HSBC’s $35M Scam Protection Penalty: What ASIC’s Case Means for Australian Scam Victims

HSBC Australia was ordered to pay a $35 million penalty for serious scam protection failures. Learn what ASIC’s case means for Australian scam victims, HSBC compensation, the ePayments Code, bank refund disputes and escalating complaints to AFCA.

HSBC’s $35M Scam Protection Penalty: What ASIC’s Case Means for Australian Scam Victims
HSBC $35 million scam protection penalty in Australia, showing ASIC enforcement action, suspicious bank transfer alerts and what the case means for Australian scam victims

A bank saying “you authorised the transfer” is not the end of the story. It is the beginning of the evidence fight.

In June 2026, the Federal Court of Australia ordered HSBC Bank Australia to pay a $35 million civil penalty after HSBC admitted serious scam protection failures. ASIC’s case involved failures connected with scam controls, handling of unauthorised transactions, ePayments Code obligations, and customer access after scams. HSBC has also established a remediation program for affected customers, with ASIC stating on 18 June 2026 that around $21.5 million had been paid in compensation, further payments were expected before the end of July 2026, and $6.5 million had been recovered and returned to customers. Readers should check HSBC’s current notices for the latest remediation status.

No, this does not mean every Australian scam victim automatically gets refunded. That fantasy belongs in the same bin as fake recovery agents and “guaranteed refund” clowns. Eligibility still depends on the transaction type, evidence, timing, bank conduct, and the rules that apply.

TL;DR

  • The ASIC HSBC scam case resulted in a $35 million Federal Court penalty against HSBC Bank Australia for admitted scam protection failures.
  • ASIC’s case concerned unauthorised transactions, scam controls, customer handling, and obligations connected with the ePayments Code, not the Scams Prevention Framework.
  • If you lost money in a bank transfer scam, report it to your bank immediately, request written reasons, preserve evidence, and prepare for escalation. For broader payment-scam rules, Dollar Vigil’s guide to Authorized Push Payment scam rules in 2026 explains why “authorised” does not always mean simple, fair, or refund-friendly.
  • HSBC’s remediation program does not mean all Australian bank scam victims are automatically entitled to compensation.
  • Australia’s Scams Prevention Framework is a separate regime aimed at future scam prevention duties across banking, telecommunications, and key digital platforms.

ASIC’s HSBC scam case led to a $35 million Federal Court penalty against HSBC Bank Australia after the bank admitted serious failures in scam protection, unauthorised transaction handling, ePayments Code processes, and customer support after scams. HSBC has a remediation program for affected customers, but the case does not guarantee refunds for every scam victim. Individual compensation depends on the facts, the payment type, the ePayments Code, bank handling, and complaint outcomes through the bank or the Australian Financial Complaints Authority.

Key Takeaways

  • The ASIC HSBC $35 million penalty is a civil penalty, not a universal refund pool.
  • ASIC Media Release 26-126MR announced the penalty sought and HSBC’s admissions.
  • ASIC Media Release 26-127MR confirmed the Federal Court order and explained the remediation program.
  • The case focused on payments treated as unauthorised transactions under the ePayments Code.
  • HSBC’s compensation program is for affected customers assessed under relevant liability rules.
  • Authorised push payment scams and unauthorised transactions are not the same thing.
  • AFCA may be relevant if your bank rejects your complaint or handles it poorly.
  • The Scams Prevention Framework Australia regime is separate from the HSBC enforcement case.

What Happened in ASIC’s HSBC Scam Case?

ASIC took HSBC Bank Australia to the Federal Court over serious failures in protecting customers from scams and handling scam-related complaints. The case started as civil penalty proceedings commenced by ASIC on 13 December 2024. ASIC later announced in Media Release 26-126MR that HSBC had admitted serious failures and that ASIC and HSBC would ask the Federal Court to impose a $35 million penalty.

