The Broker Times · Scam Risk at Settlement
The scam category that breaks broker files is not the one in this week’s headlines
Bank impersonation gets the coverage. Payment redirection takes the money — and it fires on the one day every purchase file is most exposed.
Four numbers to hold together
Each traces to a regulator or statistical agency release.
Where Australia’s scam losses actually went in 2025
Top five categories by reported loss. Total reported losses: $2.18 billion across 481,523 reports.
How one redirected payment rewrites a file
Based on a case described to Broker Daily by Eva Loisance, principal at Finni Mortgages (26 August 2026).
One character
An email address differing from the solicitor’s by a single special character requests the funds.
$80,000 gone
The client transfers, believing the money is going to their solicitor’s account.
Two years to recover
Recovery took more than two years — long after the transaction needed to complete.
80% becomes 95%
The application was resubmitted at 95% LVR instead of 80%: new product, new lender shortlist, LMI, full rework.
Who the Scams Prevention Framework covers — and when
Scams Prevention Framework Act 2025 (Cth); Stage 1 designation effective 23 May 2026, per legal analysis of the instruments.
Designated in Stage 1
- Banks
- Telecommunications carriers
- Digital platforms
Not designated in Stage 1
- Mortgage brokers and aggregators
- Conveyancers and solicitors
- The settlement email chain itself
When obligations bite
- “Reasonable steps” duties: earliest 31 March 2027
- AFCA as the SPF dispute scheme: expected 31 March 2027
- A client scammed today has no SPF remedy
The takeaway
No money passes through a broker at settlement, so the loss never touches your account — but a redirected payment still turns an approved 80% file into a 95% rebuild. A written warning at week one, a call-back rule the client understands, and a dated file note are the cheapest controls available.
ASIC Just Published Six Months of Bank Impersonation Data. The Scam That Breaks Your File Isn’t In It
Payment redirection cost Australians $166.8 million last year — the second-largest scam category in the country. It fires on the one day every purchase file is most exposed, and the statutory framework built to deal with it doesn’t cover the settlement chain.
ASIC published six months of bank impersonation scam data on 24 August. The numbers are real, but they are small next to the scam category that actually empties a property settlement — one that cost Australians $166.8 million in a single year, sits in a different bucket, and lands on your file rather than your trust account.
What ASIC published, and what it doesn’t measure
On 24 August 2026, ASIC drew attention to National Anti-Scam Centre data covering 1 January to 30 June 2026: 5,262 bank impersonation scam reports and $3,249,618 in reported losses. ASIC Commissioner Alan Kirkland framed the mechanism plainly.
“These scams are designed to create fear and urgency. Scammers make people believe their money is at risk and convince them to act quickly without stopping to check.”
Bank impersonation is a specific pattern — someone poses as your client’s bank and pressures them into moving money to a “safe account”. It is worth knowing about. But it is not the pattern that shows up in broker files, and the $3.25 million figure is not the number to quote when you talk to a client about settlement risk.
The relevant number is in the ACCC’s annual scam reporting. In its 30 March 2026 release covering calendar 2025, the ACCC put total reported scam losses at $2.18 billion across 481,523 reports, up 7.8% year on year. Broken down by type, payment redirection scams accounted for $166.8 million — the second-largest loss category in the country, behind only investment scams at $837.7 million, and ahead of romance ($139.9m), phishing ($97.6m) and remote access ($69.9m).
Payment redirection is the settlement scam. It is the fake invoice, the intercepted email thread, the account details that changed at the last minute. It does not involve impersonating a bank. It involves impersonating the person your client already trusts — usually their conveyancer or solicitor, occasionally their builder, and occasionally the broker.
Fewer victims, bigger single hits
Here is the part the “scams are surging” headlines usually skip. The Australian Bureau of Statistics’ Personal Fraud release for 2024–25, published 12 March 2026, found scam victimisation actually fell — 2.7% of people aged 15 and over, down from 3.1% in 2023–24, or about 600,000 people and roughly 80,000 fewer victims than the prior year. One in seven Australians (3.2 million) experienced some form of personal fraud, but the bulk of that is card fraud: 2.3 million people, $2.2 billion gross, reduced to $350 million in net loss to individuals once reimbursements are counted, with 72% of card fraud victims fully reimbursed.
