Australia · Bank disputes · ReportCyber and AFCA · 26 min read

What to Do After a Scam in Australia — Bank, ReportCyber and AFCA

If you have lost money to a scam in Australia, contact the bank, card issuer or payment provider immediately, stop further transfers, secure every affected account and make the official ReportCyber report. Whether the institution must reimburse you depends heavily on what payment occurred and who authorised it. The ePayments Code gives important protections for unauthorized transactions at subscribing institutions, but its definition generally excludes a transaction the user performed or knowingly consented to, even where a scammer supplied the reason. Card chargeback, a bank-transfer recovery attempt, internal dispute resolution, AFCA review and the new receiving-bank jurisdiction are separate routes. The federal Scams Prevention Framework exists, but AFCA states that its SPF complaint jurisdiction applies only to matters occurring on or after 31 March 2027. This guide uses the rules available on 28 July 2026 and does not present a future regime as a current guarantee.

01Scamwatch and ReportCyber functions kept separate
02ePayments Code definitions applied before deadlines
03AFCA’s March 2026 receiving-bank change included
$2.18bnreported combined scam lossescalendar 2025, across five reporting datasets
21 daysinitial Code investigation pointoutcome or written notice that more time is needed
45 daysusual Code investigation limitsubject to exceptional circumstances
30 daysusual financial complaint responsecalendar days for most complaints
Sources for the introduction, figures and summary

The direct answer: use the route that matches the transaction

Direct answer: Notify the provider and ReportCyber immediately, then classify the loss as unauthorized, personally authorized, mistaken, card-based or crypto-based before asking for reimbursement or escalating a complaint.

There is no single Australian ‘scam refund’ procedure. An unauthorized online-banking transfer can fall under the ePayments Code if the institution and facility are covered. A customer who personally sends money to a false investment account has experienced a scam, but the payment may be authorized under the Code’s definition. A card purchase can support a chargeback under card-scheme rules. A true typing error in an account identifier can engage mistaken-internet-payment procedures, yet the Code expressly says those procedures were not intended for a transfer made to a recipient as the result of a scam. Starting with the wrong category can waste the short period when funds might still be contained.

Write down five facts for each payment: date and time, amount, product and rail, recipient, and who operated the device or gave consent. Add the representation that caused the payment and the exact moment the deception became clear. If a scammer used remote access, state what they could see and control. If you pressed confirm after being coached, say so. An accurate description allows the bank and AFCA to assess both the payment rules and whether the institution should have intervened.

The size of the problem does not establish liability in an individual file. The National Anti-Scam Centre’s combined 2025 report recorded $2.18 billion in reported losses from 481,523 reports across Scamwatch, ReportCyber, IDCARE, the Australian Financial Crimes Exchange and ASIC. Investment scams accounted for $837.7 million of reported loss. Those figures are evidence of scale, not a reimbursement rate and not a reason to skip the transaction-level analysis.

Australian scam-payment classifier
What happenedFirst financial routeCritical question
Someone transferred money without your approvalUnauthorized-transaction investigationIs the provider a Code subscriber and the facility covered?
You sent a bank transfer after a false storyUrgent recovery request and conduct complaintWhat warnings and intervention occurred?
You entered the wrong BSB or account numberMistaken internet payment processWas it a genuine identifier error rather than a scam?
You paid by credit or debit cardChargeback assessmentWhat reason and deadline apply under the card rules?
You sent cryptocurrencyExchange, wallet and ReportCyber routeCan a custodial provider identify or freeze the destination?

Source: Scamwatch: Targeting Scams Report 2025Published 30 March 2026

Source: ASIC ePayments Code, published versionEffective 2 June 2022

What to do immediately: bank, ReportCyber, security and evidence

Direct answer: Contact the financial provider first, ask it to stop transactions and alert the receiving side, then secure accounts, preserve evidence and complete the official ReportCyber report.

