By Joshua Clouston, Head of Product, ezyshield

News 9 min read

Australia's CoP Has Run 100 Million Checks - Here's What It Still Can't Stop

CoP hit 100M checks and blocked 10,000+ payments to criminal accounts. Here's what the milestone means - and the fraud gaps that remain wide open.

Close-up of two hands typing on a laptop keyboard showing a financial revenue dashboard with dollar figures, in a cafe setting

A couple finalising their property settlement checked their email, saw the bank transfer details from their solicitor, and sent more than $800,000 to the account listed. By the time they spoke to their solicitor in person, it was too late. The email had come from their solicitor’s compromised inbox. The bank details had been swapped. The money was in a mule account and already moving.

That case became one of the defining arguments for why Australia needed Confirmation of Payee (CoP). The logic was simple: if the account name had been checked against the bank’s records before the transfer went through, the mismatch would have flagged before a dollar moved.

Australia’s banks launched CoP in July 2025. This week, the Australian Banking Association published the first major scorecard on how it is performing. The numbers are significant. So are the gaps they reveal.

The Scoreboard: 100 Million Checks, 10,000 Criminal Accounts Flagged

Since launch, Australians have run Confirmation of Payee more than 100 million times. The service is now live at 82 financial institutions - from the big four down to mutuals and regional credit unions - covering more than 143 million bank accounts. Banks collectively invested $100 million to build the infrastructure, and the rollout has moved faster than initial forecasts.

The headline result: at one major bank alone, more than 450,000 payments were abandoned by customers after they received a ‘no match’ result. Of those abandoned payments, more than 10,000 were heading to accounts already listed on the Australian Financial Crimes Exchange (AFCEX) - a shared database of accounts linked to known fraud and criminal activity (ABA).

Ten thousand payments, at a single institution, intercepted before a dollar moved to accounts the industry had already flagged as criminal. That is not a modest outcome. That is the system working exactly as intended.

The UK introduced a similar scheme in 2020, and the Australian model draws directly on that experience. Before scam losses in Australia peaked above $3 billion, the Scam-Safe Accord committed all major retail banks to a minimum set of anti-scam controls. CoP was the centrepiece - the infrastructure that makes it possible to verify a payee’s account details in real time, before the payment is authorised (Finextra).

One hundred million checks in nine months tells you adoption is real. The 10,000 AFCEX intercepts tell you organised fraud networks were already seeded and waiting when CoP went live.

Why BEC and Payment Redirection Keep Rising Anyway

Here is the thing: despite all of that, business email compromise (BEC) attacks in Australia are up 7 per cent year-on-year, according to the federal government’s Annual Cyber Threat Report. Self-reported BEC losses hit $84 million in the 2023-24 financial year. The ACCC has confirmed overall annual scam losses have exceeded $2 billion. Phishing losses reached $97.6 million in 2025, up from $84.5 million the year before (Cuscal, 2026).

CoP is running at scale. Fraud is still rising. Why?

Part of the answer came from CommBank’s Behavioural Science Centre of Excellence, which published research in April 2026 based on a study of 1,126 Australian employees, managers, and business owners. Participants assessed a series of realistic workplace emails - some genuine, some fraudulent - and indicated whether each was legitimate or a scam.

The finding that matters most: 76 per cent of frontline employees correctly identified a scam email targeting their workplace. Senior managers? Just 53 per cent. The people with authority to approve payments are the least reliable at spotting a fraudulent request (CommBank/SecurityBrief).

The research also found that in 61 per cent of cases where a workplace scam succeeded, victims failed to identify subtle abnormalities in the email or payment request. Not obvious signs - subtle ones. A slightly different domain in the reply-to field. A new account number on an otherwise identical invoice template. A sense of urgency that bypassed the usual checklist.

BEC works because it targets the approval layer, not the technical perimeter. The attacker does not need to breach your systems. They need to intercept one email thread, change one account number, and send it back before anyone checks. The pressure of a property settlement, an end-of-month payment run, or a supplier chasing a late invoice does the rest.

Cuscal’s 2026 Fraud and Scams Report found that 57 per cent of Australians face scam attempts weekly, and almost one in three has been impacted. Nine in ten expect their financial institution to do more. The gap between what CoP can catch and what fraud networks are targeting is exactly where those losses are still landing.

What CoP Can - and Can’t - See

Confirmation of Payee works by querying the recipient’s bank when a payer enters a BSB and account number. The bank returns a ‘match’, ‘close match’, or ‘no match’ result based on whether the account name aligns with their records. If it does not match, the payer sees a warning before confirming the transfer.