Read those two datasets together and the picture sharpens. Scam incidence is flat to falling. Card fraud, the highest-volume category, is largely absorbed by the banks. What is not absorbed, and what does not get reimbursed, is a single large authorised transfer made by a client who thought they were paying their solicitor.
That is the exposure sitting in your pipeline right now. Not a diffuse risk spread across your database — a concentrated, one-shot risk that fires on a specific day, for a specific amount, in every purchase file you write.
Your exposure is the file, not the funds
No money moves through a mortgage broker at settlement. That fact reassures brokers more than it should, because the loss does not have to touch your account to destroy your file.
Broker Daily reported on 26 August on a case described by Eva Loisance, principal at Finni Mortgages, in which a client lost $80,000 to a settlement impersonation scam. The scammer used an email address that differed from the legitimate solicitor’s by a single special character. The client transferred the funds believing they were going to the solicitor’s trust account. Recovery took more than two years — and in the meantime, the client had to resubmit the mortgage application at 95% LVR instead of 80%.
Sit with what that means operationally. A clean, approved 80% file becomes a 95% file. That is a different product, a different lender shortlist, mortgage insurance where there was none, a different serviceability outcome, a re-verification of everything, possibly a rescinded contract with penalty interest attached, and a client whose confidence in the entire transaction chain — including you — is gone. The broker did nothing wrong and still absorbed the rework, the delay and the reputational damage.
“I would always recommend calling up and confirming account details over the phone. It may take an extra five minutes, but you may have an extra $100,000 in your pocket.”
The recovery path your client actually has
This is where brokers most often give clients false comfort, usually without meaning to. The instinct is to say “the bank will sort it out”. Frequently it will not, and the reason is technical.
ASIC’s ePayments Code draws a hard line between an unauthorised transaction — one the customer did not make and did not consent to — and a payment the customer made themselves. The Code’s protections for unauthorised transactions are meaningful. Its “mistaken internet payment” provisions, which oblige the sending institution to chase the receiving institution for recovery, were expressly narrowed in ASIC’s 2022 update to exclude mistaken payments resulting from a scam. A typo in a BSB is a mistaken internet payment. A payment made to a scammer because the client was deceived is not.
A scammed client, in other words, has authorised the transfer. They fall outside the strongest part of the Code, and their recovery depends on how fast the receiving bank freezes the account, whether the funds have already been moved on, and whether the sending bank’s own controls should have caught it.
That last point is now live law rather than theory. On 18 June 2026, in ASIC release 26-127MR, the Federal Court ordered a $35 million penalty against HSBC for scam protection failures. HSBC admitted, among other things, failing to implement scam controls on the internal payment rail where most customer losses occurred, taking an average of 144 days to investigate customer scam reports, failing to apply ePayments Code rules when determining loss liability, and lacking adequate systems to restore banking access for affected customers. Justice Bennett held the failures were serious. HSBC had paid $21.5 million in compensation as at the release, with further payments due by the end of July 2026, and $6.5 million recovered and returned to customers. ASIC Chair Sarah Court’s assessment was that “Banks have been well on notice about the risks of scams for some time.”
For brokers, the reading is not that banks are now liable for every scam. It is narrower and more useful: banks are being held to standards on detection, response time and correct application of the Code. So when a client is hit, the questions that matter are how quickly the sending bank was told, what it did, and whether it applied the Code properly — which means the first hour after the client realises is worth more than the first month of complaint letters.
Stage 1 of the Scams Prevention Framework covers three sectors. Settlement isn’t one of them
Australia now has a statutory anti-scam regime. The Scams Prevention Framework Act 2025 (Cth) took effect on 21 February 2025, amending the Competition and Consumer Act 2010. Stage 1 designation followed: according to legal analysis of the instruments published in June 2026, the Competition and Consumer (Scams Prevention Framework – Regulated Sectors) Designation 2026 took effect on 23 May 2026 and designates three sectors — banks, telecommunications carriers and digital platforms. The same analysis indicates the “reasonable steps” obligations commence at the earliest on 31 March 2027, with AFCA expected to become the external dispute resolution scheme for those three sectors from the same date.