Scamwatch tells victims to contact the bank or card provider immediately, report the scam, ask it to stop transactions and stop sending more money. Use a telephone number or secure channel found independently. If the criminal is still on the line, end the call before contacting the bank. Ask for a case reference and confirmation of the affected payments. Where a transfer is pending or funds may remain with the recipient institution, request urgent recovery or freezing action. A completed payment can be hard to retrieve, but the provider cannot act on a loss it has not been told about.

Secure every linked service. Change banking and email credentials from a clean device, remove remote-access software, revoke unknown sessions, review payees and limits, and tell the institution if the scammer saw a one-time code or identification document. If identity information was exposed, IDCARE provides free support, and the official Scamwatch page lists its contact route. Do not send a full identity pack to a person who calls claiming to follow up the report.

Complete ReportCyber for the police report and preserve its reference. The Scamwatch reporting portal explicitly says a Scamwatch report is not an official police report and directs people who lost money to cybercrime to ReportCyber. Scamwatch reports still provide valuable intelligence to the National Anti-Scam Centre. Use both for their intended jobs rather than assuming one submission automatically reaches every bank, platform and police investigator.

  1. 01
    Stop the payments

    Call the provider through an independently verified channel and identify pending and completed transactions.

  2. 02
    Ask for interbank action

    Request a recall, recipient-bank alert or freeze attempt and obtain a case reference.

  3. 03
    Secure the accounts

    Change credentials, end sessions, remove remote access and protect email and mobile services.

  4. 04
    Preserve the evidence

    Export chats, receipts, statements, domains, advertisements and warnings.

  5. 05
    Report officially

    Use ReportCyber for the police report and Scamwatch for National Anti-Scam Centre intelligence.

Source: Scamwatch: what to do if you have been scammedAccessed 28 July 2026

Source: Scamwatch: report a scamAccessed 28 July 2026

Source: Australian Signals Directorate: recover from scamsAccessed 28 July 2026

Authorized and unauthorized payments lead to different tests

Direct answer: Under the ePayments Code, a transaction is not unauthorized merely because a scammer supplied a false reason if the user performed it or acted with knowledge and consent.

This distinction is factual before it is legal. In an account takeover, a criminal may log in and make a transfer the customer never saw or approved. In an impersonation scam, the customer may create the payee and press confirm because the caller claims to be from a bank or government body. Both are crimes, but the Code’s unauthorized-transaction allocation is designed for the first type. AFCA’s factsheet makes the same point: a transaction is not unauthorized simply because the customer thought they were paying someone else if they carried it out or authorized it.

Remote access can complicate the picture. Record who entered each field, who read or received a passcode, who pressed the final button, and whether the customer could see the transfer. Do not reduce the story to ‘the scammer was on my computer’. Transaction and internet-banking logs can show devices, sessions and authentication events. AFCA commonly seeks those logs when assessing whether a transaction was authorized and whether the consumer contributed to the loss.

An authorized classification does not end every complaint. A bank can still face questions about unusual-transaction monitoring, the quality of its warning, questions asked in a branch, its response after notice, or recovery efforts. The receiving bank can now fall within AFCA’s scam jurisdiction in defined circumstances. Present those issues separately. An argument about bank conduct is stronger when it does not depend on inaccurately relabelling a payment as unauthorized.

What the ePayments Code can protect

Direct answer: At a subscribing institution, the Code can allocate unauthorized-transaction loss away from the account holder where the cause lies with the provider, merchant or system, the device or passcode was forged or defective, notice had already been given, or the user did not contribute to the loss.

The ePayments Code is voluntary, so the first check is whether the institution subscribes and whether the account and electronic facility are covered. ASIC maintains the Code and subscriber information. It commonly covers consumer ATM, EFTPOS, card, internet and mobile banking and BPAY facilities. It is not a general compensation statute for every interaction with a financial service. Quote its provisions only after confirming that the provider and transaction sit within its scope.

Clause 10 describes circumstances where a holder is not liable for an unauthorized transaction, including fraud or negligence by the subscriber or relevant merchant, a forged, faulty, expired or cancelled device or passcode, certain duplicate debits, transactions after the loss or security breach was reported, and cases where it is clear the user did not contribute. Other clauses allocate loss where a passcode was disclosed or the holder acted with extreme carelessness. The use of the correct passcode is relevant evidence but should not replace the required factual analysis.

