AFCA holds Australia's best scam data — let’s use it!

Banks treat each scam as a customer mistake. Put the cases side by side and the same mule accounts, money laundering methods and banks keep appearing. That is actionable scam intelligence, and it is being wasted sitting in complaints that take years to resolve.

6 suggestions could change everything

  1. Part 1 sets out cultural and procedural changes AFCA can make immediately, without any rule change.

  2. Part 2 explains how the Scam Rules and Operational Guidelines should reverse the burden of proof, so the firms that hold the evidence must produce it.

  3. Part 3 asks AFCA to share verified scam intelligence with regulators within 5 business days, so that each complaint helps stop the next fraud.

  4. Part 4 draws lessons from three typologies our members have taken through AFCA, with a focus on property settlement misdirection fraud.

  5. Part 5 maps what ASIC's regulatory guides and the SPF legislation already require.

  6. Part 6 sets out our recommended rule changes and answers to AFCA's 19 questions

Our organisation sees firsthand how difficult AFCA's scam dispute process can be. Scams are engineered to make the victim look responsible. Criminals use deception and trusted bank infrastructure to induce a payment, then launder funds the victim appears to have "authorised" through a mule account. When the dispute reaches AFCA, the victim carries the burden of proving a crime they did not see, against a bank that holds the logs, KYC records and transaction trail.

AFCA also sits on some of the most valuable verified scam loss intelligence in Australia, and it is reaching regulators too slowly to stop the next victim. Banks face civil penalties if they fail to report actionable scam intelligence to the ACCC within prescribed periods under SPF laws. AFCA, which tests that same intelligence against evidence from both sides, should face deadlines sooner than 2027.

Our key recommendations TO IMPROVE SCAM VICTIM OUTCOMES AT AFCA

  • Fix the process and administrative burden harms now. Record and confirm every Agent Authority form within 2 business days and never ask for it again. Never close a scam complaint for "no response" without a phone call and a checked portal log. Issue evidence preservation notices to sending and receiving banks on the day a complaint is registered.

  • Reverse the burden of proof. A standard evidence package from every Regulated Entity in the funds chain within 21 days, with mandatory adverse inference, a payment to the victim, and referral to ASIC, AUSTRAC and APRA if it is not produced.

  • Share verified scam intelligence fast. A new Scam Rule requiring AFCA to refer verified scam identifiers to SPF regulators and the National Anti-Scam Centre (NASC) within 5 business days, with typology alerts shared with regulators after 3 matching complaints.

  • Hold the receiving bank chain accountable to prevent money laundering. Expressly include receiving and intermediary institutions in Rule 1.4.3(b), join every regulated entity in the funds chain by default, and treat KYC, AML and CTF failures as failures to take "reasonable steps".

  • No silencing settlements. Settlements must never stop victims reporting to regulators or police, consistent with RG 267.61.

  • Publish a scam league table. Annual public reporting of complaints, recoveries and reimbursements by firm, as the UK's Payment Systems Regulator does.

Part 1: Changes AFCA cOULD make tomorrow

The fastest way to reduce harm is to stop AFCA's own processes adding to it. None of the changes in this Part needs a rule amendment or ASIC approval. They are decisions about how AFCA staff work, what its systems record and what its letters say. AFCA's draft Rule 1.2.2 already says its Engagement Charter sets out the behaviour expected of AFCA employees as well as parties. These changes would give that commitment practical effect for scam victims.

1. Correct the administrative failures of losing agent nominations or automatically closing victim cases

Many scam victims rely on a family member, community advocate or SVA volunteer to deal with AFCA, because they are traumatised, unwell, elderly or not confident in English. That relationship depends on AFCA's Agent Authority Form. Our members report forms lodged and then requested again, authorities not linked to a second complaint about the same scam, and representatives told they cannot be spoken to while the victim waits.

In case 12-26-406829, SVA asked AFCA to consider six victims across four disputes as a group, because they had lost money to a similar type of scam. AFCA closed the file because it held no signed Agent Authority Form for each person and does not consider "group complaints" for unrelated complainants. The letter records that AFCA held no information about the six victims; rather than contacting them to ask whether they wanted to proceed, it left each to start again alone.

Do now: Log every authority form on receipt and confirm it to the victim and representative in writing within 2 business days. Attach it to every current and future complaint by that victim about the same scam, and never request it again unless it is revoked. Accept consent given by the victim over the phone and recorded by AFCA. Before closing or excluding any complaint because authority is unclear, including under proposed Rule 2.2.2(j), phone the victim directly.

2. No scam complaint closed by automatic notice

Proposed Rule 1.9.6(b) allows AFCA to refuse to continue considering a complaint if the complainant fails to comply with a requirement within a specified timeframe. In practice, our members have received closure notices wrongly stating they failed to respond, after they had responded through the portal, by email, or by phone to their case manager. Portal outages and broken information exchange templates make this more likely. For a victim with trauma-related cognitive load, a closure notice can end their pursuit of redress entirely.

Do now: No scam complaint should close for non-response unless AFCA has (a) tried to reach the victim on two channels, including a phone call; (b) checked portal, email and call logs for anything received; and (c) sent a final notice giving at least 10 business days. A victim who shows they did respond should have the file reopened automatically, with no new lodgement and no loss of place. AFCA should publish how many scam complaints close for non-response each quarter.

Do now: Stop sending substantive outcomes from "do not reply" addresses. Every scam complainant should have one named case manager and a direct phone number.

3. Investigate first, process second

Scam data is perishable and highly changeable, yet AFCA's process runs as a sequence of delays that let the value of this data as actionable intelligence perish: registration, refer-back to the firm for another 30 days, then information requests, then conciliation. Where more than one entity is involved, refer-backs can run one after the other. By the time AFCA asks for evidence, it may be gone.

The cost is visible in our members' cases. In case 12-24-120119, the victim asked for CCTV of his branch visit, which police had also sought. The bank told AFCA the footage showed only the foyer, the victim had been taken to a private room, and releasing the footage would breach other customers' privacy. In an HSBC matter (Ms Q), IP and login logs requested in April 2025 were never produced. In the Supercheap Security matter, it took an AFCA information request in January 2025 before CBA confirmed it had been notified about the recipient account at 6:53pm on 17 June 2022 and had only blocked future payments.

Do now: On the day a scam complaint is registered, send every Regulated Entity in the funds chain a preservation notice covering transaction and session logs, device and IP data, call recordings, branch file notes, CCTV, Confirmation of Payee results, account-opening and KYC records, and recall and recovery messages. Run refer-backs in parallel, not in sequence. Triage every new scam complaint for a live threat: if the receiving account may still be open or receiving funds, send the identifiers to the NASC and the receiving bank the same day, without waiting for the refer-back to end.

4. Start from what has already been proven

AFCA runs each new complaint as a new, discrete case to be considered on its merits in complete confidentiality. HSBC admitted in the Federal Court that it failed to comply with the ePayments Code in 97% of cases over 44 months, yet our members with HSBC complaints are still asked to establish what went wrong after this case has proven the victims did not "voluntarily authorise" their scam. AFCA relies on court decisions when they assist the bank, by excluding matters a court has dealt with, but not when court findings would assist the victim.

Do now: Keep an internal and confidential register of regulator findings, AFCA determinations and confirmed systemic issues by firm and typology. Require case managers to check it, maintain confidentiality and tell the complainant whether regulators and law enforcement have confirmed that the member firm complied with "best industry practice". Where a firm has admitted a failure, the firm (not the victim-survivor, as in the current process) must demonstrate to AFCA why it does not apply.

5. Case managers should not talk victims into settling for meagre amounts

Victims regularly tell us they were advised by AFCA staff, early and informally, to expect little, even where published determinations favoured them. Coming from the ombudsman, that advice carries weight and pushes victims toward low settlements. Complainants are also asked to "open" conciliation calls with a statement outlining the legal facts of their case, without ever being told this would happen. Complainants must then explain a complex fraud typology unassisted, against senior bank lawyers who know precisely what legal points they can stand on.

Do now: Dispute resolution advice to a scam victim must be consistent with AFCA's own determinations and given in writing rather than verbally. AFCA staff could run "Ask AFCA anything" Q&A sessions where complainants can get guidance about how complex AFCA cases are resolved. AFCA should summarise the fraud typology so the victim does not have to.

6. Pause the interest on stolen money, especially when defrauded through criminal deception

In seven of the settlement fraud cases in Appendix 1, a bank continued to charge interest on the stolen funds while the complaint was open. One victim waited 20 months for a determination on a $270,000 mule account scam while the sending bank charged interest. The victim is paying the bank for the crime they were victimised by, and AFCA determinations endorse this.

Do now: Ask every Regulated Entity to suspend interest, fees and collection activity on loans connected to the stolen funds for as long as a scam complaint is open, and record and publish which firms decline in a proposed Scam League Table.

