The Broker Times · Scam Risk at Settlement

The scam category that breaks broker files is not the one in this week’s headlines

Bank impersonation gets the coverage. Payment redirection takes the money — and it fires on the one day every purchase file is most exposed.

Four numbers to hold together

Each traces to a regulator or statistical agency release.

$166.8m Payment redirection scam losses in 2025 — the second-largest loss category in Australia ACCC, 30 March 2026
$3.25m Bank impersonation losses across 5,262 reports, 1 Jan – 30 Jun 2026 NASC data, published by ASIC 24 Aug 2026
2.7% Scam victimisation in 2024–25 — down from 3.1% the year before ABS Personal Fraud, 12 March 2026
$35m Federal Court penalty against HSBC for scam protection failures ASIC 26-127MR, 18 June 2026

Where Australia’s scam losses actually went in 2025

Top five categories by reported loss. Total reported losses: $2.18 billion across 481,523 reports.

Investment$837.7m
Payment redirection — the settlement scam$166.8m
Romance$139.9m
Phishing$97.6m
Remote access$69.9m

Bars are scaled to the largest category. Source: ACCC media release, 30 March 2026. These five categories represented 60% of total reported losses.

How one redirected payment rewrites a file

Based on a case described to Broker Daily by Eva Loisance, principal at Finni Mortgages (26 August 2026).

1

One character

An email address differing from the solicitor’s by a single special character requests the funds.

2

$80,000 gone

The client transfers, believing the money is going to their solicitor’s account.

3

Two years to recover

Recovery took more than two years — long after the transaction needed to complete.

4

80% becomes 95%

The application was resubmitted at 95% LVR instead of 80%: new product, new lender shortlist, LMI, full rework.

Who the Scams Prevention Framework covers — and when

Scams Prevention Framework Act 2025 (Cth); Stage 1 designation effective 23 May 2026, per legal analysis of the instruments.

Designated in Stage 1

  • Banks
  • Telecommunications carriers
  • Digital platforms

Not designated in Stage 1

  • Mortgage brokers and aggregators
  • Conveyancers and solicitors
  • The settlement email chain itself

When obligations bite

  • “Reasonable steps” duties: earliest 31 March 2027
  • AFCA as the SPF dispute scheme: expected 31 March 2027
  • A client scammed today has no SPF remedy

The takeaway

No money passes through a broker at settlement, so the loss never touches your account — but a redirected payment still turns an approved 80% file into a 95% rebuild. A written warning at week one, a call-back rule the client understands, and a dated file note are the cheapest controls available.

CreditPolicy
Compliance Risk & Process 9 min read

ASIC Just Published Six Months of Bank Impersonation Data. The Scam That Breaks Your File Isn’t In It

Payment redirection cost Australians $166.8 million last year — the second-largest scam category in the country. It fires on the one day every purchase file is most exposed, and the statutory framework built to deal with it doesn’t cover the settlement chain.

ASIC published six months of bank impersonation scam data on 24 August. The numbers are real, but they are small next to the scam category that actually empties a property settlement — one that cost Australians $166.8 million in a single year, sits in a different bucket, and lands on your file rather than your trust account.

What ASIC published, and what it doesn’t measure

On 24 August 2026, ASIC drew attention to National Anti-Scam Centre data covering 1 January to 30 June 2026: 5,262 bank impersonation scam reports and $3,249,618 in reported losses. ASIC Commissioner Alan Kirkland framed the mechanism plainly.

“These scams are designed to create fear and urgency. Scammers make people believe their money is at risk and convince them to act quickly without stopping to check.”
Alan Kirkland, Commissioner, ASIC — 24 August 2026

Bank impersonation is a specific pattern — someone poses as your client’s bank and pressures them into moving money to a “safe account”. It is worth knowing about. But it is not the pattern that shows up in broker files, and the $3.25 million figure is not the number to quote when you talk to a client about settlement risk.

The relevant number is in the ACCC’s annual scam reporting. In its 30 March 2026 release covering calendar 2025, the ACCC put total reported scam losses at $2.18 billion across 481,523 reports, up 7.8% year on year. Broken down by type, payment redirection scams accounted for $166.8 million — the second-largest loss category in the country, behind only investment scams at $837.7 million, and ahead of romance ($139.9m), phishing ($97.6m) and remote access ($69.9m).