Ask the provider to identify the Code clause and facts supporting its allocation. If it says the transaction was authorized, request the logs and explain the disputed consent. If it accepts that the transaction was unauthorized but says the holder contributed, ask which conduct, time period and loss calculation it relies on. A Code complaint should be anchored to those findings rather than a broad statement that banks always refund fraud.

  • Confirm the institution appears on the current subscriber list.
  • Confirm the consumer account and electronic facility are covered.
  • Identify whether the provider accepts or disputes lack of authorisation.
  • Request the specific liability clause and transaction logs.
  • Separate passcode facts from the broader contribution and causation test.

The Code’s 21-day and 45-day investigation points

Direct answer: For a reported unauthorized transaction, the subscriber should complete the investigation and give the outcome within 21 days or explain in writing why more time is needed, and should ordinarily finish within 45 days absent exceptional circumstances.

The Code requires an effective and convenient reporting process. The subscriber should acknowledge a report with a reference or other verifiable record of the date. That date matters because it shows when the provider could act and starts the investigation record. Within 21 days it should either complete the investigation and communicate the result or tell the customer that more time is required. The written notice should explain the delay and status rather than simply leaving the disputed transactions under review.

The ordinary outside period is 45 days, with exceptions for circumstances such as waiting for information that is reasonably required. Keep every information request and response. If the provider asks for a police reference, device detail or declaration, respond promptly or explain what is unavailable. A firm should not refuse to investigate an unauthorized transaction merely because a card-scheme chargeback period has expired; the Code itself notes that the investigation duty and chargeback machinery are not the same thing.

Regulatory enforcement shows why these distinctions matter. On 18 June 2026 ASIC announced a Federal Court penalty of $35 million against HSBC for systemic scam-protection failures involving unauthorized transactions. ASIC reported an average investigation time of 144 days and failures in applying Code liability. The release also recorded remediation paid and funds recovered or returned. That is an institution-specific enforcement result, not an automatic entitlement in another case, but it confirms that Code investigation and allocation duties are substantive, not optional customer service targets.

Unauthorized-transaction investigation record
PointWhat to expectWhat to retain
ReportAccessible channel and verifiable acknowledgementReference and report date
21 daysOutcome or written notice that more time is neededDecision or delay explanation
During extensionReasonable information requests and statusRequests, replies and missing items
45 daysOrdinary completion point absent exceptionFinal reasons and Code clauses

Source: ASIC ePayments Code, published versionEffective 2 June 2022

Source: ASIC: Federal Court penalty for HSBC scam-protection failuresPublished 18 June 2026; judgment update 7 July 2026

A mistaken internet payment is not a payment induced by a scam

Direct answer: The Code’s mistaken-internet-payment process is for a transfer sent to the wrong account because the payer entered an incorrect identifier; the Code expressly says it was not intended for a transfer sent to a recipient as the result of a scam.

This is one of the most important corrections to generic online advice. The mistaken-payment provisions use specific timing bands, including reports made within ten business days, between ten business days and seven months, and after seven months. Those bands determine the process between sending and receiving institutions where the wrong account identifier was entered. They are not a shortcut for a person who intentionally entered the account details supplied by a fake seller or investment adviser.

If the case is a true typing mistake, notify the institution immediately and provide the intended and actual identifiers. Moneysmart explains the timing categories and advises obtaining a reference. If the case is a scam, still notify the institution immediately, but describe it as a scam-induced payment and request fraud recovery action. Do not force the facts into the mistaken-payment definition simply because its early-report process looks favourable.

Some complaints contain both. A customer may first send an intentional scam payment and later mistype a different account number while trying to move remaining funds. List each transaction and its cause separately. The bank can then apply the mistaken-payment process to the genuine error and the scam or unauthorized route to the other loss. A single emotional narrative should not obscure distinct transaction facts.

