NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

SIM card hijacking costs Kiwis big money

Chris Keall
By Chris Keall
Technology Editor/Senior Business Writer·NZ Herald·
18 Mar, 2020 04:00 PM7 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Image / 123rf

Image / 123rf

Cert NZ is warning about a new cybercrime that's made its way to New Zealand: SIM card hijacking, also known as a SIM card swap attack - which allows a hacker to take control over your mobile phone number and pretend to be you.

The Crown cybersecurity agency says "less than 10" Kiwis have been hit by the scam.

But Cert director Rob Pope says because it gives a hacker such pervasive control over your life, the average loss has been large: some $30,000 per victim.

And as the Herald pointed out back in October last year, it's a nightmare to sort out.

In detailed comments, Spark (keep reading) said safeguards were tricky to implement under current legislation because an attempt to contact a customer to confirm they wanted to leave and take their mobile number to another provider was regarded as an anticompetitive attempt to win them back.

Advertisement
Advertise with NZME.

READ MORE:
• Cert NZ warns about three types of Covid-19 scams
• Coronavirus: Spark latest ISP to remove caps on all broadband plans
• Councils' parking app hit by ransomware attack

Cert (the initials stand for Computer Emergency Response Team). Was set up as a kind of cyber triage unit. It can direct people or small businesses to the right law enforcement or technical help in the event of an online attack, or attempted scam.

SIM hijacking is where an attacker uses "social engineer" (old fashioned con artist) skills to get your mobile phone number added to their SIM card.

Advertisement
Advertise with NZME.

The hacker can then receive all voice calls and texts meant for you.

"Once the attacker has the victim's mobile phone number on their SIM card, they try to access their accounts, such as bank accounts, using stolen or guessed credentials," Cert NZ warns.

Discover more

Business

Councils' parking app hit by ransomware attack

11 Mar 04:17 AM
Business

$12b coronavirus package: IT leaders on what needs to happen next

17 Mar 04:42 AM
Business

Coronavirus: Cert NZ warns about three types of Covid-19 scams

17 Mar 07:48 PM
Business

Spark latest ISP to wipe data caps on all plans amid work-from-home surge

17 Mar 09:21 PM

"When prompted for a two-factor authentication code, the attacker uses the stolen number to receive two-factor authentication by SMS – working around the security control.

"There is a significant risk to the people and businesses targeted by these attacks because the attacker can perform sensitive tasks, like changing passwords or authorising financial transactions."

Anecdotal reports show that incidents of SIM swapping are increasing, "as motivated
attackers find ways to circumvent additional security controls," Cert says in its latest quarterly report.

SIM swap attacks the process of porting or "number portability" which lets you take your phone number with you when you switch mobile service providers - something that was introduced in NZ and elsewhere to boost competition.

It's been around a while overseas, Cert NZ director Rob Pope says, but the fourth quarter of last year was the first time it appeared in New Zealand.

Pope says the key step people should take to protect themselves is to not use two-factor authentication (or "2FA") that involves a mobile phone. That's when you don't just have to type a password into your computer to access a website but also a code sent to your phone by txt.

Advertisement
Advertise with NZME.

People should look for an alternative confirmation, such as a code sent to an app.

Also, two-factor authentication also commonly asks for the answer to a security question you've setup, such as "What is your mother's maiden name". Pope says unfortunately that information is usually easy to find online. The solution is to setup security questions with untrue answers.

Industry group the Telecommunications Forum (TCF), whose members include Spark, Vodafone and 2degrees, oversees number porting. Its head, Geoff Thorn told the Herald:

"The TCF is very aware of the hardship the SIM swap frauds cause.

Cert NZ director Rob Pope warns that getting a code sent to your phone - as an extra logon precaution when accessing a banking website or other service - is not as secure as it seems. Photo / File
Cert NZ director Rob Pope warns that getting a code sent to your phone - as an extra logon precaution when accessing a banking website or other service - is not as secure as it seems. Photo / File

"Each of the mobile operators has changed its processes to make it harder for fraudsters to swap a number to their own device.

"The TCF exploring the possibility of making technical changes which will provide additional protection to consumers."

