Skip to content
AussieLedger
Scams, safety & emergenciesHow to17 min read · verified

How to get your money back after a scam payment

Recovery turns on one question: was the payment unauthorised, mistaken, or one you were tricked into authorising? Each carries different rules, different deadlines and very different odds of getting the money back.

Short answer

Work out first whether the payment was unauthorised, mistaken, or one you were tricked into authorising — that classification decides which rules apply. Report it to your bank immediately and in writing, and ask for a recall and a trace. If the bank refuses to reimburse you, complain internally, then take it free to AFCA on 1800 931 678.

Reporting a scam and recovering money from one are different problems with different owners. Reporting is quick, free and mostly administrative — you tell Scamwatch, you tell ReportCyber, you get a reference number. Recovery is slow, adversarial and decided almost entirely by a single classification made in the first hours: whether the money left your account without your permission, whether it went to the wrong account by mistake, or whether you pressed send yourself because somebody talked you into it. Those three things look identical on a bank statement. They are governed by completely different rules, and they carry completely different odds.

The rule book that matters most is ASIC's ePayments Code. It is voluntary, but nearly every retail bank, credit union and building society in Australia subscribes to it, and it does two specific things: it sets the rules for who pays for an unauthorised transaction, and it establishes a regime for recovering mistaken internet payments. What it does not do — and this is the whole difficulty — is give you a right to a refund when you authorised the payment yourself. That is the category almost every scam falls into, and it is the category the law has only recently started to address.

The recent movement is real but its timing is awkward. The Scams Prevention Framework Act 2025 built an economy-wide regime of obligations on banks, telecommunications providers and digital platforms, and AFCA has been authorised as the single external dispute resolution scheme for scam complaints under it. But AFCA can only consider SPF complaints about matters occurring on or after 31 March 2027. Separately, and more useful to you today, AFCA's Rules changed on 12 March 2026 to let it investigate scam complaints involving receiving banks and mule accounts — meaning the bank that took the money in can now be brought into the case.

This page is about what you can actually do, in what order, and against whom. It sets out what to demand from your own bank and what machinery sits behind that demand, how the ePayments Code allocates liability, the clocks that run on mistaken payments, how to build the argument that gets an authorised scam payment reimbursed, where card chargebacks fit, which payment rails are effectively unrecoverable, and how to escalate. It is deliberately honest about the odds. The National Anti-Scam Centre's own reporting shows most scam losses are never returned.

Work out which of three things happened before you argue anything

An unauthorised transaction is money moved out of your account without your permission — a stolen card, a compromised login, a payment made by someone who got your codes. Moneysmart defines it exactly that way: someone transferring money from your account without your permission. This is the strongest position you can be in, because the ePayments Code sets rules for who bears the loss and the default is not you.

A mistaken transaction is a payment you made deliberately but to the wrong account — you keyed a digit wrong, you used an old BSB, you paid an invoice whose bank details had been altered. Moneysmart's definition is paying the wrong person or company by using the wrong bank details. This has its own recovery machinery under the Code, run between the sending and receiving institutions rather than through a liability argument.

An authorised payment procured by deception is the third and by far the commonest scam case. You were shown a fake invoice, a fake investment portal, a fake romance, a fake bank employee telling you to move funds to a 'safe' account. You typed the details, you approved the payment, and the transaction is genuine in every technical sense. Historically this category had the weakest protection of the three, because nothing was unauthorised and nothing was keyed incorrectly.

The boundaries between the three are not always where you expect. If a scammer using remote access software moved money while you watched the screen, that is closer to unauthorised than authorised. If you paid a real supplier's real invoice but a criminal had intercepted the email and swapped the account details, that is payment redirection — the National Anti-Scam Centre recorded $166.8 million of it in 2025 — and it sits awkwardly between mistaken and authorised, which is precisely why it is worth arguing about.

Write down which category you are claiming and why, before you call. Banks triage on this classification, and a claim that drifts between categories during the call gets handled as the weakest of them. If you genuinely do not know — for example, you shared a one-time code under pressure and are not sure what was done with it — say so plainly and ask the bank to establish from its own logs which of its systems authenticated the payment.

Keep the raw material. Screenshots of the messages, the phone number that called you, the website address, the invoice as it arrived and the invoice as it should have read, the exact times. Every subsequent step — the bank's internal review, an AFCA complaint, a police report, a civil claim — runs on the same evidence, and it is far easier to gather on day one than on day sixty.

What to demand from your bank, and the machinery sitting behind it

Call the fraud line, then follow up the same day in writing through internet banking or email. The phone call starts the clock; the written record proves when. Moneysmart's advice is blunt about why this matters — the sooner you contact your bank, the more likely you are to get your money back, and where the transaction is unauthorised the sooner the bank can stop further transactions.

Ask for five specific things and name them: an attempted recall of the payment, a trace of where the funds went, a block on further payments to that payee, a review or freeze of the account if your credentials or device were compromised, and a written complaint reference number. Moneysmart specifically tells you to get a reference number when you report a mistaken or unauthorised transaction, because you will need it every time you contact them again.

The recall is not a phone call between two managers. Under the Australian Banking Association's Scam-Safe Accord, all ABA and Customer Owned Banking Association members committed to joining the Australian Financial Crimes Exchange and the automated Fraud Reporting Exchange — the FRX being, in the ABA's own words, the system used to recover money that customers have paid to another account. When your bank raises a recall, it is putting a request into that shared system for the receiving bank to freeze what remains.

That is why hours matter more than days. The FRX can only freeze funds that are still sitting in the receiving account. Scam proceeds are routinely broken up and moved through several mule accounts within minutes, or converted to cryptocurrency, and once they have left the regulated banking system the ABA itself describes recovery as virtually impossible. A recall raised on the same morning has a materially different prospect from one raised the following week.

Ask, in writing, what the bank's own systems did before the payment left. The Scam-Safe Accord also committed retail banks to a confirmation-of-payee name-checking system, to increased warnings, payment delays and security questions when you pay someone new or raise a limit, and to limiting payments to high-risk channels including some crypto platforms. If none of that fired on a large, out-of-character payment to a brand-new payee, that is a question the bank has to answer, and it becomes the spine of any later complaint.

Do not accept a verbal decline. Ask for the outcome in writing, with the reason, and for the internal dispute resolution reference. Banks are required to have an internal dispute resolution process, and Moneysmart's instruction is explicit: your first step is a formal complaint through that process, and only then can you take it to AFCA.

Finally, secure the rest of the account. If you shared a password, a one-time code, or gave anyone remote access to your device, the bank should be treating the account as compromised rather than treating one payment as an isolated event. Say the words 'remote access' if they apply — Moneysmart lists remote access scams as one of the three main banking scam types, and it changes how the claim is handled.

Unauthorised transactions: what the ePayments Code makes the bank carry

ASIC's ePayments Code applies to consumer electronic payment transactions — ATM, EFTPOS and credit card transactions, online payments, internet and mobile banking, and BPAY — and it expressly sets out the rules for determining who pays for unauthorised transactions. If your institution is a subscriber, those rules are not a matter of goodwill. Check ASIC's subscriber list if you are unsure whether yours has signed up.

Moneysmart sets out the circumstances in which you are more likely to get your money back, and they read as a list of situations where the bank or a third party, rather than you, created the exposure: a forged, expired, blocked or cancelled card was used; a bank employee or a seller made the transaction fraudulently; the transaction happened before you received your card, PIN or password; a seller debited your account more than once; the transaction happened after you told the bank your card was lost or stolen; or after you told the bank someone may know your PIN or password.

The catch-all in that list is the most important line in the whole area: you are more likely to be reimbursed where it is clear that you have not contributed to the loss. That is the pivot. The argument in an unauthorised transaction case is almost never about whether the transaction happened — it is about whether you contributed to it, and the practical burden of showing that you did sits with the bank.

Moneysmart is equally clear about where you lose. You are less likely to get your money back if you acted fraudulently, did not keep your PIN or password secret, unreasonably delayed telling the bank your card was lost or stolen, unreasonably delayed telling the bank that someone else may know your PIN or password, or left your card in an ATM. Three of those five turn on delay or on secrecy of credentials, which is why the first call and an honest account of what you disclosed both matter so much.

The soft spot in most real cases is the one-time code. Scammers running bank-impersonation scripts talk people into reading out an SMS code, or into approving an in-app prompt while being told it is a security check. Moneysmart's own guidance is that while your bank may contact you about a suspicious transaction, it will never ask for online banking passwords or codes, ask you to download software, ask you to transfer money, or ask you to log in through a link in a text or email. A bank will lean on a disclosed code to argue you contributed to the loss.

