Vodacom sim swap fraud - my personal experience

daelm

Expert Member
Joined
Nov 27, 2009
Messages
1,521
Reaction score
2,025
I noticed in the articles recently that Vodacom has been getting attention for sim swap fraud. So, I thought I would share my experience. I want to give people a heads up about (a) the rash of sim swap fraud that seems to be sweeping through Vodacom, and (b) the uphill you're going to have when you try to get someone to do anything about it.

Basically, someone in their organization swapped one of my (dormant) numbers. Fortunately, I made my main number the master and so I received an sms. I notified them and it took a week for them to even take me seriously, during which time I was promised all sorts of things. Then, out of the blue they suspended all my lines, essentially shutting down my business, and I could literally only call the call center, who could not do anything.So i escalated the case, which got me many more promises and no more action.

My case has already been escalated to their executive and theoretically receives attention from the office of the CEO. Further, I am what they once called an "Onyx" customer and therefore supposedly due good service.

Unfortunately not.


So this mail was from this morning...

______________

Please be aware that I am dissatisfied with the lack of response, the failure to perform promised actions and the general lack of service I have received. Not only has this been evident in the call center, but the same has been the case after I escalated these questions and concerns to your executive. No promises have been kept and the matter remains unaddressed. It seems that it is entirely viable for a range of staff at Vodacom to simply ignore me, after placing me at risk, handing my account details out to stranger and illegally performing sim swaps.

Here are the basics of my experience, since I notified you of these issues.

I first notified you of your internal fraud and your governance failure on February 16th, as you can check in the email, sms and account correspondence. It is now the 22nd of March. You are therefore vastly in excess of your own SLA and fraud turn-around time. I have received no correspondence in respect of this "investigation", nor any feedback.

Secondly, I have provided a list of my questions on a number of occasions. To date they have not been answered, despite a number of people promising to do so. In sheer frustration, I compiled an extensive and complete list in prior correspondence. That has been ignored.

Third, I have been promised specific actions will be taken, including the correction of my account balances. This has not been done. I provided a dated list of such promises in earlier correspondence. That has been ignored.
Lastly, I have requested multiple account cancellation quotes. These have not been provided.

Going forward, I am dealing with this via ICASA, who will receive all correspondence from me, and through public and media sources where available and/or accessible. (Vodacom is currently relevant in this regard, with both sim-swap fraud and internal lack of governance an area of focus.)

At the same time, I fully maintain my expectation that Vodacom will address these issues swiftly, as our contract remains intact and as such imposes on you an obligation to address all such issues.

I have now placed a stop on all debit-orders attempted by Vodacom until you resolve this matter, as I cannot trust you not to attempt to extract the results of your internal fraud from my accounts. I am informing you of this well in advance, in order to give you the opportunity to avoid a real and unfortunate stalemate.


Please provide a reference number for this matter, and advise how you would like to proceed.


________________________

The mail below, was a week ago, when I tried to get anyone to take action:



Can someone also please urgently explain why, despite extensive correspondence on this subject going back weeks, my current invoice still reflects the amount of R241,188.52 outstanding of which R237,615.24 is the very same internal fraud that I have been asking you to attend to. It is also the same line item that I was previously promised would be removed from my account, and for which you have apologised in writing. Further, to that: I note that this fraudulent amount is now R237 000. When I first requested that this be investigated and stopped and that the lines be closed, it was R165 000. If my lines were closed, as I was told, (a) how is it that this amount has grown, and (b) if this was removed from my account, how is it that it is on my invoice?

My experience has been as follows:

1. 17 days ago: I asked a number of questions, as follows:

How was it possible for anyone to action a sim swap without sight of my identification?
Once I caught that attempt, and requested that it be canceled, how was it possible - as per Marelise Carelse - for it to be done again? How was it possible for a locked account - locked, as per your call center - to be used by others? Why were my lines opened then suspended again multiple times between the start of this and now? On Sunday night, I was informed that the fraudulent number was active again. How is that possible? Why was this behavior not flagged by your team? Why was the sudden burst of activity on a number that has been dormant for years not picked up internally? Irrespective of whether the user was identifiable or not, these actions occurred after blocks and checks and so on were supposedly placed on my account. Why then were these illegal actions not flagged? Once I had notified you, why was there no default handling or protocol in place to communicate with me, get information from me and ensure my continued safety? As a customer of yours in excellent standing for years, your first priority should be to secure my account on my behalf. Why was I not notified about the next steps, requirements and measures being put in place?
Why did no-one ever return my numerous calls or send any of the promised emails? Why did this only start getting attention last night when I escalated it?


