
Photo by SDM ProdStudio
Payment redirection fraud is one of the fastest-growing scam types routed through money transfer operators, and your frontline staff are the last line of defence before a customer's money leaves the country. The single most effective control is a structured intervention at the point of transaction — pausing a payment to ask targeted questions when behavioural red flags appear. According to Scamwatch, Australians reported losses exceeding $2 billion across all scam types in recent reporting periods, and a large share of that money moves through remittance channels because transfers are fast, cross-border, and difficult to reverse once settled.
For remittance operators, this is both a customer-protection obligation and a regulatory exposure. AUSTRAC expects reporting entities to identify and mitigate the money laundering and terrorism financing risks associated with their designated services — and scam proceeds flowing through your business create suspicious matter reporting obligations and reputational risk. This guide shows you how to detect payment redirection fraud, train your agents to intervene, and build controls that stop a transfer before it becomes an irreversible loss.
Key Takeaways
- Point-of-transaction intervention — pausing and questioning high-risk transfers — is the single most effective control against redirection scams
- Payment redirection scams exploit urgency, changed payment details, and third-party instructions, all of which produce detectable behavioural red flags
- Scamwatch reports Australians lost over $2 billion to scams, with remittance channels heavily targeted because transfers are fast and hard to reverse
- MTOs must file a Suspicious Matter Report (SMR) with AUSTRAC within 24 hours (terrorism financing) or 3 business days (other) once a suspicion forms
- A documented scam-interruption procedure protects your customers, your licence, and your banking relationships
What Is Payment Redirection Fraud?
Payment redirection fraud occurs when a scammer deceives a customer into sending money to an account the scammer controls, usually by impersonating a legitimate payee or intercepting and altering payment instructions. In the remittance context, the customer believes they are paying a genuine beneficiary — a family member, a supplier, a property agent, or a fiancé — but the destination account belongs to a criminal.
The defining feature is that the customer authorises the payment willingly. Unlike card fraud, there is no unauthorised access to an account. This makes these scams hard to reverse and places the burden of detection on the human and system controls at the point of sale.
Common variants routed through MTOs include:
- Business email compromise (BEC): a scammer poses as a supplier and sends altered bank details for an invoice payment.
- Romance scams: a long-distance "partner" requests transfers for emergencies, travel, or investment opportunities.
- Investment and crypto scams: the customer is directed to remit funds to an overseas account for a fraudulent trading platform.
- Impersonation scams: a fraudster poses as the ATO, a bank, a government agency, or a family member in distress.
- Invoice interception: legitimate payee details are replaced mid-transaction.
Why Remittance Channels Are Targeted
Scammers favour money transfer operators for the same reasons legitimate customers do: transfers are fast, cross-border, and settle quickly. Once a payout is collected overseas — often in cash — recovery is almost impossible.
The ABS and World Bank Remittance Prices Worldwide data show Australia sends billions annually across high-volume corridors to Asia, the Pacific, and Africa. High transaction volumes give scammers cover: a fraudulent transfer looks structurally identical to a genuine family remittance. Your controls must distinguish intent, not just transaction mechanics.
Cash-collection corridors carry the highest risk because the payout leg offers no beneficiary account trail. This is also why AUSTRAC's scrutiny of cash remittance channels has intensified, and why documented scam controls now feature in banking relationship reviews.
Behavioural Red Flags Your Staff Must Recognise
Most redirection scams produce the same behavioural signals regardless of the underlying story. Train your frontline staff to treat the following as triggers for a structured intervention.
| Red flag | What it looks like | Scam type it signals |
|---|---|---|
| Urgency and pressure | Customer is anxious, rushed, insists it "can't wait" | Impersonation, BEC, emergency |
| Coaching on a phone call | Customer is on the phone receiving instructions while transacting | Investment, impersonation |
| First-time large transfer | New or inactive customer sending an unusually large amount | Investment, romance |
| Reluctance to explain purpose | Vague, rehearsed, or shifting explanations | All types |
| Beneficiary the customer has never met | Sending to an "online partner" or "adviser" | Romance, investment |
| Changed bank details | Paying an invoice to newly supplied account details | BEC, invoice interception |
| Instructed not to tell the bank or agent | Customer says they were told to keep it confidential | Impersonation, investment |
| Repeat transfers to the same new beneficiary | Escalating amounts over days or weeks | Romance, investment |
No single flag confirms a scam. Two or more flags together should always prompt a pause and structured questioning before you process the transfer.