Thorn says the TCF backs Cert NZ's advice not to use two-factor authentication that involves a text sent to a mobile phone. "Although it is better than nothing, SMS authentication is not a secure means of obtaining the authentication," Thorn says.

Spark: Well-intended protection backfires

Spark spokeswoman Sam Smith told the Herald, "To prevent fraudulent sim swapping, Spark has implemented a process whereby customers must visit a Spark store and present identification before the swap can be approved.

"These measures have been extremely effective, however porting fraud where customers port (move) their number to another service provider is more complicated and requires a coordinated industry-wide change to the porting rules.

"Currently, the information requested when someone wishes to port is as per industry and regulatory requirements, that is: customer name, MSISDN (unique phone identification number) to be ported, and current Postpay Account number or Prepay SIM card number. This information is submitted to IPMS (the Industry number portability coordinating system managed by TCF) and is then verified and approved/declined by the LSP (losing service provider).

"As it stands, the regulated industry code for porting determines the process and it is up to the LSP, to verify and approve the port.

"This, unfortunately, makes it tricky to identify when a porting request is fraudulent, as due to the current legislation, the LSP is not permitted to contact the customer directly as it could be considered as an attempt to 'win back' the customer which is against the original anti-competitive spirit of the porting rules."

Communications Minister Kris Faafoi has been asked for comment on the possibility of a legislative update.

In the meantime, Smith said, "The industry is currently exploring whether it is feasible to introduce a validation step to the porting process so the customer has to confirm the port is valid before it will proceed."

A TCF working party is also developing a code that would see one central place for all scam reports to be filtered into. "The code involves organisations such as banks, Police, online safety organisations, as well as telcos and would therefore provide a full and accurate picture of the scamming landscape in New Zealand. Industry has a similar Code for scam calling today and we are seeking to replicate this for mobile messages, too," Smith said.

Vodafone: Increasingly sophisticated attacks

For Vodafone NZ, spokeswoman Nicky Preston said, "It's frustrating and upsetting that scammers continue to increase their efforts to defraud Kiwis, with phishing scams on the rise.

"We urge New Zealanders to be aware of potential phishing attacks and stay vigilant – as fraudsters will try to obtain a customer's personal information from many different organisations, via increasingly sophisticated methods, and by using topical situations like the current Covid-19 pandemic."

She added, "As an ongoing measure, we ask all customers to regularly change their passwords and PINs and never give out personal information unless they are certain who they are dealing with.

"SIM swapping fraud is complex but we are doing everything we can to combat fraudsters and to further protect Vodafone customers. We are working closely with other telcos and the TCF to develop additional industry-wide measures to make SIM swapping fraud more difficult, including assessing international best practices."

More online attacks

Overall, Cert's fourth-quarter 2019 report found a modest decrease in online scam activity, with total reports falling from the year-ago 1333 to 1197, and reported financial losses declined from $5.9m to $4.7m.

However, for 2019 as a whole, the agency reported a 38 per cent increase in reports of cyber attacks. A total of 689 involved financial loss, 603 of those to individuals.

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Premium
Shares

Market close: Geopolitical tensions keep NZ market flat, US Fed decision looms

18 Jun 06:09 AM
Premium
Business

Fringe Benefit Tax: Should you be paying it if your business owns a ute?

18 Jun 06:00 AM
New Zealand

'Life-changing': International flights return to Hamilton Airport

18 Jun 05:23 AM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Premium
Market close: Geopolitical tensions keep NZ market flat, US Fed decision looms

Market close: Geopolitical tensions keep NZ market flat, US Fed decision looms

18 Jun 06:09 AM

The S&P/NZX 50 Index closed down 0.10%, falling to 12,627.32.

Premium
Fringe Benefit Tax: Should you be paying it if your business owns a ute?

Fringe Benefit Tax: Should you be paying it if your business owns a ute?

18 Jun 06:00 AM
'Life-changing': International flights return to Hamilton Airport

'Life-changing': International flights return to Hamilton Airport

18 Jun 05:23 AM
Premium
Liam Dann: 'Brick wall' – why tomorrow’s GDP data won’t tell the real story

Liam Dann: 'Brick wall' – why tomorrow’s GDP data won’t tell the real story

18 Jun 05:17 AM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP