By Joshua Clouston, Head of Product, ezyshield
PayTo's $3 Million Wake-Up Call: Why Faster Rails Demand Smarter Verification
A $3M fraud via 250 zombie accounts exposed a critical verification gap in Australia's PayTo rails. Here's what every business needs to know before money moves.
Revolut launched PayTo top-ups for Australian customers in March 2026. Eight weeks later, the feature was disabled - suspended after 250 dormant mule accounts drained roughly $3 million through fraudulent PayTo mandates, processed on Banking Circle’s infrastructure without a single receiving-account check catching the pattern in time.
The speed of PayTo was supposed to be a feature. In this case, it was a weapon.
What Happened: 250 Zombie Accounts and a Very Convenient Gap
PayTo works like this: a business or individual sets up a mandate at the payer’s bank, authorising future pulls of funds under agreed terms. The payer approves, and from that point the payee can draw money in real time on the NPP.
The Revolut incident turned that mechanism against consumers. Customers were tricked - through phishing or social engineering - into approving PayTo mandates that routed their funds into Revolut accounts they didn’t control. Those accounts belonged to a network of roughly 250 zombie mule accounts: inactive accounts established months earlier, sitting dormant long enough to look clean, then reactivated when the scheme was ready to move.
Once the mandates fired, money moved fast. Funds landed in the Revolut mule accounts and were redirected through Banking Circle’s technology stack before either institution’s controls registered an anomaly.
The gap was a missing check. The PayTo authorisation layer confirmed a mandate had been approved. What it didn’t do was verify whether the receiving account was legitimate - whether it was tied to a real, verified business, whether it had a normal transaction history, or whether it appeared on any fraud watchlist. The mandate said yes. Nobody asked whether the destination deserved a yes.
As PayDay News Australia and Banking Day both reported, the incident triggered an emergency industry meeting to resolve a question PayTo’s governance framework had left unanswered: when fraudulent mandates result in customer losses spread across multiple institutions, who carries the liability? That question is still being resolved.
Why This Is Happening Now - and Getting Worse
New payment rails attract fraud early. Controls haven’t caught up with the capability yet, and fraudsters run structured experiments on fresh infrastructure to find the gaps before they’re closed. PayTo only went live for most consumers in 2025. Revolut brought it to its customer base in March 2026. The fraud hit in May. Eight weeks is a very short runway.
Now compound that with one of the biggest structural changes to Australia’s payment system in years. From 1 July 2026, Payday Super is live. Employers must pay superannuation contributions on every payday, with each contribution required to reach the employee’s fund within seven business days via the NPP. Australian Payments Plus reports the NPP now moves nearly $7 billion per day.
PayTo sits at the centre of that infrastructure. The rail that was successfully attacked in May is now running at enormously larger volumes - and the industry’s liability framework is still being worked out. The window for exploiting the same gap has not closed.
The Liability Question Nobody Had Answered
The Banking Circle-Revolut incident exposed more than a technical gap. It exposed a governance gap. When a fraudulent PayTo mandate drains a consumer’s account across multiple participants - the payer’s bank that authorised the mandate, the infrastructure provider processing it, and the neobank holding the receiving account - the existing framework didn’t clearly assign responsibility.
This matters because the Scams Prevention Framework (SPF) - which passed Parliament in February 2025 and landed its first wave of obligations on 1 July 2026 - is about to make vague liability very expensive. Banks, telcos and designated digital platforms are now legally required to take reasonable steps to prevent, detect and disrupt scams. From 31 March 2027, civil penalties of up to $50 million per contravention apply, enforced by ASIC for banks, the ACCC for digital platforms, and the ACMA for telcos. AFCA has been accepting SPF-related complaints since 1 July.
“Reasonable steps” is doing a lot of work in that framework. Regulators don’t apply it as a checklist - they assess it against what was available, what was known, and what a firm chose to implement. In a world where the Confirmation of Payee system stopped 10,000+ payments heading to known fraud accounts in its first year of operation, “we didn’t check the receiving account” is not a strong defence.
What Verification at Scale Actually Looks Like
Australia is not starting from scratch on this. The Confirmation of Payee system - built with $100 million in pooled industry investment under the Scam-Safe Accord and launched in July 2025 - gives payers the ability to verify that an account name, BSB and account number match before a transfer goes out. Since launch, Australians have used it over 100 million times across more than 100 financial institutions.
The results are concrete. One major bank reported more than 450,000 payments abandoned after “no match” CoP results - and more than 10,000 of those abandoned payments were destined for accounts listed on the Australian Financial Crimes Exchange as linked to fraud. CoP didn’t slow those transactions down. It stopped them.
