Regulatory Updates

Scam Losses Hit $2.18 Billion in 2025 — Why Payment Redirection Is a Remittance Problem

The ACCC's National Anti-Scam Centre reports 481,523 scam reports and $2.18B in losses. Payment redirection scams intersect directly with cross-border transfers.

Compliance Desk
10 min read

Australian businesses and consumers lost $2.18 billion to scammers in 2025, with payment redirection fraud emerging as one of the most damaging categories by value. For remittance operators handling cross-border transfers, this represents a critical operational risk that demands immediate attention.

The Australian Competition and Consumer Commission (ACCC) released its annual scam data on 30 March 2026, revealing that despite a slight decrease from 2024's record $2.74 billion, scammers still extracted billions from the Australian economy through 481,523 reported incidents. Payment redirection — where fraudsters trick victims into sending money to accounts they control — continues to devastate businesses handling high-value, irreversible transfers.

Key Takeaways

  • Australian scam losses totalled $2.18 billion in 2025 across 481,523 reports
  • Payment redirection fraud remains a top loss category, particularly affecting cross-border transfers
  • Remittance operators face unique vulnerabilities due to irreversible transfers and faster payment rails
  • AUSTRAC expects enhanced verification procedures for high-risk transactions
  • Recovery rates for cross-border scam payments remain below 5%

Payment Redirection: The Silent Killer of Cross-Border Transfers

Payment redirection scams operate through deceptively simple mechanics. Fraudsters gain access to legitimate email accounts or create convincing impersonations, then intercept payment instructions and substitute their own account details. By the time victims realise the deception, funds have typically moved through multiple jurisdictions.

For remittance operators, three factors amplify this risk:

Speed of settlement: Modern remittance rails settle within minutes or hours, leaving minimal time for intervention once fraud is detected.

Irreversibility: Unlike domestic bank transfers that may be recalled within certain timeframes, international transfers through correspondent banking networks or alternative rails become practically irretrievable once settled.

Jurisdictional complexity: Cross-border recovery requires coordination between financial intelligence units, law enforcement agencies, and financial institutions across multiple countries — a process that rarely succeeds before funds disappear.

Why Remittance Channels Are Particularly Vulnerable

The National Anti-Scam Centre's Targeting Scams report for 2025 identifies several attack vectors that disproportionately affect remittance transactions:

Business Email Compromise (BEC)

Scammers target businesses making regular international payments, particularly those paying overseas suppliers or contractors. They monitor email communications for weeks or months, learning payment patterns and relationships. When a large invoice arrives, they strike — either by compromising the supplier's email account or creating a lookalike domain.

A typical scenario: An Australian importer receives an invoice from their Chinese supplier for AUD 85,000. The email looks identical to previous invoices, complete with correct product codes and shipping details. The only difference? The bank account details have changed to a mule account in Hong Kong. By the time the real supplier queries the missing payment weeks later, the funds have vanished through cryptocurrency exchanges.

Romance Baiting and Emotional Manipulation

Romance scams generated $201.1 million in losses during 2025, with many victims using remittance services to send money to fake partners overseas. Scammers build relationships over months, creating elaborate backstories about business opportunities, medical emergencies, or travel costs.

Remittance operators often see the final transaction in these scams — a desperate customer insisting on sending their life savings to someone they've never met in person. While [INTERNAL LINK: /compliance/aml-ctf-program-guide] AML/CTF programs require monitoring for unusual transactions, distinguishing between legitimate support for overseas family and romance scam payments requires sophisticated behavioural analysis.

Investment and Cryptocurrency Scams

Fake investment platforms continue to proliferate, with scammers directing victims to transfer funds internationally before "converting" them to cryptocurrency or other investments. These scams netted $298.3 million in 2025, often routing initial payments through remittance channels to create an appearance of legitimacy.

The Faster Rails Dilemma: Speed Versus Security

The remittance industry's push toward real-time settlement creates a fundamental tension. Customers demand instant transfers at lower costs, but faster rails eliminate the traditional "cooling-off" period that allowed fraud detection and intervention.

