Could a recent ruling change the game for scam victims? Here’s why the banks will be watching closely
<div class="theconversation-article-body"><em><a href="https://theconversation.com/profiles/jeannie-marie-paterson-6367">Jeannie Marie Paterson</a>, <a href="https://theconversation.com/institutions/the-university-of-melbourne-722">The University of Melbourne</a> and <a href="https://theconversation.com/profiles/nicola-howell-1160247">Nicola Howell</a>, <a href="https://theconversation.com/institutions/queensland-university-of-technology-847">Queensland University of Technology</a></em></p>
<p>In Australia, it’s scam victims who foot the bill for the overwhelming majority of the money lost to scams each year.</p>
<p>A 2023 <a href="https://download.asic.gov.au/media/mbhoz0pc/rep761-published-20-april-2023.pdf">review</a> by the Australian Securities and Investments Commission (ASIC) found banks detected and stopped only a small proportion of scams. The total amount banks paid in compensation paled in comparison to total losses.</p>
<p>So, it was a strong statement this week when it was revealed the Australian Financial Conduct Authority (AFCA) had <a href="https://my.afca.org.au/searchpublisheddecisions/kb-article/?id=f9f8941f-7379-ef11-ac20-000d3a6acbb4">ordered</a> a bank – HSBC – to compensate a customer who lost more than $47,000 through a sophisticated bank impersonation or “spoofing” scam.</p>
<p>This decision was significant. An AFCA determination is binding on the relevant bank or other financial institution, which has <a href="https://www.afca.org.au/make-a-complaint#:%7E:text=Any%20determinations%20we%20make%20are,service%20is%20free%20to%20access">no direct right of appeal</a>. It could have implications for the way similar cases are treated in future.</p>
<p>The ruling comes amid a broader push for sector-wide reforms to give banks more responsibility for <a href="https://www.fico.com/blogs/detection-prevention-tackling-scams-every-angle">detecting</a>, deterring and responding to scams, as opposed to simply telling customers to be “more careful”.</p>
<p>Here’s what you should know about this landmark ruling, and what it might mean for consumers.</p>
<h2>A highly sophisticated ‘spoofing’ scam</h2>
<p>You might be familiar with “push payment” scams that trick the victim into paying money to a dummy account. These include the “<a href="https://www.acma.gov.au/articles/2024-01/scam-alert-re-emergence-hi-mum-scam">mum I’ve lost my phone</a>” scam and some <a href="https://www.scamwatch.gov.au/types-of-scams/online-dating-and-romance-scams">romance</a> scams.</p>
<p>The <a href="https://www.smh.com.au/national/dragged-kicking-and-screaming-banking-giant-loses-battle-against-scam-victim-20241015-p5kide.html">recent case</a> concerned an equally noxious “bank impersonation” or “spoofing” scam. The complainant – referred to as “Mr T” – was tricked into giving the scammer access to his HSBC account, from which an unauthorised payment was made.</p>
<p>The scammer sent Mr T a text message, purportedly asking him to investigate an attempted Amazon transaction.</p>
<p>In an effort to respond to the (fake) unauthorised Amazon purchase, Mr T revealed security passcodes to the scammer, enabling them to transfer $47,178.54 from his account and disappear with it.</p>
<p>The fact Mr T was dealing with scammers was far from obvious – scammers had information about him one might reasonably expect only a bank would know, such as his bank username.</p>
<p>On top of this, the scam text message appeared in a thread of other legitimate text messages that had previously been sent by the real HSBC.</p>
<h2>AFCA’s ruling</h2>
<p>HSBC argued to AFCA that having to pay compensation should be ruled out under the <a href="https://download.asic.gov.au/media/lloeicwb/epayments-code-published-02-june-2022.pdf">ePayments Code</a>, a voluntary code of practice administered by ASIC.</p>
<p>Under this code, a bank is not required to compensate a customer for an unauthorised payment if that customer has disclosed their passcode. The bank argued the complainant had voluntarily disclosed these codes to the scammer, meaning the bank didn’t need to pay.</p>
<p>AFCA disagreed. It noted the very way the scam had worked was by creating a sense of urgency and crisis. AFCA considered that the complainant had been manipulated into disclosing the passcodes and had not acted voluntarily.</p>
<p>AFCA awarded compensation covering the vast majority of the disputed transaction amount, lost interest charged to a home loan account, and $5,000 towards Mr T’s legal costs.</p>