On 18 June 2026, ASIC announced in Media Release 26-127MR that the Federal Court had ordered HSBC to pay the $35 million penalty. The Court also ordered HSBC to publish adverse publicity orders on its website, app, and in letters to impacted customers.

That matters because this was not a vague “bank should try harder” lecture. ASIC said the case concerned payments that were “unauthorised transactions” under the ePayments Code, which ASIC administers. HSBC admitted failures in how it handled those matters.

The clean version: ASIC’s case showed serious failures, HSBC admitted them, and the Federal Court imposed a $35 million civil penalty for the admitted contraventions.

What Did HSBC Admit It Got Wrong?

HSBC admitted failures involving scam protection, ePayments Code handling, and customer support after scams. In plain English, ASIC’s case was about whether the bank’s systems and processes were strong enough when customers were being hit by scam-related unauthorised transactions.

According to ASIC’s 2026 court outcome announcement, HSBC admitted failures including:

  • taking too long to investigate customer scam reports
  • not properly applying ePayments Code rules about who should bear certain losses
  • not having adequate systems to help customers regain access to banking after being scammed
  • failing to implement key scam controls on the IAT internal payment rail, where ASIC said the majority of customer losses occurred

ASIC said HSBC took 144 days on average to investigate customer scam reports. That is not a delay. That is a customer being left in financial limbo while the paperwork factory warms its hands over the file.

ASIC also said the Court held HSBC’s failures in respect of the ePayments Code were widespread and systemic.

For victims, this distinction matters. The issue was not merely that scams happened. Scams happen because criminals are professional parasites. The issue was whether HSBC’s controls, investigation timelines, liability assessments, and customer support met the standards required in the circumstances.

Why Was HSBC Ordered to Pay a $35 Million Penalty?

The $35 million was a civil penalty ordered by the Federal Court. It is punishment and deterrence. It is not the same thing as compensation paid directly to every scam victim.

This is where bad internet summaries can poison a victim’s expectations. A penalty, remediation payment, recovered fund, and refund decision are four different animals.

Money category What it means Does it automatically go to every victim?
Civil penalty A Court-ordered penalty for legal contraventions No
Remediation A program to assess and compensate affected customers where criteria are met No
Recovered funds Scam money recovered and returned where possible No
Individual reimbursement A case-specific outcome after bank review, code assessment, settlement, or complaint No

ASIC said HSBC had established a large-scale remediation program. As of ASIC’s 18 June 2026 release, the program had paid around $21.5 million in compensation, further payments were expected before the end of July 2026, and HSBC had recovered $6.5 million and returned those funds to customers. Readers should check HSBC’s current notices for the latest remediation status.

That is significant. It is also not a magic refund button.

A Court penalty says: the conduct was serious enough to justify punishment.

A compensation program says: some affected customers may be owed money after assessment.

Recovered funds say: money was intercepted and retrieved before the scammer could cash out.

A refund decision says: your particular facts support reimbursement under the rules, the bank’s obligations, a remediation process, a settlement, or an AFCA outcome.

Confuse those four and you hand yourself the wrong map.

Is HSBC Compensating Scam Victims?

Yes, HSBC has established a remediation program for affected customers, but eligibility is not universal. ASIC said HSBC’s remediation program assesses affected customers and compensates those who were not liable for losses under the ePayments Code, including for lost earnings caused by delays in accessing funds.

That wording matters. “Affected customers” does not mean “everyone who has ever lost money to a scam involving HSBC.” It means customers who fall within the scope of the program and whose circumstances meet the relevant assessment criteria.

If you are an HSBC customer affected by scam-related unauthorised transactions, the practical move is to:

  1. Check HSBC’s current official customer notices.
  2. Ask HSBC whether your case is within the remediation program.
  3. Request the assessment criteria or written explanation.
  4. Keep every transaction record, message, call log, complaint reference, and bank response.
  5. Escalate if the response is vague, delayed, or unsupported.

Do not let a bank bury you under soft phrases like “not eligible” without explaining why. A denial without clear reasons should not be treated as the final word. It is a locked filing cabinet wearing a customer-service badge.