7. Make it possible to deal with AFCA paperwork from a mobile phone

Many victims have no desktop or laptop computer at home, and AFCA's portal is hard to use on a mobile device. This is a particular barrier for people with English as a second language, low digital literacy or trauma-related cognitive load. AFCA's duty to help complainants lodge is inconsistently applied, and proposed Rule 1.3.2 says only that AFCA "may" assist.

Do now: Offer phone lodgement and verbal updates over the phone as standard service levels for complex scam complaints, accept documents by email and photograph, and use interpreters by default when a victim asks.

Table 2: Summary of what AFCA can implement today to make EDR a safer experience for scam victimsWhat victims experience nowWhat AFCA can do tomorrowBurden it would removeAuthority forms re-requested; representatives shut out; linked victims closed as a "group"Confirm authority in an email or SMS; attach to all linked complaints from lodgement; phone the victim to talk through before any closure for authorityComplaints closed for authority issuesFiles closed by automated "no response" noticesPhone high-loss scam victims within 10 days before closure; automatic reopening if the victim needs itScam complaints closed for non-responseEvidence lost while refer-backs run in sequenceDay-one preservation notices; parallel refer-back; same-day triage of live mule accountsMedian days from registration to first evidence requestVictims asked to re-prove admitted failuresRegister of admissions and determinations checked at registration; a Scam League Table publishedComplaints resolved by reference to prior findingsInformal advice to expect littleWritten, determination-consistent settlement advice; member firm states its position firstSettlement value as a share of loss, by typologyInterest charged on stolen fundsRequest suspension of interest and collection while the complaint is openFirms declining to suspend interestPortal unusable on a phonePhone lodgement, email and photo documents, interpreters by defaultScam complaints lodged by phone

Part 2: Reverse the burden of proof

A person who has just lost their life savings must currently build their own case at AFCA to have any chance of reimbursement. The evidence they need is held by the banks, which routinely invoke "privacy" to withhold it. The SPF means Regulated Entities must take reasonable steps to prevent, detect, disrupt and respond to scams, and give complainants a statement of compliance with their IDR response. The table below sets out the standard evidence package we recommend AFCA move towards under the new rules to prevent and disrupt scams.

Table 3: The evidence gap in many AFCA scam complaints our community experiencesEvidenceWho holds itWhy the victim cannot get itWhat AFCA could requireTransaction, session, device and IP logs; changes to limits or payeesSending bankInternal systems; sometimes refused as "confidential" until an APP 12 request is madeProduced in every complaint within 21 daysFraud alerts, risk scores and whether a payment was held or queriedSending bankFirms say disclosure would help criminals, but this is already happeningProduced to AFCA; summary shared with victimConfirmation of Payee result, shown to the victim only during the transfer; the bank records relied on for a "match" are never revealed or verifiedSending bankNot visible after the eventProduced in every complaint; banks must prevent payment rather than let scam victims override name matchingTime the firm was notified; recall requests; AFCX messages; funds frozen or returnedSending and receiving banksVictims told recovery "was attempted", nothing moreTimestamped recovery log from each entity, with verified proof from a regulator that the bank recovered the funds it says it didAccount opening date, KYC and CDD records, beneficial owner, first transaction, limit changesReceiving bankVictim is not the receiving bank's customerProduced by receiving bank as a joined partyOnward transfers (at least 3–5 hops)Receiving and all intermediary institutionsVictim cannot see beyond the first accountMoney trail report in every complaint, with confidentiality preserved for law enforcement but assurance given to victimsSuspicious matter reportsAUSTRACConfidential by lawAFCA–AUSTRAC confidentiality arrangement so AFCA can confirm whether the account was reported, as backing for "compliance statements"Police reports and arrestsState and federal policeAvailable only by FOI or subpoena, and usually blocked when they show police failed to investigateAFCA could request "compliance statements" with State and Federal incident numbers to confirm whether the scam is a verified crime

What the rules should say

Every Regulated Entity joined to a scam complaint should produce the items in Table 3 within 21 days, without waiting for AFCA to ask for each one. Sending and receiving banks should produce a money trail report covering at least 3–5 hops and explain, with evidence, why funds could not be recovered. In case 12-24-130239, a bank that was both the sending and receiving institution satisfied AFCA with a single internal Jira note and no explanation of why funds could not be recovered. That should never be enough.

Adverse inference should be the default when information is not supplied

Rule A.9 already requires firms to provide information, and it is routinely resisted. Proposed Rule 1.9.6(a) says an adverse inference "will generally be drawn". Without automatic consequences, Rule 1.9 will suffer the same fate as Rule A.9. We recommend that where material evidence is not produced on time, AFCA must infer that the relevant control failed, must require a statutory declaration after one missed deadline, may order a payment to the complainant for the delay, and must refer repeated non-compliance to ASIC, AUSTRAC and APRA.

Image 7: Criminally architected thefts and frauds are designed to evade prosecution and reimbursement at AFCA. It's time to break the cycle to disrupt and prevent the crime.

The statement of compliance must be evidenced

A statement of compliance under s 58BZDA that asserts "reasonable steps" without the underlying records should not carry any weight. AFCA's Operational Guidelines should say that the firm bears the onus of showing, with contemporaneous records, which steps it took, when, and why they were reasonable for the scam type.

Deception always defeats "authorisation"

The SPF defines a scam by the presence of deception. A payment induced by bank impersonation, a doctored settlement statement or a fake term deposit is not a free and informed instruction in any meaningful sense. AFCA's Operational Guidelines should state that a victim's apparent authorisation of a deception-induced payment does not, on its own, establish that a Regulated Entity took reasonable steps, and that victims do not need to prove the criminal's intent.

Every entity in the chain is joined

Joinder currently happens in only 1.3% of complaints, yet victims' money often passes through several institutions. AFCA should presume that every Regulated Entity the money passed through is joined, and should do the work of identifying them. Proposed Rule 1.3.2 should say AFCA "will", not "may", help identify Regulated Entities that may be a party.

KYC and AML failures are SPF failures

Mule accounts are created through identity takeover, rented out, or opened through ASIC-registered companies. In the Supercheap Security case, the NSW Supreme Court found the director opened a NAB business account so it could be handed to a third party, and its per-transaction limit was raised from $10,000 to $100,000 before any funds arrived. Failures of account opening, customer due diligence and ongoing monitoring at the receiving bank should count as failures to take reasonable steps under the SPF, and a complaint alleging them should never be excluded as a complaint about "practice or policy" under Rule 2.2.2(c).

Image 8: Without reimbursement, there are no genuine scam prevention or disruption controls in place.

Part 3: Share verified scam intelligence within days, not months

AFCA should refer verified scam identifiers to regulators within 5 business days of a complaint opening. Our community has evidence that mule accounts are being generated at scale onshore in Australia. Criminals rotate mule accounts in days, while AFCA's proposed reporting pathways take months.

SVA considers the proposed Scam Rules a genuine improvement on what happens today. But they treat AFCA's systemic issues function as a slow, firm-first process built for product failures, not for organised crime that moves money through multiple institutions by exploiting insider loopholes that even Australia's Prime Minister is not immune to. AFCA's own consultation paper acknowledges that scams are, by design, committed at scale and intended to have systemic effects.

AFCA holds some of the best verified scam intelligence in Australia

A bank's actionable scam intelligence can be a single unverified report to a regulator. AFCA's evidence has more layers of verification and should be weighted above a bank report. By the time a scam complaint reaches AFCA, the same facts have been tested: the victim's evidence, the sending bank's IDR response, the receiving bank's records, and often a police report. AFCA also sees across institutions in a way no single bank can. Our members' cases show what AFCA already knows:

  • Linked mule accounts as a systemic problem. In case 12-00-1045764, AFCA was given evidence that doctored settlement instructions contained hidden text layers naming at least two other Commonwealth Bank mule accounts. One held a balance of more than $2.7 million, with transaction data showing Opal card use and small everyday purchases. That evidence stayed confidential when it could have prevented future mortgage misdirection fraud.

  • One account, many victims. At least 12 Australians paid about $1.36 million into a single NAB business account in the name of Supercheap Security Pty Ltd between 20 May and 22 June 2022. AFCA did not join the complaints together, nor disrupt other high-loss term deposit impersonation scams affecting our community.

  • Repeated Confirmation of Payee evasion. Criminals used the real, ASIC-registered names of unrelated businesses so the name check returned a match; see case 12-25-247156.

  • A typology hiding in plain sight. More than 400 HSBC scam victims complained to AFCA before ASIC acted to investigate the bank. The bank later admitted in the Federal Court that it failed to comply with the ePayments Code in 97% of cases over 44 months.

