Insight,

Countdown to the SPF: Recent developments in the scams regulatory landscape

AU | EN
Current site :    AU   |   EN
Australia
Singapore

The Australian regulatory landscape relating to scams is evolving rapidly. Just as scammers regularly change their tactics to target gaps in systems and other vulnerabilities, regulated participants in the scams ecosystem must remain vigilant to manage risk, meet legal obligations, and address regulatory expectations.

Most obligations under the landmark Scams Prevention Framework (SPF) legislation will commence on 31 March 2027. This will introduce an ecosystem-wide approach to combating scams and preparations are being made by banks, telecommunications businesses and digital platforms (which are the first sectors to be designated).

With just over 7 months to go, a significant amount of preparatory work is required. In addition, cases involving banks and telecommunications providers show that the SPF is only part of the story when it comes to the regulatory obligations relevant to scams. For example, general conduct obligations of holders of Australian financial services licences and Australian credit licences can provide an existing avenue for regulatory scrutiny and potentially significant exposure. The National Anti-Scam Centre is also continuing to publish valuable information on common scam typologies and statistics, including insights from their taskforces targeting specific types of scams.

In this alert, we provide updates on the following:

  • key SPF developments in the lead-up to launch
  • changes to AFCA’s mandate
  • recent scams-related cases and AFCA determinations
  • National Anti-Scam Centre reports
  • other key developments

Key SPF developments 

1. Draft SPF rules and sector codes released

During June 2026, Treasury consulted on draft SPF codes and rules. Common code obligations are proposed for all regulated sectors as well as sector-specific codes. Key common code obligations proposed include requirements to:

  1. have reasonable systems and processes to prevent brand, brand assets or likeness from being used to facilitate scams;
  2. make consumers aware of common types of scams relating to the entity’s regulated services and mechanisms that may assist consumers to protect themselves from scams;
  3. provide specific training to staff in relation to identifying and supporting consumers that that may be impacted by scams;
  4. notifying consumers who may have been impacted by a scam; and
  5. taking action to disrupt scams, as well as reversing disruptive actions as soon as practicable after determining that an activity is not a scam.

Civil penalties apply to breaches of these obligations. Each code also includes certain sector-specific content.

The consultation also set out proposals relating to apportionment of liability where a scam involves multiple regulated participants, as well as an automatic reimbursement regime for verified scam losses under $3,000.

Final instruments are expected in the second half of 2026 and most obligations will commence on 31 March 2027.

Key takeaway: Entities that are captured by the SPF should consider developing processes, systems and controls to address the draft codes and rules, while seeking to maintain flexibility to respond to changes in the final instruments.

2. SPF regulated entities must be AFCA members from 1 September 2026

AFCA will have responsibility for the external dispute resolution (EDR) scheme for scam-related complaints under the SPF.

Since 1 July 2026, entities regulated under the SPF have been able to apply for AFCA membership, with AFCA encouraging applications by 14 August to ensure sufficient processing times. These entities must be AFCA members from 1 September 2026 to meet their obligations under the SPF.

While the government has provided $14.2 million in funding to AFCA in connection with the SPF, regulated entities expect to be required to pay additional levies imposed by AFCA to assist with establishing its framework to deal with complaints made under the SPF.

Key takeaway: If your organisation falls within the scope of the SPF, check that you are already an AFCA member and if not, apply as soon as possible. Further information is available here: https://www.afca.org.au/members

Beyond SPF: AFCA’s mandate has already expanded

3. AFCA’s expanded jurisdiction

On 12 March 2026, AFCA’s jurisdiction was updated in two important ways:

  • Unauthorised account opening. AFCA’s jurisdiction was expanded to allow AFCA to investigate and address complaints made by a consumer or small business against a financial institution that has allegedly facilitated the opening of an account in that person’s name by a scammer. Importantly, the complainant does not need to have a contractual relationship with the financial institution to file their complaint.
  • Receiving banks. AFCA’s jurisdiction was also expanded to allow it to investigate all banks involved in the flow of scam funds, not just the scam victim’s bank. AFCA can investigate complaints made by a consumer or small business against a financial institution that has allegedly provided services to a scammer and received funds from the complainant.

Key takeaway: While Australian courts have been generally reluctant to impose duties of care on banks in relation to non-customers, AFCA members should keep in mind that providing services to wrongdoers may lead to exposure outside their customer base.