That argument is not automatically fatal. Whether a disclosure amounts to contributing to a loss is a judgement, not an arithmetic result, and it is exactly the kind of judgement AFCA is set up to review. Where you disclosed a code because a spoofed number and a convincing script made you believe you were speaking to the bank's own fraud team, say so in those terms and put it in writing, because that framing is what an external reviewer will weigh.

Watch the account for a second wave. Moneysmart's advice after any compromise includes signing out of all accounts and devices, creating new and previously unused passwords, monitoring the account closely for further unauthorised transactions, requesting a temporary ban on your credit report so no new credit can be taken out in your name, and requesting a free copy of that report to check for applications you do not recognise.

Mistaken internet payments: the clock that starts the moment you report

If you paid the wrong account, the ePayments Code establishes a regime for recovering mistaken internet payments. This is a process rather than a liability contest — your bank contacts the receiving institution, the receiving institution investigates whether the funds are still there, and the money is returned if the rules are satisfied. You do not have to prove anybody was at fault.

Two things determine whether it works, and Moneysmart names both: how quickly you report it, and whether the unintended recipient still has enough money in their account to cover the payment. The second is outside your control, which makes the first everything. Money in an ordinary account belonging to a person who mistyped a digit tends to stay put; money in an account controlled by a criminal does not.

The timing thresholds are the part most people never hear about. Under the ePayments Code, as Moneysmart summarises it, different rules apply depending on whether you make the report within 10 business days, after 10 business days, or after seven months. Reporting inside the first threshold gives you the strongest version of the process. After seven months the position weakens considerably. Ask your bank which threshold your report falls into and have the answer recorded.

Payment redirection sits on the boundary of this category and is worth arguing carefully. If an invoice arrived with a criminal's BSB and account number because the sender's email was compromised, you used the wrong bank details — which is the literal definition of a mistaken transaction — even though the details were wrong by design rather than by typing error. Whether your bank treats it as mistaken or as an authorised scam payment materially changes the process applied, so raise the point rather than letting it be decided silently.

Where the receiving bank identifies the account holder and the funds are still there, the process can be quick. Where the account holder disputes that the payment was mistaken, or the funds have been withdrawn, it stops — the Code's machinery does not compel a stranger to hand money back if it has already gone. At that point the question becomes whether you can pursue the recipient directly, which is dealt with further down this page.

Do not let the mistaken-payment process substitute for a complaint. If your bank declines to pursue a recovery, delays past a threshold, or cannot tell you what the receiving institution said, that is itself a complaint about the bank's conduct — separate from whether the money comes back — and Moneysmart specifically directs people to internal dispute resolution and then AFCA where their institution is not doing enough to help retrieve mistaken payments.

Payments you authorised: the hardest case, and what changed in 2026

This is the category most scams fall into, and until recently it was close to a dead end. You approved the payment, the bank executed the instruction you gave, and the ePayments Code liability rules — built around transactions you did not authorise — have nothing direct to say. AFCA's own framing of the problem is stark: in 2023 Australians lost over $2.74 billion to scams and 65 per cent of victims received no refund or remedy.

The Scams Prevention Framework Act 2025 was the response. It amends the Competition and Consumer Act 2010 to create an economy-wide regime under which the Minister designates sectors — beginning with banks, telecommunications providers and digital platform services covering social media, paid search engine advertising and direct messaging — and requires participants in those sectors to have measures to prevent, detect, report, disrupt and respond to scams. Treasury describes the design as deliberately whole-of-ecosystem, with tough penalties for non-compliance and dispute resolution pathways for consumers to seek redress.

The redress pathway is AFCA, and its timing needs to be understood precisely because it is easy to misread. AFCA has been authorised as the single external dispute resolution scheme for scam complaints under the Framework from 1 July 2026. Designated organisations must be AFCA members from 1 September 2026. But consumers and small businesses can only make an SPF scam complaint to AFCA from 31 March 2027, and AFCA states plainly that it has no jurisdiction to consider SPF complaints about matters occurring before that date.

The change that helps a scam victim today is a different one. AFCA's Rules were amended with ASIC's approval and took effect on 12 March 2026, expanding AFCA's jurisdiction to consider complaints involving receiving banks and mule accounts in scam complaints. Before that, your complaint was effectively confined to your own bank. Now the institution that opened and operated the account the money landed in can be brought into the same case, and its account-opening and monitoring conduct examined.