Each of these was actionable scam intelligence that AFCA could have escalated to save the next victim from harm. None reached regulators fast enough, because AFCA is overwhelmed with cases that it can never have enough staff, or accessible technology, to process fast enough.

Banks face a deadline to report scam intelligence, and AFCA should too

The SPF requires regulated entities to report actionable scam intelligence to the ACCC within a period prescribed by the SPF rules, backed by civil penalties (s 58BR). They must also take reasonable steps within a reasonable time to disrupt the activity (s 58BX). Treasury's Explanatory Memorandum says efficient and timely sharing is critical to the SPF's object. AFCA's obligations under s 58DD of the Competition and Consumer Act 2010 (Cth), and proposed Rules 1.17 and 1.18, work very differently.

Table 4: The proposed referral pathway compared with SVA's modelProposed Scam RulesSVA's recommended modelTriggerA systemic issue is identified after investigationAFCA holds evidence that a mule account, mobile number, fake domain or website, or entity was used in a scamFirst stepRaise with the firm and give it a reasonable opportunity to respond (1.17.2)Refer identifiers to the NASC, AUSTRAC, Australian Signals Directorate and SPF regulators; notify the firm in parallel; ensure complainants receive this as part of any "statement of compliance" notification; include it in Scam League Table reportingTimeframeNone specifiedWithin 5 business days of verificationPattern alertsOnly once a systemic issue is confirmedTypology alert after 3 matching AFCA complaints within 90 days, also included in any "compliance statement" and Scam League Table reportingPersonal informationDe-identified by default (1.17.5, 1.18.3)Scam identifiers shared in full, using the existing exception where de-identification defeats the SPF's objectSettled complaintsAFCA "may" refer a settlement (1.18.2)Identifiers from every settled scam complaint referred; confidentiality terms trigger RG 267.61 review by ASIC, and victims can open new cases on the same factsRecipientsSPF General Regulator and Sector RegulatorACCC/NASC, ASIC, AUSTRAC and APRA, and police where a crime is allegedPublic reportingAnnual report (1.20)Quarterly scam intelligence report and annual Scam League Table

AFCA's consultation paper says information-sharing arrangements and memoranda of understanding with SPF regulators are still being developed. We urge AFCA to settle them before the Scam Rules commence, with fixed timeframes written into the rules as quickly as possible.

Confidentiality is not a reason to delay

The SPF already contemplates sharing personal information where it is needed to disrupt scams. Treasury's Explanatory Memorandum gives the examples of the receiving bank account, the scammer's phone number and scam advertisement details. A mule account number is evidence of a crime, not a victim's private information. Proposed Rule 1.17.5 already lets AFCA share identified information where de-identification would not achieve the SPF's object. AFCA's Operational Guidelines should state that scam identifiers will always be shared this way.

Regulators should also share back. AFCA's own scams guidance asks banks whether they received ASIC or AUSTRAC warnings about a recipient. AFCA should receive those warnings directly, and should consider police and regulator reports in its decisions, protecting their confidentiality where necessary.

Why each regulator needs AFCA's intelligence

  • ACCC and the NASC can issue alerts and use fusion cells to disrupt fast-rising typologies before they scale, as the HSBC scam did in 2023–24.

  • AUSTRAC can test mule accounts against suspicious matter reports and pursue AML/CTF failures at receiving banks. It has already issued notices to 10 lenders over coordinated mortgage fraud.

  • ASIC can act on misuse of ASIC-registered companies to open mule accounts and evade Confirmation of Payee, and can use its oversight of AFCA under RG 267 to check that scam settlements comply with RG 267.61.

  • APRA can treat concentrations of mule accounts, unrecovered scam losses and repeated control failures at an authorised deposit-taking institution as operational risk and a governance issue for its board, not just a consumer complaint. AFCA referral data would give APRA an early, cross-institution view that no single ADI's own reporting provides.

Recommendation: a new Scam Intelligence Referral rule (1.17A)

SVA recommends AFCA insert a new rule alongside Rules 1.17 and 1.18:

  1. Verified identifier referral. Within 5 business days of holding evidence that an account, phone number, website, social media profile or entity was used in a scam, AFCA must give those identifiers to the NASC and relevant SPF regulators.

  2. Early typology alert. Where 3 or more complaints within 90 days share a typology, receiving institution or identifier, AFCA must alert regulators immediately, without waiting to confirm a systemic issue.

  3. Settlements don't erase intelligence. Identifiers from every settled scam complaint must be referred, and settlement terms must never prevent victims reporting to regulators or police.

  4. Money trail reports. The money trail produced under the standard evidence package must be passed to AUSTRAC and the NASC.

  5. Excluded complaints still count. Identifiers in complaints AFCA excludes, including those over its monetary limits, should still be referred.

  6. Public accountability. AFCA should publish quarterly the number of referrals, median days to referral, and funds frozen or recovered, and an annual Scam League Table by firm. Making corporations' scam prevention actions public is a low-cost and simple measure that would immediately make Australia more scam-safe.

Part 4: Lessons from mortgage settlement fraud, HSBC and Supercheap Security

Three different scam typologies, involving different banks and different AFCA cases, all failed at AFCA for the same five reasons. Further detail is in the Appendices.

  1. The deception was architected by criminals exploiting insider threats and cybercrime-as-a-service networks in Australia and offshore. Data leaks, email compromises and other cyber-enabled tricks are sold and traded as cybercrime-as-a-service, with organised criminal groups at the top of the chain. These deceptions are increasing exponentially as Australia allows more data leaks to occur, and frontier AI is ramping up the risk. Scams are a microcosm of failed policy, where delays over "consultation" hurt everyday citizens while illicit capital wins, steals more money and sets up closer to Australian shores in Papua New Guinea and East Timor.

  2. The role of mule accounts was ignored. Whether a mule account was created by identity takeover, rented out, opened through an ASIC-registered company, or operated by a complicit or exploited mule, the sending and receiving banks' roles are rarely tested, even after AFCA's March 2026 receiving bank changes.

  3. The money trail was only traced by law enforcement, and the crime went unpunished. Victims were told by banks that recovery "was attempted", with no evidence of what was tried, frozen or returned. Victims are never assured that banks genuinely recovered the amounts returned to them, nor that funds impounded through proceeds of crime seizures will ever be returned to them. AFCA is their only hope of any recovery, unless they spend hundreds of thousands of dollars in legal fees (as the complainant in case 12-00-1034883 did).

  4. Law enforcement evidence was not used. Logs, recordings and KYC records did not come before AFCA. Any victim who gains reimbursement through AFCA's existing EDR processes has had to find evidence of the criminality behind their fraud themselves.

  5. The pattern was never joined up. Connected complaints were handled one by one, and some were closed by confidential settlement, which we believe is inconsistent with RG 267.61. Scams are evading "classification" as AI ramps up the threat vectors, data breaches and more.

Property settlement misdirection fraud

Criminals obtain a homebuyer's settlement details, usually through a compromised email account at the buyer, conveyancer, law firm or agent. They impersonate the solicitor, conveyancer or PEXA and send doctored payment instructions that redirect the settlement payment into a mule account. The funds are laundered within hours, through gold bullion purchases, ATM cash and foreign exchange, often before the bank tells the homebuyer the money is missing.

SVA has supported 16 cases totalling about $4.42 million, 13 at settlement and 3 after it. Mules were arrested in at least 5, yet 5 matters recovered $0, 6 closed with a confidential settlement, and victims were often left paying interest on the stolen funds. Only 2 of the 13 settlement cases were publicly reimbursed, at about 70%.

The problem is systemic. Treasury and AUSTRAC documents obtained under FOI show CBA had identified around $1 billion in suspect home loans by February 2026, and AUSTRAC has issued notices to 10 major lenders over coordinated mortgage fraud. Lawyers, conveyancers and real estate agents only became subject to AML/CTF obligations on 1 July 2026, leaving the settlement chain exposed for years. Confirmation of Payee is already being evaded: criminals use the real name of an unrelated ASIC-registered business so the name check returns a match (cases 12-25-247156 and 12-25-194305).

Image 9: This evidence, given to AFCA in 2023, could have prevented the property settlement frauds perpetrated against Australians in 2024 if it had been escalated to regulators under SVA's recommendations.

Mortgage fraud typologies, from loan application fraud to settlement misdirection, share the same laundering infrastructure, which operates onshore in Australia. Local bank mules with "lifestyle spending" on their accounts are recruited and then exploited by crime networks to withdraw cash from ATMs, transfer through foreign currency and buy gold bullion (which is apparently also "unrecoverable").

These property-buying frauds threaten the integrity of Australia's $11 trillion residential property market, yet AFCA and the civil courts rarely recognise the criminal deception. Our legal system was not designed for this level of exploitation. First and second homebuyers are especially exposed because they have no established pattern of large payments for a bank's fraud monitoring to compare against. A settlement-sized payment to a new payee, days before settlement, to an account opened recently, should be treated as a known high-risk pattern.