Does This Mean Australian Banks Must Refund Every Scam?

No. Australian banks do not have a blanket rule requiring them to refund every scam loss. The HSBC case is important, but it does not turn every authorised bank transfer scam into an automatic compensation claim.

The legal reality is more annoying, more detailed, and more useful if you understand it.

Authorised payments

An authorised payment is generally one the customer made or approved, even if the customer was tricked by a scammer. Many authorised push payment scams fall into this category. A scammer manipulates the victim into sending money voluntarily.

That does not always mean the bank is off the hook. But it does mean the analysis is different. The complaint may turn on warnings, unusual activity monitoring, vulnerability, payment friction, bank response, recall attempts, account-opening controls at the receiving bank, and applicable rules. For a wider legal-rights breakdown, read Dollar Vigil’s guide on whether you can sue your bank for failing to stop a scam.

Unauthorised transactions

An unauthorised transaction is one the customer did not authorise. ASIC said its HSBC proceedings concerned payments that were “unauthorised transactions” under the ePayments Code.

That distinction is the spine of the HSBC case. If a scammer gained access to an account and made transfers without the customer’s authorisation, the liability analysis may involve ePayments Code rules about passcodes, reporting, investigation timelines, and whether the customer or bank bears the loss.

APP scams

APP means authorised push payment. In these scams, the victim is manipulated into pushing money to the scammer, often through impersonation, fake investment platforms, fake invoices, romance fraud, bank impersonation, or business email compromise.

APP scam bank Australia disputes are often messy because the transfer may be technically authorised while the consent was poisoned by deception. That is why “you authorised it” should not be accepted as the full explanation. It may be relevant. It is not always the whole file.

Disputed transfers

A disputed transfer may involve authorisation, account takeover, mistaken payment, fraud, scam manipulation, bank delay, poor warnings, or weak controls. The label matters less than the facts.

The real question is not: “Was this a scam?”

The real question is: “What type of transaction was it, what rules apply, what did the bank know or fail to do, how quickly did the customer report it, and what evidence proves the timeline?”

Evidence beats outrage. Outrage may be justified. Evidence moves the complaint.

Understanding the ePayments Code

The ePayments Code is an ASIC-administered code that applies to subscribers and covers many electronic payments, including internet banking, mobile banking, BPAY, ATM, EFTPOS, and card transactions. It sets out rules for issues such as unauthorised transactions, mistaken internet payments, complaint handling, and liability.

In ASIC’s HSBC case, the ePayments Code mattered because ASIC said the proceedings concerned unauthorised transactions as defined by the Code. ASIC also said HSBC admitted failures because it took too long to investigate customer scam reports and did not apply rules in the Code for deciding when customers or the bank should bear losses.

In practical terms, the ePayments Code can matter when:

  • a scammer accessed your account without permission
  • your passcode, login, or authentication details were compromised
  • the bank must investigate whether you are liable
  • the bank must give written outcomes within required timeframes
  • the bank must decide whether loss sits with the customer or institution

The Code is not a fairy godmother with a refund wand. It is a rulebook. You need to build your complaint around the rulebook, not around vibes.

What consumers should know before contacting the bank

Before you call or write to the bank, get clear on these points:

  • Did you personally make the transfer, or did the scammer access the account?
  • Did you share a passcode, one-time code, remote access, card details, login, or device control?
  • When did you first notice the scam?
  • When did you report it?
  • What did the bank do after the report?
  • Did the bank restrict your account, delay access, or fail to explain the outcome?
  • Did the bank provide written reasons?

If your case involves HSBC, ask directly whether the remediation program applies. If your case involves another bank, ask what rules, code provisions, internal procedures, or dispute framework the bank used to assess your claim.

Do not accept “you authorised it” as a complete answer unless the bank explains the actual reasoning.

What Is Australia’s Scams Prevention Framework?

