Blog

Telstra Called About My Slow Internet. There Was Just One Problem.

Aug 27, 2026

I recently received an unsolicited phone call from someone claiming to be from Telstra technical support.

The caller said they were contacting me about a problem with my slow internet. Or my home internet speed. Something along those lines.

There was one fairly major problem with this story.

I do not have an internet service with Telstra.

That made the call quite a short one. There was no need for careful forensic analysis or a dramatic moment of deduction. Someone rang me claiming to be from Telstra about "my" Telstra internet, and I am not a Telstra internet customer.

I did challenge the caller. I told them I was very aware they were not from Telstra, and then gave them a brief lecture that their scam attempt would be reported to the Australian cybersecurity authorities for investigation. That seemed to bring the call to a fairly prompt end.

As scam calls go, it was not especially sophisticated. But that is exactly why it is worth talking about.

Why This Works Anyway

Telstra is one of Australia's biggest and most recognisable telecommunications brands. If a scammer makes enough calls claiming to be from Telstra, they will inevitably reach people who actually are Telstra customers.

And almost everyone has experienced slow or unreliable internet at some point.

So when someone hears, "We're calling from Telstra about the problem with your internet speed", it is not hard to see how the first reaction might be something like this.

"Actually, it has been a bit slow lately."

At that point, the caller has made a connection and "hooked you" without necessarily knowing much about the person they called. They do not need the victim's address, account number, router model or recent fault history. They only need a large brand and a common annoyance.

In my case, the mismatch was obvious. In someone else's case, it may not be.

That is the useful lesson. The call did not fail because the technique was absurd. It failed because the caller guessed the wrong provider.

Know Who Actually Looks After Your Technology

The practical security principle is simple. Know who actually provides and manages your technology, and do not let an unsolicited caller establish legitimacy merely by naming a recognisable company.

For a household, that can include things like:

  • internet provider
  • mobile provider
  • router or network equipment
  • email provider
  • cloud storage
  • IT support provider

For a small business, the list is usually longer:

  • domain registrar
  • DNS provider
  • website host
  • web developer
  • Microsoft 365 or Google Workspace provider
  • accountant or bookkeeper
  • payment systems
  • remote IT support
  • SaaS services

This is one reason I keep returning to documentation in security work. A simple list of providers and authorised contacts is not exciting, but it is useful. If a business owner receives a call supposedly from Microsoft, the bank, the web host, the domain registrar or an IT support company, they should not have to guess whether that organisation has a legitimate reason to be calling.

The question should be answerable.

Who provides the service? Who has admin access? Who is allowed to request changes? Which phone number, app or support portal should be used for verification?

That kind of clarity is part of practical cyber security. It is also closely related to the work I do around small business cyber security reviews, secure home office IT and domain, DNS and email security. The common thread is understanding who controls what.

Do Not Help the Caller Improve the Script

There is another small point that matters.

If someone says, "I'm calling from your internet provider", it may be tempting to correct them.

"That's impossible, I'm with [real provider name]."

Likewise, if someone claims to be from a bank you do not use, there is no need to tell them which bank you do use.

That information may simply make the next attempt better. Scamwatch notes that callers may already have some details about you, and the whole point of many scams is to collect more personal information. That little snippet of truth you just gave away could then be used in a later call.

If a suspicious caller has guessed incorrectly, that is useful to you. It does not need to become useful to them. The safer course is usually to end the call and verify independently if needed.

This is not about being rude. It is about not supplying extra facts to someone who has not earned trust.

What Telstra and Australian Scam Advice Say

The current official advice is pleasingly undramatic. Hang up, do not share information, do not install software, and verify through a channel you choose.

Telstra's own Protect yourself from scam calls guidance says suspicious calls should be ended, personal or financial information should not be shared, links or apps suggested during the call should not be used, and the organisation should be contacted directly using details from its official website or app.

Telstra also tells customers who are unsure whether Telstra is calling to reject or end the call and contact Telstra directly in its Is it really Telstra contacting you? support material. Its unwelcome calls advice says Telstra will not call about a service or technical matter unless the customer contacted Telstra first.

That last point is the one that makes my call especially tidy. I had not contacted Telstra, and I did not have Telstra internet.