Image 10: Mortgage fraud has many different lead–deceive–bleed–clean typologies, but all are connected to insider problems that no "compliance statement" will ever reveal.

What would have changed the outcome: a day-one preservation notice to the receiving bank; a money trail report showing where the funds went within the first hours; referral of the hidden-text mule accounts in case 12-00-1045764 to the NASC and AUSTRAC; suspension of interest on the stolen funds; and a lead-case approach so each homebuyer did not have to prove the same typology from scratch.

Table 5: Victims absorb the cost of weak mule account and money laundering controlsProperty settlement misdirectionHSBC bank impersonationSupercheap Security term deposit fraudScale16 SVA cases, about $4.42m lost (13 at settlement, 3 post-settlement)1,000+ customers in ASIC's case; 400+ took complaints to AFCAAt least 12 victims transferred $1.36m into one NAB account; evidence Suncorp was also used, and domain evidence shows the pattern was widespread across multiple Australian banksWhere the money wentMule accounts with lifestyle spending and wages mixed inNewly created identity-takeover mule accounts, or direct overseas transfersA NAB business account of an ASIC-registered company, handed over for fraud before its first transactionHow it was launderedGold bullion, ATM cash and foreign exchange; Confirmation of Payee evaded using real business namesCoordinated exploitation of weak banking controlsDispersed to shell companies in the UK and Dubai; $0 recovered despite a Supreme Court winWhat a court or regulator foundMules charged in at least 5 cases; AUSTRAC notices to 10 lendersFederal Court admissions: ePayments Code breached in 97% of cases over 44 monthsO'Brien v Supercheap Security Pty Ltd [2024] NSWSC 1117; criminal charges later droppedWhat AFCA didOnly 2 of 13 settlement cases publicly reimbursed, at about 70%; banks allowed to keep charging interestVictims blamed for "voluntary" passcode disclosure; 8 cases reopened in 2026 for under-compensation but still delayed, despite Federal Court findingsMinimal reimbursement under a confidentiality deed

Scam or fraud?

SVA believes the word "scam" shifts attention to victim behaviour and away from corporations enabling theft. Criminal law professor Penny Crofts' research shows how corporations use sanitised narratives that obscure crime enabled through corporate structures. The UK has shown that mandatory reimbursement can keep a lid on an escalating fraud crisis: its Payment Systems Regulator reports that fraud losses are down, more victims are reimbursed and firms are investing in prevention. Australia should recognise these losses for what they are: fraud committed through the banking system. The Supercheap Security scam was highly architected using ASIC-registered entities and multiple domain registrations for fake versions of real Australian banks (domains the real banks have since bought for themselves).

Image 12: If Supercheap Security had been disrupted in 2022, SVA president Harriet Spring would likely not have lost $1.6 million to the same typology in 2023–24.

Part 5: What the law and ASIC's guidance already require

Much of what SVA suggests in this paper is not new policy. It is contained in existing regulatory guidance for AFCA and its member firms, applied consistently to scam complaints. ASIC must approve the Scam Rules and will consult the other SPF regulators before doing so. We ask ASIC to use that approval, and its ongoing oversight under RG 267, to make sure these requirements are met.

Table 6: Existing obligations and how AFCA should apply them to scamsSourceWhat it requiresHow it should apply to scam complaintsRG 267.61 (EDR settlements)AFCA must oversee settlements so they are limited to the complaint, do not stop referral to a regulator, and are not offered on onerous terms, to avoid AFCA scrutiny, or under duress or misrepresentationReview every scam settlement with confidentiality, non-disparagement or withdrawal terms, or an acceptance window under 5 business days; never allow terms that stop reporting to police or regulatorsRG 267 (systemic issues) and s 1052E Corporations ActAFCA must identify and report systemic issues, including problems affecting many customers or producing repeated similar complaintsTreat repeated complaints about one typology at one firm as systemic once 3 share a pattern; refer identifiers before the systemic investigation endsRG 277 (consumer remediation)Remediation cannot remove a right to complain to the firm or AFCA; assumptions should favour consumers; people wrongly excluded need a review pathwayApply to bank-run scam redress programs such as HSBC's; assess interest at a consumer-favourable rate and consider non-financial lossSPF s 58BR and s 58BXRegulated entities must report actionable scam intelligence within prescribed periods and take reasonable steps to disruptHold AFCA to an equivalent timeframe through a new Rule 1.17A; test each firm's own reporting and disruption in every complaintSPF s 58BZDAIDR responses must include a statement of complianceRequire the records behind the statement; an unsupported statement carries no weight and would continue today's information asymmetrySPF s 58DDAFCA must report systemic issues and certain matters to SPF regulatorsInclude APRA, AUSTRAC and police as recipients where relevant, not only the General and Sector RegulatorsAFCA Rule A.17Once a systemic issue is found, AFCA can require the firm to remedy loss for everyone affected, including people who never complainedCarry this power into the Scam Rules and use it for confirmed typologiesAFCA Rule D.3AFCA can award compensation for non-financial lossAssess non-financial loss in every scam complaint, including where a bank redress program paid none

Part 6: Answers to AFCA's questions

Operational guidelines SVA would like to see to help victims

  • Scam identifiers (accounts, mobile numbers, domain URLs and other common entities) are always shared with regulators in identified form under Rule 1.17.5.

  • The contents of the standard evidence package, the 3–5 hop money trail, and what counts as an adequate explanation of failed recovery are shared with complainants, with confidentiality preserved where needed for investigative purposes.

  • How AFCA weighs police reports, FOI releases, court findings and regulator admissions, even when the law is complex.

  • That apparent "voluntary authorisation" of a deception-induced payment under the ePayments Code does not by itself show reasonable steps, and victims do not need to prove intent.

  • Worked examples for property settlement misdirection, bank impersonation, term deposit impersonation and account takeover.

  • Plain-English guidance on how the six-year time limit applies when a victim learns of a loss years later, along with "Ask AFCA anything" education sessions for victims and a published Scam League Table.

  • Service standards for authority forms, closure for non-response, phone access and interpreters, with quarterly public reporting.

3.1 SPF complaint lodgement and referral to regulated entities

Q1. Is AFCA's proposed approach to refer-back appropriate for multi-party scam complaints?

No, not as currently framed.

Draft Rule 1.5.2 rightly keeps AFCA's discretion to start immediately, but a default of up to 30 days per entity is inappropriate where several regulated entities have not each had an equal chance to respond positively through IDR. The Treasury draft SPF Rules already give each entity 21 days to issue a Statement of Compliance, so a further 30-day refer-back risks duplicating that period and compounding harmful delays to complainants.

A blanket 30-day refer-back multiplies delay when several entities are involved. Refer-backs should run in parallel, not one after another. AFCA should skip refer-back where crime is alleged or less than 10% of funds were recovered. We believe that a scam league table, and a standard "scam information sheet" shared with the complainant that links the entities and makes the scam infrastructure clear, will also expedite these complaints. We recommend:

  • Parallel, not sequential. Refer-back periods should run concurrently across all named regulated entities, starting on the same day, so delay does not multiply with each bank, telco or platform in the chain.

  • Immediate progression in defined cases. AFCA should proceed immediately, without refer-back, where the victim shows the scam involves a reported and valid crime (a ReportCyber or police reference), where less than 10% of funds have been recovered, or where the same scam event is already before AFCA from another complainant (see Q8). This is consistent with our June 2025 and January 2026 SPF submissions.

  • Pause, never restart. A refer-back period should be paused, not restarted, where a victim is in demonstrated financial hardship, for example where mortgage interest is accruing on a loan the stolen funds were meant to repay. If the same financial banking group already has a scam-related determination on the same scam typology, it should not get a fresh 30 days.

  • Publish the effect. AFCA should publish how often refer-back is used, for how long, and its effect on time to resolution, so its real-world impact on victims can be scrutinised.

The HSBC complaint cohort shows that refer-back can end a complaint rather than pause it:

  • AFCA referred complaint 971494 to HSBC on 14 April 2023. It closed the file as "Resolved by FF" on 30 May 2023, although HSBC's fraud investigation was open and nothing had been paid.

  • In complaint 1069438, HSBC issued a "Final Resolution" letter in January 2024. Its fraud investigation outcome was not issued until 3 May 2024.

  • HSBC's IDR investigations ran far beyond ePayments Code timeframes. Mr B (12-00-1048367) reported his loss on 26 November 2023 and received HSBC's outcome on 31 July 2024, more than eight months later. His loss came from his home loan account, so interest accrued throughout.