Australia’s Scams Prevention Framework is a separate regulatory regime from the ASIC HSBC enforcement case. It did not create the HSBC penalty. Do not let anyone weld those two together with a hot glue gun and call it legal analysis.

The Scams Prevention Framework is designed to impose obligations on regulated sectors to prevent, detect, report, disrupt, and respond to scams. Official Australian Government material states that banking, telecommunications, and key digital platforms have been designated as the first sectors under the framework.

AFCA has also stated that the Scams Prevention Framework includes a dedicated external dispute resolution scheme for scam-related complaints, and that the Government expressed its intention to authorise AFCA as the external dispute resolution scheme for the first three sectors: banks, telcos, and social media companies.

What the SPF may change

The Scams Prevention Framework is aimed at making regulated participants more accountable for scam prevention and response. For banking participants, that may mean clearer obligations around scam detection, reporting, disruption, and customer response as the regime is implemented.

But here is the legal guardrail: the SPF does not mean every scam victim is guaranteed compensation. It also does not retroactively explain the HSBC penalty unless an official source says so. ASIC’s HSBC case was its own enforcement action involving HSBC’s admitted failures and obligations connected with the ePayments Code and financial services law.

Why the distinction matters

If you are making an AFCA scam complaint or bank complaint, mixing up legal regimes can weaken your argument. You want a clean file, not a conspiracy board.

Use the HSBC case to show regulatory expectations around scam controls and handling where relevant.

Use the ePayments Code when your dispute involves unauthorised electronic transactions and subscriber obligations.

Use the Scams Prevention Framework as a future-facing accountability regime, especially where designated sectors and scam-related external dispute resolution become relevant.

Different tools. Different jobs. Same fraud battlefield.

Can You Take a Scam Complaint to AFCA?

Yes, many scam-related complaints can be taken to the Australian Financial Complaints Authority, but you usually need to complain to the financial firm first and give it a chance to respond.

AFCA says it provides free, fair, and independent dispute resolution for financial complaints. AFCA also explains that, when considering scam complaints, it currently looks at whether the transactions were authorised or unauthorised and considers entitlement to compensation based on how the transactions were made and the surrounding circumstances.

That is a crucial point. AFCA does not simply ask, “Were you scammed?” It examines the transaction, evidence, bank conduct, applicable legal principles, industry codes, good industry practice, and fairness.

Practical complaint pathway

Follow the boring path. Boring wins files.

  1. Report immediately to the bank.Ask the bank to freeze affected access, attempt recall or recovery, secure your account, and give you a complaint reference number.
  2. Request written reasons.If the bank refuses compensation, ask for the exact reasons, the rules applied, and the evidence relied on.
  3. Lodge an internal dispute.Make it formal. Use the bank’s complaints process. Do not rely only on branch conversations or call-centre sympathy noises.
  4. Preserve evidence.Keep transaction receipts, screenshots, SMS messages, emails, call logs, remote-access app details, crypto wallet addresses if relevant, and names used by scammers.
  5. Escalate to AFCA when eligible.If the bank’s final response is unsatisfactory, delayed, or unsupported, prepare an AFCA complaint with a clear chronology and evidence pack.

What AFCA will likely care about

AFCA scam complaints may turn on factors such as:

  • whether the transaction was authorised or unauthorised
  • how the scammer obtained access or persuaded payment
  • whether passcodes or security credentials were shared
  • when the customer reported the issue
  • whether the bank followed applicable timelines and procedures
  • what warnings or friction appeared before the transfer
  • whether the bank attempted recovery promptly
  • whether the bank’s denial was fair and properly reasoned

Some denials are valid. Some are lazy. Your job is to build the file well enough to tell the difference.

What Should You Do If Your Australian Bank Refuses Compensation?

If your Australian bank refuses compensation after a scam transfer, do not panic-email a wall of rage. Build the file like you expect someone independent to read it later.

Here is the working checklist.