Scamwatch's current phone scam guidance says to let unknown numbers go to voicemail where appropriate, hang up if you are not sure who the caller is, never use contact details supplied by the caller or in an email or SMS, and contact the organisation using a number you find yourself or through a secure authenticated portal or app.

The ACMA's phone and SMS scams advice is similar. Do not engage when unsure, use official websites or apps rather than message links, and do not provide personal details. ACMA's caller ID scam guidance also makes the important point that caller ID can be spoofed, so a displayed number is not proof by itself.

This is not just Telstra advice. TPG's scams awareness guidance tells customers not to provide personal details during unexpected calls and to hang up if a suspicious call claims to be from TPG. It also tells customers not to use contact details supplied in a suspicious message, and to contact TPG through known official channels if unsure.

The wording varies, but the pattern is consistent.

End the contact. Do not use the caller's details. Find the organisation yourself through its real website, authenticated app, bill, card or another trusted source.

A Landline Precaution Worth Remembering

There is one extra caution worth knowing, particularly for people still using older fixed-line services.

Some telephone scams have historically exploited the way a landline connection can remain open briefly after one party hangs up. The scammer tells the victim to verify the call with their bank or provider, appears to hang up, keeps the line open, presents or simulates a dial tone, and then pretends to answer when the victim thinks they have dialled the real organisation.

HSBC Australia described this in a 2024 warning about scammers posing as banks or couriers. The scammer can pretend to hang up while keeping the line open, leaving the customer still connected when they believe they are calling the bank.

This is not the main point of my Telstra call, and it should not be overstated. I am not saying every NBN voice service behaves this way in 2026, and I am certainly not saying it applies to ordinary mobile calls.

The practical advice is narrower. If you have just received a suspicious call on a landline and need to verify the organisation, use another device where possible. Call from your mobile instead of immediately redialling from the same fixed-line phone. If the suspicious contact was on your mobile, use the provider's authenticated app or website.

For example:

  • suspicious call comes to landline, verify using a mobile
  • suspicious call comes to mobile, check the provider's authenticated app or website
  • suspicious SMS, do not use its link or number
  • alleged bank call, use the number on the bank card or inside the official banking app

The strongest idea is the same throughout. Break the caller's channel of control.

Why This Matters More in Small Businesses

A small business owner can receive calls supposedly from Telstra or another ISP, Microsoft, a bank, a web host, a domain registrar, an accountant, a payment provider or an IT support company. Some may genuinely have a reason to contact the business. Some may not.

The problem is that many small businesses do not have a clear map of their own technology. The domain might be registered through an old web developer. DNS might be with one provider, email with another, hosting somewhere else, and the website maintained by a different person again.

In that environment, a fake support call has room to breathe.

If responsibility is unclear, the owner may genuinely not know whether a call about the web host, Microsoft account, domain renewal or internet service is plausible.

A simple provider list is a useful control. It should record the service, provider, account owner, authorised support contacts, official login or support routes, renewal details, and who can approve changes. It does not need to be complicated. It just needs to exist and be kept current.

Private Households and Family Offices Have the Same Problem

The same issue appears in private households and family offices, just with different labels.

A household with several properties, accountants, financial advisers, assistants, smart-home installers, network equipment, security systems and multiple technology providers can have a surprisingly complicated digital environment.

Expecting everyone in that environment to detect every convincing fake call is not realistic. A better approach is to establish a verification process.

Unsolicited support requests are not acted on immediately. Remote access is not granted because someone called first. Financial or account-change requests are independently verified. Trusted providers and their official contact routes are documented.

That sounds plain because it is plain. Most useful security controls are.

What I Took From the Call

The fake Telstra call I received was easy for me to reject because the caller's guess was wrong.

But if the same call reached a Telstra customer during a week when the internet had actually been slow, it could feel more plausible. Not because the scammer knew anything clever, but because the claim matched a common provider and a common frustration.

That is the bit worth remembering.

Do not let a familiar company name do too much work. Know who provides your services. Know who is allowed to contact you. End suspicious calls without feeding the caller better information. Verify through a channel you choose yourself.

And if Telstra rings about your Telstra internet when you do not have Telstra internet, you have at least been handed a very efficient opening paragraph.

Share on LinkedIn