I receive the following reply amongst others:

"We are working through the details provided in your correspondence to us. We will revert shortly."

Current date: Seventeen days later, I have not had an answer to any of my questions. (Now 23 days)


2. 17 days ago I receive the following mail:

"We have added an alert onto your account that will restrict sim swaps, activation of International dialing or roaming on your mobile numbers. Your account will be monitored whilst we are investigating the usage on mobile number 076 *** ****. We will attend to the charges linked to mobile number 076 *** ****, when the next invoice is generated."

Currently: Invoice is produced with the incorrect charges; Two activations subsequently go through on my line without my permission - I receive no information about their nature despite requesting it.



3. 10 days ago, on my request:

"We have requested for a premature cancellation quote to be forwarded to you. I will forward the quote to you within 24 hours."

Current date: no such quote provided after 10 days. (now 16 days)



4. 09 days ago, I ask the following question:

"Please advise why my account reflects as "in arrears" again, on your online portal."

I receive the following reply: "I have requested for feedback from the relevant team. Feedback will be provided shortly."

Current date: No feedback has been provided, and the invoice amounts are wrong. (Now after 15 days)

______________________


If anyone is having similar problems, you can PM me and I'll provide you with the correspondence addresses you can route your problem to.

regards


d
 
Last edited:
in short:

Vodacom staff members, identified as "sales" or "Vodacom direct" actioned a sim-swap on my line more than once, both before and after I reported this to them. I have received a range of answers to queries from them - from ignoring them to apologizing for the errors. what I have not received to date is any explanation of how this happened, why the supposed checks and balances didn't work, whether they exist at all, and any reassurance that my accounts have now been secured.

i was promised a number of things, but most consistently I was promised that my lines were secure. subsequent to that, the same "direct" etc staff processed further sim,-swaps, my lines were not secured and three times longer than their so-called SLA, no investigation has completed and no feedback has been provided to me.

be aware that this should be a simple matter of (a) identifying the error through user date and time stamps, and (b) locking the account from further tampering. this is straight forward. it appear that Vodacom can do neither of those things. I suspect, speaking personally, that their internal processes are so poor that (a) they cannot meaningfully execute any such investigation, (b) that their organizational control is so limited that they cannot enforce any of their supposed SLA's - which is why their "investigation" is out of their control - and (c) that their internal governance is nil, which is why they cannot prevent such fraud.

considering that this happened in the same period of time that a couple of other news articles identified similar issues, I suspect that Vodacom has an internal problem and that syndicates have become more active. Vodacom's responsibility in that regard is to take appropriate action, and apart from anything else, my issue with them is that they clearly haven't.

caveat emptor. I'll be updating this as we go.
 
Last edited:
Keep us posted. I'm sure this will gain a lot of attention here.
 
Can't wait for the "technical" explanation of the company rep. Especially considering the comments made in the ABSA SIM swap thread.
 
Can't wait for the "technical" explanation of the company rep. Especially considering the comments made in the ABSA SIM swap thread.
Don't confuse the issue of banks using OTPs as a 2nd-level of authentication - which I wrote about - with Vodacom's apparent inability to service this customer. Which is patently bad.

The original point stands; if institutions don't use OTPs to help secure their customer's details, there would be no attack on the SIM in the first place. But it's the reality today so we must all deal with it.

The fact that daelm is getting the runaround is just common or garden k@k service. I'll escalate it.
 
Don't confuse the issue of banks using OTPs as a 2nd-level of authentication - which I wrote about - with Vodacom's apparent inability to service this customer. Which is patently bad.

The original point stands; if institutions don't use OTPs to help secure their customer's details, there would be no attack on the SIM in the first place. But it's the reality today so we must all deal with it.

The fact that daelm is getting the runaround is just common or garden k@k service. I'll escalate it.

If we don't drive cars there'll be no hi-jackings.
 
Don't confuse the issue of banks using OTPs as a 2nd-level of authentication - which I wrote about - with Vodacom's apparent inability to service this customer. Which is patently bad.

The original point stands; if institutions don't use OTPs to help secure their customer's details, there would be no attack on the SIM in the first place. But it's the reality today so we must all deal with it.

The fact that daelm is getting the runaround is just common or garden k@k service. I'll escalate it.

Spot on. Vodacom failed spectacularly on customer experience in this case.
 
