By Joshua Clouston, Head of Product, ezyshield
AUSTRAC Tranche 2 Is Live: You Can Verify Clients, Not the Bank Account
AUSTRAC Tranche 2 is live. 90,000 firms must now do KYC - but a WA court ruling shows the real liability is still the bank account. Here's what's missing.
Picture this: a Sydney conveyancer wraps up settlement on a $1.1 million property. They’ve enrolled with AUSTRAC. They verified the vendor’s identity. Their AML program is current. All the right boxes are ticked.
Then a criminal who has been monitoring the vendor’s email account for three weeks sends an updated bank details form. Settlement proceeds land in a mule account in Melbourne. The money is gone inside 90 minutes.
The conveyancer did everything AUSTRAC asked. They still lost their client’s money.
This is the gap that Australia’s most significant compliance overhaul in a decade has not closed - and as of 1 July 2026, nearly 90,000 professional services businesses just came under new rules without realising what those rules don’t cover.
What AUSTRAC Tranche 2 Actually Requires
From 1 July 2026, AUSTRAC’s anti-money laundering and counter-terrorism financing (AML/CTF) framework expanded to capture businesses that were previously unregulated. Lawyers, accountants, conveyancers, real estate agents, trust and company service providers, and precious metals dealers are now subject to the same core obligations that banks have operated under since 2006.
The enrolment deadline was 29 July 2026 - two days ago. Those obligations are real and substantive:
- Enrol with AUSTRAC before commencing designated services
- Customer due diligence (CDD): verify who your client is before providing a designated service
- Sanctions and politically exposed person (PEP) screening
- Suspicious matter reporting (SMR): lodge within three business days, no minimum dollar threshold
- Threshold transaction reporting (TTR): cash transactions of $10,000 or more
- Seven-year record retention
The maximum civil penalty for a corporate breach is $33 million. For an individual practitioner, $6.6 million.
And rightly so. Professional services - particularly conveyancers and lawyers - have long been identified as high-risk conduits for money laundering. Property is the classic vehicle: buy with dirty money, sell legitimately, receive clean proceeds. Tranche 2 closes that channel.
But it doesn’t close the one that costs ordinary Australians the most money.
The Compliance Gap Nobody Is Talking About
Tranche 2 requires you to verify the person you are dealing with. It says nothing about verifying the bank account you are paying into.
This distinction sounds technical. In practice, it is the difference between doing the thing regulators check and doing the thing that actually stops fraud.
Payment redirection fraud - also called business email compromise (BEC) or invoice fraud - cost Australian businesses and individuals $166.8 million in 2025, up 9.3% from the year before, according to the National Anti-Scam Centre’s March 2026 Targeting Scams report. That figure only captures losses reported to Scamwatch. The real number is higher.
The attack is straightforward. A criminal gains access to an email account - usually through credential phishing or malware. They monitor conversations quietly for weeks. At the moment a large payment is about to be made, they send an email appearing to come from the expected party, asking the recipient to update bank details. The recipient complies. The payment goes to a criminal-controlled account.
In conveyancing and property settlement, those payments are typically $500,000 to $1.5 million. They move in a single transfer. There is usually no reversal.
The Court Ruling That Changed Who Carries the Loss
In December 2024, the Western Australian District Court handed down a judgment that every professional services firm in Australia should read.
In Mobius Group Pty Ltd v Inoteq Pty Ltd [2024] WADC 114, a hacker accessed Mobius’s email account and sent fraudulent requests to their client Inoteq, asking for an update to Mobius’s bank details. The hacker provided what looked like confirmation. Inoteq updated the details and transferred $191,859 to the criminal’s account.
The court ordered Inoteq - the paying party - to repay the full amount.
The key finding: Inoteq had taken some steps to verify the account change. But verifying via the same email thread that had already been compromised was not adequate. The court held that only a phone call to an independently sourced, trusted number would have met the standard.
The paying party carried the loss because they failed to independently verify the destination account before sending funds.
This is the second Western Australian District Court decision establishing this principle. It will not be the last. And as 90,000 newly regulated firms take on higher-value professional services transactions - property settlements, corporate completions, estate distributions - the population of organisations exposed to this exact scenario has just grown dramatically.
