By Joshua Clouston, Head of Product, ezyshield
Australia's Scams Prevention Framework Is Now Law - and the September Clock Is Ticking
Australia's Scams Prevention Framework is now law. Banks, telcos and platforms face $50M fines per breach. Here's what changed on 1 July 2026 and what's coming 1 September.
A private Sydney hospital. A compromised email account. More than $3 million gone.
The criminals never breached a server or cracked a database. They intercepted an email chain, swapped out the banking details on a legitimate invoice, and waited. The hospital’s accounts payable team kept processing payments, month after month, to an account that looked right but belonged to criminals. By the time anyone noticed, over $2 million had already moved offshore.
The whole thing came down to one question nobody asked: does this bank account actually belong to who we think it does?
That question is now a legal obligation for every bank, telco and major digital platform in Australia.
On 1 July 2026, the Scams Prevention Framework became law.
What Changed on 1 July
The Scams Prevention Framework (SPF) is the most significant shift in payment fraud liability since the National Consumer Credit Protection Act. Banks, telecommunications providers and designated digital platforms are now legally required to take reasonable steps to prevent, detect and disrupt scams before they reach consumers and businesses.
The ACCC is the general regulator. ASIC oversees banks. The Australian Communications and Media Authority (ACMA) watches telcos. And the penalties are not symbolic - regulated entities that breach their obligations face civil penalties of up to $50 million per contravention.
For context: Australian scam losses totalled $2.18 billion in 2025. The SPF is the government’s most direct intervention yet - shifting liability away from victims and onto the platforms and institutions through which fraud travels.
Six Things Banks and Platforms Must Now Do
The SPF imposes six core obligations on every regulated entity. They define what “reasonable steps” looks like in practice.
Govern - appoint a senior accountable person for scam prevention. This is not a tick-box exercise; ASIC expects a named executive with documented responsibility.
Prevent - stop scams reaching consumers in the first place. For banks, that means filtering and blocking known fraud vectors before a payment prompt ever reaches a customer.
Detect - identify scams while they are happening. Real-time transaction monitoring, behavioural signals, pattern matching against known fraud typologies.
Disrupt - stop them mid-flight. If a scam is detected after initiation, the bank must be able to intervene - not just log it.
Respond - handle reports quickly and compensate where obligations were breached. There is a proposed $3,000 automatic reimbursement threshold for verified losses below that amount, removing the need for a full investigation on smaller claims.
Report - share intelligence with regulators and, where required, with consumers.
AFCA begins handling SPF-related complaints from 1 January 2027. Regulated entities must be AFCA members by 1 September 2026 - the date the formal SPF Rules commence.
The September 1 Compliance Window
The SPF became law on 1 July. But the formal SPF Rules that underpin detailed compliance obligations don’t start until 1 September 2026. That gives banks, telcos and digital platforms roughly six weeks to have their house in order before they can be found in formal breach.
Full sector code compliance for banks is targeted by end of 2027. But the detect, disrupt and respond obligations are live from September 1. If a bank allows a payment redirection scam through that a reasonable detection system would have caught, they are exposed.
For businesses, this matters in a way it never did before. Your bank now has direct financial skin in the game. The SPF doesn’t just tell banks to try harder - it makes breach of those obligations actionable, with a compensation pathway for affected customers.
Confirmation of Payee: The Infrastructure Doing the Work
The SPF doesn’t operate in isolation. It sits on top of infrastructure the banking industry has been building quietly for the past 12 months.
Confirmation of Payee launched in July 2025. In its first year, Australians ran more than 150 million checks - verifying that the name on an invoice or payment form matches the account name held by the recipient bank before a single dollar moved.
The numbers are striking:
- More than 570,000 payments were abandoned after a “no match” result
- Over 10,000 of those abandoned payments were heading to accounts listed on the Australian Financial Crimes Exchange - the shared database of known fraud accounts
- The service is now live at over 100 financial institutions, covering more than 144 million bank accounts
- Banks invested $100 million in building this technology
The behavioural data is just as telling. Customers spend three times longer reviewing a “no match” result than a match. The friction is working. People are pausing to think before they send.
One customer-owned bank in Newcastle stopped a $6,000 scam directly through the tool. Westpac has reported declining payment redirection scam losses over the past year. Lynn Kraus, CEO of Australian Payments Plus, put it plainly: “Trust in payments matters to everyone - households and businesses alike.”
Eight in 10 Australians have now seen or used Confirmation of Payee. That adoption rate, in 12 months across a service most people didn’t know existed a year ago, is a genuine bright spot.
AUSTRAC Tranche 2: The Other Shoe Dropped on 1 July
The SPF wasn’t the only thing that changed on 1 July 2026.
AUSTRAC’s Tranche 2 AML/CTF reforms also went live - the largest expansion of Australia’s Anti-Money Laundering and Counter-Terrorism Financing regime since the original legislation passed in 2006. Around 80,000 new businesses came under the regime: real estate agents, lawyers, conveyancers, accountants, and dealers in precious metals and stones.
