WealthWorks WealthWorks

Bank Scam Losses in Australia: Reimbursement Rights, the ePayments Code and the 2026 Enforcement Shift

WealthWorks Team
11 min read

Losing money to a scam creates two urgent questions: can the transfer be recovered, and who legally bears the loss? The answer in Australia is more complicated than either “the bank always pays” or “the customer authorised it, so nothing can be done”.

The distinction between an unauthorised transaction and a payment a customer was manipulated into authorising is central. So are the bank’s fraud controls, the warnings given, the speed of its response and the evidence preserved by the customer. On 18 June 2026, the Federal Court ordered HSBC Bank Australia to pay a $35 million penalty after admitted failures concerning scam protection. ASIC said HSBC’s remediation program had paid about $21.5 million by then, with additional payments expected, and recovered another $6.5 million for customers.

That decision is a major enforcement signal, but it is not an automatic reimbursement rule. This guide sets out a practical response for Australian households and small businesses.

The scale of the problem

ASIC’s 17 July 2026 warning about pump-and-dump schemes cited $2.18 billion in Australian scam losses reported for 2025. Investment scams accounted for $837.7 million, or about 38.4% of that amount.

2025 reported Australian scam measureAmount
Total reported losses$2.18 billion
Investment scam losses$837.7 million
Investment share of total38.4%

These numbers reflect reported losses. Shame, uncertainty and lack of awareness mean the true harm may be greater. Losses also include disrupted retirement plans, tax consequences, legal fees and emotional damage.

Authorised versus unauthorised transactions

Unauthorised transactions

An unauthorised transaction may occur when a criminal obtains credentials and transfers money without the account holder’s actual authority. Card theft, account takeover and some remote-access events can fall into this category. The ePayments Code contains allocation rules, including circumstances involving passcode security, reporting delays and limits on liability.

Labels are not decisive. A bank cannot simply call a transaction authorised because a correct passcode was used. Conversely, a customer saying “I was scammed” does not prove the payment was unauthorised. Investigators examine who performed each step, what authentication occurred and whether the customer knowingly gave a payment instruction.

Authorised push-payment scams

In an authorised push-payment scam, the customer instructs the bank to send money but does so because of deception. Examples include a fake conveyancer changing settlement details, an investment impersonator directing a transfer, or a criminal posing as the bank and claiming funds must be moved to a safe account.

These cases can be harder under rules focused on unauthorised transactions. However, that does not end the inquiry. A complaint may examine whether the bank responded to clear red flags, complied with legal and code obligations, made misleading representations, or failed after notification.

What the HSBC outcome actually says

ASIC described the case as one of the first of its kind globally and a strong warning to banks. The $35 million court penalty followed HSBC admissions about serious failures to protect customers and help victims. Compensation and recovered funds were separate from the civil penalty paid as a regulatory sanction.

HSBC-related figure reported by ASICAmount
Federal Court penalty$35 million
Compensation paid by June 2026About $21.5 million
Funds recovered and returned$6.5 million

The case concerned particular systems, conduct and unauthorised transactions. Another bank, customer and scam will have different facts. Consumers should cite relevant principles in a complaint, not assume the penalty proves their individual entitlement.

The first hour after discovering a scam

Call the bank using a verified number

Use the number on the bank’s official website, app or card, not a number in the suspicious message. Tell the fraud team that a scam or account compromise is occurring. Ask it to block further transfers, cards, payees and online sessions as appropriate.

For a transfer, request an urgent recall and contact with the receiving institution. Recovery becomes more difficult once money moves through mule accounts, cryptocurrency or overseas channels. Note the time, staff name or identifier and reference number.

Secure access from a clean device

If remote-access software or malware may be involved, do not change passwords on the compromised device. Disconnect it, use a clean device and secure email first because email often controls password resets. Change banking credentials and enable strong multi-factor authentication. Contact the mobile provider if a SIM swap is suspected.

Preserve evidence

Take screenshots of messages, profiles, websites, wallet addresses and call histories. Export emails with headers where possible. Write a timeline while memory is fresh. Do not continue engaging merely to collect evidence if doing so risks further loss.

The first 24 hours

Report the matter through relevant Australian channels. ReportCyber can generate a reference and route cybercrime information. Scamwatch collects intelligence. Police involvement may be appropriate, especially for identity theft, threats or a substantial loss. IDCARE can assist with identity compromise.