Before SPF: Scams-related cases and AFCA determinations

4. Regulators are actively taking enforcement action in relation to scams

On 18 June 2026, the Federal Court of Australia ordered HSBC to pay a $35 million penalty for breaching its obligation to take all steps necessary to ensure financial services were provided efficiently, honestly and fairly on the following basis:

  1. Application of fraud controls. ASIC alleged that HSBC had inadequate prevention and detection controls to manage the risk that unauthorised payments could be made on customer accounts by using internal payment rails. This included failing to consistently implement biometric and device-based identification measures to detect fraud across all instruction channels. 
  2. ePayments Code. ASIC alleged HSBC did not comply with requirements in the ePayments Code relating to timeframes for investigating and responding to unauthorised transactions.
  3. Reinstating access to services. ASIC alleged that HSBC failed to ensure that customers were appropriately advised of the process to reinstate full use of their accounts within a reasonable time following a report of an unauthorised transaction.

Outside the banking sector, in May 2026 the Australian Communications and Media Authority (ACMA) imposed a penalty of $59,400 on SpinTel Pty Ltd (SpinTel) following an investigation that found scammers used a vulnerability in its systems to access one-time verification codes used in multi-factor identification processes. SpinTel also entered into an 18-month enforceable undertaking to review and improve is security arrangements. ACMA also issued a formal warning to Yomojo Pty Ltd for failing to comply with a requirement under the Telecommunications (Mobile Number Pre-Porting Additional Identity Verification) Industry Standard 2020 to publish information advising consumers whose mobile number has been ‘ported’ to another provider about what steps to take if they suspect their number has been fraudulently transferred.

Key takeaway: While preparing for the SPF is an important area of focus, general conduct obligations under section 912A of the Corporations Act 2001 (Cth) / section 47(1)(a) of the National Consumer Credit Protection Act 2009 (Cth)) and industry codes should always be considered. In particular, banks and payment service providers should ensure that fraud controls are applied consistently (especially where multiple instruction channels can be used to access services) and gaps are identified and addressed in a timely manner.

5. A duty to inquire about unusual payment instructions?

On 24 April 2026, AFCA ordered Bendigo and Adelaide Bank to refund $475,000 to SMSF trustee customers who were scammed into making payments for an investment to a bank account that they believed was held with a second bank (Bank B) but was in fact held by the scammer with a third bank (Bank C).

The customers were sent an email by the scammer with a payment instruction. The customer forwarded that instruction to Bendigo and Adelaide Bank ahead of attending the branch in person to effect the payment. The document forwarded to Bendigo and Adelaide Bank included the logo of Bank B (suggesting that the customer intended to pay Bank B). However, the BSB and account number specified in the instruction were for a destination account belonging to the scammer and held with Bank C. This was not apparent on the face of the instruction, but a check of the BSB numbers would have shown the discrepancy between Bank B and Bank C. While Bendigo and Adelaide Bank did not actually identify this discrepancy, the AFCA member considered the discrepancy was sufficient to put the bank on inquiry, and Bendigo and Adelaide Bank should not have processed the transaction until any ambiguity was resolved.

Key takeaway: Financial institutions should continue to monitor AFCA’s approach to investigating and handling scam complaints and, where appropriate and practicable, respond by amending training and other processes to assist in identifying scams and limit potential complaints exposures.

National Anti-Scam Centre reports provide valuable insights

6. National Anti-Scam Centre (NASC) Report shows scams continue to result in significant losses

The NASC's report on Targeting Scams, released in March 2026, reports that Australians lost $2.18 billion to scams in 2025, an increase of 7.8% from 2024. Key statistics include the following:

  1. The top five scam types by loss were investment scams ($837.7m), payment redirection scams ($166.8m), romance scams ($139.9m), phishing scams ($97.6m) and remote access scams ($69.9m). Other types of scams accounted for $872.1 million in losses.
  2. Reports of scams involving text messages fell sharply from 77,365 in 2024 to 29,058 in 2025, but overall financial loss for texting scams was higher than in 2024. Online-based scam losses increased by more than 21%. 
  3. The median loss for each reported scam fell from $500 in 2024 to $400 in 2025. 

Key takeaway: Statistics released by the NASC regarding scams can be valuable to assist businesses in determining what types of scams pose the higher risks in relation to their services and channels (and allocating resources accordingly).