But CoP operates on outbound transfers initiated by the payer. PayTo mandates - where a payee initiates pulls from a customer’s account - sit in a different position. Verifying the receiving party before the mandate activates is a distinct check that CoP’s current architecture doesn’t fully address. The Revolut incident illustrated exactly that gap.
The question isn’t whether verification technology exists. It does. The question is whether it’s being applied at every point in the payment chain where money can be redirected.
The Business Case for Checking Before You Move
This isn’t a problem that only banks need to solve. Any business using PayTo - whether setting up mandates to collect from customers or paying suppliers via real-time rails - has a direct interest in verifying the accounts at both ends before money moves.
The ACCC’s 2025 data puts the cost in plain terms. Payment redirection scams cost Australian businesses and consumers $166.8 million last year - a 9.3% increase on 2024. It was the only fraud category in the top five to record a year-on-year rise. The mechanism in nearly every case is the same: a fraudster substitutes bank account details at some point in the payment process, and the payer - trusting those details - sends funds to the wrong destination.
Recovery rates on real-time payments are lower than on batch rails precisely because money moves before disputes can be flagged. The AFP recovered $777,000 for one BEC victim earlier this year - a genuine outcome, but a fraction of what that case involved. The pattern holds: businesses that verify payment destinations before initiating transfers fare better than those relying on their bank’s controls to catch the problem.
Three Checks That Would Have Broken This Chain
Looking at the structure of the Banking Circle-Revolut fraud, three controls - applied before mandate activation - would have interrupted it:
Account status verification. The 250 mule accounts were dormant, reactivated specifically for this scheme. An account with no meaningful transaction history that suddenly becomes the destination for a PayTo mandate is an anomaly worth flagging. Checking whether a receiving account is genuinely active - and has been consistently active, not just recently reactivated - costs very little compared to the losses it can prevent.
Business identity verification for payees. The receiving accounts were Revolut accounts - not accounts tied to a verifiable Australian business. If PayTo mandate setup required the payee to have a verified business identity (ABN match, director confirmation, account name match), zombie personal accounts would fail at the first step.
Real-time cross-referencing against known fraud networks. The AFCE data shows thousands of accounts associated with known fraud. Applying that cross-reference to receiving accounts at mandate setup - not after funds have moved - is the same logic that made CoP effective. The data exists. It needs to be applied earlier in the transaction lifecycle, not as an afterthought.
The Regulatory Signal Is Clear
ASIC’s annual enforcement results, published 20 July 2026, set a record: $830 million in civil penalties in FY2025-26, an eightfold increase on the prior year’s $104.1 million. ANZ was hit for $250 million. HSBC and Macquarie Securities for $35 million each. Westpac for $26 million. More than $644 million is being returned to Australians.
The message is not subtle. Governance failures, scam-related harm, and failures of consumer protection are being enforced at a scale that was unthinkable three years ago. With the SPF’s $50 million per-contravention regime coming into full force in March 2027, any firm relying on the assumption that regulators won’t look closely is carrying unnecessary risk.
The window for building demonstrable verification controls - and documenting them as evidence of reasonable steps - is closing.
Start Before the Mandates Do
The PayTo/Banking Circle incident is a well-structured lesson. Faster rails don’t change the fundamental attack pattern of payment fraud - a fraudster replaces a legitimate destination account with one they control, and the payer sends money to the wrong place. What faster rails change is the time available to detect and reverse a transfer once it’s happened.
That means pre-payment verification isn’t optional on real-time infrastructure. It’s the only layer that reliably works. Once a PayTo mandate executes, the clock is ticking. The question isn’t whether to verify - it’s whether to verify before or after you’ve already lost the money.
One hundred million Confirmation of Payee lookups since July 2025 tell you Australians will use verification tools when they’re available. The task now is extending that same logic to every part of the payment chain - including the account at the other end of a PayTo mandate, before a single dollar moves.
ezyshield is on a mission to eliminate payment fraud in Australia. We verify the person, the business, and the bank account before money moves - so payments only ever land with who they’re meant to. Learn more
Keep reading
When PayTo Mandates Go Rogue: Inside Australia's $3 Million Zombie Account Fraud
250 zombie mule accounts. $3 million stolen. How fraudsters abused Revolut's PayTo feature weeks after launch - and what account verification would have stopped.
newsAustralia's CoP Has Run 100 Million Checks - Here's What It Still Can't Stop
CoP hit 100M checks and blocked 10,000+ payments to criminal accounts. Here's what the milestone means - and the fraud gaps that remain wide open.
newsConfirmation of Payee Is Live: What It Covers, What It Misses
Australia's banks reached industry-wide Confirmation of Payee coverage in 2026. What it covers, what it misses, and what B2B businesses need to do next.
Stop payment fraud before money moves
Verify the person, business, and bank account before any payment leaves your account.