Consider the difference between traditional correspondent banking and modern alternatives:

Traditional SWIFT transfers: 2-5 business days for settlement, multiple checkpoints for compliance review, higher costs but greater recovery options.

Modern instant rails: Settlement within minutes, lower costs, minimal intervention windows, near-zero recovery rates once completed.

This speed-security tradeoff requires remittance operators to implement stronger pre-transaction controls. Waiting until after payment authorisation is too late when settlements occur in minutes.

Building a Scam Prevention Framework

Effective scam prevention for remittance operators requires multiple layers of defence:

1. Enhanced Customer Verification

Beyond standard KYC requirements, implement additional verification for high-risk scenarios:

  • First-time beneficiaries: Require callback verification for new recipients above certain thresholds
  • Changed payment details: Flag any modification to previously used beneficiary accounts
  • Unusual patterns: Monitor for sudden increases in transfer frequency or amounts

2. Payee Confirmation Systems

While Australia's domestic PayID system provides name matching for local transfers, cross-border payments lack equivalent infrastructure. Remittance operators should:

  • Implement beneficiary name screening where supported by receiving institutions
  • Require customers to verify beneficiary details through secondary channels
  • Display clear warnings when beneficiary details cannot be confirmed

3. Transaction Monitoring and Anomaly Detection

Your [INTERNAL LINK: /compliance/austrac-registration-guide] AUSTRAC-compliant transaction monitoring system should include scam-specific rules:

Risk IndicatorThresholdAction
New beneficiary + high value> AUD 5,000Manual review
Multiple transfers to new beneficiaries> 3 in 24 hoursEnhanced verification
Customer age + unusual corridor> 65 years + first-time corridorCallback required
Beneficiary name mismatchAny amountBlock and investigate

4. Customer Education at Point of Sale

Education must occur during the transaction process, not just through general warnings:

  • Display targeted warnings based on transaction characteristics
  • Require customers to acknowledge specific scam risks for high-risk transfers
  • Provide examples of current scam types affecting the specific corridor

Post-Transaction Recovery: A Playbook for When Things Go Wrong

Despite best efforts, some fraudulent transactions will succeed. Having a documented recovery procedure can mean the difference between total loss and partial recovery:

Immediate Actions (0-2 hours)

  1. Freeze any pending transactions to the same beneficiary
  2. Contact your banking partner or payment rail provider to attempt recall
  3. Lodge a report with your local police and obtain a reference number
  4. Notify AUSTRAC via a Suspicious Matter Report (SMR) if fraud is confirmed

Short-term Actions (2-24 hours)

  1. Contact the receiving institution directly if you have established relationships
  2. Engage local law enforcement in the destination country through AUSTRAC's FIU-to-FIU channels
  3. Document all communications for potential insurance claims or legal action

Recovery Strategies by Corridor

Recovery success varies dramatically by destination:

Tier 1 corridors (USA, UK, Singapore): Established frameworks exist for fraud recovery, though success rates remain low. Focus on speed of notification.

Tier 2 corridors (India, Philippines, China): Recovery depends heavily on existing relationships with receiving institutions. Pre-established contacts are crucial.

Tier 3 corridors (Pacific Islands, Africa, Latin America): Limited recovery infrastructure means prevention is your only realistic defence.

What AUSTRAC and ACCC Expect from Remittance Operators

Regulatory expectations continue to evolve as scam losses mount. While no specific "anti-scam" rules exist in the AML/CTF framework, AUSTRAC increasingly views scam prevention as part of broader risk management obligations.

The ACCC's Deputy Chair Catriona Lowe emphasised in the March 2026 release that "continued coordinated efforts are necessary" across all payment channels. For remittance operators, this translates to:

Documentation: Maintain records of anti-scam measures, staff training, and customer warnings. Regulators will expect evidence of proactive efforts during investigations.