The obligations: enrol with AUSTRAC by 29 July 2026, run customer due diligence, conduct ongoing transaction monitoring, report suspicious matters, and maintain a documented AML/CTF program.
This matters for payment fraud in a way that’s easy to miss. Property settlements, legal disbursements and accounting intermediaries are among the most commonly exploited channels in payment redirection scams.
The AFP documented a case in South Australia where a client lost $338,000 during a property settlement after criminals compromised the conveyancing firm’s email and swapped the banking details on a settlement invoice. The funds were recovered - but only because the victim reported quickly. In Tasmania, a $120,000 BEC loss went unrecovered because the delay in reporting was too long for Operation Dolos to intercept the funds before they moved offshore.
If the conveyancing firms, accountants and property lawyers in those cases had been running identity and bank account verification on their counterparties, the outcome could have been different. From 1 July, they are legally required to ask those questions.
Why Payment Redirection Is Still Rising
With all of this in place - CoP, SPF, AUSTRAC Tranche 2 - you might expect payment redirection fraud to be in decline.
Not yet.
Payment redirection scams cost Australians $167 million in 2025, a 9.3% increase on the prior year. BEC attacks cost businesses $152.6 million in the 2024 financial year, a 66% jump from the $91.6 million lost in 2023. These numbers moved in the wrong direction while Confirmation of Payee was rolling out across the network.
The reason sits in what CoP does and doesn’t check.
Confirmation of Payee verifies the account name against the BSB and account number. It stops mistaken payments and some direct fraud. It does not verify whether the business or person behind that account is who they claim to be.
A fraudster can register a business, open a legitimate bank account in that business name, and send invoices that look exactly right - with a CoP “match” result, because the account name, BSB and number all genuinely match each other. They just don’t belong to the supplier your accounts payable team thinks they’re paying.
AFP Assistant Commissioner Cyber Command Richard Chin put it directly: “Taking a moment to stop and verify can be the difference between protecting your hard-earned cash and becoming a victim.” Operation Dolos has been running since January 2020 to intercept BEC funds before they reach overseas accounts. The fact that it is still needed, six years later, is the clearest signal of how persistent the threat is.
The AFP’s current priority focus is the construction sector: high-value transactions, complex subcontracting chains, frequent invoicing, and limited cybersecurity resources among smaller businesses. A Queensland construction company lost over $1 million. A NSW business lost $41,800 - recovered in full because they reported immediately. Reporting speed is the difference between recovery and permanent loss.
What to Do Before September 1
The SPF Rules commence 1 September 2026. Here is a practical checklist for finance, compliance and AP teams.
Check your bank’s CoP setup. Confirm that Confirmation of Payee is active on your business accounts and that your payment workflows pause - not auto-override - on a “no match” result. An override that bypasses the warning is a control gap that criminals know to look for.
Review your bank detail change protocol. Changed banking details on supplier invoices are the single most common trigger in payment redirection fraud. Establish an out-of-band verification step - a phone call to a number held independently, not from the email chain where the change arrived - for every bank detail change, every time.
If you’re a Tranche 2 entity, enrol with AUSTRAC now. The deadline is 29 July 2026 - eight days from today. Real estate agents, lawyers, accountants, conveyancers: if you haven’t enrolled, do it today.
Ask your bank what they’re doing under the SPF. Under the framework, your bank has legally defined obligations to prevent, detect and disrupt scams. Ask your relationship manager how they’re fulfilling those obligations for business banking customers.
Verify the business, not just the account. CoP checks the account name. It doesn’t check whether the business is registered, legitimate, or actually the counterparty you intend to pay. Add an independent business identity check to your supplier onboarding process - ABN verification, ASIC search, and bank account owner verification - before the first payment goes out.
The SPF is a significant step. CoP is proving its value at scale. AUSTRAC Tranche 2 closes a channel that fraudsters have been exploiting for years. But the verification gap that let a Sydney hospital lose $3 million is still there for any business that doesn’t close it on its own side.
ezyshield is on a mission to eliminate payment fraud in Australia. We verify the person, the business, and the bank account before money moves - so payments only ever land with who they’re meant to. Learn more
Keep reading
Australia's Scams Prevention Framework Is Live - and Confirmation of Payee Is Now the Law
Australia's SPF Stage 1 went live 1 July 2026. Banks must now verify payees before money moves or face $50M fines. Here's what changed - and what still hasn't.
newsAustralia's Scams Prevention Framework: What Payee Verification Means for Your Business
Australia's SPF consultation closes 25 June. Banks must verify payees before payments. Here's what changes - and what it means for your business.
news$152 Million Lost as Australia's New Payment Fraud Law Arrives in 26 Days
BEC losses jumped 66% to $152.6M in 2024. Three charged in May. Australia's Scam Prevention Framework goes live 1 July. Here's what it fixes - and what it doesn't.
Stop payment fraud before money moves
Verify the person, business, and bank account before any payment leaves your account.