That is a meaningful layer of protection. The couple in the property settlement would have seen a ‘no match’ result - the mule account carrying their $800,000 would not have been registered in their solicitor’s name.

But here is what CoP does not check:

  • Whether the business entity behind the account is registered with ASIC or holds an active ABN
  • Whether the ABN was registered last week or a decade ago
  • Whether the company name on the invoice matches the registered business name held against the account
  • Whether the account was recently opened by a money mule recruited on social media
  • Whether the person authorising the payment on your side has been verified against the mandate they hold
  • Whether the supplier whose bank details just changed is actually the same legal entity you have been paying for three years

Each of those gaps is a lane that fraud networks are actively working. Shell company fraud has adapted to CoP. Fraudsters now register real ABNs, open real bank accounts under real business names, and position those accounts to receive diverted funds. The ‘match’ result shows up correctly - because technically, the account name does match - but the business behind it exists solely to capture stolen payments.

AI-driven fraud is accelerating this further. Australian regulators - AUSTRAC, ASIC, and the AFP - have all signalled intensifying enforcement focus on AI-enabled payment fraud in 2026, including deepfake voice cloning used to impersonate CFOs and authorise urgent transfers. Voice cloning now requires as little as three seconds of audio. Research from April 2026 found that 70 per cent of people cannot reliably distinguish a cloned voice from a real one (Trend Micro). A ‘match’ result on the account means nothing if the instruction to make the transfer was delivered by a synthetic voice.

The Three Checks That Close the Gap

The property settlement case is solved by CoP. That is a real win.

The harder cases - the ones driving the 7 per cent rise in BEC attacks - require more than a name-to-account match. They require three parallel checks before money moves.

Verify the bank account. CoP handles the name-to-account match and every business should be using it. But verification should also include checking whether the account was recently registered, whether the BSB traces to a known and active financial institution, and whether the account history is consistent with a legitimate business. CoP is the floor, not the ceiling.

Verify the business. Is the ABN active and registered to the entity named on the invoice? Does the company registration with ASIC align with the bank account holder? Has the business been operating long enough to be a credible counterparty for the transaction value involved? A new account number from a long-term supplier is a low-risk event only if the business behind it still checks out. A first-time payee requires a higher threshold.

Verify the person. Who is authorising this payment on the receiving side? Has the account signatory been identity-verified against the mandate held for that account? Mule recruitment targets real people - sometimes people who have consented to let their accounts be used, sometimes people who have been coerced. Identity verification at the point of payment setup, not just at onboarding, is what catches this.

These three checks work in parallel. Account verification catches the obvious mule account. Business verification catches the shell company with a fresh ABN. Person verification catches the mule and the insider threat.

The Scam-Safe Accord was designed as a starting framework, not a ceiling. AUSTRAC and ASIC have made clear that regulatory expectations on payment verification are heading toward requiring demonstrable processes - not just policy commitments. Businesses that treat CoP as the end of their payment verification obligations are already behind where regulators are heading.

What Australian Businesses Should Do Right Now

The 100 million CoP checks are a genuine achievement. The 10,000 AFCEX-flagged intercepts represent real money that stayed where it belonged.

But the 7 per cent rise in BEC attacks means fraud networks have not slowed down - they have adapted. The targets have shifted toward the gaps CoP does not cover: the business entity layer, the authorisation layer, the identity layer.

For any Australian business making payments to suppliers, contractors, or new payees, the practical steps are clear.

Run CoP checks as a mandatory step, not an optional prompt. Do not allow staff to bypass a ‘close match’ or ‘no match’ result without escalation to a decision-maker who understands the risk.

Verify the ABN and business registration independently when adding a new payee or updating bank details for an existing one. A call to a verified number on file is the minimum. A business registry check against ASIC records is better.

Confirm the identity of whoever is authorising a payment change on the other side of the transaction - especially for high-value or first-time payees.

Treat any urgent request involving updated bank details as a reason to slow down. The urgency is almost always part of the method, not the message.

The couple who lost $800,000 were not careless. They acted on instructions from a trusted email address, following a process that looked exactly like the one they expected. The fraud was designed to look routine. That is what makes it effective - and that is what makes the next layer of verification, beyond the account name match, matter.

CoP would have caught it. Three-layer verification catches the ones CoP misses.


ezyshield is on a mission to eliminate payment fraud in Australia. We verify the person, the business, and the bank account before money moves - so payments only ever land with who they’re meant to. Learn more

Stop payment fraud before money moves

Verify the person, business, and bank account before any payment leaves your account.