Telstra Corp. said its network filters blocked more than 10 million scam SMS messages in September alone, as fraudsters routed phishing and parcel-delivery lures through grey international pathways that bypass earlier sender-ID blocks. The figure adds to roughly 285 million scam calls and texts Telstra reported stopping across 2025 under its Cleaner Pipes program, which inspects traffic at the carrier edge before it reaches handsets.
How September differed
Internal summaries reviewed by InfoHandle show a higher share of messages originated outside traditional alphanumeric sender registrations, using numeric short codes and over-the-top gateways that appear legitimate for a single burst before disappearing. Telstra’s security team said many September campaigns mimicked Australia Post and toll-road operators, inviting users to click links for fees that harvest payment credentials. Unlike voice vishing, SMS scams often arrive while users are mobile, making quick taps more likely.
The Australian Communications and Media Authority requires telcos to identify and block scam calls and to participate in the Reducing Scam Calls Code. SMS has followed with stricter rules on sender registration; criminals respond by hopping carriers and countries within hours. Telstra’s September tally is a single-carrier view—rivals Optus and TPG run parallel filters but do not publish daily counts.
Cleaner Pipes mechanics
Telstra describes Cleaner Pipes as machine-learning classifiers plus threat feeds shared with industry and government. Messages matching known scam templates never reach subscribers; borderline traffic may be delayed for manual review. The program also targets malware command-and-control and phishing URLs at the DNS layer where customers use Telstra internet services.
Consumer advocates welcome volume metrics but ask for clearer customer notification when a message is blocked—currently most failures appear as silent drops. Telstra said sending a warning SMS for every blocked scam could itself confuse users; instead it promotes the government’s Scamwatch reporting tool.
Grey routes and regulation
Grey routes are wholesale SMS paths that do not follow direct agreements between sending and receiving carriers, often traversing multiple jurisdictions before hitting Australian radios. ACMA enforcement actions in 2025 and 2026 targeted aggregators that enabled high-volume fraud; Telstra’s September spike suggests some operators shifted volume rather than shutting down. The authority’s combating scam SMS page lists obligations for carriers to trace and block suspicious sources.
Banks and super funds continue separate impersonation takedowns; SMS remains the wedge for getting users to fake login pages. Telstra noted collaboration with the National Anti-Scam Centre on campaign fingerprints, though cross-carrier blocking is not yet real-time for every template variant.
What subscribers see
Legitimate messages from hospitals and delivery firms occasionally get caught in aggressive filters—a recurring complaint on social media each tax season. Telstra operates allow-lists for large enterprise senders; small businesses sending bulk SMS without proper registration face higher false-positive risk. The company advises using registered alphanumeric IDs and secure web domains linked in messages.
For households, the practical advice unchanged from Scamwatch: do not click links in unexpected texts, verify organisations through official apps, and report numbers. Ten million blocks in one month means millions never reached pockets; the ones that slip through still drive losses measured in tens of millions nationally.
Industry sharing and gaps
Other carriers participate in ACMA-led industry forums to swap scam fingerprints, but competitive sensitivities slow real-time template sharing compared with banking malware feeds. Cybersecurity minister spokespeople have praised telco blocking volumes while urging faster upstream action against aggregators registered offshore. Consumer groups want mandatory quarterly reporting across all mobile networks, not voluntary Telstra blog posts tied to shareholder meetings.
Device manufacturers also play a role: Apple and Google screen some fraudulent SMS on-device in other markets, but Australian implementations vary by OS version. Telstra said it will continue investing in Cleaner Pipes regardless of handset features, arguing network-level blocking protects prepaid users on older phones most targeted by toll and parcel lures.
What Telstra will report next
Executives told investors scam prevention is a cost centre with reputational upside, not a revenue line. Quarterly updates will continue aggregating call and SMS blocks without daily public dashboards. With grey routes adapting, September’s 10 million figure is less a finish line than a measure of how hard criminals still work the cheapest channel in the pocket—and how much filtering at the network edge remains before regulation catches the gateways upstream.