Notify other affected institutions. A false invoice may expose a business email account and other customers, not just one transfer. Change supplier bank details only through a separately verified contact method.

ActionWhy timing matters
Bank fraud reportMay stop or recall funds
Receiving-bank notificationCan support account restraint
Credential resetLimits repeat access
Evidence captureWebsites and messages disappear
Cybercrime reportCreates a dated official record
Credit-file protectionReduces identity fraud risk

Building a reimbursement complaint

Start with a neutral chronology

State dates, amounts and actions in order. Separate what you knew at the time from what became clear later. If $48,000 was sent in three transfers, list each amount, recipient, warning, authentication step and bank contact.

Avoid overstating facts. Saying “the bank gave no warning” can damage credibility if a generic warning appeared. A stronger account may be: “A warning appeared, but it referred to online shopping and did not address the bank-impersonation scenario I reported.”

Identify the transaction pathway

For every disputed transaction, record:

  • who entered the payment details;
  • who pressed confirm;
  • whether a one-time code or app approval was used;
  • whether the scammer had remote access;
  • whether the bank called or paused payment;
  • what the customer told the bank;
  • when the transaction settled; and
  • what recovery attempts followed.

This evidence helps distinguish actual authority, passcode use and post-notification failures.

Quantify the remedy

Request the exact principal loss, fees and appropriate interest. Do not mix the stolen amount with speculative investment returns. If the loss was $75,000 and $12,000 was recovered, the unrecovered principal is $63,000. Explain consequential loss separately and provide evidence.

The ePayments Code

ASIC administers the ePayments Code, which applies to subscribing entities and many consumer electronic payment products. It covers areas including unauthorised transactions, passcodes, mistaken internet payments, receipts and complaint investigation.

Passcodes and customer conduct

The Code does not mean any use of a passcode makes the customer liable for the entire loss. It contains nuanced rules about contribution to loss, fraud, unreasonable delay and liability limits. Banks should investigate rather than rely on a single authentication fact.

Customers should nevertheless protect passcodes, never disclose one-time codes and promptly report loss, theft or compromise. A bank employee should not ask a customer to transfer funds to a “safe account” or disclose a full authentication code.

Mistaken payments are different

Sending money to the wrong BSB or account number without deception may engage mistaken internet payment procedures rather than scam rules. Tell the bank precisely whether the recipient was incorrect, the invoice was altered, or a criminal induced the payment.

Internal dispute resolution and AFCA

Give the bank a clear written complaint

Mark the communication as a complaint and ask for an internal dispute resolution reference. Request the reasons for the decision, relevant transaction logs, warnings, recovery steps and the provisions relied upon. Financial firms have prescribed response timeframes, although urgent recovery activity should occur immediately rather than wait for the complaint process.

Escalate when necessary

If the response is late or unsatisfactory, AFCA may consider an eligible complaint. AFCA can examine law, codes, good industry practice and fairness within its rules and monetary jurisdiction. Lodging is free for consumers, though legal or financial advice may still be valuable for a large or complex case.

Do not miss limitation periods. The bank’s final response generally explains AFCA rights and deadlines. A court claim has different costs, procedures and limitation issues.

Small-business scam risks

Business email compromise can bypass consumer protections, and the ePayments Code may not cover every business facility. A $120,000 invoice diverted to a criminal account can exceed transfer patterns yet still use valid employee credentials.

Use dual verification

Require two approvals above a threshold such as $10,000. Verify new or changed bank details by calling a known contact using a number already held, not the invoice. Separate the person who creates a payee from the person who approves payment.

Set bank controls

Use daily transfer limits, payee whitelists, alerts and dual authorisation. A business that rarely sends international transfers should ask whether that function can be disabled. Review dormant users promptly after staff departures.

Rehearse the response

A one-page plan should name the bank fraud number, insurer, IT provider, lawyer and executive decision-maker. Fifteen minutes spent finding contacts during an incident can materially reduce recovery prospects.

Investment scam warning signs

ASIC’s July 2026 alert described fake celebrity endorsements and messaging groups used to promote shares before orchestrators sold into an inflated price. Warning signs include unsolicited WhatsApp or Telegram invitations, guaranteed returns, screenshots of profits, pressure to buy a thinly traded stock and instructions to conceal the group’s activity.