Authorized bank-transfer scams: recovery and bank-conduct questions

Direct answer: For an authorized transfer, ask the sending bank to alert the receiving bank and attempt recovery immediately, then examine warnings, unusual-transaction intervention and post-report handling rather than assuming Code reimbursement.

A completed bank transfer is not reversed by the customer pressing an undo button. The sending institution can send a recovery request, and the receiving institution may restrict funds that remain, but the outcome depends on timing, account status and lawful authority. Give the bank the recipient name, BSB, account number, amount, transfer reference and the reason you know it was a scam. Ask what recovery action was taken and when. A vague note that ‘the payment could not be recalled’ does not answer whether the receiving side was notified promptly.

Next examine the sending bank’s conduct. Was the amount or recipient unusual for the account? Did the bank display a tailored warning? Did staff ask why the money was being sent? Did the criminal coach the customer to conceal the true reason? Was a cooling-off delay or confirmation-of-payee feature available? The existence of a red flag does not itself prove legal liability, and the absence of intervention does not guarantee compensation. It identifies the evidence needed for internal dispute resolution and AFCA.

Keep later movements distinct. In an investment scam, the customer may transfer money to a genuine exchange account in their own name and then send cryptocurrency to a fraudster. In another case, the first bank transfer may go directly to a mule account. The receiving-bank jurisdiction and causation analysis can differ. A payment-chain diagram should name who controlled every account and the precise point at which value left the customer’s control.

  1. 01
    Request recovery

    Ask the sending bank to notify the receiving bank and record the time of action.

  2. 02
    Map every leg

    Identify account ownership, BSB, account number, exchange and wallet transactions.

  3. 03
    Collect intervention evidence

    Retain warnings, branch conversations, limit changes and call records.

  4. 04
    Obtain written reasons

    Ask what the bank recovered and why it accepts or rejects compensation.

Chargeback is conditional and has no universal Australian deadline

Direct answer: Ask the card issuer promptly to assess a chargeback using the correct card-scheme reason and evidence; availability and deadlines depend on the scheme, transaction and cardholder agreement.

AFCA says a consumer should first try to resolve an appropriate dispute with the merchant and then give the bank the disputed transactions, reason and evidence. A chargeback may be relevant where goods or services were not supplied, were materially different from what was promised, or a card transaction was unauthorized. The issuer submits the request through the card scheme; the merchant’s bank can accept or contest it. Chargeback is not a guaranteed statutory refund and is not available for every scam narrative.

Time limits vary by reason and network. Report as soon as possible and ask the issuer for the exact deadline. Avoid publishing ‘120 days’ as a universal Australian rule. Some clocks can be linked to expected delivery, discovery or transaction dates, and an issuer may have an earlier notification requirement in the card agreement. AFCA’s factsheet says the card-scheme process can take up to eight weeks to reach a final decision.

A crypto or investment loss needs a leg-by-leg review. If a legitimate exchange supplied the cryptocurrency purchased with the card, the later transfer to a scam wallet may not establish that the exchange failed to provide its service. If the statement merchant was the fake platform and no genuine service existed, a different reason may apply. Give the issuer accurate merchant descriptors, receipts and onward transactions. AFCA can review whether the bank made reasonable efforts to submit and follow up a chargeback, but cannot rewrite the card scheme’s final rules.

Chargeback evidence by issue
IssueCore evidenceCommon mistake
Unauthorized card useStatement, possession and authentication factsCalling an authorised purchase unauthorized
Goods not receivedOrder, expected date and merchant contactReporting before the agreed delivery point without context
Service misrepresentedOffer, contract, output and cancellation requestSupplying only a complaint narrative
Crypto on-rampExchange receipt and onward TXIDTreating the genuine exchange as the fraudster automatically

Make a formal internal dispute resolution complaint

Direct answer: If the fraud team’s decision is disputed, clearly make an IDR complaint; most financial complaints require a written response within 30 calendar days under ASIC’s enforceable complaint standards.