The Point-of-Transaction Intervention
The most powerful control you have is a conversation. Research by UK and Australian banks into "scam interruption" consistently shows that targeted questions at the point of payment break the spell scammers rely on. Build a simple, scripted intervention your staff can deploy without feeling awkward.
A five-step intervention script
- Pause the transaction. "Before I send this, I need to ask a few quick questions — it's a standard check we do to protect your money."
- Establish the relationship. "How do you know the person receiving this money? Have you met them in person?"
- Test the purpose. "What is this payment for? Did someone contact you and ask you to send it?"
- Check for coaching and secrecy. "Did anyone tell you to keep this transfer private, or help you with what to say to me?"
- Introduce doubt. "Many scams look exactly like this. If this turns out to be a scam, this money cannot be recovered. Are you completely confident this is genuine?"
If answers reveal red flags, do not process the transfer immediately. Refer to a supervisor, suggest the customer verify payee details through an independent channel, and provide Scamwatch resources. A delayed transfer is reversible; a sent transfer is not.
Building a Scam-Prevention Control Framework
Intervention works only when it sits inside a documented system. Integrate scam prevention into your AML/CTF program rather than treating it as a separate initiative — the two share risk-assessment logic and reporting obligations.
System-level controls
- Transaction thresholds and holds: flag first-time beneficiaries, large amounts, and rapid repeat transfers for manual review.
- Beneficiary screening: match destination accounts against internal lists of previously reported scam accounts.
- Velocity monitoring: detect escalating transfer patterns consistent with romance and investment scams.
- Cooling-off for new high-value transfers: a short, documented hold on a customer's first large transfer to a new beneficiary.
Process-level controls
- Mandatory intervention script triggered by defined red flags.
- Supervisor escalation for transactions where two or more flags appear.
- Customer confirmation records — document the questions asked and answers given.
- Scam warning signage at agent locations and in your app or online flow.
Governance controls
- Board and management reporting on scam incidents and intervention outcomes.
- Regular review of your scam typologies against AUSTRAC and Scamwatch alerts.
- Clear link to SMR obligations so staff know when detection becomes a reporting duty.
Training Frontline Staff to Intervene
Controls fail at the counter if staff are reluctant to challenge a customer. Effective scam training is behavioural, not just informational.
Build your programme around three capabilities:
- Recognition — staff can name the common red flags and scam typologies affecting your corridors.
- Intervention — staff can run the pause-and-question script confidently, including with distressed or hostile customers.
- Escalation and reporting — staff know when to refer to a supervisor and how scam detection feeds your Suspicious Matter Report obligations.
Use role-play scenarios drawn from real cases: the elderly customer sending to a "partner" they met online, the small-business owner paying an invoice with changed details, the young customer coached by phone to send money to a "trading platform". Reinforce that protecting a customer from a scam is a core part of the job, not an obstacle to a sale. For a broader approach, align this with your staff training framework and compliance-culture programme.
Your AUSTRAC Reporting Obligations When You Detect a Scam
Detecting a scam triggers regulatory duties, not just customer-service ones. Under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, if you form a suspicion that a transaction relates to proceeds of crime — which scam proceeds are — you must submit a Suspicious Matter Report (SMR) to AUSTRAC.
