Telstra's numbers had been compromised sometime during the first week of April 2012. After that, anyone whose telephone number began with 4963 was vulnerable.
Someone used a Caller ID Spoof to use those lines to call 1900 910 080. This was the Runescape paybyphone line. Each time it was called, it cost the account holder the price of membership into the game.
These lines weren't just used once, but many times.
The operator would have charged the account and handed over a Surfpin code. That four figure number allowed one month's membership into the game.
No-one was any wiser until the itemized bills came out. Then, one by one, the complaints came flooding into Telstra. The company quickly realized that something fraudulent had taken place.
Chris Cusack, speaking on behalf of Telstra, told the Newcastle Herald, "Our investigation is continuing and we have now briefed police." Naturally no other details were forthcoming.
It's understood that Jagex, Surfpin and Cloudtel, who all have a stake in facilitating this mode of buying Runescape subscriptions, are all helping police with their inquiries. It's not known, at this stage, if the 'phone phreaks were even Australian. They could have called from anywhere in the world.
In the meantime, many Australian house-holders are left with bills reaching into the hundreds of dollars.
Comments
This is the first I've heard about this (obviously a little slow when it comes to news) but scary to think especially since I'm now a Telstra customer.
Unfortunately I don't know enough about the phone networks to comment about it. But I think it will be incredibly difficult to trace them. Not impossible, just difficult.
Wow. That's different. :|
How do they manage to do that? Is it traceable to the original phone line that made the call, or will they have a harder time finding the thieves?
It confused me too. It can't be bog standard Caller ID Spoofing, because they actually did get the number. It has to be some kind of box phreaking to my mind.
What an odd story.
I'd like to know how the phreaks managed to do it, as the technology has had anti-phreaking systems in place since the early 90's. Saying that, TeaMp0isoN allegedly used a phreaking technique when they screwed around with Scotland Yard earlier this year.
Just another reason to ditch landlines