Australia · Bank disputes · ReportCyber and AFCA · 26 min read
What to Do After a Scam in Australia — Bank, ReportCyber and AFCA
If you have lost money to a scam in Australia, contact the bank, card issuer or payment provider immediately, stop further transfers, secure every affected account and make the official ReportCyber report. Whether the institution must reimburse you depends heavily on what payment occurred and who authorised it. The ePayments Code gives important protections for unauthorized transactions at subscribing institutions, but its definition generally excludes a transaction the user performed or knowingly consented to, even where a scammer supplied the reason. Card chargeback, a bank-transfer recovery attempt, internal dispute resolution, AFCA review and the new receiving-bank jurisdiction are separate routes. The federal Scams Prevention Framework exists, but AFCA states that its SPF complaint jurisdiction applies only to matters occurring on or after 31 March 2027. This guide uses the rules available on 28 July 2026 and does not present a future regime as a current guarantee.
Sources for the introduction, figures and summary
- Scamwatch: Targeting Scams Report 2025Published 30 March 2026
- ASIC ePayments Code, published versionEffective 2 June 2022
- Scamwatch: what to do if you have been scammedAccessed 28 July 2026
- Scamwatch: report a scamAccessed 28 July 2026
- Australian Signals Directorate: recover from scamsAccessed 28 July 2026
- Australian Financial Complaints Authority: unauthorized transactions factsheetAccessed 28 July 2026
- Australian Securities and Investments Commission: ePayments CodeCode effective 2 June 2022; accessed 28 July 2026
- ASIC: Federal Court penalty for HSBC scam-protection failuresPublished 18 June 2026; judgment update 7 July 2026
- Moneysmart: unauthorized and mistaken transactionsUpdated 18 June 2026
- Australian Financial Complaints Authority: receiving-bank jurisdiction for scam complaintsJurisdiction effective 12 March 2026; page updated 13 March 2026
- Australian Financial Complaints Authority: chargebacks factsheetAccessed 28 July 2026
- ASIC Regulatory Guide 271: internal dispute resolutionIssued 2021; accessed 28 July 2026
- Australian Financial Complaints Authority: the process we followAccessed 28 July 2026
- Australian Financial Complaints Authority: rules and monetary limitsLimits effective 1 January 2024; accessed 28 July 2026
- Australian Financial Complaints Authority: Scams Prevention FrameworkAccessed 28 July 2026
- Scamwatch: money recovery scamsAccessed 28 July 2026
The direct answer: use the route that matches the transaction
Direct answer: Notify the provider and ReportCyber immediately, then classify the loss as unauthorized, personally authorized, mistaken, card-based or crypto-based before asking for reimbursement or escalating a complaint.
There is no single Australian ‘scam refund’ procedure. An unauthorized online-banking transfer can fall under the ePayments Code if the institution and facility are covered. A customer who personally sends money to a false investment account has experienced a scam, but the payment may be authorized under the Code’s definition. A card purchase can support a chargeback under card-scheme rules. A true typing error in an account identifier can engage mistaken-internet-payment procedures, yet the Code expressly says those procedures were not intended for a transfer made to a recipient as the result of a scam. Starting with the wrong category can waste the short period when funds might still be contained.
Write down five facts for each payment: date and time, amount, product and rail, recipient, and who operated the device or gave consent. Add the representation that caused the payment and the exact moment the deception became clear. If a scammer used remote access, state what they could see and control. If you pressed confirm after being coached, say so. An accurate description allows the bank and AFCA to assess both the payment rules and whether the institution should have intervened.
The size of the problem does not establish liability in an individual file. The National Anti-Scam Centre’s combined 2025 report recorded $2.18 billion in reported losses from 481,523 reports across Scamwatch, ReportCyber, IDCARE, the Australian Financial Crimes Exchange and ASIC. Investment scams accounted for $837.7 million of reported loss. Those figures are evidence of scale, not a reimbursement rate and not a reason to skip the transaction-level analysis.
| What happened | First financial route | Critical question |
|---|---|---|
| Someone transferred money without your approval | Unauthorized-transaction investigation | Is the provider a Code subscriber and the facility covered? |
| You sent a bank transfer after a false story | Urgent recovery request and conduct complaint | What warnings and intervention occurred? |
| You entered the wrong BSB or account number | Mistaken internet payment process | Was it a genuine identifier error rather than a scam? |
| You paid by credit or debit card | Chargeback assessment | What reason and deadline apply under the card rules? |
| You sent cryptocurrency | Exchange, wallet and ReportCyber route | Can a custodial provider identify or freeze the destination? |
Source: Scamwatch: Targeting Scams Report 2025Published 30 March 2026
Source: ASIC ePayments Code, published versionEffective 2 June 2022
What to do immediately: bank, ReportCyber, security and evidence
Direct answer: Contact the financial provider first, ask it to stop transactions and alert the receiving side, then secure accounts, preserve evidence and complete the official ReportCyber report.
Scamwatch tells victims to contact the bank or card provider immediately, report the scam, ask it to stop transactions and stop sending more money. Use a telephone number or secure channel found independently. If the criminal is still on the line, end the call before contacting the bank. Ask for a case reference and confirmation of the affected payments. Where a transfer is pending or funds may remain with the recipient institution, request urgent recovery or freezing action. A completed payment can be hard to retrieve, but the provider cannot act on a loss it has not been told about.
Secure every linked service. Change banking and email credentials from a clean device, remove remote-access software, revoke unknown sessions, review payees and limits, and tell the institution if the scammer saw a one-time code or identification document. If identity information was exposed, IDCARE provides free support, and the official Scamwatch page lists its contact route. Do not send a full identity pack to a person who calls claiming to follow up the report.
Complete ReportCyber for the police report and preserve its reference. The Scamwatch reporting portal explicitly says a Scamwatch report is not an official police report and directs people who lost money to cybercrime to ReportCyber. Scamwatch reports still provide valuable intelligence to the National Anti-Scam Centre. Use both for their intended jobs rather than assuming one submission automatically reaches every bank, platform and police investigator.
- 01Stop the payments
Call the provider through an independently verified channel and identify pending and completed transactions.
- 02Ask for interbank action
Request a recall, recipient-bank alert or freeze attempt and obtain a case reference.
- 03Secure the accounts
Change credentials, end sessions, remove remote access and protect email and mobile services.
- 04Preserve the evidence
Export chats, receipts, statements, domains, advertisements and warnings.
- 05Report officially
Use ReportCyber for the police report and Scamwatch for National Anti-Scam Centre intelligence.
Source: Scamwatch: what to do if you have been scammedAccessed 28 July 2026
Source: Scamwatch: report a scamAccessed 28 July 2026
Source: Australian Signals Directorate: recover from scamsAccessed 28 July 2026
Related steps:UK APP scam reimbursement rules · Recovering money after a scam in Canada
What the ePayments Code can protect
Direct answer: At a subscribing institution, the Code can allocate unauthorized-transaction loss away from the account holder where the cause lies with the provider, merchant or system, the device or passcode was forged or defective, notice had already been given, or the user did not contribute to the loss.
The ePayments Code is voluntary, so the first check is whether the institution subscribes and whether the account and electronic facility are covered. ASIC maintains the Code and subscriber information. It commonly covers consumer ATM, EFTPOS, card, internet and mobile banking and BPAY facilities. It is not a general compensation statute for every interaction with a financial service. Quote its provisions only after confirming that the provider and transaction sit within its scope.
Clause 10 describes circumstances where a holder is not liable for an unauthorized transaction, including fraud or negligence by the subscriber or relevant merchant, a forged, faulty, expired or cancelled device or passcode, certain duplicate debits, transactions after the loss or security breach was reported, and cases where it is clear the user did not contribute. Other clauses allocate loss where a passcode was disclosed or the holder acted with extreme carelessness. The use of the correct passcode is relevant evidence but should not replace the required factual analysis.
Ask the provider to identify the Code clause and facts supporting its allocation. If it says the transaction was authorized, request the logs and explain the disputed consent. If it accepts that the transaction was unauthorized but says the holder contributed, ask which conduct, time period and loss calculation it relies on. A Code complaint should be anchored to those findings rather than a broad statement that banks always refund fraud.
- Confirm the institution appears on the current subscriber list.
- Confirm the consumer account and electronic facility are covered.
- Identify whether the provider accepts or disputes lack of authorisation.
- Request the specific liability clause and transaction logs.
- Separate passcode facts from the broader contribution and causation test.
Source: Australian Securities and Investments Commission: ePayments CodeCode effective 2 June 2022; accessed 28 July 2026
Source: ASIC ePayments Code, published versionEffective 2 June 2022
Source: Australian Financial Complaints Authority: unauthorized transactions factsheetAccessed 28 July 2026
The Code’s 21-day and 45-day investigation points
Direct answer: For a reported unauthorized transaction, the subscriber should complete the investigation and give the outcome within 21 days or explain in writing why more time is needed, and should ordinarily finish within 45 days absent exceptional circumstances.
The Code requires an effective and convenient reporting process. The subscriber should acknowledge a report with a reference or other verifiable record of the date. That date matters because it shows when the provider could act and starts the investigation record. Within 21 days it should either complete the investigation and communicate the result or tell the customer that more time is required. The written notice should explain the delay and status rather than simply leaving the disputed transactions under review.
The ordinary outside period is 45 days, with exceptions for circumstances such as waiting for information that is reasonably required. Keep every information request and response. If the provider asks for a police reference, device detail or declaration, respond promptly or explain what is unavailable. A firm should not refuse to investigate an unauthorized transaction merely because a card-scheme chargeback period has expired; the Code itself notes that the investigation duty and chargeback machinery are not the same thing.
Regulatory enforcement shows why these distinctions matter. On 18 June 2026 ASIC announced a Federal Court penalty of $35 million against HSBC for systemic scam-protection failures involving unauthorized transactions. ASIC reported an average investigation time of 144 days and failures in applying Code liability. The release also recorded remediation paid and funds recovered or returned. That is an institution-specific enforcement result, not an automatic entitlement in another case, but it confirms that Code investigation and allocation duties are substantive, not optional customer service targets.
| Point | What to expect | What to retain |
|---|---|---|
| Report | Accessible channel and verifiable acknowledgement | Reference and report date |
| 21 days | Outcome or written notice that more time is needed | Decision or delay explanation |
| During extension | Reasonable information requests and status | Requests, replies and missing items |
| 45 days | Ordinary completion point absent exception | Final reasons and Code clauses |
Source: ASIC ePayments Code, published versionEffective 2 June 2022
Source: ASIC: Federal Court penalty for HSBC scam-protection failuresPublished 18 June 2026; judgment update 7 July 2026
A mistaken internet payment is not a payment induced by a scam
Direct answer: The Code’s mistaken-internet-payment process is for a transfer sent to the wrong account because the payer entered an incorrect identifier; the Code expressly says it was not intended for a transfer sent to a recipient as the result of a scam.
This is one of the most important corrections to generic online advice. The mistaken-payment provisions use specific timing bands, including reports made within ten business days, between ten business days and seven months, and after seven months. Those bands determine the process between sending and receiving institutions where the wrong account identifier was entered. They are not a shortcut for a person who intentionally entered the account details supplied by a fake seller or investment adviser.
If the case is a true typing mistake, notify the institution immediately and provide the intended and actual identifiers. Moneysmart explains the timing categories and advises obtaining a reference. If the case is a scam, still notify the institution immediately, but describe it as a scam-induced payment and request fraud recovery action. Do not force the facts into the mistaken-payment definition simply because its early-report process looks favourable.
Some complaints contain both. A customer may first send an intentional scam payment and later mistype a different account number while trying to move remaining funds. List each transaction and its cause separately. The bank can then apply the mistaken-payment process to the genuine error and the scam or unauthorized route to the other loss. A single emotional narrative should not obscure distinct transaction facts.
Source: ASIC ePayments Code, published versionEffective 2 June 2022
Source: Moneysmart: unauthorized and mistaken transactionsUpdated 18 June 2026
Related steps:Getting money back after a scam in the United States · Crypto scam recovery: realistic options
Authorized bank-transfer scams: recovery and bank-conduct questions
Direct answer: For an authorized transfer, ask the sending bank to alert the receiving bank and attempt recovery immediately, then examine warnings, unusual-transaction intervention and post-report handling rather than assuming Code reimbursement.
A completed bank transfer is not reversed by the customer pressing an undo button. The sending institution can send a recovery request, and the receiving institution may restrict funds that remain, but the outcome depends on timing, account status and lawful authority. Give the bank the recipient name, BSB, account number, amount, transfer reference and the reason you know it was a scam. Ask what recovery action was taken and when. A vague note that ‘the payment could not be recalled’ does not answer whether the receiving side was notified promptly.
Next examine the sending bank’s conduct. Was the amount or recipient unusual for the account? Did the bank display a tailored warning? Did staff ask why the money was being sent? Did the criminal coach the customer to conceal the true reason? Was a cooling-off delay or confirmation-of-payee feature available? The existence of a red flag does not itself prove legal liability, and the absence of intervention does not guarantee compensation. It identifies the evidence needed for internal dispute resolution and AFCA.
Keep later movements distinct. In an investment scam, the customer may transfer money to a genuine exchange account in their own name and then send cryptocurrency to a fraudster. In another case, the first bank transfer may go directly to a mule account. The receiving-bank jurisdiction and causation analysis can differ. A payment-chain diagram should name who controlled every account and the precise point at which value left the customer’s control.
- 01Request recovery
Ask the sending bank to notify the receiving bank and record the time of action.
- 02Map every leg
Identify account ownership, BSB, account number, exchange and wallet transactions.
- 03Collect intervention evidence
Retain warnings, branch conversations, limit changes and call records.
- 04Obtain written reasons
Ask what the bank recovered and why it accepts or rejects compensation.
Source: Scamwatch: what to do if you have been scammedAccessed 28 July 2026
Source: Australian Financial Complaints Authority: unauthorized transactions factsheetAccessed 28 July 2026
Source: Australian Financial Complaints Authority: receiving-bank jurisdiction for scam complaintsJurisdiction effective 12 March 2026; page updated 13 March 2026
Chargeback is conditional and has no universal Australian deadline
Direct answer: Ask the card issuer promptly to assess a chargeback using the correct card-scheme reason and evidence; availability and deadlines depend on the scheme, transaction and cardholder agreement.
AFCA says a consumer should first try to resolve an appropriate dispute with the merchant and then give the bank the disputed transactions, reason and evidence. A chargeback may be relevant where goods or services were not supplied, were materially different from what was promised, or a card transaction was unauthorized. The issuer submits the request through the card scheme; the merchant’s bank can accept or contest it. Chargeback is not a guaranteed statutory refund and is not available for every scam narrative.
Time limits vary by reason and network. Report as soon as possible and ask the issuer for the exact deadline. Avoid publishing ‘120 days’ as a universal Australian rule. Some clocks can be linked to expected delivery, discovery or transaction dates, and an issuer may have an earlier notification requirement in the card agreement. AFCA’s factsheet says the card-scheme process can take up to eight weeks to reach a final decision.
A crypto or investment loss needs a leg-by-leg review. If a legitimate exchange supplied the cryptocurrency purchased with the card, the later transfer to a scam wallet may not establish that the exchange failed to provide its service. If the statement merchant was the fake platform and no genuine service existed, a different reason may apply. Give the issuer accurate merchant descriptors, receipts and onward transactions. AFCA can review whether the bank made reasonable efforts to submit and follow up a chargeback, but cannot rewrite the card scheme’s final rules.
| Issue | Core evidence | Common mistake |
|---|---|---|
| Unauthorized card use | Statement, possession and authentication facts | Calling an authorised purchase unauthorized |
| Goods not received | Order, expected date and merchant contact | Reporting before the agreed delivery point without context |
| Service misrepresented | Offer, contract, output and cancellation request | Supplying only a complaint narrative |
| Crypto on-ramp | Exchange receipt and onward TXID | Treating the genuine exchange as the fraudster automatically |
Source: Australian Financial Complaints Authority: chargebacks factsheetAccessed 28 July 2026
Make a formal internal dispute resolution complaint
Direct answer: If the fraud team’s decision is disputed, clearly make an IDR complaint; most financial complaints require a written response within 30 calendar days under ASIC’s enforceable complaint standards.
A fraud report asks the institution to contain and investigate transactions. An IDR complaint challenges the institution’s act, omission or decision. Use the word complaint, identify the disputed transactions, state the alleged error and give the outcome sought. Ask for acknowledgement and the date the complaint entered IDR. Without that step, a customer can spend weeks exchanging messages with frontline support while believing a formal clock is running.
Regulatory Guide 271 sets a maximum response period of 30 calendar days for most complaints. Shorter 21-day periods apply to specified hardship, default and enforcement matters. Exceptions can apply where a complaint is particularly complex or circumstances outside the firm’s control prevent a response, but the firm must explain the delay, expected timing and AFCA rights. The customer should not have to infer whether an unexplained investigation remains open.
Focus the complaint on the firm. Possible issues include incorrect authorization classification, failure to investigate under the Code, delay, inadequate recovery attempts, failure to consider warnings or unusual activity, refusal to pursue a chargeback, or an unsupported liability allocation. Attach the ReportCyber reference and scam evidence, but do not ask IDR to arrest the recipient. If more than one institution is involved, give each a complaint directed to its own conduct.
- Mark the communication as a complaint.
- State the date IDR received it and keep the acknowledgement.
- Identify the provider decision or conduct challenged.
- Request a reasoned written response and the remedy.
- Keep any delay notice and the AFCA information supplied.
Source: ASIC Regulatory Guide 271: internal dispute resolutionIssued 2021; accessed 28 July 2026
Source: Australian Financial Complaints Authority: the process we followAccessed 28 July 2026
AFCA eligibility, time limits and compensation limits
Direct answer: After giving the financial firm an opportunity to resolve the complaint, an eligible consumer can use AFCA’s free external process, generally within the earlier of six years from awareness of the loss or two years after the firm’s final IDR response.
AFCA can consider banking deposit and payment complaints against member financial firms. Its process may involve referral back to the firm, negotiation, conciliation, a preliminary assessment and, where necessary, a determination. If the consumer accepts a favourable determination, the financial firm must comply. If the consumer rejects it, court rights may remain. That structure does not mean every complaint reaches a determination or that AFCA substitutes for a criminal investigation.
For most complaints the time limit is the earlier of six years from when the customer knew or should reasonably have known of the loss, or two years from the final IDR response. AFCA can sometimes extend time in special circumstances, but a claimant should not rely on discretion. Preserve the final-response date and submit before the ordinary limit. High-value cases also require attention to court limitation periods, which are not paused merely because a consumer is collecting information informally.
From 1 January 2024 the general AFCA claim limit is $1,263,000, and the direct-financial-loss compensation cap for most claims is $631,500. Other limits apply to different claim types, and capped amounts are not entitlements. AFCA may also address limited non-financial loss, interest or costs under its rules. State the actual loss and causal link; do not demand the maximum because it appears on an information page.
| Element | Document | Purpose |
|---|---|---|
| IDR stage | Complaint and final response or delay record | Shows the firm had an opportunity to resolve it |
| Time limit | Discovery and final-response dates | Allows AFCA to assess jurisdiction |
| Firm conduct | Logs, warnings, investigation and recovery record | Keeps the complaint within AFCA’s role |
| Loss | Transaction schedule and credits received | Prevents double counting and supports causation |
Source: Australian Financial Complaints Authority: the process we followAccessed 28 July 2026
Source: Australian Financial Complaints Authority: rules and monetary limitsLimits effective 1 January 2024; accessed 28 July 2026
AFCA can now examine defined receiving-bank conduct
Direct answer: Since 12 March 2026, AFCA can investigate eligible scam complaints involving the bank that received the funds and unauthorized accounts, even where the complainant was not that bank’s customer.
The expanded jurisdiction addresses a long-standing practical gap. A victim normally complains to the sending bank, yet the receiving account may have been opened using false identity information, linked to known mule activity, or mishandled after a freeze. AFCA’s current framework allows defined complaints about the receipt, internal movement or onward transfer of the complainant’s funds and accounts or credit opened without consent. The customer should first complain to the receiving bank where the framework requires it, then bring the unresolved issue to AFCA.
This is not automatic joint liability. Identify what the receiving bank allegedly did wrong and how that caused loss. Relevant allegations might concern onboarding, warnings already held, delay after notice, release of restricted funds or an unauthorized account in the victim’s name. The sending-bank complaint should continue separately. AFCA can coordinate issues within its rules, but a claimant should not send the same undifferentiated accusation to every institution in the payment chain.
AFCA’s March 2026 announcement also provides useful context: it received 6,228 scam complaints in calendar 2025, with an average claimed loss of $30,333, and closed 6,516. These are complaint volumes and claimed amounts, not successful recovery statistics. The fall or rise of complaints can reflect prevention, reporting behaviour, jurisdiction and case processing. Use the figures to describe workload, never as the odds that a receiving-bank case will be upheld.
- 01Identify the receiving bank
Use the BSB, account details and payment confirmation rather than a name supplied later by a recovery agent.
- 02State the receiving-bank issue
Describe onboarding, known-risk, freeze or post-notice conduct alleged.
- 03Complain to that institution
Give it the opportunity required by the applicable AFCA process.
- 04Keep the sending-bank claim
Do not abandon the separate complaint about the institution that sent the funds.
Source: Australian Financial Complaints Authority: receiving-bank jurisdiction for scam complaintsJurisdiction effective 12 March 2026; page updated 13 March 2026
Source: Australian Financial Complaints Authority: the process we followAccessed 28 July 2026
The Scams Prevention Framework is not yet a current refund right
Direct answer: Although the framework legislation was enacted in 2025 and AFCA became the authorised external dispute body from 1 July 2026, AFCA says SPF complaints apply only to matters occurring on or after 31 March 2027.
This timing matters because search results often compress passage, commencement and consumer eligibility into one sentence. The Scams Prevention Framework Act was enacted in February 2025. Sector codes and obligations require staged implementation. AFCA’s official page says it was authorised as the external dispute resolution scheme for the framework from 1 July 2026, but it can only consider SPF complaints about matters occurring on or after 31 March 2027. A July 2026 loss must therefore be assessed under the law, codes, contracts and AFCA jurisdiction currently in force.
Do not cite a future obligation as if the bank breached it before commencement. It is legitimate to explain the direction of reform and to preserve evidence that may be relevant under existing duties. It is not legitimate to promise reimbursement because a headline says a framework has passed. Ask the institution which current rule it applied: ePayments Code, card rules, Banking Code, general law, licence obligations, its contract or another standard.
The same date discipline should govern future updates. Record the date of the scam event, each payment and each complaint. When a sector code commences, update the article with the code text and transition provisions, not a press-release paraphrase. Keep historical claims in the version of the law that governed them. This approach protects users from both stale advice and premature advice.
Source: Australian Financial Complaints Authority: Scams Prevention FrameworkAccessed 28 July 2026
Protect the evidence and avoid a second money-recovery scam
Direct answer: Do not pay an unsolicited person who claims police, ASIC, a lawyer or a blockchain team has recovered your money and needs an advance fee, tax, wallet transfer or remote access to release it.
Scamwatch says money-recovery scammers target people who have already lost funds. They may impersonate government, lawyers, law enforcement, charities or other victims. Some buy search ads or build polished websites. The contact often knows details of the first fraud and says money has been located, but asks for a fee, percentage, tax, security payment or access to the victim’s device. That knowledge may come from the original criminal or traded victim lists; it is not proof of an official recovery.
Verify every identity independently. Look up the agency or law firm through its regulator and call the published number. ASIC does not ask people to pay money to release assets. Police do not request cryptocurrency, seed phrases, gift cards or a transfer to a safe wallet. A genuine adviser can describe a scoped service under written terms, but cannot guarantee what a bank, AFCA, court, exchange or police agency will decide. Never disclose passwords, one-time codes, seed phrases or private keys as part of a ‘case assessment’.
Preserve the second approach as evidence. Save the full message, sender, domain, telephone number, wallet, invoice and payment instructions. Add it to ReportCyber and the bank complaint where relevant. Keep an outcome ledger that distinguishes requested recall, account restriction, recovered funds, provisional credit, reimbursement, AFCA determination and money actually received. A screenshot saying funds are frozen is not a payment. This editorial discipline makes the site useful without manufacturing success stories.
| Offer | Why it is unsafe | Independent action |
|---|---|---|
| ‘Pay tax before release’ | Government recovery is being tied to a private payment | Contact the named agency through its official site |
| ‘Move funds to a safe wallet’ | The new transfer creates another irreversible loss | Do not transfer; secure the existing wallet |
| ‘Give us remote access’ | The caller can control accounts and evidence | End the session and secure the device |
| ‘Guaranteed AFCA result’ | Only AFCA can decide its complaint | Verify the adviser and obtain written scope and fees |
Source: Scamwatch: money recovery scamsAccessed 28 July 2026
Source: Scamwatch: what to do if you have been scammedAccessed 28 July 2026
Source: Australian Signals Directorate: recover from scamsAccessed 28 July 2026
Concise answers
Frequently asked questions
Will an Australian bank refund an authorized scam transfer?
Not automatically. A payment you personally performed is generally not an unauthorized transaction under the ePayments Code merely because a scammer deceived you. Ask for immediate recovery action and examine the bank’s warnings, intervention and complaint handling. AFCA can review eligible disputes.
Should I report to Scamwatch or ReportCyber?
Use ReportCyber for the official police cybercrime report where money was lost. Scamwatch reporting supplies intelligence to the National Anti-Scam Centre but its portal states that it is not an official police report. Notify the financial provider separately and immediately.
How long can a bank investigate an unauthorized transaction?
Under the ePayments Code, a subscriber should complete the investigation within 21 days or give written notice that more time is needed, and should ordinarily finish within 45 days unless exceptional circumstances apply.
Can AFCA investigate the bank that received scam money?
Yes, for eligible matters from 12 March 2026 AFCA’s jurisdiction includes defined receiving-bank and unauthorized-account complaints even where the victim was not that bank’s customer. Liability still depends on the receiving bank’s conduct and causation.
Does the Scams Prevention Framework already guarantee reimbursement?
No. AFCA states that it can consider SPF complaints only for matters occurring on or after 31 March 2027. Losses before that date must use the law, codes, contracts and AFCA jurisdiction then in force.
Evidence register
Sources and relevant dates
We link to primary sources whenever available. Sources are grouped under the section they support; the displayed date may be a publication, effective or editorial-review date. A public outcome does not promise the same result in another case.
- Scamwatch: Targeting Scams Report 2025Published 30 March 2026
- ASIC ePayments Code, published versionEffective 2 June 2022
- Scamwatch: what to do if you have been scammedAccessed 28 July 2026
- Scamwatch: report a scamAccessed 28 July 2026
- Australian Signals Directorate: recover from scamsAccessed 28 July 2026
- Australian Financial Complaints Authority: unauthorized transactions factsheetAccessed 28 July 2026
- Australian Securities and Investments Commission: ePayments CodeCode effective 2 June 2022; accessed 28 July 2026
- ASIC: Federal Court penalty for HSBC scam-protection failuresPublished 18 June 2026; judgment update 7 July 2026
- Moneysmart: unauthorized and mistaken transactionsUpdated 18 June 2026
- Australian Financial Complaints Authority: receiving-bank jurisdiction for scam complaintsJurisdiction effective 12 March 2026; page updated 13 March 2026
- Australian Financial Complaints Authority: chargebacks factsheetAccessed 28 July 2026
- ASIC Regulatory Guide 271: internal dispute resolutionIssued 2021; accessed 28 July 2026
- Australian Financial Complaints Authority: the process we followAccessed 28 July 2026
- Australian Financial Complaints Authority: rules and monetary limitsLimits effective 1 January 2024; accessed 28 July 2026
- Australian Financial Complaints Authority: Scams Prevention FrameworkAccessed 28 July 2026
- Scamwatch: money recovery scamsAccessed 28 July 2026