens if I cannot complete a standard identity check?
Advise us, because an alternative process exists and is required by the Determination. The rules recognise that some customers cannot complete a standard check through no fault of their own, and require providers to make provision for people in vulnerable circumstances. This includes a customer who is overseas and has lost their mobile device, a customer affected by an emergency or natural disaster, and a customer experiencing domestic or family violence, as well as any customer who, because of their circumstances, cannot access their service or device or provide the usual identity documents. In these cases a staff member who has completed fraud mitigation training may apply an alternative identity authentication process appropriate to the circumstances. Raising the matter early in the conversation allows the correct process to be applied from the outset.
I received a notification about a change I did not request. What should I do?
Contact us immediately and treat the matter as urgent. When a high-risk customer interaction is initiated on an account, a notification is sent advising what has been requested and what to do if the request was not authorised. Where a customer confirms that they did not authorise the interaction, the transaction is stopped, steps are taken to reverse it if it has already been carried out, and the customer is advised of the action taken and of the measures available to protect the account. Do not use contact details contained in a message you are unsure about; use the number published on this page. No charge is applied for these notifications or for any messages used to verify identity. Note also that a message of this kind may itself be fraudulent and designed to prompt a call to a false number, which is a further reason to dial only the published number.
What will never be asked of me?
You will never be asked for a code or PIN issued to you by another organisation, including your bank or your email provider. You will never be asked to transfer funds to a safe account; no legitimate organisation makes that request, and it is among the most damaging frauds currently operating in Australia. You will never be asked to install remote access software, and payment will never be requested by gift card, cryptocurrency or transfer to a personal account. You will not be pressured to act immediately, and you will never be discouraged from ending a call and telephoning the published number. Where any contact causes uncertainty, ending it and calling us directly is always appropriate, because verification over a channel of your own choosing removes any advantage held by an impersonator. No member of our team will regard that as an inconvenience.
Can additional protection be applied to my account?
Yes. Under section 13 of the Determination, providers must have systems in place to identify customers at risk of fraud and provide those customers with fraud mitigation protections, and must offer such protections in response to a reasonable request from a customer who believes they are at risk. Fraud mitigation protections are additional or tailored measures designed to prevent fraud in relation to a customer's telecommunications service. They may include notifying the customer of suspected fraudulent activity, flagging the account for heightened scrutiny, and applying further verification requirements before any high-risk transaction is carried out. A request may be appropriate where you have been affected by a data breach at another organisation, where you have previously been targeted by fraud, or where you are experiencing domestic or family violence. No charge applies.

Contacting Us

Where a transaction has been carried out without authorisation, it can be stopped or reversed, the account secured, and fraud mitigation protections applied. No charge applies to any of these measures. Your financial institution should be contacted at the same time.

About This Page

This page is published to meet the customer awareness and safeguard information requirements in section 14 of the Telecommunications Service Provider (Customer Identity Authentication) Determination 2022 (Cth), made by the Australian Communications and Media Authority under subsection 99(1) of the Telecommunications Act 1997 (Cth).

It describes VOCPhone processes in general terms and does not constitute legal advice. Last reviewed 4 August 2026.