The same cohort shows why an existing determination on the same typology should stop a fresh refer-back:

  • AFCA published the Mr T determination against HSBC (12-00-1016692) in August 2024. It found that passcodes obtained by a scammer impersonating the bank in HSBC's genuine SMS thread were not voluntarily disclosed, and awarded full reimbursement plus interest.

  • That same month, AFCA told a complainant it was meeting the Lead Ombudsman "about the HSBC complaints and our approach". Yet complaints 12-00-1048367 and 12-00-1065766 settled at AFCA in November 2024, and the complainant in 12-25-221597 accepted an HSBC offer in April 2025. Each settled below the full loss that the Mr T determination supported.

  • The Federal Court's orders of 18 June 2026 list the reports behind 12-00-1048367 and 12-00-1065766 among the 1,022 customers affected by HSBC's systemic failures.

SVA also supports raising the automatic IDR reimbursement threshold well above the $3,000 proposed in Treasury's IDR position paper, to $25,000. That is a matter for the SPF Rules rather than AFCA's Scam Rules, but it bears directly on AFCA's workload. Lower-value matters resolved quickly at IDR leave AFCA's limited investigative capacity for complex, high-loss, multi-party cases, which are the cases we see AFCA fail to resolve.

Q2. Have you identified any unintended gaps or consequences in coverage of classes of consumer who may be inadvertently included or excluded by the proposed complaint eligibility settings?

Yes. There are many gaps, particularly in high-loss scam cases.

  • Impersonation scams, including fixed-term investment and property settlement fraud. The Supercheap Security matters and settlement misdirection scams are examples. Victims risk falling outside coverage where the first point of compromise sits outside a Regulated Entity, even though a financial firm allowed the impersonation to succeed. AFCA should confirm that the sending and receiving banks remain in scope wherever the initial compromise happened. In ASIC v HSBC, HSBC admitted systemic failures in handling reports of unauthorised transactions, and payments made through account compromise, including by social engineering, were treated as made without the customer's authority.

  • Accounts opened in the victim's name. In complaint 12-26-397786 (earlier 971494, 12-24-161718 and 12-25-221597), the victim's money went into an HSBC Global Account opened in her name, which she says she did not open. It then left in pounds sterling to overseas mule accounts. Her loss spans a sending account, a receiving account, a foreign-currency product and a merchant. The telco layer is also missing from AFCA's view. ACMA found that TeleSign, a transit carrier, failed to pass on or report traceback notices covering more than 11,000 malicious SMS messages in November 2023 and February 2024. Carriers like TeleSign were never before AFCA. The SPF must close that gap.

  • Membership at the date of lodgement. Requiring the regulated entity to be an AFCA member "when the complaint is submitted" risks excluding victims whose funds passed through a fintech, crypto ATM or foreign-currency platform that later exits the market. Membership at the time of the payment loss transfer should be sufficient. In exploitative crypto ATM scams, for example, the victim can be groomed for three to six months before lodging any complaint.

  • Who is the "SPF Consumer". Family members, older people and people experiencing coercive control or elder financial abuse are often not the named account holder in a high-loss scam. In HSBC complaints 1049413 and 1066263, the elderly account holders' adult children acted as their representatives, and developed serious health conditions of their own, including a heart condition, anxiety and insomnia. Victims who hold savings through a family trust or small-business entity, as at least two Supercheap Security victims did, should not have to argue their way into eligibility. AFCA should confirm that the person who suffers the loss can complain, and that trust and small-business structures are covered where the Regulated Service is supplied to or for an individual's benefit.

  • Non-regulated wrongdoers. Mule account holders and shell-company directors are not regulated entities. AFCA should confirm that an unsatisfied court judgment against them does not reduce or exclude a complaint against the regulated entities, beyond preventing double recovery. O'Brien v Supercheap Security Pty Ltd (No 2) [2024] NSWSC 1196 is an example of such a judgment.

Q3. What further guidance regarding this proposed approach would be useful for the AFCA Operational Guidelines?

The Operational Guidelines should:

  • Explain in plain English, with worked examples, how the six-year time limit applies when a victim learns of the loss quickly but only much later discovers which entity received the funds, or what that entity knew. SVA recommends the limit run from the later date.

  • Include worked examples for complex typologies: bank impersonation and term deposit scams, settlement misdirection, investment scams using a shell-company mule account, and superannuation scams.

  • Commit to regular plain-language communications and open "Ask AFCA anything" sessions for complainants and their support people on the Scam Rules and guidelines.

"Awareness of loss" and "awareness of the regulated entity's role" are different dates, as two sets of cases show:

  • Supercheap Security. The victims knew within days that they had been scammed. They did not learn who held the receiving account, or what the receiving bank knew, until police inquiries, media investigation and court subpoenas years later.

  • HSBC. Victims knew within hours that money had gone. They learned that HSBC lacked adequate controls on its internal account transfer (IAT) payment rail only on 22 May 2026, when HSBC's Statement of Agreed Facts was published in the Federal Court. The complainants in 12-00-1065766 settled in November 2024, learned of ASIC's proceedings two months later, and HSBC refused to reopen on 20 January 2025.

3.2 Exclusions

Q4. What further guidance regarding this proposed approach to mandatory exclusions would be useful for the AFCA Operational Guidelines?

AFCA should confirm it can still consider a large loss up to the $1.263m limit, and point complainants to court options and legal help for the balance. Complex scams routinely force complainants to run parallel disputes against different parties, for example through the Telecommunications Industry Ombudsman or the OAIC.

In HSBC complaints 1049413 and 1066263, an elderly couple lost $388,350 of their retirement downsizing proceeds across 13 transactions. Partial recoveries came only after their family chased the receiving institutions themselves (Westpac, Cuscal and Monoova). Losses of this size, spread across several entities, need parallel pathways from the start.

Guidance should:

  • Confirm that the mandatory exclusion for complaints above $1,263,000 in direct financial loss is applied with clear written reasons. AFCA should refer the victim to alternative avenues (court, legal assistance, litigation funding information and the relevant regulator) rather than simply closing the file.

  • Explain how the exclusion will operate for high-value property settlement and superannuation losses, given fast-rising property values.

  • Make clear that court proceedings against a mule account holder or non-member entity do not trigger any exclusion for "matters already dealt with by a court" against a different, regulated respondent, provided there is no double recovery.

  • Report each year, as part of the Scam League Table, how many SPF complaints are excluded on monetary grounds and the total value excluded.

Q5. What further guidance about how AFCA may approach its discretion to exclude complaints would be useful for the Operational Guidelines?

SVA's main concern is proportionality and trauma-informed practice. Guidance should make clear that the discretion to exclude a complaint as "frivolous, vexatious, misconceived or lacking in substance" is not used against a genuine victim who:

  • repeatedly seeks clarification because AFCA or a regulated entity has not adequately explained a complex, multi-hop scam;

  • raises new evidence that emerged after a decision (for example from court proceedings, police or FOI);

  • pursues other lawful avenues at the same time; or

  • is highly traumatised and so is not always responding with clarity. Dealing with AFCA commonly puts victims back into a trauma state, where they can quickly become frustrated that they are not being heard.

The HSBC cohort shows why:

  • One victim holds four AFCA case numbers (971494, 12-24-161718, 12-25-221597 and 12-26-397786). No earlier complaint ever reached a merits decision.

  • Complaints 12-26-406450 and 12-26-439028 were lodged on genuinely new evidence: the Federal Court record in ASIC v HSBC, which did not exist when the earlier complaints (12-00-1048367 and 1069438) closed.

None of these complainants should be treated as vexatious. This is consistent with AFCA's duty to help complainants lodge and progress complaints. AFCA should also publish, in de-identified aggregate form, how often each discretionary exclusion ground is used and against which classes of complainant, so consumer groups can monitor for disproportionate impact.

3.3 Multi-party complaints and complaint resolution approach

Q6. Does the proposed AFCA approach appropriately reflect the multi-party nature of SPF complaints?

Partially.

The joinder and removal mechanisms in draft Rule 1.6 are a sound framework. But AFCA's own data shows joinder occurred in only 1.3% of complaints in FY26. That rate must rise substantially, because SVA members typically report their funds moving through several institutions.

SVA recommends a presumption that every regulated entity through which funds are shown to have passed is joined, unless AFCA records reasons why it should not be. The complainant, who by definition cannot see the money trail, should not have to identify each party and request its joinder.

  • Supercheap Security. The victims only learned the receiving account belonged to a shell company, not to themselves, after the money was gone. The receiving bank is best placed to explain how that account was opened, monitored and allowed to move funds offshore. In O'Brien v Supercheap Security [2023] NSWSC 21, Ball J struck out the victims' claims against NAB, the receiving bank. His Honour held that a duty on a bank to stop its own customer defrauding strangers would, in effect, be a duty owed to the world at large. Before the SPF, a receiving bank that hosted a mule account owed a non-customer victim almost nothing in negligence. The SPF changes that, and AFCA's joinder practice must now bring receiving banks in as a matter of course.