7. Scam typologies – “fusion cells” to help target specific scams

The NASC operates “fusion cells”, which are time-limited public-private taskforces that focus on identifying actions to target specific scam problems. There have been three fusion cells so far, each focussing on one of the following types of scams:

  1. Investment scams. In May 2024, the NASC published the Investment Scam Fusion Cell Final Report. This fusion cell targeted imposter bond and term deposit scams and AI trading platform scams. Key outputs include the creation of a direct referral process for the takedown of scam advertisements, resulting in more than 1000 instances being removed by digital platforms, takedown of 220 investment scam website and diversion of 113 attempted calls to confirmed scam phone numbers to a recorded warning.
  2. Jobs scams. The NASC’s Job Scam Fusion Cell Final Report was published in May 2025. This fusion cell aimed to identify job scam campaigns and their enabling technologies, block these enables and identify barriers to prevention and disruption. Key outputs include referral of 836 scammer cryptocurrency wallets to digital currency exchanges for analysis and investigation, intelligence sharing leading to Meta’s removal of approximately 29,000 accounts engaged in job scams and 1,850 scam enablers such as scam advertisements referred for removal.
  3. Romance scams. In March 2026, the NASC published the Romance Scam Fusion Cell Final Report. This fusion cell considered the two most common romance scams methodologies: romance baiting scams, which typically involve fake cryptocurrency investments, and long-term romance scams in which scammers groom victims over a long period of time and steal money by fabricating crises. Key achievements include the establishment of new frameworks between banks and digital currency exchanges for sharing suspected scam transactions, stopping the theft of funds before it occurs.

Key takeaway: As we have seen in the AML/CTF arena, typologies are highly valuable fact patterns. Leveraging them as part of operational controls (including transaction monitoring parameters) can significantly aid compliance; ignoring them can prove disastrous and fuel future claims.

Other key developments

8. Scam mitigation measures for superannuation trustees

While superannuation is not one of the sectors that has been initially designated under the SPF and the number of complaints to AFCA about scams in relation to superannuation is comparatively low, the approach taken by superannuation trustees to combat scams remains under significant regulatory scrutiny. The Treasurer has indicated that superannuation may become subject to the SPF in future.

We understand that some superannuation funds are seeing sophisticated targeting of members who have reached presentation age. As this cohort increases in line with the changes to Australian demographics and because preservation no longer prevents immediate access to those members superannuation, ASIC expects that they will be an attractive target for scammers.

In the meantime:

  1. In February 2026, ASIC urged immediate action from superannuation trustees to strengthen anti-scam and fraud practices after its latest review exposed significant gaps.
  2. On 1 July 2026, the Financial Services Council (FSC) Standard No. 29 Fraud & Scam Mitigation Measures for Superannuation Funds became fully effective. It requires FSC members that are superannuation trustees to have internal fraud and scam policies that comply with the standard, implement enhanced controls for high-risk transactions, have defined incident response protocols and make annual attestations relating to compliance with the standard. 
  3. In 2025, The Association of Superannuation Funds of Australia issued and Scams and Fraud Toolkit, a Scams Prevention Policy Template and Minimum Fraud Controls for Superannuation Funds and Cyber Security Toolkit.

Key takeaway: While non-compliance with industry guidance may not directly result in regulatory penalties, it is possible that regulators may take enforcement action against superannuation trustees for non-compliance with their other duties (for example, under the Superannuation Industry (Supervision) Act 1993 (Cth) and general conduct obligations as AFS licensees). Co-operation and compliance with industry standards is likely to be taken into account in determining the likelihood, and type, of any enforcement action.

9. ACMA SMS Sender ID Register went live on 1 July 2026

From 1 July 2026, ACMA’s SMS Sender ID Register requires all organisations using branded sender IDs to register those identifiers with their telecommunication or electronic message service provider. SMS messages sent with an unregistered sender ID are now labelled as "Unverified" and grouped in a single message thread, signaling to consumers that the message may not be legitimate. Rules were made in October 2025, with businesses required to register between November 2025 and June 2026 ahead of the go-live date.

Key takeaway: Businesses with branded sender IDs should ensure they have registered with their telecommunications register or electronic message service provider. Businesses addressing complaints from customers relating to scams involving text messages should consider the impact of this change and whether consumer-facing education materials should be updated.

Latest Thinking
Publication
The inaugural edition of Formwork brings together our observations across real estate disputes and shares practical insights into the legal issues affecting the sector.

25 August 2026

Insight
On 19 August 2026, the Assistant Treasurer proposed a package of reforms under the Protecting Consumers in the Superannuation System (PCSS) banner, together with the Government’s response to the February 2026 managed investment scheme (MIS) consultation.

21 August 2026

Insight
The review period proved to be a defining year for securities class actions in Australia.

20 August 2026