Amaysim slugged with $138,600 penalty for unverified number ports
Key points
- Amaysim has paid a $138,600 infringement notice and entered an enforceable undertaking after ACMA found it ported 13 mobile numbers without required identity checks.
- The breaches stemmed from two failures: eight ports went through Amaysim’s online channel and five through its customer service channel without additional verification.
- Under the 12-month undertaking, Amaysim must appoint an independent consultant to review its porting governance and file board-approved compliance reports with ACMA.
Mobile provider Amaysim has paid a $138,600 infringement notice and entered an enforceable undertaking after the Australian Communications and Media Authority (ACMA) found the telco ported 13 mobile numbers without identity checks designed to stop them being hijacked.
The regulator found Amaysim, owned by Optus, contravened the Telecommunications (Mobile Number Pre-Porting Additional Identity Verification) Industry Standard 2020 on 13 occasions between May 9 and October 29 2025.
That standard requires the provider gaining a number to use an additional verification process to confirm the person requesting the port holds the rights to the number and has direct access to a phone using it.
This is to prevent hijacked numbers allowing criminals to intercept one-time authentication codes sent by banks and online services.
ACMA’s findings drew partly on cybercrime reports lodged with law enforcement through ReportCyber and the Australian Financial Crimes Exchange (AFCX) about alleged unauthorised ports to Amaysim.
Two separate failures were behind the breaches.
Eight ports went through Amaysim’s online porting channel without any additional identity verification.
Another five were initiated through its customer service channel, also without verification.
ACMA redacted its description of how both failures occurred.
However, the undertaking lists among Amaysim’s remedial steps “strengthening controls relating to the manual override of port-in requests”.
iTnews understands the override applied to the customer service channel, where staff could bypass the requirement to send a verification code.
The infringement notice, issued in May, covers seven of the 13 contraventions.
Each attracted a penalty of $19,800 per contravention.
Paying an infringement notice is not an admission of liability, although Amaysim’s undertaking states it acknowledges the ACMA’s findings.
Under the 12-month undertaking, Amaysim must appoint a regulator-approved independent consultant to review its porting governance, systems, staff training and access to fraud and security expertise.
It must also audit every port-in, port reversal and number cancellation request each quarter, and file board-approved compliance reports with ACMA after seven and 12 months.
“Amaysim acknowledges ACMA’s findings. [We have] taken action to strengthen its verification processes, compliance controls and governance arrangements,” a spokesperson said.
“We are not aware of any financial harm to customers arising from these incidents.”
ACMA has also said it is not aware of any financial losses from the breaches.
Amaysim did not say what caused the eight online ports to proceed without verification, or when that issue was fixed.