That reframes how you should write the complaint. Rather than only asking whether your bank should have stopped you, ask whether the receiving bank should have allowed the account to exist and to receive the payment. Name the receiving institution if you know it — it appears on your transaction record and your bank's trace should confirm it. Moneysmart now says this in terms: you can make a complaint against your bank, or a receiving bank, if you think they contributed to your loss.

Build the case on conduct, not sympathy. The Scam-Safe Accord commitments give you a concrete standard to measure against: confirmation-of-payee name checking, biometric checks for new online account openings at major banks, increased warnings and payment delays and security questions on new payees and raised limits, shared intelligence through the AFCX and FRX, and limits on payments to high-risk channels. Set out which of those should have fired on your payment and did not, on either side of the transaction.

Expect the argument to be about apportionment rather than a binary. AFCA says it will only provide a remedy where it decides you incurred loss or harm caused by the financial firm's conduct, and that it seeks either to put you in the position you would have been in had that conduct not caused the loss, or to compensate you to the extent it holds the firm responsible. Partial outcomes are normal, and a partial recovery is still a recovery.

Card payments, crypto, remittance and cash: where each rail leaves you

If you paid a scammer by credit or debit card, you have a second and independent route: a chargeback through the card scheme rules, raised by your bank against the merchant's bank. Moneysmart's instruction for card payments is the same as for transfers — contact your card provider immediately, ask them to stop any transactions and ask what other action to take — but the chargeback mechanism itself runs on scheme deadlines rather than the ePayments Code, so it has its own clock. Raise both claims, not one.

Cryptocurrency is the hardest rail. Moneysmart's guidance where you have paid a scammer in crypto is to report it to the platform, virtual asset service provider or digital currency exchange you used, and that is essentially the whole of the remedy — there is no scheme reversal and no code-based recovery regime. The Australian Banking Association's own description of why banks now limit payments to some crypto platforms is that once money has moved to these higher-risk channels it is virtually impossible to recover.

That does not make the report pointless. A registered Australian exchange holds identity records and can freeze a receiving wallet if it is still holding the funds and is told fast enough, and the report becomes evidence for the argument that your bank should have applied high-risk channel limits before the transfer left. Report it the same day, in writing, and keep the transaction hash.

Money transfer apps and remittance channels sit in between. Moneysmart directs you to report to the app provider — the seller or developer, not the app store — and the same speed logic applies, because these services settle quickly and the funds are collected at the other end. Where the transfer went overseas through a remittance provider, ask both your bank and the provider to attempt a recall and ask each of them to confirm in writing whether the payout has been collected.

Gift cards are reported to the company that issued the card, and cash sent by mail or courier is chased by asking Australia Post or the delivery service to intercept the package. Both are long odds, and both depend on the funds or the parcel not yet having been collected. Neither has any dispute mechanism behind it, which is the practical reason scammers ask for them.

Whatever the rail, put the request in writing and keep the timestamp. A refusal from a crypto exchange, remittance provider or gift card issuer is not the end of the matter — whether your bank should have intervened before the money reached that rail survives the refusal, and that question is one AFCA can decide.

When the bank says no: internal dispute resolution, then AFCA

Moneysmart sets the sequence out plainly for both unauthorised transactions and mistaken payments: if you feel your financial institution is not doing enough, or is unwilling to refund unauthorised transactions you believe should be refunded, your first step is a formal complaint through its internal dispute resolution process, and if you are unhappy with that you take the complaint to AFCA. Skipping the internal step tends to send the file straight back.

Write the internal complaint as a document, not a phone call. State the transaction date, amount, payee and receiving institution; state which of the three categories you say it falls into and why; set out what you asked the bank to do and when; identify the specific controls that did not operate; and state the outcome you want. Ask for a final response in writing. That document becomes the AFCA complaint almost unchanged.

AFCA is free, fair and independent, funded by financial firms rather than by complainants, and it covers banking deposits and payments among its complaint categories. Making a complaint online takes roughly 30 to 50 minutes and you can save your progress and return to it. You can also complain by phone on 1800 931 678, by email, or in writing, and you can appoint an authorised agent to act for you using AFCA's agent authority form.

Support is built in if you need it. AFCA publishes translated complaint forms and information in other languages, and you can reach it through the Translating and Interpreting Service on 131 450 by asking for your language and then for AFCA, or through the National Relay Service quoting 1800 931 678. None of that costs anything.