  • HSBC. In complaints 1049413 and 1066263, 13 transactions went to newly created payees, mostly accounts at HSBC itself. HSBC was therefore both the sending and the receiving bank, yet no receiving-account evidence was volunteered. The victims were left to chase the other receiving institutions themselves.

  • The telco layer. The spoofed SMS messages that began these scams travelled through a transit carrier that was never before AFCA.

  • AFCA's view of the cohort. Advocates acting for several HSBC victims were told AFCA saw "not enough commonality" to treat them as a group. SVA's group complaint (12-26-431688) tests that view.

Q7. What further guidance regarding this proposed approach would be useful for the AFCA Operational Guidelines?

Guidance should set default expectations for:

  • Tracing depth. AFCA (or the regulators it reports to) should trace a minimum of three to five "hops" as a matter of course, consistent with bank insiders' confirmation that financial institutions can typically trace transactions this far.

  • Who pays for tracing. The cost should fall on the regulated entities, not the complainant.

  • Receiving-account evidence. Where a receiving bank is joined, it should produce its account-opening file, beneficial-owner verification and the account's first 30 days of activity, subject to the legal limits on disclosing suspicious matter reports.

  • Apportionment beyond AFCA's reach. How liability is apportioned where a later-hop entity is a non-member, offshore platform or unregulated individual. The unrecoverable share should not simply fall back on the victim.

The HSBC cases show what happens without these defaults:

  • HSBC C240138552445 and AFCA complaint 12-26-454918. The complainants were scammed on 27 January 2024. Their funds went to other HSBC accounts and left on 29 January 2024, a two-day window in which they could have been blocked. Their questions to AFCA about where the money went next remain unanswered.

  • Complaint 12-25-221597. On 23 April 2025, the complainant asked through AFCA for receiving-account and recall records. They were never produced.

Statements of Compliance must carry real accountability. Each regulated entity should explain, in writing, why funds could not be recovered through IDR, EDR, law enforcement or ReportCyber, and when it first learned of suspicious activity on the account.

Q8. How should AFCA adapt its current complaint resolution and decision-making approaches to handle similar SPF complaints under Rule 1.8.2(c)?

Scams increasingly defy categorisation as frontier AI rapidly scales up the financial harm of a targeted exploit. Mortgage fraud, the HSBC SMS impersonation scam and the Supercheap Security case all show why a cohort approach is needed.

Supercheap Security. In the AFCA cases relating to this fraud, the complainants dealt with the same fake AMP staff using the same fake email domains, and paid the same NAB account in their own names within the same week. At least one other CBA customer did the same. Only one CBA customer had a payment blocked, after CBA received intelligence about the fraudulent NAB business account. This is exactly the "same Scam event or activity" that draft Rule 1.8.2(c) is designed to address.

HSBC. The Federal Court's orders list 1,022 customers who reported unauthorised transactions between January 2020 and August 2024. HSBC's redress program is reassessing 1,045 customers. Across the cohort the victims describe the same features:

  • the same spoofed messages appearing inside HSBC's genuine SMS thread;

  • the same "fraud team" phone script;

  • the same internal transfer rail; and

  • the same control gap, which HSBC admitted ran for 12 months from 29 May 2023.

AFCA had two published determinations covering this typology:

  • 934078 (September 2023, Beyond Bank). Passcodes disclosed to a caller spoofing the bank were not voluntarily disclosed.

  • 12-00-1016692 (August 2024, HSBC). The Mr T determination.

Yet most HSBC complaints closed by settlement below full loss, including 12-00-1048367, 12-00-1065766 and 12-25-221597. We believe a correctly applied lead-case approach would have applied the Mr T reasoning across the cohort. Other bank impersonation scams using the same typology (spoofed SMS bank impersonation) could also have been prevented.

Image 13: Mr C's AFCA case 12-24-130239 revealed that ANZ told him his account was not "eligible" for Falcon security protection, and only showed AFCA a screenshot of an email to its own staff to "prove" the bank had tried to recover stolen funds. Mr C did not voluntarily authorise his payments, and police told him mule accounts were reinstated because they had genuine lifestyle spending. This bank-to-bank mule typology was also present in the HSBC scam for which HSBC was later penalised.

SVA strongly supports AFCA developing a "lead case" or cohort approach under Rule 1.8.2(c) for near-identical scam complaints, so victims do not each have to re-establish the same facts about a common fraud. This matters most where identifiable scam infrastructure is shared, such as domains, spoofed sender IDs and common mule accounts. Any such approach must:

  • let each victim seek their own compensation and have their individual circumstances weighed;

  • never justify a lower standard of individual inquiry;

  • treat what a regulated entity learned from one victim's report as relevant to its conduct towards every later victim of the same event;

  • take a consistent investigative approach (as outlined in Part 1, building a timeline and a lead–deceive–bleed–clean vector); and

  • trigger a systemic-issue review and referral under s 1052E of the Corporations Act 2001 (Cth) where the same entity appears across a cohort.

Where a determination already exists against the same bank for the same scam type, it should apply by default unless the member firm shows the facts are materially different. Each victim must still get an individual resolution, with no assumption that an authorisation engineered through deception was voluntary.

3.4 How AFCA will gather and share information for SPF complaints

Q9. Does the proposed information gathering approach appropriately enable AFCA to obtain information necessary to resolve SPF complaints?

No. An information-gathering power is only as strong as the consequence for ignoring it. Banks have already shown they will ignore AFCA requests for information.

Draft Rule 1.9.3 narrows the confidentiality exception, which SVA welcomes. But member firms routinely rely on confidentiality to withhold transaction histories, CCTV, KYC records and account-opening files. SVA members also report bank file notes that do not match their own recollection or records. The HSBC cohort shows each of these problems:

  • Logs withheld. In complaint 12-25-221597, the complainant asked in writing for her internet banking and IP logs before deciding on HSBC's time-limited offer. She never received them.

  • Bank findings contradicted by the victim's own records. In complaint 12-00-1065766, HSBC held the complainants liable partly because they had ignored "clear and proximate" in-app warnings. The complainants' contemporaneous notes and screenshots indicate those warnings were introduced months after their scam.

  • Logs that do not support the finding. In complaints 1049413 and 1066263, HSBC's own logs, obtained through AFCA, showed that the passcodes HSBC relied on could explain fewer than half the disputed transactions.

  • Alerts not acted on. A consumer advocate who reviewed several HSBC files reports that the logs showed a login from an overseas IP address within a minute of the customer's own login. He also reports HSBC conceding in conciliation that fraud alerts were not reviewed for 12 to 14 hours.

  • The standard applied versus the facts later admitted. AFCA's preliminary view in 12-00-1048367 (April 2024) was that there is no contractual or legislative requirement for a bank to manually monitor accounts for scams. HSBC later admitted in the Federal Court that it lacked adequate fraud rules, behavioural biometrics and device-identification controls on the rail used in these scams. None of this was known to complainants when they were asked to settle.

SVA recommends the Scam Rules:

(a) Require a standard information package without a request. Sending and receiving regulated entities should automatically produce:

  • the transaction history for 28 days either side of the scam;

  • login, device and IP records and any fraud alerts generated;

  • evidence of the funds' onward path for two to five hops;

  • Confirmation of Payee name-match results;

  • the receiving account's opening and beneficial-owner verification file; and

  • the date and content of any scam intelligence the entity held or received about the account.

(b) Make the adverse inference mandatory. Draft Rule 1.9.6(a) already says an adverse inference will "generally" be drawn. It should be drawn unless the entity proves special circumstances by statutory declaration under Rule 1.9.4. Non-compliance should also be referred to ASIC, AUSTRAC or APRA as a matter of course, using AFCA's reporting duty under s 1052E of the Corporations Act 2001 (Cth).

Image 14: When AFCA fails, individuals lose trust in governments and banks.

(c) Treat KYC and AML/CTF conduct as relevant to the complaint. AFCA should reverse the position in Determination 651819 that AML obligations are owed only to the government. Whether or not those obligations create private rights, a regulated entity's compliance with them is plainly relevant to whether it met its SPF "prevent", "detect" and "disrupt" obligations. That is the correct frame under Part IVF of the Competition and Consumer Act 2010 (Cth). The unexplained opening of an HSBC Global Account in the name of the complainant in 12-26-397786 shows why.

AFCA should also work with regulators and police to supply "compliance statements". These would protect confidentiality for law enforcement purposes while assuring complainants that authorities are taking their scam seriously and trying to hold corporations to account. The information package can exclude the fact or content of a suspicious matter report while still disclosing account-opening, monitoring and timing evidence.

Q10. Is a $10,000 cap appropriate for expert advice costs?