Payment redirection is the settlement scam. It is the fake invoice, the intercepted email thread, the account details that changed at the last minute. It does not involve impersonating a bank. It involves impersonating the person your client already trusts — usually their conveyancer or solicitor, occasionally their builder, and occasionally the broker.

Fewer victims, bigger single hits

Here is the part the “scams are surging” headlines usually skip. The Australian Bureau of Statistics’ Personal Fraud release for 2024–25, published 12 March 2026, found scam victimisation actually fell — 2.7% of people aged 15 and over, down from 3.1% in 2023–24, or about 600,000 people and roughly 80,000 fewer victims than the prior year. One in seven Australians (3.2 million) experienced some form of personal fraud, but the bulk of that is card fraud: 2.3 million people, $2.2 billion gross, reduced to $350 million in net loss to individuals once reimbursements are counted, with 72% of card fraud victims fully reimbursed.

Read those two datasets together and the picture sharpens. Scam incidence is flat to falling. Card fraud, the highest-volume category, is largely absorbed by the banks. What is not absorbed, and what does not get reimbursed, is a single large authorised transfer made by a client who thought they were paying their solicitor.

That is the exposure sitting in your pipeline right now. Not a diffuse risk spread across your database — a concentrated, one-shot risk that fires on a specific day, for a specific amount, in every purchase file you write.

Your exposure is the file, not the funds

No money moves through a mortgage broker at settlement. That fact reassures brokers more than it should, because the loss does not have to touch your account to destroy your file.

Broker Daily reported on 26 August on a case described by Eva Loisance, principal at Finni Mortgages, in which a client lost $80,000 to a settlement impersonation scam. The scammer used an email address that differed from the legitimate solicitor’s by a single special character. The client transferred the funds believing they were going to the solicitor’s trust account. Recovery took more than two years — and in the meantime, the client had to resubmit the mortgage application at 95% LVR instead of 80%.

Sit with what that means operationally. A clean, approved 80% file becomes a 95% file. That is a different product, a different lender shortlist, mortgage insurance where there was none, a different serviceability outcome, a re-verification of everything, possibly a rescinded contract with penalty interest attached, and a client whose confidence in the entire transaction chain — including you — is gone. The broker did nothing wrong and still absorbed the rework, the delay and the reputational damage.

“I would always recommend calling up and confirming account details over the phone. It may take an extra five minutes, but you may have an extra $100,000 in your pocket.”
Eva Loisance, Principal, Finni Mortgages — as reported by Broker Daily, 26 August 2026

The recovery path your client actually has

This is where brokers most often give clients false comfort, usually without meaning to. The instinct is to say “the bank will sort it out”. Frequently it will not, and the reason is technical.

ASIC’s ePayments Code draws a hard line between an unauthorised transaction — one the customer did not make and did not consent to — and a payment the customer made themselves. The Code’s protections for unauthorised transactions are meaningful. Its “mistaken internet payment” provisions, which oblige the sending institution to chase the receiving institution for recovery, were expressly narrowed in ASIC’s 2022 update to exclude mistaken payments resulting from a scam. A typo in a BSB is a mistaken internet payment. A payment made to a scammer because the client was deceived is not.

A scammed client, in other words, has authorised the transfer. They fall outside the strongest part of the Code, and their recovery depends on how fast the receiving bank freezes the account, whether the funds have already been moved on, and whether the sending bank’s own controls should have caught it.

That last point is now live law rather than theory. On 18 June 2026, in ASIC release 26-127MR, the Federal Court ordered a $35 million penalty against HSBC for scam protection failures. HSBC admitted, among other things, failing to implement scam controls on the internal payment rail where most customer losses occurred, taking an average of 144 days to investigate customer scam reports, failing to apply ePayments Code rules when determining loss liability, and lacking adequate systems to restore banking access for affected customers. Justice Bennett held the failures were serious. HSBC had paid $21.5 million in compensation as at the release, with further payments due by the end of July 2026, and $6.5 million recovered and returned to customers. ASIC Chair Sarah Court’s assessment was that “Banks have been well on notice about the risks of scams for some time.”