Yep...... Vodacom.

They cancelled my (082) contract instead of my son's sim-only one on the morning of 31 Jan. All data and voice minutes were gone.

The cherry on top. By 1 Feb they kinda acknowledged their mistake, but told me it would take up to 14 business days to re-instate the contract... and I should buy airtime and data in the interim.

That same evening my number was ported out.
 
Yep...... Vodacom.

They cancelled my (082) contract instead of my son's sim-only one on the morning of 31 Jan. All data and voice minutes were gone.

The cherry on top. By 1 Feb they kinda acknowledged their mistake, but told me it would take up to 14 business days to re-instate the contract... and I should buy airtime and data in the interim.

That same evening my number was ported out.

Hi,

Please can you post this in your own thread. :p

Maybe if there are many threads about the SAME thing VC will start admitting that their system is badly flawed.
:rolleyes:

Then jannievanzyl can tell the bosses at VC that the customers are tired of VC crap
 
Don't confuse the issue of banks using OTPs as a 2nd-level of authentication - which I wrote about - with Vodacom's apparent inability to service this customer. Which is patently bad.

The original point stands; if institutions don't use OTPs to help secure their customer's details, there would be no attack on the SIM in the first place. But it's the reality today so we must all deal with it.

The fact that daelm is getting the runaround is just common or garden k@k service. I'll escalate it.

There is no confusion here - it is quite simple: Even if banks move to 2FA to authenticate transactions, Vodacom and others are still eft with SIM swop issues due to lack of internal controls. Once banks move to 2FA, you will notice that criminal elements will exploit SIM swops to use voice- and data associated with the customer account.

I am not going to argue openly about how poorly service providers manage security and protect from data-leakage. We all know that leakage occurs with teams with privileged access (developers having access to production data which was replicated to staging environments, DBAs leaking backups and database dumps etc) - there is no point in defending this point as it happens weekly and remains mostly undetected. The ones which get caught are inherently daft and leak information why your customer care systems. The syndicates operate on a different level altogether. Without derailing too much: Prime example of what happened two weeks ago: A prominent company noticed a WiFi dongle and a USB stick being plugged into some of their servers within their cage and are now scrambling to figure out what happened.

The big question is really: How on earth is it still possible that unauthorised SIM swaps happen and how can it take weeks to address the issue. I get that you will refund the customer. Begs the question how many similar issues occurred without you even knowing (because no-one complained).
 
The big question is really: How on earth is it still possible that unauthorised SIM swaps happen and how can it take weeks to address the issue. I get that you will refund the customer. Begs the question how many similar issues occurred without you even knowing (because no-one complained).

This has been my question from the start - not only how can it be done, but once it has been done, why can it not be stopped? I reported this, and then had it happen twice more apparently. Further, despite me asking to have the lines locked, they stayed open. So there's a bunch of things that are unanswered here. Their inability to provide service around the resolution of this issue, while shocking in principle, is sadly unexpected these days. They have been unable to render any kind of service for a long time. If there was viable competition to them in South Africa, they'd go out of business.

I should also point out something I didn't mention in the previous posts.

From the 16th February when I reported their fraud to them, to the present day (one month, 7 days and counting), I have not ever been contacted by their fraud investigators. Not once. In fact, the existence of these folks only became known to me after I escalated to their EXCO and I still have had no contact with them. What they did manage to do in that period was cut me off from my business without warning, make me inaccessible to everyone who knows me, suspend my other (main) lines without notification, refuse to escalate the matter on request, and send me on a merry run-around to Vodacom stores to be "identified" and do a legal sim-swap. (The stores, of course, told me that they couldn't, because the case was flagged "fraud", so I just wasted my time.)

This makes me believe that their internal process is broken. If you're relying on them to manage your data, rather take steps to protect it yourself. They have given me no indication that they can.


Update as at 01 April: I have to date never been contacted by their "fraud investigators". You can read this a number of ways. Mostly, it implies that they don't need to - this is wholly an internal affair. That reading alone makes their continued disengagement from me even worse - if its's all internal, then it's all on you and you should be all over your customer, apologising for screwing them over and ensuring that they are not further disadvantaged. Effectively, their fraud department is a "fraud".


Update as at 13 April: I have to date still never been contacted by their "fraud investigators". Further, I have not been contacted by any of the "senior people" who are referenced later in this thread, nor have I received any of the information I requested. Vodacom has managed to screw up my account reference online, which continues to go in and out of arrears state. The matter has been delegated to a service agent to handle and Vodacom has washed their hands of it. FYI.