Evidence checklist for a stronger bank or AFCA complaint

Evidence Why it matters
Transaction receipts Proves amount, date, receiving account, payment reference, and timing
Bank complaint reference Shows you reported and began the internal process
Scam messages Shows impersonation, pressure, deception, and instructions
Call logs Supports timing and contact pattern
Screenshots of websites or apps Preserves scam infrastructure before it vanishes
Police or ReportCyber reference Supports formal reporting, where applicable
Written bank decision Shows the bank’s reasoning and rules relied upon
Chronology of events Helps the reviewer understand sequence and urgency
Evidence of vulnerability May matter where health, age, coercion, disability, distress, or dependency affected decisions
Recovery attempt records Shows whether recall, freezing, or escalation happened promptly

For a deeper breakdown of how institutions review fraud claims, read Dollar Vigil’s guide on why banks reject scam refund claims and what evidence actually changes their minds.

What to write back to the bank

Ask the bank, in writing:

  • Was the transaction assessed as authorised or unauthorised?
  • Which rule, code, policy, or legal basis did the bank apply?
  • What evidence did the bank rely on?
  • Did the bank consider scam warnings, unusual account activity, payment pattern, and timing?
  • Did the bank attempt recall or recovery?
  • If the transaction involved unauthorised access, how did the bank apply the ePayments Code?
  • If compensation was refused, what exact facts led to that decision?
  • Is this the bank’s final response for AFCA purposes?

This is not about sounding dramatic. It is about forcing the denial to become specific. Vague denials love darkness. Specific questions turn the lights on.

Mistakes that weaken a complaint

Avoid these file-killers:

  • deleting scam messages because they are embarrassing
  • relying only on phone calls with no written follow-up
  • sending emotional accusations without evidence
  • waiting weeks before reporting
  • accepting a verbal refusal as final
  • paying a “recovery expert” who promises bank refunds
  • confusing authorised scam payments with unauthorised account access
  • quoting UK rules as if they automatically apply in Australia

The scam already stole enough. Do not let bad complaint handling steal your second chance at a proper review.

HSBC Case vs UK’s APP Reimbursement Rules

Australia and the United Kingdom do not have identical APP scam reimbursement rules. Do not import UK rights into an Australian complaint like contraband legal luggage.

In the UK, the Payment Systems Regulator introduced APP scam reimbursement protections for certain Faster Payments and CHAPS claims from 7 October 2024, with an initial maximum reimbursement level of £85,000 per claim. UK rules include exceptions, including where a customer is found to have been complicit or grossly negligent, with special treatment for vulnerable consumers.

Australia’s position is different. The ASIC HSBC case involved HSBC Bank Australia, unauthorised transactions under the ePayments Code, admitted failures, and a Federal Court penalty. Australia’s Scams Prevention Framework is developing separately as a broader scam prevention regime across sectors.

The comparison is useful for one reason: it shows that regulators internationally are getting less patient with scam excuses and payment-system shrugging. But UK reimbursement rules do not automatically give Australian victims the same rights.

Use the right jurisdiction or your complaint starts limping before it leaves the driveway.

What This Means for Australian Banking Going Forward

Confirmed fact: ASIC secured a $35 million Federal Court penalty against HSBC Bank Australia for admitted scam protection failures, and HSBC established a remediation program.

Analysis: the case sends a hard message to Australian banks. Scam protection is no longer just a customer education poster with a stock photo of a worried person holding a phone. Regulators are looking at controls, payment rails, investigation delays, customer access, and whether banks apply the rules correctly when losses happen.

The banking direction is clear:

  • stronger operational monitoring
  • better scam controls across payment systems
  • faster investigation timelines
  • clearer customer communication
  • more serious treatment of unauthorised transaction reports
  • greater scrutiny of “you authorised it” denial logic
  • more pressure from ASIC, AFCA, Treasury, and the Scams Prevention Framework

But do not turn that into fake certainty. Australian bank scam compensation still depends on facts. The future may bring stronger obligations, but your current complaint still needs evidence, timing, and the right legal route.