Know the limits before you lodge. AFCA states that it may not be able to help where a court has already decided the matter, where the complaint falls outside the issues its Rules allow it to consider, where it is outside the relevant time limits, or where the organisation is not an AFCA member. Time limits are the one that catches scam victims — Moneysmart's instruction is to complain to AFCA as soon as possible after your institution has finished considering your complaint, because time limits apply.

The remedies are broader than a refund. AFCA can order payment of a sum of money, the forgiveness or variation of a debt, the repayment or waiver of a fee, the variation or setting aside of a contract, and an apology, among others. It cannot impose punitive or exemplary damages. Where a scam payment was funded by a loan or a credit card the bank pushed through, the debt-side remedies can matter as much as the cash.

Determinations bind the financial firm, not you — if you reject the outcome, you keep whatever rights you had to go to court. Since the 12 March 2026 Rules changes AFCA can also publish the names of financial firms that fail to comply with its Determinations, which is a meaningful lever. If the loss has left you unable to meet repayments in the meantime, the National Debt Helpline on 1800 007 007 provides free, confidential financial counselling while the complaint runs.

Assemble one evidence file and reuse it for everything. The internal complaint, the AFCA complaint, a police report and any civil claim all draw on the same material — the transaction record, the reference numbers the bank gave you, the scam communications, and a timeline recorded in times rather than dates. A ReportCyber lodgement is worth making early because it produces the police reference number banks and credit reporting bodies ask for, and the Australian Cyber Security Hotline on 1300 292 371 operates around the clock if a device or account also needs cleaning up.

If you know who received the money: pursuing the recipient directly

Sometimes the trace succeeds and the money is sitting in an identifiable Australian account whose holder will not give it back. This happens most often with mistaken payments and with payment redirection, and occasionally with a mule account holder who has been recruited rather than being the scammer. The banking recovery process cannot compel a stranger to return funds once they dispute it, but a court can.

The claim is an ordinary civil one for money the recipient has no right to keep. It is filed in the small claims or minor civil jurisdiction of the state or territory where the defendant lives, and each jurisdiction runs its own body with its own monetary ceiling and its own filing fee. These are designed to be used without a lawyer, and the filing fees are modest relative to the amounts usually at stake.

You need the recipient's name and an address for service, which is the practical obstacle. Your bank will not hand over another customer's details on request. The routes that do work are a court order for the information, or the receiving bank disclosing it as part of a mistaken payment recovery, or the recipient identifying themselves when contacted through their bank. Ask your bank in writing what it can lawfully tell you and what it needs to see before it will.

Be realistic about which cases are worth it. Pursuing a genuine mistaken recipient who has spent the money is usually a matter of an enforceable judgement and a payment plan. Pursuing a professional mule account is usually pursuing someone with no assets, an address that no longer exists, and often another victim of the same scam. A judgement you cannot enforce costs you the filing fee and months of effort.

Run the civil claim in parallel with the bank complaint, not instead of it. AFCA cannot consider a complaint a court has already decided, so sequencing matters — but a claim against a third-party recipient is a different matter from a complaint about your bank's conduct, and pursuing the recipient does not usually close off the AFCA route against the bank. If you are unsure, ask AFCA before you file.

Finally, guard against the second scam. Moneysmart's warning list is specific: after a loss you may be approached by someone offering to help recover what you lost, offering to swap your investment for another one, offering to buy your shares at a premium if you pay a fee to lift 'restrictions', or claiming they can recover your losses for a percentage or for a payment described as a tax, deposit, retainer or refundable insurance bond. These are strategies to take more money from you. No legitimate recovery route in Australia — not your bank, not AFCA, not the courts' filing process — is sold to you by someone who contacts you first.

Where a small civil claim against an identified recipient is filed, by state and territory
State or territoryBodyNotes
New South WalesLocal Court of NSWCivil claims begin in the Local Court; small claims are dealt with in its Small Claims Division
VictoriaMagistrates' Court of VictoriaCivil jurisdiction of the Magistrates' Court
QueenslandQueensland Civil and Administrative TribunalMinor debt disputes, for a fixed or agreed sum up to and including $25,000
Western AustraliaMagistrates Court of Western AustraliaMinor cases and general civil claims
South AustraliaMagistrates Court of South AustraliaCivil (general) and civil (minor) claims divisions
TasmaniaMagistrates Court of TasmaniaMinor civil claim for $15,000 or less; larger claims proceed as general civil
Australian Capital TerritoryACT Civil and Administrative TribunalCivil disputes, including disputes about debt
Northern TerritoryLocal Court of the Northern TerritoryFirst-tier court dealing with civil as well as criminal matters

Compiled from each body's own website in August 2026: the Local Court of NSW, the Magistrates' Court of Victoria, QCAT, the Magistrates Court of Western Australia, the Courts Administration Authority of South Australia, the Magistrates Court of Tasmania, ACAT and the Local Court of the Northern Territory. The $25,000 Queensland figure is QCAT's published minor debt threshold and the $15,000 Tasmanian figure is that court's published minor civil claim threshold; both are set by state law and change, so confirm before filing.