A fraud report asks the institution to contain and investigate transactions. An IDR complaint challenges the institution’s act, omission or decision. Use the word complaint, identify the disputed transactions, state the alleged error and give the outcome sought. Ask for acknowledgement and the date the complaint entered IDR. Without that step, a customer can spend weeks exchanging messages with frontline support while believing a formal clock is running.

Regulatory Guide 271 sets a maximum response period of 30 calendar days for most complaints. Shorter 21-day periods apply to specified hardship, default and enforcement matters. Exceptions can apply where a complaint is particularly complex or circumstances outside the firm’s control prevent a response, but the firm must explain the delay, expected timing and AFCA rights. The customer should not have to infer whether an unexplained investigation remains open.

Focus the complaint on the firm. Possible issues include incorrect authorization classification, failure to investigate under the Code, delay, inadequate recovery attempts, failure to consider warnings or unusual activity, refusal to pursue a chargeback, or an unsupported liability allocation. Attach the ReportCyber reference and scam evidence, but do not ask IDR to arrest the recipient. If more than one institution is involved, give each a complaint directed to its own conduct.

  • Mark the communication as a complaint.
  • State the date IDR received it and keep the acknowledgement.
  • Identify the provider decision or conduct challenged.
  • Request a reasoned written response and the remedy.
  • Keep any delay notice and the AFCA information supplied.

AFCA eligibility, time limits and compensation limits

Direct answer: After giving the financial firm an opportunity to resolve the complaint, an eligible consumer can use AFCA’s free external process, generally within the earlier of six years from awareness of the loss or two years after the firm’s final IDR response.

AFCA can consider banking deposit and payment complaints against member financial firms. Its process may involve referral back to the firm, negotiation, conciliation, a preliminary assessment and, where necessary, a determination. If the consumer accepts a favourable determination, the financial firm must comply. If the consumer rejects it, court rights may remain. That structure does not mean every complaint reaches a determination or that AFCA substitutes for a criminal investigation.

For most complaints the time limit is the earlier of six years from when the customer knew or should reasonably have known of the loss, or two years from the final IDR response. AFCA can sometimes extend time in special circumstances, but a claimant should not rely on discretion. Preserve the final-response date and submit before the ordinary limit. High-value cases also require attention to court limitation periods, which are not paused merely because a consumer is collecting information informally.

From 1 January 2024 the general AFCA claim limit is $1,263,000, and the direct-financial-loss compensation cap for most claims is $631,500. Other limits apply to different claim types, and capped amounts are not entitlements. AFCA may also address limited non-financial loss, interest or costs under its rules. State the actual loss and causal link; do not demand the maximum because it appears on an information page.

Preparing an AFCA referral
ElementDocumentPurpose
IDR stageComplaint and final response or delay recordShows the firm had an opportunity to resolve it
Time limitDiscovery and final-response datesAllows AFCA to assess jurisdiction
Firm conductLogs, warnings, investigation and recovery recordKeeps the complaint within AFCA’s role
LossTransaction schedule and credits receivedPrevents double counting and supports causation

Source: Australian Financial Complaints Authority: the process we followAccessed 28 July 2026

Source: Australian Financial Complaints Authority: rules and monetary limitsLimits effective 1 January 2024; accessed 28 July 2026

AFCA can now examine defined receiving-bank conduct

Direct answer: Since 12 March 2026, AFCA can investigate eligible scam complaints involving the bank that received the funds and unauthorized accounts, even where the complainant was not that bank’s customer.

The expanded jurisdiction addresses a long-standing practical gap. A victim normally complains to the sending bank, yet the receiving account may have been opened using false identity information, linked to known mule activity, or mishandled after a freeze. AFCA’s current framework allows defined complaints about the receipt, internal movement or onward transfer of the complainant’s funds and accounts or credit opened without consent. The customer should first complain to the receiving bank where the framework requires it, then bring the unresolved issue to AFCA.

This is not automatic joint liability. Identify what the receiving bank allegedly did wrong and how that caused loss. Relevant allegations might concern onboarding, warnings already held, delay after notice, release of restricted funds or an unauthorized account in the victim’s name. The sending-bank complaint should continue separately. AFCA can coordinate issues within its rules, but a claimant should not send the same undifferentiated accusation to every institution in the payment chain.