Collaboration: Participate in industry initiatives like the National Anti-Scam Centre's intelligence sharing programs. Isolation increases vulnerability.

Continuous improvement: Regular review and enhancement of controls based on emerging threats. Static defences quickly become obsolete.

Technology Solutions and Future-Proofing

Investing in technology can multiply the effectiveness of anti-scam efforts:

Behavioural Analytics

Modern platforms analyse customer behaviour patterns to identify transactions that deviate from established norms. A customer who typically sends AUD 500 monthly to family in Vietnam suddenly attempting AUD 25,000 to a new beneficiary triggers immediate review.

API-Based Verification

Where available, integrate with beneficiary bank APIs to verify account ownership before processing transfers. Several Asian corridors now support real-time name matching.

Machine Learning Models

Train models on known scam patterns to identify suspicious transactions before completion. Focus on corridor-specific risks rather than generic fraud detection.

Building Customer Trust While Adding Friction

The challenge for remittance operators is implementing additional security measures without driving customers to less secure competitors. Frame enhanced verification as customer protection:

Wrong approach: "New regulations require additional ID verification."

Right approach: "We're protecting your transfer with additional security checks — this ensures your money reaches the right person."

What To Do Now

  1. Audit your current controls: Review existing transaction monitoring rules and identify gaps specific to payment redirection risks

  2. Implement callback procedures: Establish mandatory voice verification for first-time transfers above AUD 3,000 or corridor-specific thresholds

  3. Update customer warnings: Revise transaction screens to include specific, scenario-based scam warnings rather than generic text

  4. Train frontline staff: Ensure customer-facing staff can identify and respond to common scam indicators

  5. Document your framework: Create written procedures for scam prevention, detection, and response that demonstrate regulatory compliance

The Road Ahead

Scam losses may have decreased from 2024's peak, but $2.18 billion in annual losses remains unacceptable for Australian regulators and the community. Payment redirection fraud's prominence in these statistics places remittance operators squarely in the firing line.

The combination of irreversible transfers, faster settlement rails, and sophisticated social engineering tactics creates a perfect storm of vulnerability. Success requires balancing customer experience with security, speed with verification, and automation with human judgment.

As cross-border payment volumes continue growing and new corridors emerge, staying ahead of scammers demands constant vigilance and adaptation. The operators who thrive will be those who view anti-scam measures not as regulatory burden but as competitive advantage — building trust in an industry where trust is currency.


For comprehensive guidance on building a compliant AML/CTF program that incorporates anti-scam measures, access our [INTERNAL LINK: /tools/compliance-checklist] AML/CTF Compliance Checklist or explore our library of corridor-specific guides.

Frequently Asked Questions

What's the difference between fraud and scams in remittance context?

Fraud typically involves unauthorised access to accounts or payment credentials without the customer's knowledge. Scams involve deceiving customers into willingly authorising transfers to criminals. Remittance operators face both risks, but scams are harder to prevent because the customer actively participates in the transaction.

Can remittance operators be held liable for customer scam losses?

Currently, Australian law doesn't mandate reimbursement for authorised scam payments. However, regulatory expectations are shifting globally, with UK and Singapore implementing liability frameworks. Operators should prepare for potential future obligations by strengthening preventive measures now.

How quickly must I report suspected scams to AUSTRAC?

Submit a Suspicious Matter Report (SMR) within 24 hours of forming a reasonable suspicion. For payment redirection scams, suspicion typically forms when the legitimate beneficiary reports non-receipt or the customer discovers the deception. Don't wait for complete investigation before reporting.

What's the minimum transaction amount that should trigger enhanced scam checks?

No universal threshold exists — it varies by corridor and customer profile. Consider factors like average transaction size, corridor risk rating, and customer history. Many operators implement staged verification: light checks at AUD 1,000, enhanced at AUD 5,000, and mandatory callbacks above AUD 10,000.

ScamsConsumer ProtectionFraudcomplianceAcccFraud PreventionAUSTRACRisk Management
Was this article helpful?