Two consequences follow, and both are worth understanding before you repeat anything about the framework to a client.
First, mortgage brokers, aggregators and conveyancers are not in the Stage 1 designated sectors. Nothing in the framework currently imposes SPF obligations on your business. That is a reprieve, not an endorsement — Stage 1 is called Stage 1 for a reason, and the professional services that sit inside the property settlement chain are an obvious candidate for later consideration.
Second, and more immediately relevant: the framework’s obligations and its dedicated dispute pathway do not bite until 2027. A client scammed at settlement this week has no SPF remedy. Their route runs through their bank’s internal dispute resolution, the ePayments Code where it applies, and AFCA under existing jurisdiction. If a client has read a headline about the new scam laws and believes they are protected today, correcting that gently is a genuine service.
On your own obligations: whether anything in the National Consumer Credit Protection Act 2009, the best interests duty, or ASIC’s guidance extends to warning clients about payment security is a question for your licensee and your professional indemnity insurer — not something to settle from a trade article. What is beyond argument is the commercial consequence: a scammed client is a broken file, and broken files are your problem regardless of where the duty sits.
The settlement-week protocol
The fix here is process, not vigilance. Vigilance fails because the scam lands on the one day the client is most rushed and least sceptical. Build the following into the file instead.
- Warn early, in writing, at the front of the file. Put the payment-redirection warning in your initial engagement communication, not at settlement. At settlement it reads as noise. At week one it sets an expectation that account details never change by email.
- Set the “no change by email” rule explicitly. Tell them: no solicitor, conveyancer, agent or lender will ever change bank account details by email, and if an email says they have, it is a scam until proven otherwise by a phone call.
- Give them the call-back rule, and the number source. Verify account details by calling the firm on a number the client sourced independently — from the engagement letter, the firm’s website, or a prior call log — never a number in the email carrying the new details.
- Do not become the source of truth. This is the trap. Do not confirm, forward or hold trust account details on the client’s behalf. If you supply account details and they are wrong, you have moved the exposure onto yourself. Point the client to the source; do not become it.
- Flag the high-risk windows. Deposit payment, any variation to the contract, and the day before settlement. Those are the moments the intercepted thread pays off.
- Note it in the file. Date-stamp that the warning was given and the rule explained. If the worst happens, the file note is the record of what you did.
- Know the first-hour script. If a client calls you first — and some will — the sequence is: call the sending bank immediately and report a scam payment, ask them to contact the receiving institution, report to the client’s bank in writing the same day, report to Scamwatch and Cyber.gov.au, then notify the solicitor so they can warn other clients on the same compromised thread. Speed is the only variable you control.
ASIC’s own consumer guidance runs on a three-step model — stop, check, protect: don’t act under pressure, verify contact details independently, and report to the bank, Cyber.gov.au and Scamwatch. It is a reasonable frame to hand a client, and it costs you nothing to be the person who hands it to them.
Why clients don’t check
Broker Daily’s coverage cited Commonwealth Bank Behavioural Science Centre research finding that scam victims often skipped verification for reasons that were social rather than technical: 34% felt embarrassed, 33% did not think it was necessary, and 31% were confident they could handle it themselves. The same report noted Bankwest data putting phishing at 52% of its scam cases in the last financial year — the only scam type to increase in volume year on year across all demographics — and ANZ figures showing a 24% fall in scam losses alongside more than $100 million prevented or recovered.
The embarrassment finding is the operationally useful one. Clients do not verify because checking feels like accusing a professional of being a fraud. Which means your job is not to tell them to be careful — it is to give them permission, in advance, to make the awkward phone call. “Everyone in this transaction expects you to ring and confirm the account before you send anything. Nobody will be offended” is a more effective control than any warning about scams.