<p>It also ordered the bank to pay compensation of $1,000 for poor customer service in dealing with the matter, including communication delays.</p>
<h2>Other cases may be more complex</h2>
<p>In this case, the determination was relatively straightforward. It found Mr T had not voluntarily disclosed his account information, so was not excluded from being compensated under the ePayments Code.</p>
<p>However, many payment scams fall outside the ePayments Code because they involve the customer directly sending money to the scammer (as opposed to the scammer accessing the customer’s account). That means there is no code to direct compensation.</p>
<p>Still, AFCA’s jurisdiction is broader than merely applying a code. In considering compensation for scam losses, AFCA must consider what is “fair in all the circumstances”. This means taking into account:</p>
<ul>
<li>legal principles</li>
<li>applicable industry codes</li>
<li>good industry practice</li>
<li>previous AFCA decisions.</li>
</ul>
<p>Relevant factors might well include whether the bank was proactive in responding to known scams, as well as the challenges for individual customers in identifying scams.</p>
<h2>Broader reforms are on the way</h2>
<p>At the heart of this determination by AFCA is a recognition that, increasingly, detecting sophisticated scams can be next to impossible for customers, which can mean they don’t act voluntarily in making payments to scammers.</p>
<p>Similar reasoning has informed a range of recent reform initiatives that put more responsibility for detecting and responding to scams on the banks, rather than their customers.</p>
<p>In 2023, Australia’s banking sector committed to a new “<a href="https://www.ausbanking.org.au/scam-safe-accord/">Scam-Safe Accord</a>”. This is a commitment to implement new measures to protect customers, including a confirmation of payee service, delays for new payments, and biometric identity checks for new accounts.</p>
<p>Changes on the horizon could be more ambitious and significant.</p>
<p>The proposed <a href="https://treasury.gov.au/consultation/c2024-573813">Scams Prevention Framework</a> legislation would require Australian banks, telcos and <a href="https://pursuit.unimelb.edu.au/articles/accc-vs-big-tech-round-10-and-counting">digital platforms</a> to take reasonable steps to prevent, detect, report, disrupt and respond to scams.</p>
<p>It would also include a compulsory external dispute resolution process, like AFCA’s, for consumers seeking compensation for when any of these institutions fail to comply.</p>
<p>Addressing scams is not just an Australian issue. In the United Kingdom, newly introduced <a href="https://www.bbc.com/news/articles/cy94vz4zd7zo">rules</a> make paying and receiving banks responsible for compensating customers, for scam losses up to £85,000 (A$165,136), unless the customer is grossly negligent.<!-- Below is The Conversation's page counter tag. Please DO NOT REMOVE. --><img style="border: none !important; box-shadow: none !important; margin: 0 !important; max-height: 1px !important; max-width: 1px !important; min-height: 1px !important; min-width: 1px !important; opacity: 0 !important; outline: none !important; padding: 0 !important;" src="https://counter.theconversation.com/content/241558/count.gif?distributor=republish-lightbox-basic" alt="The Conversation" width="1" height="1" /><!-- End of code. If you don't see any code above, please get new code from the Advanced tab after you click the republish button. The page counter does not collect any personal data. More info: https://theconversation.com/republishing-guidelines --></p>
<p><em><a href="https://theconversation.com/profiles/jeannie-marie-paterson-6367">Jeannie Marie Paterson</a>, Professor of Law, <a href="https://theconversation.com/institutions/the-university-of-melbourne-722">The University of Melbourne</a> and <a href="https://theconversation.com/profiles/nicola-howell-1160247">Nicola Howell</a>, Senior lecturer, <a href="https://theconversation.com/institutions/queensland-university-of-technology-847">Queensland University of Technology</a></em></p>
<p><em>Image credits: Shutterstock </em></p>
<p><em>This article is republished from <a href="https://theconversation.com">The Conversation</a> under a Creative Commons license. Read the <a href="https://theconversation.com/could-a-recent-ruling-change-the-game-for-scam-victims-heres-why-the-banks-will-be-watching-closely-241558">original article</a>.</em></p>
</div>