Spear Phishing Specifically Targets Settlement Moments
The Mobius case is not unusual. Australian security firm PhishByte, citing ACCC data, identified five attack scenarios that specifically target Australian payment workflows. Interception of legal and conveyancing communications - at the moment funds are about to be transferred - is named explicitly as a high-frequency vector.
These are not generic attacks. Criminals research their targets. They monitor email accounts for weeks, learning the parties involved, the property address, the approximate settlement date, and the expected transfer amount. The fraudulent bank details update arrives at exactly the right moment and is written to match the existing correspondence precisely.
The Group-IB AUNZ Intelligence Insights Report for Q2 2026 confirms the broader threat trajectory: the ANZ region is seeing expanded targeting from financially driven cybercriminals and nation-state-affiliated groups alike, with a new wave of mobile banking trojans designed specifically to exploit Australian banking infrastructure. Credential compromise is the entry point for many of these attacks - and once credentials are compromised, payment interception follows.
Tranche 2 compliance obligations do not protect against any of this.
What the Scams Prevention Framework Adds - and Where It Falls Short
From 1 July 2026, Australia’s Scams Prevention Framework Act 2025 commenced its first sector obligations. Banks, telecommunications providers, and a subset of digital platforms are now required by law to detect, disrupt, and respond to scams - with civil penalties of up to $50 million per contravention taking full effect from 31 March 2027.
The banking industry has committed $100 million to rolling out Confirmation of Payee (CoP) - a real-time check that alerts the payer when the name on the receiving account doesn’t match what they entered.
CoP is a meaningful step. But it operates at the bank interface, covering account name. It does not verify that the business is registered and legitimate. It does not verify that the account belongs to the entity the payer believes they’re dealing with. It is one layer. For professional services firms managing payments on behalf of clients - particularly in property settlement - one layer is not enough.
Verifying the Person Is Step One. Verifying the Bank Account Is Step Two.
Payment security is sequential. Tranche 2 delivers step one: know your client. The Confirmation of Payee system is working toward a partial version of step two at the banking layer.
What remains is combining those checks so every large payment - particularly in professional services - goes through identity verification and bank account verification before money moves.
In property settlement, that means:
- Verify the identity of the vendor, the purchaser, and the counterparty’s firm before acting on payment instructions
- Verify that the BSB and account number belong to a real, registered business whose identity matches who you expect to be paying - before the transfer is made
- Treat any last-minute change to bank details as a red flag that triggers both a phone verification call and a fresh account check
The Mobius ruling makes clear that independent phone verification is now a legal expectation, not just a recommended practice. Real-time bank account verification - confirming that an account exists, is active, and belongs to the right entity - is what makes that expectation scalable across a business that handles dozens of settlements a week.
The Bottom Line
Ninety thousand Australian businesses just came under AUSTRAC’s compliance framework. That is a good outcome for the integrity of Australia’s financial system. Knowing your client matters.
But knowing your client and knowing the bank account you are about to pay are different things. The $166.8 million Australians lost to payment redirection fraud in 2025 did not flow from businesses that skipped identity checks. It flowed from businesses that verified the person and then sent money to an account they never confirmed.
Tranche 2 is necessary. It is not sufficient.
The courts have made the liability clear. The regulators are raising the stakes. The criminals are getting more precise. The only control that actually stops the money from leaving is verifying the payee - the person, the business, and the bank account - before the payment goes out.
ezyshield is on a mission to eliminate payment fraud in Australia. We verify the person, the business, and the bank account before money moves - so payments only ever land with who they’re meant to. Learn more
Keep reading
AUSTRAC's Warning: AI Is Now Forging the Identities Your Payments Land With
AUSTRAC warns AI is fabricating identities to launder $166.8M in redirected payments. Here is what breaks the chain before money leaves your accounts.
newsConfirmation of Payee Is Live: What It Covers, What It Misses
Australia's banks reached industry-wide Confirmation of Payee coverage in 2026. What it covers, what it misses, and what B2B businesses need to do next.
newsAustralia's CoP Has Run 100 Million Checks - Here's What It Still Can't Stop
CoP hit 100M checks and blocked 10,000+ payments to criminal accounts. Here's what the milestone means - and the fraud gaps that remain wide open.
Stop payment fraud before money moves
Verify the person, business, and bank account before any payment leaves your account.