Australians reported $554.1 million in combined scam losses across 122,550 reports to Scamwatch and ReportCyber in the first six months of 2026, according to the Australian Competition and Consumer Commission (ACCC). The figures, released during Scams Awareness Week (August 24 to 28), confirm a trend the ACCC’s Targeting Scams 2025 report established in March: losses increased 7.8% compared with 2024, reaching $2.18 billion across 481,523 combined reports for the full 2025 year. For insurance brokers, the headline loss figure is context. The actionable story is what surrounds it: a Federal Court penalty that has set a new standard for institutional scam liability, a regulatory framework reshaping complaint rights from next year, and policy wordings that may not respond to the losses clients are most likely to suffer.
In June 2026, the Federal Court ordered HSBC Bank Australia to pay a $35 million penalty after the bank admitted to serious failures in protecting customers from scams. Australian Securities and Investments Commission (ASIC) chair Sarah Court described the outcome as “the strongest scam wake-up call yet to the banking industry,” adding that “banks have been well on notice about the risks of scams for some time.”
Between January 2020 and August 2024, HSBC received more than 1,000 reports of unauthorised transactions with a total transaction value of $34.6 million. HSBC admitted it failed to do all things necessary to ensure that its financial services were provided efficiently, honestly, and fairly. To date, HSBC has paid approximately $21.5 million in compensation, with a further $6.5 million recovered and returned to customers.
The case originated from a series of spoofed SMS scams in which fraudsters impersonated the bank inside legitimate message threads, then manipulated customers into disclosing account passcodes. The Australian Financial Complaints Authority’s (AFCA) published determination in the lead case – case number 12-00-1016692, handed down August 22, 2024 – found the complainant did not voluntarily disclose passcodes to the scammer, as the scammer’s tactics created coercion that impacted the complainant’s free will. That determination informed the ASIC proceedings that culminated in the Federal Court penalty. The implication for brokers is direct: institutional liability for scam losses is no longer theoretical. Financial firms are facing court-ordered penalties and compensation programs. The question of whether clients’ policies respond to the losses that flow from these events is now a live coverage question, not a hypothetical one.
The ACCC’s Scams Awareness Week campaign highlighted a building client who lost a $20,000 deposit after a fraudulent payment link replaced a legitimate request from his builder – a textbook business email compromise (BEC) scenario, and one of the most commonly sublimited coverage lines in the Australian market. Social engineering and business email compromise can also be subject to specific sublimits or exclusions rather than the full cyber policy limit. Epic IT’s June 2026 review of the Australian SMB cyber market identified social engineering and business email compromise sublimits among the coverage restrictions appearing in current policies. The National Anti-Scam Centre (NASC) recorded $166.8 million in reported losses from payment redirection scams in 2025, highlighting the scale of a loss category that can create significant coverage questions for businesses.
The Scams Prevention Framework Bill 2025 passed both houses of Parliament on Feb. 13, 2025 – the first specific legislative attempt to combat scams in Australia – imposing obligations on banks, telecommunications companies, and digital platforms, with fines of up to $50 million for entities that fail to take reasonable steps. From July 1, 2026, AFCA became the authorised external dispute resolution scheme for scam-related complaints under the framework across banking, telecommunications, and digital platforms. From March 31, 2027, consumers and small businesses will be able to lodge formal scam complaints with AFCA under that framework. The Scams Prevention Framework does not currently include insurers within its designated sectors, but it directly shapes the liability environment in which brokers’ clients operate – and the adequacy of scam-related coverage sits squarely within that environment. During 2024-25, financial firms received more than 159,000 scam and fraud complaints, according to ASIC, while AFCA itself received 5,977 scam-related complaints in 2024-25, with total compensation and refunds across all complaint types reaching $390.9 million.
ACCC deputy chair Catriona Lowe framed the underlying exposure in terms relevant to any broker reviewing a client's risk profile. “Behind every reported loss is a person who has been harmed, whose life has been disrupted by criminals using pressure, impersonation, psychology, and technology including AI to steal their money or identity,” Lowe said. Under section 912B of the Corporations Act 2001, every AFSL holder providing services to retail clients must hold adequate professional indemnity insurance covering financial services activities. Where a broker places a cyber or business crime policy with a social engineering sublimit that leaves a client materially exposed to the loss types the ACCC data shows are prevalent and growing, that advice gap carries its own professional indemnity dimension.
The questions worth raising with clients and their insurers include: whether the policy responds to social engineering losses where no network intrusion occurred; what sublimit applies to business email compromise; whether a commercial crime policy provides layered cover for losses that fall outside the cyber trigger; and whether recent policy cycles have introduced AI-specific exclusions or narrowed existing social engineering definitions.
The ACCC’s consumer-facing framework – Stop, Check, Protect – is aimed at individuals. The parallel obligation for brokers is structural: confirming before renewal that clients’ policy schedules reflect the documented and growing risk that scam losses will occur, will be of a type that standard wordings may sublimit or exclude, and will land in a regulatory environment where the institutional accountability bar has now been set by a Federal Court judgment.