For brokers, the reading is not that banks are now liable for every scam. It is narrower and more useful: banks are being held to standards on detection, response time and correct application of the Code. So when a client is hit, the questions that matter are how quickly the sending bank was told, what it did, and whether it applied the Code properly — which means the first hour after the client realises is worth more than the first month of complaint letters.

Stage 1 of the Scams Prevention Framework covers three sectors. Settlement isn’t one of them

Australia now has a statutory anti-scam regime. The Scams Prevention Framework Act 2025 (Cth) took effect on 21 February 2025, amending the Competition and Consumer Act 2010. Stage 1 designation followed: according to legal analysis of the instruments published in June 2026, the Competition and Consumer (Scams Prevention Framework – Regulated Sectors) Designation 2026 took effect on 23 May 2026 and designates three sectors — banks, telecommunications carriers and digital platforms. The same analysis indicates the “reasonable steps” obligations commence at the earliest on 31 March 2027, with AFCA expected to become the external dispute resolution scheme for those three sectors from the same date.

Two consequences follow, and both are worth understanding before you repeat anything about the framework to a client.

First, mortgage brokers, aggregators and conveyancers are not in the Stage 1 designated sectors. Nothing in the framework currently imposes SPF obligations on your business. That is a reprieve, not an endorsement — Stage 1 is called Stage 1 for a reason, and the professional services that sit inside the property settlement chain are an obvious candidate for later consideration.

Second, and more immediately relevant: the framework’s obligations and its dedicated dispute pathway do not bite until 2027. A client scammed at settlement this week has no SPF remedy. Their route runs through their bank’s internal dispute resolution, the ePayments Code where it applies, and AFCA under existing jurisdiction. If a client has read a headline about the new scam laws and believes they are protected today, correcting that gently is a genuine service.

On your own obligations: whether anything in the National Consumer Credit Protection Act 2009, the best interests duty, or ASIC’s guidance extends to warning clients about payment security is a question for your licensee and your professional indemnity insurer — not something to settle from a trade article. What is beyond argument is the commercial consequence: a scammed client is a broken file, and broken files are your problem regardless of where the duty sits.

The settlement-week protocol

The fix here is process, not vigilance. Vigilance fails because the scam lands on the one day the client is most rushed and least sceptical. Build the following into the file instead.

  1. Warn early, in writing, at the front of the file. Put the payment-redirection warning in your initial engagement communication, not at settlement. At settlement it reads as noise. At week one it sets an expectation that account details never change by email.
  2. Set the “no change by email” rule explicitly. Tell them: no solicitor, conveyancer, agent or lender will ever change bank account details by email, and if an email says they have, it is a scam until proven otherwise by a phone call.
  3. Give them the call-back rule, and the number source. Verify account details by calling the firm on a number the client sourced independently — from the engagement letter, the firm’s website, or a prior call log — never a number in the email carrying the new details.
  4. Do not become the source of truth. This is the trap. Do not confirm, forward or hold trust account details on the client’s behalf. If you supply account details and they are wrong, you have moved the exposure onto yourself. Point the client to the source; do not become it.
  5. Flag the high-risk windows. Deposit payment, any variation to the contract, and the day before settlement. Those are the moments the intercepted thread pays off.
  6. Note it in the file. Date-stamp that the warning was given and the rule explained. If the worst happens, the file note is the record of what you did.
  7. Know the first-hour script. If a client calls you first — and some will — the sequence is: call the sending bank immediately and report a scam payment, ask them to contact the receiving institution, report to the client’s bank in writing the same day, report to Scamwatch and Cyber.gov.au, then notify the solicitor so they can warn other clients on the same compromised thread. Speed is the only variable you control.

ASIC’s own consumer guidance runs on a three-step model — stop, check, protect: don’t act under pressure, verify contact details independently, and report to the bank, Cyber.gov.au and Scamwatch. It is a reasonable frame to hand a client, and it costs you nothing to be the person who hands it to them.

Why clients don’t check

Broker Daily’s coverage cited Commonwealth Bank Behavioural Science Centre research finding that scam victims often skipped verification for reasons that were social rather than technical: 34% felt embarrassed, 33% did not think it was necessary, and 31% were confident they could handle it themselves. The same report noted Bankwest data putting phishing at 52% of its scam cases in the last financial year — the only scam type to increase in volume year on year across all demographics — and ANZ figures showing a 24% fall in scam losses alongside more than $100 million prevented or recovered.