Check the ASIC professional registers and investor alerts. Confirm an Australian financial services licence independently; scammers clone real licence details. Search the company’s ASX announcements and understand liquidity. A licence does not make a particular investment safe.

A household prevention framework

Create a transfer rule

For any unexpected request above $2,000, pause and verify through a second channel. Households can choose a threshold that fits their position. The key is a predetermined rule, because urgency and authority impersonation weaken judgment.

Protect vulnerable family members

Agree that no genuine family member will object to a verification call. Use transaction alerts and trusted contacts with consent. Avoid taking control in a way that removes autonomy; the aim is a safe circuit-breaker.

Review information exposure

Criminals personalise approaches using social media, property listings and leaked credentials. Limit public birthday, employer and travel information. Use unique passwords and a password manager. Treat an unexpected call displaying the bank’s number as unverified because caller ID can be spoofed.

Common mistakes after a loss

Victims sometimes pay a supposed recovery agent, creating a second loss. Others delete messages from embarrassment, wait days before calling the bank, or post details publicly that compromise an investigation. Some accept an initial verbal rejection without requesting written reasons.

Do not pay anyone who guarantees recovery or claims to have hacked the scammer’s wallet. Verify lawyers, investigators and advisers through independent registers. Be cautious about upfront cryptocurrency fees.

Worked example

An Australian homeowner receives a call from someone impersonating the bank. After seeing a spoofed number, the homeowner installs remote software. Three payments totalling $92,000 leave the account. The bank recovers $17,000.

The complaint should not merely say “refund $92,000”. It should explain remote access, each approval step, whether codes were read aloud, alerts generated by unusual payees, the first notification time and the bank’s recall actions. The net principal claim starts at $75,000 after recovery, with interest and consequential loss separately calculated.

The result will depend on evidence. If the criminal operated the device without actual authority, unauthorised transaction provisions may be central. If the homeowner knowingly confirmed the payments under deception, other duties and the adequacy of bank intervention may become more important.

Final perspective

Australia’s 2026 enforcement activity shows banks can face serious consequences for systemic scam-control and victim-support failures. It also shows why precise categories matter. A regulatory penalty against one institution does not promise reimbursement in every case, while a payment technically authenticated by a customer does not necessarily resolve every legal and fairness issue.

Act quickly, preserve evidence and insist on a reasoned written response. For help rebuilding cash flow, reviewing investment exposure or strengthening household safeguards after a loss, find an Australian financial adviser on WealthWorks.

Frequently Asked Questions

Must Australian banks reimburse customers for scam losses in 2026?

Not automatically. Liability depends on whether a payment was unauthorised or authorised, the ePayments Code, the bank's terms, warnings and controls, and the customer's conduct. ASIC's 2026 HSBC enforcement concerned unauthorised transactions and serious protection failures; it does not create a blanket guarantee for every scam victim.

What should an Australian scam victim do in the first 24 hours?

Contact the bank's fraud team immediately, ask for payments to be stopped or recalled, secure accounts, change compromised credentials, preserve messages and report through ReportCyber and Scamwatch where appropriate. Fast action can improve recovery prospects, but consumers should not delete evidence after blocking the scammer.

Can an Australian consumer take a bank scam dispute to AFCA?

Eligible consumers can generally complain to the Australian Financial Complaints Authority after giving the bank an opportunity to resolve the matter through internal dispute resolution. AFCA is free for consumers and can consider applicable law, industry codes and what is fair in all the circumstances within its jurisdiction.

How much did Australians lose to scams in 2025?

ASIC cited the National Anti-Scam Centre's Targeting Scams Report figure of $2.18 billion in reported Australian scam losses during 2025, including $837.7 million attributed to investment scams. Reported losses do not capture every incident because many scams are not reported.

What evidence helps an Australian bank scam reimbursement claim?

Keep transaction records, bank alerts, call logs, emails, text messages, screenshots, remote-access details, police or ReportCyber references and a chronological account. Record exactly what the bank knew, when it was notified and what steps it took. Do not alter screenshots or guess facts you cannot confirm.

What is the ePayments Code in Australia?

The ePayments Code is administered by ASIC and regulates many electronic payment facilities offered by subscribing Australian institutions. It includes rules for unauthorised transactions, passcodes, mistaken internet payments and complaint handling. Coverage and liability depend on the facts and the provider's subscription.

Related Articles