Doubling the cap from $5,000 to $10,000 is a reasonable start, but it will not be enough for the largest matters.

The cap will not cover the largest multi-hop, multi-jurisdiction matters SVA members describe, some involving losses over $1 million and laundering through cryptocurrency, gold or offshore company accounts. SVA recommends AFCA use its "special circumstances" discretion to exceed the cap in genuinely complex matters, and report annually how often and by how much the cap is exceeded.

Our proposed "compliance statements" from regulators and law enforcement would also help establish special circumstances. At present, victims have no assurance that state police are investigating their matters. This is despite state police working with the Australian Financial Crimes Exchange, as part of the Joint Policing Cybercrime Coordination Centre (JPC3), to stop funds leaving Australia. Meanwhile, the lack of transparency means victims cannot tell what happens to funds that are never recovered.

The HSBC cohort illustrates the gap. In Mr B's matter (12-00-1048367), police records later obtained under FOI (SAP2400031153) showed the calls came from spoofed numbers, and that officers initially sought a warrant before realising the scam was architected to move money through different mule accounts and make it unrecoverable. Police then filed the matter on 23 December 2024 with "no further avenues identified".

This should form part of broader fee-transparency reporting, in which AFCA members disclose how they resource their EDR obligations, including internal and external legal and advisory costs to support AFCA cases. The National Anti-Scam Centre could also target fusion cells at fast-rising typologies, such as the Chinese authority impersonation scam, before they scale as the HSBC scam did in 2023–24.

Q11. What guidance should be developed by AFCA to manage the use of GenAI-generated content by parties to a complaint?

Don't penalise victims who use AI to organise their evidence; for many, it is an access-to-justice tool.

SVA supports sensible management of excessively long or repetitive submissions, but cautions against guidance that limits a genuine victim's ability to use AI tools to organise complex evidence and state a claim they could not otherwise afford legal help to prepare. This matters most for people with English as a second language or low digital literacy.

The complainant in 12-26-397786 told AFCA she needed a Mandarin interpreter as early as 14 April 2023. Assisted drafting was the only way she was finally able to answer the 21 questions HSBC put to her in 2026. Several of those questions had no bearing on her facts, for example whether she had downloaded remote-access software. This suggests AI-generated or templated bank or AFCA questionnaires, which are another likely source of strain on AFCA.

Guidance should distinguish clearly between:

  • (a) a complainant using AI to help present their own genuine evidence and account, which should be encouraged as an access-to-justice measure; and

  • (b) a regulated entity or its paid representative using AI to generate bulk, templated or evasive responses. This is the more likely source of the "strain" AFCA describes and should be the primary target of any guidance.

All parties should remain responsible for the accuracy of what they submit, consistent with the Federal Court's Generative AI Practice Note cited in AFCA's paper.

We are also concerned about law firms profiting from the rise in AFCA cases by offering "no frills" legal dispute services. Some firms are charging superannuation fraud victims up to $15,000 per case. That is up to twice what other victims of similar superannuation frauds have been asked to pay, with some signed up at $7,500. We welcome AFCA's acknowledgment that the new rules will make this practice proliferate, and we urge government and regulators to do everything possible to stop the continued financial exploitation of people suffering life-changing scam losses.

3.5 Proposed monetary and compensation limits for SPF complaints

Q12. Do the proposed compensation limits appropriately reflect the nature and impact of scam-related harm that should be considered by AFCA?

Aligning the direct financial loss limit with the $1,263,000 monetary limit is an improvement, but not a sufficient one, given the rising harm from property and superannuation fraud. In particular:

  • (a) the limit will still exclude the largest property settlement and investment scam losses SVA members report, some above $2,000,000 in a single event;

  • (b) doubling the non-financial loss cap to $12,600 per regulated entity is welcome but modest against the reality of scam trauma, which members describe as relationship breakdown, loss of housing and diagnosed mental health impacts lasting years; and

  • (c) none of the limits address the compounding harm of a victim paying interest on a loan, or drawing down retirement savings, while a complaint is unresolved. In one NAB mule-account case SVA has raised with AFCA, the victim has waited more than 20 months for a determination.

HSBC victims show how this plays out:

  • In 12-00-1048367, $49,900 was scammed from a home loan, and interest was charged on the loss for the whole of the eight-month IDR investigation and the AFCA process that followed.

  • A single mother of three lost $49,965 on 2 February 2024. She borrowed from friends for eight months to cover rent, food and school costs before her funds were returned.

  • HSBC's own 2026 redress program has since paid interest to complainants such as those in 12-00-1065766, which shows interest was always calculable, yet it was not awarded while those complaints were before AFCA.

SVA recommends AFCA's decision-making approach explicitly direct Decision Makers to consider suspending or reversing interest on the disputed amount as a standard interim step while an SPF complaint is on foot, not only in a final determination. Where a victim has had to access superannuation early because of the scam, the lost earnings and any tax cost should be recognised as indirect financial loss.

Q13. Are the proposed limits for legal and other professional costs adequate?

No.

The $5,000 cap (plus indexation) is inadequate for property settlement and complex multi-party investment scam matters, where victims may need a lawyer, forensic accountant or fraud specialist simply to understand their own case.

In HSBC complaints 1049413 and 1066263, the family was asked, after the dispute had been negotiated, to sign an additional indemnity letter. They feared it would affect their rights if new information emerged, and avoided signing it only because a not-for-profit legal centre intervened. SVA recommends:

  • raising the cap for losses above $100,000, and wherever a victim needs a professional to respond to a regulated entity's own legal representation in conciliation;

  • allowing AFCA to recognise reasonable costs of prior court proceedings against non-regulated wrongdoers where those proceedings produced evidence AFCA relies on; and

  • publishing fee data for paid representatives (see Q19), so the right level for these limits is evidence-based.

We also propose that raising the IDR reimbursement limit to $25,000 would give complainants a "standing start" to resort to civil litigation if they need to. SVA would prefer that AFCA becomes the free, fair and accessible dispute resolution service intended under legislation, but regularly sees that this is impossible in scam complaints where criminals use insider threats to exploit broken internal systems that AFCA, regulators and law enforcement will never become aware of.

3.6 Decision-making approach

Q14. Does the proposed alignment of non-financial loss wording with AFCA's existing Financial Firm Rules appropriately capture the degree of non-financial loss that may be suffered in SPF complaints?

No. Scam harm includes trauma, suicidal thoughts, family breakdown and losing a home, often made worse by the trauma of dispute resolution.

Scam-related non-financial loss is qualitatively different from the "inconvenience" contemplated by the existing wording, which was developed for ordinary financial services disputes. Victims in our network report post-traumatic stress, suicidal ideation, family breakdown and loss of their home, arising from the scam and compounded by an institution's conduct during the dispute, such as continuing debt collection or interest charges.

The HSBC cohort shows harm caused by the institution's conduct after the scam, not only by the scam itself:

  • In 12-00-1048367, the complainant wrote that being told the liability fell on him, rather than on the bank whose systems were spoofed, was "almost as distressing as the scam itself".

  • In 1049413 and 1066263, the victims' adult children were also traumatised and developed a heart condition, anxiety and insomnia while managing the dispute for their non-English-speaking parents.

  • In 1069438, the complainant's account was restricted from 30 October 2023 to 3 May 2024. The Federal Court penalised this type of conduct separately.

SVA recommends scam-specific wording that expressly recognises psychological and relationship harm caused or worsened by a regulated entity's conduct during and after the scam, including delay, poor communication and refusal to engage with new evidence, not only harm from the entity's role in enabling the scam. AFCA's own paper acknowledges these post-scam conduct harms; the rule wording should reflect them. Delay is the most harmful factor of all, which is why SVA also supports raising automatic IDR reimbursement to $25,000 (see Q1).

Q15. Should parties be required to notify AFCA of terms of settlement of any EDR complaint for the purposes of public reporting and closing the complaint?

Yes. Parties should be required to notify AFCA of settlement terms.

AFCA should publish de-identified, aggregate settlement data for scam complaints, including typical settlement amounts as a proportion of loss, by scam typology and by regulated entity, so systemic under-compensation can be identified. The HSBC cohort shows why. The resolution letter in 12-00-1048367 recorded that the bank "assumes no liability" and foreshadowed a deed of release. In 12-25-221597, the complainant accepted an offer within a 14-day window. She had not received the logs she had asked for, and did not have the interpreter she had told AFCA she needed. When the complainants in 12-00-1065766 asked HSBC to reopen after learning of ASIC's proceedings, HSBC relied on their settlement and on the claim that "each case is unique".

Settlements reached through AFCA during 2023–24 had several features:

  • releases covering complaints to "any court or authority";

  • confidentiality backed by clawback;

  • non-disparagement clauses; and

  • acceptance windows as short as one business day, put to elderly or non-English-speaking complainants.

