The Australian Federal Police charged four people on Tuesday with allegedly operating a SIM-swap ring that targeted Australians holding self-custody cryptocurrency wallets, using forged identification and corrupt mobile retail staff to port numbers before resetting exchange and wallet recovery flows. Raids in Sydney’s inner west and Melbourne’s northern suburbs seized cold-storage devices, luxury goods, and about $1.2 million in cash police said was linked to rapid on-ramping of stolen assets through offshore exchanges.
What broke
According to court documents filed in New South Wales Local Court, the ring allegedly paid complicit workers at third-party mobile outlets to approve prepaid-to-postpaid conversions that triggered number ports without triggering higher-friction verification. Once SMS-based recovery codes routed to attacker-controlled SIMs, affiliates drained hot wallets and pressured victims through spoofed support chats to surrender seed phrases for hardware devices.
Investigators tied at least 38 victim reports across six states to the same Telegram coordination channel, with losses exceeding $9 million since March. AFP Cyber Command said several victims were small-business owners who kept treasury funds in self-custody to avoid exchange counterparty risk—a profile scammers now hunt through leaked KYC broker datasets sold on criminal forums.
What AFP confirmed
AFP Commander Cybercrime Operations said the charges include dealing in identification information, unauthorized modification of telecommunications services, and money laundering. Two defendants were refused bail; two were granted conditional release with surrender of travel documents. Police did not name the mobile carriers involved but said all major telcos received intelligence packages to tighten port-out checks on accounts with recent password resets.
ASIC’s MoneySmart team published a parallel consumer alert reminding holders that SMS two-factor authentication is weak against porting fraud and that legitimate wallet vendors never ask for seed phrases on phone calls. AUSTRAC noted that rapid conversion of stolen crypto through nested exchange accounts remains a reporting trigger for digital currency exchange providers.
Who has the file
State fraud squads in Queensland and Western Australia contributed victim interviews; AFP retained lead on cross-border cryptocurrency tracing with Five Eyes partners. ACMA said it is reviewing whether additional porting safeguards announced after earlier SIM-swap waves were bypassed through in-store social engineering rather than online self-service gaps.
Telstra and Optus spokespeople declined to comment on active investigations but pointed to recent mandatory in-person checks for high-risk ports. TPG said it flagged an internal audit of franchise stores linked to suspicious port volumes in two postcodes named in the AFP brief.
What is still unknown
Prosecutors have not said whether recovered seed phrases came from cooperative victims or forensic imaging of seized devices. Attribution to overseas kingpins remains open; blockchain analytics firms assisting AFP have not published wallet cluster maps while charges are before courts. Total restitution for victims is uncertain because much of the crypto moved through mixers within hours of theft.
What wallet holders should change
Security researchers recommend removing SMS from any recovery path, using hardware keys on exchanges that support them, and storing seed backups offline without phone photos. Businesses holding treasury crypto should split signing keys across people and geographies so a single ported mobile cannot authorize transfers.
Carriers must treat franchise staff as part of the threat model: AFP alleged bribes as low as a few hundred dollars bought ports that bypassed online friction. Until porting rules assume corrupt clerks, self-custody advocates cannot pretend phone numbers are neutral infrastructure—they are the weakest link in many recovery designs.
Court and policy timeline
Defendants return to mention hearings in October. Parliament’s joint cyber committee has scheduled a closed briefing on SIM-swap losses with AFP and ACMA in the same fortnight Chalmers faces caucus pressure on unrelated consumer fraud issues. For victims, the immediate lesson is procedural: if your mobile loses service unexpectedly, assume an active swap attempt and contact your carrier from a different device before attackers finish wallet resets.