The best consumer strategy is not blind faith in the system. It is disciplined pressure.

Document everything. Ask precise questions. Escalate when the bank’s reasoning is weak. Avoid fake recovery services circling the wreckage like refund vultures with websites.

FAQ

Is HSBC paying compensation for scam protection failures in Australia?

Yes, HSBC has established a remediation program for affected customers. ASIC said the program assesses affected customers and compensates those who were not liable for losses under the ePayments Code, including for lost earnings caused by delays in accessing funds. ASIC stated on 18 June 2026 that around $21.5 million had been paid, with further payments expected before the end of July 2026. Readers should check HSBC’s current notices for the latest remediation status. This does not mean every HSBC scam victim automatically qualifies.

Can I get my money back from HSBC after a bank transfer scam?

You may be able to recover money from HSBC if your case falls within the remediation program, the ePayments Code supports your position, HSBC recovers funds, or a complaint outcome supports compensation. But there is no automatic refund rule for every bank transfer scam. Your chances depend on whether the transaction was authorised or unauthorised, how the scam happened, when you reported it, what HSBC did, and what evidence supports your complaint.

What did ASIC say HSBC did wrong?

ASIC said HSBC admitted serious failures in protecting customers from scams. ASIC’s 2026 court outcome announcement said HSBC took too long to investigate customer scam reports, did not apply ePayments Code rules for determining whether customers or the bank should bear losses, failed to implement key controls on the internal payment rail where most customer losses occurred, and lacked adequate systems to help customers regain banking access after scams.

What is ASIC Media Release 26-126MR?

ASIC Media Release 26-126MR is the ASIC announcement stating that a $35 million penalty would be sought after HSBC admitted scam protection failures and implemented a compensation plan. It explained that ASIC and HSBC would ask the Federal Court to find HSBC contravened the law and impose the agreed penalty. It is one of the key official sources for understanding HSBC’s admissions before the Federal Court made the final penalty order.

What is ASIC Media Release 26-127MR?

ASIC Media Release 26-127MR is the ASIC announcement confirming that the Federal Court ordered HSBC Bank Australia to pay a $35 million penalty for scam protection failures. It also explained the adverse publicity orders, HSBC’s remediation program, compensation already paid, recovered funds returned to customers, and ASIC’s statement that the proceedings concerned unauthorised transactions under the ePayments Code.

Does the Scams Prevention Framework guarantee compensation?

No. Australia’s Scams Prevention Framework is designed to impose scam prevention, detection, reporting, disruption, and response obligations on designated sectors. The first designated sectors include banking, telecommunications, and key digital platforms. AFCA has stated the framework includes a dedicated external dispute resolution scheme for scam-related complaints. But the SPF does not guarantee compensation for every victim, and it did not create the HSBC penalty.

How do I report an Australian bank that failed to stop a scam transfer?

Report the scam to your bank immediately, ask for recovery or recall action, secure your account, and request a complaint reference. If the bank refuses compensation, ask for written reasons and lodge a formal internal dispute. Preserve transaction records, scam communications, call logs, police or ReportCyber references where applicable, and a timeline. If the bank’s response is delayed, unsupported, or unfair, consider escalating the complaint to AFCA when eligible.

Authoritative Sources

This article is for general educational information only. It is not legal advice, financial advice, or a guarantee that money will be recovered. Scam refund rules vary by country, payment method, bank policy, evidence, timing, and case details. If you need advice about your specific situation, contact a qualified legal, financial, or consumer-rights professional in your jurisdiction.

Cold Truth

The HSBC case is a warning shot to Australian banking, not a golden ticket for every scam claim. It proves that regulators can punish weak scam handling and that compensation may follow where the facts and rules support it. But your personal recovery still depends on evidence, timing, transaction type, and whether the institution handled the file properly.

So build the file. Demand reasons. Escalate cleanly. And if a fake recovery expert promises guaranteed compensation, remember: the second scam usually arrives wearing a rescue vest.