SVA also recommends that draft Rule 1.16.3's prohibition on non-disclosure clauses be extended to settlements of SPF complaints reached at any stage of AFCA's process. At a minimum, no settlement clause should prevent a complainant from:

  • telling AFCA the terms of settlement;

  • reporting the underlying conduct to a regulator, law enforcement, a parliamentary inquiry or the media; or

  • warning other consumers about the specific fraud typology involved.

This supports AFCA's own statement that SPF outcomes should not be subject to confidentiality arrangements that prevent appropriate transparency and disclosure of participant conduct to regulators.

Q16. What further guidance about AFCA's proposed approach to decision-making would be useful?

Guidance should:

  • explain, with worked examples, how liability will be apportioned between regulated entities under the SPF framework once finalised, and confirm that a victim need not identify which entity breached which obligation before AFCA will investigate;

  • set out a clear, accessible process for a complainant to ask AFCA to reconsider or reopen a complaint when material new evidence emerges from court proceedings, police investigations, FOI or media inquiries;

  • address how AFCA will treat victims whose earlier determinations applied pre-SPF standards, for example the widespread pre-2024 banking position that the payee name in a transfer instruction is not checked, now superseded by Confirmation of Payee and the SPF "prevent" and "detect" principles; and

  • confirm whether such victims have any avenue to have their matter reconsidered under the new framework, and if not, say so plainly so they can pursue other options.

Complaint 12-00-1065766 shows the gap. HSBC refused to reopen it in January 2025. The complainants' report is listed in the Federal Court's orders among the 1,022 affected customers. HSBC's 2026 redress program then paid them interest but no further principal, leaving about $5,958 of their $47,808 loss unrecovered. Without a clear reconsideration pathway, material new evidence of this kind cannot reach a decision-maker.

Image 15: AFCA's failure to force member firms to obey the law on mule bank accounts and money laundering has directly contributed to Australia's escalating scam crisis.

3.7 Expectations of party behaviour

Q17. Does reference to AFCA's Engagement Charter in Rule 1.2.2 assist stakeholders in their understanding of how they should participate in the AFCA process?

The Engagement Charter is a helpful reference point, but it does not reset the power imbalance SVA members experience at AFCA.

HSBC victims describe this imbalance directly. In 12-00-1048367, the complainant says he was told that if he pressed harder he might end up with nothing. Another HSBC complainant says she felt pressured and threatened by her AFCA case manager and stopped engaging, which harmed her initial case outcome. Another complainant alleges that an HSBC case manager told them to "get down on my knees and thank me for the $2000".

Complainants are often asked to open conciliation calls with their own statement, only for an experienced bank lawyer or bank case manager to respond with detailed knowledge of prior determinations and banking law that the complainant had no knowledge of. SVA recommends that the Engagement Charter, or the Scam Rules directly:

  • require each regulated entity to give the complainant its position, reasons and the documents it relies on, in writing, before any conciliation call; and

  • require disclosure of the internal and external legal, accounting and advisory services the entity has engaged on the complaint, with costs measured and reported in aggregate.

This ensures AFCA does not create a new systemic problem in which victims must pay professionals to participate in what is meant to be a free, fair and accessible scheme. It also aligns with licensees' existing duty to act efficiently, honestly and fairly under s 912A(1)(a) of the Corporations Act 2001 (Cth). In the superannuation fraud cases we support, we see other victim support groups actively encourage victims to use paid legal or financial advisers at AFCA without disclosing that AFCA is supposed to be a free, fair and accessible dispute resolution service.

Q18. Should the definition of 'Paid Representative' be expanded to include lawyers and accountants? Does this give rise to any unintended consequences?

No objection, as long as financial counsellors, community workers and family members can still help freely.

SVA opposes a for-profit industry growing off scam victim harms and believes AFCA could put its revenue to better use by offering more accessible communication to help victims, including regular "Ask AFCA anything" sessions and tailored, trauma-informed case management that helps victims understand the complexity of their case rather than automatically expecting victims to deal with it. Guidance should include:

  • a plain-English, WCAG-compliant decision tree, with translations, showing which rules apply to a complaint;

  • an online training library for complainants and support people, written to a Year 9 reading level, covering complaints that span the 31 March 2027 commencement date or involve an entity that is both a Financial Firm and a Regulated Entity; and

  • links to previously published determinations on similar scams, especially panel determinations.

Q19. Are there other industry, regulatory or system-wide reforms that should be considered to address the conduct and engagement by paid representatives in EDR?

Yes.

AFCA acknowledged in its webinar that the new rules are likely to encourage more for-profit law and advice firms charging victim-survivors. We have already seen this, with SOS Super spruiking for-fee services to victims at fees between $7,500 and $15,000 for what should be a free service. SVA recommends:

  • (a) a public register or reporting mechanism under which law firms and paid representatives disclose the fees they charge clients in SPF complaints, so financially devastated victims can weigh the value of a paid service; and

  • (b) a requirement that regulated entities disclose at the outset which external legal representatives and advisers they have engaged on the complaint. Banks, telcos and digital platforms can always out-resource a complainant, and full disclosure is vital to understanding the secondary markets that fraud is creating.

Recommendation (a) is likely to need Treasury or ASIC action beyond AFCA's Rules; AFCA can nonetheless collect and publish the data it already receives as part of the Scam League Table.

Image 16: Global fraud amplifies the market power of financial criminals. AFCA must protect Australians while not allowing legal firms to further exploit scam victims who feel they need paid representatives.

Conclusion

AFCA's proposed Scam Rules are a genuine step forward, but they will not change what our members keep experiencing unless AFCA changes how it works as well as what its rules say. Criminals deceive, a mule account receives the money, the money is laundered, and the victim is left to prove it at AFCA, sometimes after their authority form has gone missing or their file has been closed by an automated notice.

The three typologies in Part 4 tell the same story. Homebuyers are losing settlement funds to mule accounts controlled by criminal networks, and even where mules were arrested, victims were left paying interest on stolen money. HSBC admitted failing to apply the ePayments Code in 97% of cases over 44 months, after more than 400 customers had been through AFCA, and some HSBC cases remain unresolved at AFCA in September 2026. Supercheap Security victims won in the NSW Supreme Court and have recovered nothing.

In each case, AFCA held pieces of the pattern but did not share them fast enough to protect the next victim. With the changes we propose, AFCA can:

  • stop its own processes adding to victims' harm, starting tomorrow;

  • place the evidence burden on the firms that hold the evidence;

  • refer verified scam identifiers to regulators within 5 business days;

  • hold receiving banks and the whole laundering chain accountable;

  • stop confidential settlements silencing victims; and

  • publish a scam league table.

Appendix 1: HSBC

Ten HSBC customers in our community remain under-compensated or awaiting resolution at AFCA, despite the Federal Court proceedings and ASIC's statement that further payments would be made by the end of July 2026.

What the Federal Court proceedings delivered

  • The Federal Court imposed a $35 million penalty on HSBC on 18 June 2026 for failing to protect customers from scams. HSBC admitted its failures.

  • The penalty was reduced partly because HSBC committed to repay 1,045 customers through a Customer Redress Program. The Court did not order the redress or set its conditions, so victims cannot enforce it.

  • The $35 million penalty (order 4) and $2.3 million in costs to ASIC (order 6) go to the Commonwealth, not to victims. Only AFCA can order compensation to individual victims.

  • Reported unauthorised transactions totalled $34.6 million. As at 21 May 2026, HSBC had returned $27.9 million, of which only $7.1 million came through the redress program (SSAFA [58]).

Why the redress program leaves HSBC scam victims short

  • HSBC reassesses its own liability. 68 Phase 1 customers (16%) were found "customer liable" and receive nothing (SSAFA [51], [55]), by the same bank that admitted systemic failure to apply the ePayments Code from January 2020 to August 2023.

  • Low interest. Lost earnings were calculated at the rate of the account the money left (SSAFA [54]), not the RBA cash rate used in AFCA's Mr T determination. RG 277 expects assumptions that favour consumers.

  • No non-financial loss. HSBC admitted some customers suffered non-financial harm, but the program pays only principal and lost earnings. AFCA can award non-financial loss, but only if the victim complains.

  • Earlier settlements. Phase 3 reassesses 138 settled complaints (SSAFA [49]). Some 2023–24 settlements carried confidentiality, withdrawal and non-disparagement terms, signed before HSBC's admissions were public.

Appendix 2: Bank complaints are rising

If July 2026 is typical, complaints against the major banks will rise again in 2026–27, with deposit-taking payments and housing finance among the top AFCA complaint types at almost every bank. Projections are SVA's simple annualisation of July 2026 and are indicative only.



Next
Next

Prudential accountability can ease harm