AFCA’s March 2026 announcement also provides useful context: it received 6,228 scam complaints in calendar 2025, with an average claimed loss of $30,333, and closed 6,516. These are complaint volumes and claimed amounts, not successful recovery statistics. The fall or rise of complaints can reflect prevention, reporting behaviour, jurisdiction and case processing. Use the figures to describe workload, never as the odds that a receiving-bank case will be upheld.

  1. 01
    Identify the receiving bank

    Use the BSB, account details and payment confirmation rather than a name supplied later by a recovery agent.

  2. 02
    State the receiving-bank issue

    Describe onboarding, known-risk, freeze or post-notice conduct alleged.

  3. 03
    Complain to that institution

    Give it the opportunity required by the applicable AFCA process.

  4. 04
    Keep the sending-bank claim

    Do not abandon the separate complaint about the institution that sent the funds.

The Scams Prevention Framework is not yet a current refund right

Direct answer: Although the framework legislation was enacted in 2025 and AFCA became the authorised external dispute body from 1 July 2026, AFCA says SPF complaints apply only to matters occurring on or after 31 March 2027.

This timing matters because search results often compress passage, commencement and consumer eligibility into one sentence. The Scams Prevention Framework Act was enacted in February 2025. Sector codes and obligations require staged implementation. AFCA’s official page says it was authorised as the external dispute resolution scheme for the framework from 1 July 2026, but it can only consider SPF complaints about matters occurring on or after 31 March 2027. A July 2026 loss must therefore be assessed under the law, codes, contracts and AFCA jurisdiction currently in force.

Do not cite a future obligation as if the bank breached it before commencement. It is legitimate to explain the direction of reform and to preserve evidence that may be relevant under existing duties. It is not legitimate to promise reimbursement because a headline says a framework has passed. Ask the institution which current rule it applied: ePayments Code, card rules, Banking Code, general law, licence obligations, its contract or another standard.

The same date discipline should govern future updates. Record the date of the scam event, each payment and each complaint. When a sector code commences, update the article with the code text and transition provisions, not a press-release paraphrase. Keep historical claims in the version of the law that governed them. This approach protects users from both stale advice and premature advice.

Protect the evidence and avoid a second money-recovery scam

Direct answer: Do not pay an unsolicited person who claims police, ASIC, a lawyer or a blockchain team has recovered your money and needs an advance fee, tax, wallet transfer or remote access to release it.

Scamwatch says money-recovery scammers target people who have already lost funds. They may impersonate government, lawyers, law enforcement, charities or other victims. Some buy search ads or build polished websites. The contact often knows details of the first fraud and says money has been located, but asks for a fee, percentage, tax, security payment or access to the victim’s device. That knowledge may come from the original criminal or traded victim lists; it is not proof of an official recovery.

Verify every identity independently. Look up the agency or law firm through its regulator and call the published number. ASIC does not ask people to pay money to release assets. Police do not request cryptocurrency, seed phrases, gift cards or a transfer to a safe wallet. A genuine adviser can describe a scoped service under written terms, but cannot guarantee what a bank, AFCA, court, exchange or police agency will decide. Never disclose passwords, one-time codes, seed phrases or private keys as part of a ‘case assessment’.

Preserve the second approach as evidence. Save the full message, sender, domain, telephone number, wallet, invoice and payment instructions. Add it to ReportCyber and the bank complaint where relevant. Keep an outcome ledger that distinguishes requested recall, account restriction, recovered funds, provisional credit, reimbursement, AFCA determination and money actually received. A screenshot saying funds are frozen is not a payment. This editorial discipline makes the site useful without manufacturing success stories.