Update as at 25 April:
I assume that Vodacom regards this as closed now. For the benefit of anyone who was following it:
1. I received no explanation of what happened, despite was is being claimed in this thread.
2. I was provided with no idea of what has been done to prevent it, again despite what has been claimed in this thread.
3. I was never given an explanation of why their service staff failed, why I was cut off from my business for such a long period, and what has been done about that.
4. No-one has apologized for that either. Apparently, I don't merit the time.

Thanks Vodacom. You've made it clear to me where I stand with you and have definitely lost me as a customer. There is zero chance that I will place any further business with you of any type, and I will actively be advising people to avoid you in future.
 
Last edited:
Don't confuse the issue of banks using OTPs as a 2nd-level of authentication - which I wrote about - with Vodacom's apparent inability to service this customer. The original point stands; if institutions don't use OTPs to help secure their customer's details, there would be no attack on the SIM in the first place. But it's the reality today so we must all deal with it.

Thanks. I replied to your PM.

On the OTP subject, you're right in theory. But there are actually two mutually distinct sets of obligations at work. On the part of the bank, they have an obligation to protect my account from intrusion. On the part of the telco, they have an obligation to protect my data and service from hijacking. The fact that the bank discharges their obligation poorly, in part by outsourcing it to the telco, doesn't change the obligation on the telco, it simply raises the telco cost-of-failure. The telco - Vodacom in this case - failed spectacularly and that has nothing to do with the bank.

There are three ways that this could have occurred.

Firstly, someone could have spoofed my ID. Since Vodacom apparently allows sim-swaps via the call center - I don't understand how - that's a weakness. and one you have no business offering. The obligation to protect my data and service was compromised, most likely to reduce costs somewhere.

Secondly, it could have been done in-house, by someone using credentials that won't lead to them, and working with a syndicate outside Vodacom. In that case, there should be a range of measures in place to flag and inspect "suspicious" transactions. For example, a sudden burst of activity on a line dormant for years is suspicious. Similarly, unusual activity following a sim-swap, or following a change of contract is suspicious and each of these are straight-forward routines that can be automated. Further, there should have been a business practice for responding to flagged transactions, such as making contact with the client and so on. The banks (for whom I have worked across South Africa and who don't do a brilliant job of this at all) manage to link flags and business processes in this way.

Third, it could have been an external intrusion into Vodacom systems, and in that case Vodacom is as much at fault as before.If the Vodacom footprint is broad enough to make external intrusion worthwhile, then that set of systems needs to be defended and suspicious events flagged as described above. Personally, my money is on number two because that's the most common.

In any event, this kind of complete breakdown - the inability to get fraud recognized and reacted to, the inability to get it investigated, the total breakdown of customer-centricity, the broken processes that no-one seems to be able to influence and so on - is interesting in light of the mobile operators arguing that they can function effectively as banks/stores-of-value.

People seem to be forgetting that it's not merely a matter of liquidity that regulates fin services - it's also the organization's ability to securely perform financial transactions and protect data. Based on these kinds of experiences, there is no way in hell that I would think Vodacom could function as a bank.
 
Last edited:
Update:

After more mailing back and forth this morning, I got the following response:

"Please be advised that our Legal colleagues are busy unpacking the feedback from our Forensics Team in order to compile an accurate response to the questions that you have posed ,this will take +/- 7 working days as we need to ensure it is an accurate account of your related experience."

Basically, they're asking for another 7 days, on top of the month and half they've wasted already. Their "forensic" team or "fraud" team has most likely simply not done anything yet, so they're starting now and they'll tick over their new SLA until they exceed it. (Their publicly stated SLA on this type of thing, by the way, is 14 days.) So, that's where we are right now. No further. In case anyone was wondering.


On a lighter note, they've misspelled my name. Not for the first time, either. :)
 
Last edited:
the other thing that bothers me about this delay -having just spoken to one of their staff and had it triggered for me - is that because they haven't told me how it happened, i don't know if my Identity Documents have been compromised.

if, for example, someone presented a facsimile ID using my details, that's pretty important for me to know because in the time that's passed, they could have been presenting that all over town. if not, and some other proof of identity was presented, it's important for me to know that too. if they identified me by reference to "security questions", that's important for me to know too, since it indicates that something in my world was compromised. there are so many things that matter in this, apart from their utter failure to handle it well.
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X