What to watch next
Three things. Whether Treasury’s Stage 2 designations under the Scams Prevention Framework reach professional services in the property chain. Whether AFCA’s determinations post-HSBC start to push harder on sending-bank detection standards for large one-off transfers. And whether lenders begin building settlement-payment verification into their own processes — the first major to do so will make it a competitive point, and brokers will be asked about it.
The bottom line
The number ASIC published this week is not the one that should change your process. $166.8 million in payment redirection losses is. Scam incidence is falling while the loss per successful event concentrates in exactly the kind of large, authorised, one-shot transfer that property settlement requires — and the statutory framework built to deal with it covers the bank, the telco and the platform, not the settlement email, and not until 2027.
That leaves a gap, and the broker sits inside it commercially even while sitting outside it legally. A four-line warning in your first client email, a call-back rule the client understands, and a file note that says you gave both is not a compliance burden. It is the cheapest protection available for the one event that can turn a settled 80% file into a 95% rebuild.
Key takeaways
- The headline category isn’t your category. ASIC’s 24 August item covered bank impersonation: 5,262 reports and $3.25m in losses over six months. Payment redirection — the settlement scam — cost $166.8m in 2025 alone.
- Scam incidence is falling, not rising. The ABS recorded 2.7% victimisation in 2024–25, down from 3.1%. The risk is concentration in single large transfers, not volume.
- No money passes through you, and it doesn’t need to. In the case reported by Broker Daily, an $80,000 redirection sent an 80% LVR application back as a 95% LVR application.
- Authorised payments sit outside the strongest Code protections. ASIC’s ePayments Code expressly excludes scam-induced payments from the “mistaken internet payment” recovery provisions.
- Brokers and conveyancers are not designated under Stage 1 of the Scams Prevention Framework, and its obligations and AFCA pathway are not expected to commence before 31 March 2027 — so a client scammed today has no SPF remedy.
- Never become the source of truth on account details. Point the client to the firm; do not confirm, forward or hold trust account details yourself.
Broker FAQ
This article does not answer that, and no article can. Your obligations under the National Consumer Credit Protection Act 2009, the best interests duty and your credit licence conditions are matters for your licensee, your aggregator’s compliance team and your professional indemnity insurer. What this article does establish is that the commercial consequence lands on you regardless: the file has to be rebuilt.
Not usually, in this scenario. The Code’s strongest protections apply to unauthorised transactions — ones the customer did not make or consent to. Its “mistaken internet payment” recovery provisions were expressly narrowed by ASIC in 2022 to exclude mistaken payments resulting from a scam. A client who was deceived into authorising the transfer has made an authorised payment.
Not yet. The Scams Prevention Framework Act 2025 took effect on 21 February 2025, and Stage 1 designation of banks, telecommunications carriers and digital platforms took effect on 23 May 2026. But per legal analysis of those instruments, the “reasonable steps” obligations commence at the earliest on 31 March 2027, with AFCA expected to take on the dedicated dispute pathway from the same date. A client scammed today relies on existing bank IDR, the ePayments Code where applicable, and AFCA’s existing jurisdiction.
No — that moves the exposure onto you. If you supply account details and they turn out to be wrong, compromised or stale, you have made yourself the source of truth for a payment you have no ability to verify. Direct the client to obtain and confirm details directly with their solicitor or conveyancer by phone, on a number sourced independently of the email carrying the details.
It does not make banks liable for every scam. What the Federal Court’s $35 million penalty on 18 June 2026 addressed was HSBC’s admitted failures on scam controls, an average 144-day investigation time, and incorrect application of the ePayments Code when determining loss liability. The practical implication for brokers is that a bank’s speed and process after being notified now matter a great deal — so reporting immediately, and in writing, is the highest-value action available.
Breaking news for modern brokers
Lender policy, regulation and market shifts — read in broker terms, without the filler.
More at The Broker Times →Sources
- ASIC, The devastating impact behind bank impersonation scams, 24 August 2026 (National Anti-Scam Centre data, 1 January – 30 June 2026).
- ACCC media release, Continued action critical to combat fraud as annual scam losses exceed $2 billion, 30 March 2026.