Recovery-offer red flags
OfferWhy it is unsafeIndependent action
‘Pay tax before release’Government recovery is being tied to a private paymentContact the named agency through its official site
‘Move funds to a safe wallet’The new transfer creates another irreversible lossDo not transfer; secure the existing wallet
‘Give us remote access’The caller can control accounts and evidenceEnd the session and secure the device
‘Guaranteed AFCA result’Only AFCA can decide its complaintVerify the adviser and obtain written scope and fees

Source: Scamwatch: money recovery scamsAccessed 28 July 2026

Source: Scamwatch: what to do if you have been scammedAccessed 28 July 2026

Source: Australian Signals Directorate: recover from scamsAccessed 28 July 2026

Concise answers

Frequently asked questions

Will an Australian bank refund an authorized scam transfer?

Not automatically. A payment you personally performed is generally not an unauthorized transaction under the ePayments Code merely because a scammer deceived you. Ask for immediate recovery action and examine the bank’s warnings, intervention and complaint handling. AFCA can review eligible disputes.

Should I report to Scamwatch or ReportCyber?

Use ReportCyber for the official police cybercrime report where money was lost. Scamwatch reporting supplies intelligence to the National Anti-Scam Centre but its portal states that it is not an official police report. Notify the financial provider separately and immediately.

How long can a bank investigate an unauthorized transaction?

Under the ePayments Code, a subscriber should complete the investigation within 21 days or give written notice that more time is needed, and should ordinarily finish within 45 days unless exceptional circumstances apply.

Can AFCA investigate the bank that received scam money?

Yes, for eligible matters from 12 March 2026 AFCA’s jurisdiction includes defined receiving-bank and unauthorized-account complaints even where the victim was not that bank’s customer. Liability still depends on the receiving bank’s conduct and causation.

Does the Scams Prevention Framework already guarantee reimbursement?

No. AFCA states that it can consider SPF complaints only for matters occurring on or after 31 March 2027. Losses before that date must use the law, codes, contracts and AFCA jurisdiction then in force.

Evidence register

Sources and relevant dates

We link to primary sources whenever available. Sources are grouped under the section they support; the displayed date may be a publication, effective or editorial-review date. A public outcome does not promise the same result in another case.

  1. Scamwatch: Targeting Scams Report 2025Published 30 March 2026
  2. ASIC ePayments Code, published versionEffective 2 June 2022
  3. Scamwatch: what to do if you have been scammedAccessed 28 July 2026
  4. Scamwatch: report a scamAccessed 28 July 2026
  5. Australian Signals Directorate: recover from scamsAccessed 28 July 2026
  6. Australian Financial Complaints Authority: unauthorized transactions factsheetAccessed 28 July 2026
  7. Australian Securities and Investments Commission: ePayments CodeCode effective 2 June 2022; accessed 28 July 2026
  8. ASIC: Federal Court penalty for HSBC scam-protection failuresPublished 18 June 2026; judgment update 7 July 2026
  9. Moneysmart: unauthorized and mistaken transactionsUpdated 18 June 2026
  10. Australian Financial Complaints Authority: receiving-bank jurisdiction for scam complaintsJurisdiction effective 12 March 2026; page updated 13 March 2026
  11. Australian Financial Complaints Authority: chargebacks factsheetAccessed 28 July 2026
  12. ASIC Regulatory Guide 271: internal dispute resolutionIssued 2021; accessed 28 July 2026
  13. Australian Financial Complaints Authority: the process we followAccessed 28 July 2026
  14. Australian Financial Complaints Authority: rules and monetary limitsLimits effective 1 January 2024; accessed 28 July 2026
  15. Australian Financial Complaints Authority: Scams Prevention FrameworkAccessed 28 July 2026
  16. Scamwatch: money recovery scamsAccessed 28 July 2026

Continue the review

Guides for adjacent questions

A final step without pressure

Check which actions may still be available

ScamCompass is an information hub, not a law firm. With your separate consent, an enquiry may be shared with an independent legal or recovery partner. Recovery is never guaranteed.

We never request an unlocking fee, seed phrase, password or remote access.

How ScamCompass earns revenue: with the separate optional consent below, we may receive payment from an independent legal or recovery partner for a qualified referral. This does not guarantee that a partner will accept the matter or that funds will be recovered. About our model.

Never include passwords, seed phrases, one-time codes or full card details.