The embarrassment finding is the operationally useful one. Clients do not verify because checking feels like accusing a professional of being a fraud. Which means your job is not to tell them to be careful — it is to give them permission, in advance, to make the awkward phone call. “Everyone in this transaction expects you to ring and confirm the account before you send anything. Nobody will be offended” is a more effective control than any warning about scams.

What to watch next

Three things. Whether Treasury’s Stage 2 designations under the Scams Prevention Framework reach professional services in the property chain. Whether AFCA’s determinations post-HSBC start to push harder on sending-bank detection standards for large one-off transfers. And whether lenders begin building settlement-payment verification into their own processes — the first major to do so will make it a competitive point, and brokers will be asked about it.

The bottom line

The number ASIC published this week is not the one that should change your process. $166.8 million in payment redirection losses is. Scam incidence is falling while the loss per successful event concentrates in exactly the kind of large, authorised, one-shot transfer that property settlement requires — and the statutory framework built to deal with it covers the bank, the telco and the platform, not the settlement email, and not until 2027.

That leaves a gap, and the broker sits inside it commercially even while sitting outside it legally. A four-line warning in your first client email, a call-back rule the client understands, and a file note that says you gave both is not a compliance burden. It is the cheapest protection available for the one event that can turn a settled 80% file into a 95% rebuild.

Key takeaways

  • The headline category isn’t your category. ASIC’s 24 August item covered bank impersonation: 5,262 reports and $3.25m in losses over six months. Payment redirection — the settlement scam — cost $166.8m in 2025 alone.
  • Scam incidence is falling, not rising. The ABS recorded 2.7% victimisation in 2024–25, down from 3.1%. The risk is concentration in single large transfers, not volume.
  • No money passes through you, and it doesn’t need to. In the case reported by Broker Daily, an $80,000 redirection sent an 80% LVR application back as a 95% LVR application.
  • Authorised payments sit outside the strongest Code protections. ASIC’s ePayments Code expressly excludes scam-induced payments from the “mistaken internet payment” recovery provisions.
  • Brokers and conveyancers are not designated under Stage 1 of the Scams Prevention Framework, and its obligations and AFCA pathway are not expected to commence before 31 March 2027 — so a client scammed today has no SPF remedy.
  • Never become the source of truth on account details. Point the client to the firm; do not confirm, forward or hold trust account details yourself.

Broker FAQ

Breaking news for modern brokers

Lender policy, regulation and market shifts — read in broker terms, without the filler.

More at The Broker Times →

Sources

  • ASIC, The devastating impact behind bank impersonation scams, 24 August 2026 (National Anti-Scam Centre data, 1 January – 30 June 2026).
  • ACCC media release, Continued action critical to combat fraud as annual scam losses exceed $2 billion, 30 March 2026.
  • Australian Bureau of Statistics, Personal Fraud, 2024–25 financial year, released 12 March 2026.
  • ASIC media release 26-127MR, Federal Court orders $35 million penalty against HSBC for scam protection failures, 18 June 2026.
  • Broker Daily, Brokers on lookout as scam activity ramps up, 26 August 2026.
  • Scams Prevention Framework Act 2025 (Cth); Competition and Consumer (Scams Prevention Framework – Regulated Sectors) Designation 2026, as described in published legal analysis of the Stage 1 instruments, June 2026.

Broker Tool

Settlement Scam Readiness: check your process, not your luck

Seven controls, a first-hour response sequence, and the wording that gives a client permission to make the awkward verification call.

Is the control in your process, or in your head?

Tick only what is actually documented and repeatable across every purchase file — not what you would do if you remembered.

Controls in place 0 / 7

Start ticking. Every control here is free. The one they replace — rebuilding an approved file at a higher LVR — is not.

Payment redirection cost Australians $166.8 million in 2025 — the second-largest scam loss category in the country.

More broker briefings at The Broker Times →
CreditPolicy

Disclaimer: This article is for general information and professional development purposes only. It does not constitute legal, compliance, or financial advice. Brokers should consult their aggregator's compliance team and, where required, seek independent legal advice regarding their obligations under the National Consumer Credit Protection Act 2009 and ASIC's responsible lending guidelines.