The timeframes are strict:
| Report type | Trigger | Deadline |
|---|---|---|
| SMR (terrorism financing) | Suspicion formed | 24 hours |
| SMR (all other grounds) | Suspicion formed | 3 business days |
| TTR | Cash transaction of AUD 10,000+ | 10 business days |
An SMR is required even if you stop the transaction — the suspicion itself triggers the obligation. Tipping off the customer that you have filed an SMR is a separate offence, so keep scam-interruption conversations factual ("this looks like a common scam") without disclosing that a report has been made.
Document your decision-making. If you process a transfer despite red flags, record why; if you decline, record the basis. This evidence protects you in a banking review or AUSTRAC supervisory engagement.
A Worked Example: The Investment Transfer
Consider a practical scenario. A customer who normally sends AUD 500 monthly to family in the Philippines arrives wanting to send AUD 18,000 to a new beneficiary account in a different country. They are on the phone throughout and appear anxious to complete quickly.
Your staff apply the intervention:
- Relationship: the customer has never met the beneficiary — an "account manager" from an online trading platform.
- Purpose: to "unlock" investment profits they can see growing on a dashboard.
- Coaching: the person on the phone is telling them what to say.
- Secrecy: they were advised not to mention "investment" to the agent.
Four red flags appear together. Your staff pause the transfer, escalate to a supervisor, explain this matches a classic investment scam, and decline to process it. The customer later confirms it was fraudulent. You file an SMR within three business days documenting the attempted transfer, the beneficiary details, and the scam indicators.
This single intervention prevents an AUD 18,000 loss, generates valuable intelligence for AUSTRAC, and demonstrates the exact control environment your banking partners want to see.
Looking Ahead: The Scams Prevention Framework
Australia's Scams Prevention Framework, legislated in 2025, imposes obligations on banks, telcos, and digital platforms to prevent, detect, and respond to scams. While the initial designated sectors centre on major banks and communications providers, the direction of travel is clear: payment businesses, including remittance operators, face rising expectations to actively disrupt scams rather than merely process instructions.
Aligning your controls now — documented interventions, SMR integration, and staff capability — positions your business ahead of the regulatory curve and strengthens your standing in de-banking and banking-review discussions.
Frequently Asked Questions
Do I have to report a scam to AUSTRAC even if I stopped the transfer?
Yes. Once you form a suspicion that a transaction relates to proceeds of crime or a scam, you must file a Suspicious Matter Report (SMR) with AUSTRAC — within 24 hours for terrorism financing grounds or 3 business days for other grounds. The obligation is triggered by the suspicion itself, not by whether the money actually moved.
Can I be penalised for processing a transfer that turns out to be a scam?
You are not automatically liable for a customer's authorised payment, but failing to identify red flags, run appropriate checks, or file required reports can expose you to AUSTRAC enforcement and damage your banking relationships. Documented scam-interruption procedures and SMR compliance are your strongest protection.
What should I say to a customer I think is being scammed without tipping them off about an SMR?
You can and should tell the customer the transaction matches a common scam pattern and that sent money cannot be recovered. What you cannot do is disclose that you have filed or intend to file a Suspicious Matter Report — tipping off is a separate offence under the AML/CTF Act. Keep the conversation about protecting their money.
How is payment redirection fraud different from money laundering?
In payment redirection fraud, the customer is the victim and authorises the payment under deception. Money laundering involves disguising the origin of illicit funds. They overlap in remittance because scam proceeds are criminal proceeds — which is why detecting a scam creates both a customer-protection duty and an SMR obligation.
Which scam types most commonly flow through MTOs?
Romance scams, investment and crypto scams, business email compromise, and impersonation scams are the most common typologies routed through remittance channels. Cash-collection corridors carry elevated risk because the payout leg leaves no beneficiary account trail.
This information is general in nature and does not constitute legal advice. Consult AUSTRAC or a qualified legal professional for advice specific to your situation.
Strengthen your scam controls by integrating them into your AML/CTF program, and explore corridor-specific risk profiles in our corridor guides. Subscribe to our newsletter for the latest AUSTRAC and Scamwatch alerts affecting remittance operators.