- Australian Bureau of Statistics, Personal Fraud, 2024–25 financial year, released 12 March 2026.
- ASIC media release 26-127MR, Federal Court orders $35 million penalty against HSBC for scam protection failures, 18 June 2026.
- Broker Daily, Brokers on lookout as scam activity ramps up, 26 August 2026.
- Scams Prevention Framework Act 2025 (Cth); Competition and Consumer (Scams Prevention Framework – Regulated Sectors) Designation 2026, as described in published legal analysis of the Stage 1 instruments, June 2026.
Broker Tool
Settlement Scam Readiness: check your process, not your luck
Seven controls, a first-hour response sequence, and the wording that gives a client permission to make the awkward verification call.
Is the control in your process, or in your head?
Tick only what is actually documented and repeatable across every purchase file — not what you would do if you remembered.
Start ticking. Every control here is free. The one they replace — rebuilding an approved file at a higher LVR — is not.
If a client rings you first, speed is the only variable you control
Recovery depends on whether the receiving account can be frozen before the funds move on. Work down this list without stopping to investigate.
- ImmediatelyCall the sending bank and report a scam paymentNot a “query” and not a dispute — use the words “scam payment” so it reaches the right team. Ask them to contact the receiving institution now.
- Same hourGet the report in writingFollow the call with an email to the bank confirming the time of the call, the amount, the receiving account and what was requested. This is the record that matters later.
- Same dayReport to Scamwatch and Cyber.gov.auASIC’s guidance directs consumers to report to their bank, Cyber.gov.au and Scamwatch. Do all three.
- Same dayNotify the solicitor or conveyancerTheir email thread may be compromised, which means other clients of theirs are exposed on the same day.
- Same dayTell the lender and reset the timetableIf settlement is at risk, the lender and the agent need to know before the date passes, not after.
- Week oneReopen the file assumption, not the fileDo not promise a like-for-like approval. Reassess deposit position, LVR, LMI and serviceability before you tell the client where they stand.
- If unresolvedBank IDR, then AFCARecovery runs through the bank’s internal dispute resolution and, if that fails, AFCA under its existing jurisdiction. The Scams Prevention Framework’s own dispute pathway is not expected to commence before 31 March 2027.
This is a general process outline, not legal advice, and it does not create or describe an obligation on your part. Confirm your own reporting and escalation duties with your licensee before adopting it.
Give the client permission to make the awkward call
Commonwealth Bank Behavioural Science Centre research cited by Broker Daily found 34% of victims skipped verification out of embarrassment, 33% didn’t think it was necessary and 31% were confident they could handle it. Wording that removes the social cost beats wording that warns.
For your week-one engagement email
“One thing to know before we go any further. Scammers monitor property transactions and send emails that look exactly like your solicitor’s, asking you to send money to a new account. Nobody in this transaction — not your solicitor, not your conveyancer, not the agent, not the lender, and not me — will ever change bank account details by email. If you receive an email that says otherwise, it is a scam until a phone call proves otherwise.”
For the deposit and settlement conversation
“Before you transfer a cent, ring your solicitor’s office on the number from their engagement letter or their website — not a number in the email — and read the account details back to them. Everyone in this transaction expects you to do that. Nobody will be offended, and it takes five minutes.”
If the client asks you to confirm the account details
“I can’t verify those, and you shouldn’t take them from me — I’d be a second-hand source. Get them from your solicitor directly, by phone, and confirm them verbally. That’s the only version anyone should be acting on.”
Why the last one matters: if you supply account details and they are wrong, compromised or stale, you have moved the exposure from the client’s process onto your business. Point to the source; do not become it.
Payment redirection cost Australians $166.8 million in 2025 — the second-largest scam loss category in the country.
More broker briefings at The Broker Times →Disclaimer: This article is for general information and professional development purposes only. It does not constitute legal, compliance, or financial advice. Brokers should consult their aggregator's compliance team and, where required, seek independent legal advice regarding their obligations under the National Consumer Credit Protection Act 2009 and ASIC's responsible lending guidelines.

