John and Julie were about to embark on a family holiday in May when Bankfirst contacted them about suspicious activity in one of their accounts.
The Melbourne-based couple then discovered John’s phone was on “SOS”.
Known as porting, someone had gained control of his identity by having his mobile number ported to another device.
John and Julie called their banks, credit card providers, and telco — Westpac, ANZ, Macquarie, Qantas Travel Money, and Woolworths Mobile — to notify them.
Thinking all their accounts were protected, they went overseas the next day.
But by the time they got home, fraudsters had drained their bank accounts by at least $325,000, sold $45,000 worth of their shares, and created 20 credit and debit accounts in their names.
And as part of their tactics, the fraudsters had ported their phones and accessed John’s email account, messaging friends, family, and work clients in an effort to pull others into their web.
The semi-retired couple, who requested to keep their surname private, had become victims of sophisticated identity theft.
While they said they were part of the Medibank and Latitude data breaches, they do not know for sure how the hackers first got access to their licence and passport details.
But in a time of high anxiety, they have had little to no reassurance from their banks that they would get their money back.
“They made us feel like we were the criminals,” John said.
Holiday becomes ‘nightmare’
John and Julie attempted to contact their banks and credit card providers, including Westpac, ANZ, Macquarie, and Qantas Money when they noticed some money missing from their accounts while overseas.
“It was a nightmare,” Julie said.
“You couldn’t get through to anybody, we were on hold for hours on end.”
The couple said they were told by multiple banks they needed to go to a branch to confirm their identity, which was not possible as they were overseas.
The couple also said Westpac requested they send through a photo of themselves holding their passport to prove their identity.
As they could not confirm their identity, they could not access their accounts and therefore did not know the extent of their financial losses.