Key takeaways

  • Classify the payment first — unauthorised, mistaken, or authorised-under-deception — because each is governed by different rules and banks triage on that classification.
  • For unauthorised transactions the ePayments Code puts the loss on the bank unless it can show you contributed to it, and Moneysmart lists exactly which circumstances cut each way.
  • Mistaken internet payments have their own recovery regime under the ePayments Code, with different rules applying within 10 business days, after 10 business days, and after seven months.
  • Since 12 March 2026 AFCA can investigate scam complaints involving receiving banks and mule accounts, so name the institution that received the money, not only your own bank.
  • The Scams Prevention Framework's consumer complaint pathway to AFCA opens on 31 March 2027 and covers only matters occurring on or after that date — until then the working routes are the ePayments Code and AFCA's ordinary jurisdiction.

Who to contact

  • Australian Financial Complaints Authority

    Free, independent external dispute resolution for complaints about your bank and, since 12 March 2026, about receiving banks and mule accounts in scam complaints. Determinations bind the firm, not you.

    1800 931 678

    9am–5pm AEST weekdays; interpreter via 131 450

  • Moneysmart — unauthorised and mistaken transactions

    ASIC's plain-English guide to what makes a transaction unauthorised or mistaken, when the bank must help, and the ePayments Code reporting thresholds.

  • IDCARE

    Free national identity and cyber support service. Build a response plan if identity documents or personal details were exposed alongside the payment.

    1800 595 160

  • Scamwatch

    National Anti-Scam Centre reporting. Feeds disruption and takedowns and builds the pattern evidence that can support your own claim; does not recover funds.

  • National Debt Helpline

    Free, confidential financial counselling if the loss has left you unable to meet repayments while a recovery claim runs.

    1800 007 007

    Weekdays 9:30am–4:30pm; live chat 9:00am–8:00pm

  • Australian Cyber Security Hotline

    24-hour technical advice on cleaning up a compromised device or account, and the route to a ReportCyber police reference number.

    1300 292 371

At a glance

The decisive question
Unauthorised, mistaken or authorisedThree categories, three sets of rules — get this right before you argue anything
Rule book
ePayments CodeASIC's code; voluntary but subscribed to by most banks, credit unions and building societies
Mistaken payments
Report inside 10 business daysMoneysmart: different rules apply within 10 business days, after 10 business days, and after seven months
Scam payments you authorised
No automatic refund rightThe ePayments Code liability rules are built around unauthorised transactions, not ones you made
Receiving bank
In AFCA's jurisdiction since 12 Mar 2026AFCA Rules now cover scam complaints involving receiving banks and mule accounts
SPF complaints to AFCA
From 31 March 2027And only about matters occurring on or after that date — earlier events are out of SPF jurisdiction
External dispute resolution
AFCA — 1800 931 678Free to you, funded by financial firms, binding on the firm and not on you
Reported losses, 2025
$2.18 billionCombined losses across Scamwatch, ReportCyber, IDCARE, AFCX and ASIC — Targeting scams report 2025
Questions people also ask

How to get your money back after a scam payment — FAQ

Can I get my money back if I sent it to a scammer myself?

Sometimes, but it is the hardest of the three categories because nothing was unauthorised. Report it to your bank the same day and ask for a recall and a trace, then complain in writing about the controls that should have flagged the payment. Since 12 March 2026 AFCA can also examine the receiving bank's conduct and the account the money landed in.

How long do I have to report a mistaken bank transfer in Australia?

Report it immediately. Moneysmart explains that under the ePayments Code different rules apply depending on whether you report within 10 business days, after 10 business days, or after seven months, and that recovery also depends on the unintended recipient still holding enough money in the account. The first threshold gives you the strongest version of the recovery process.

What is the ePayments Code and does it apply to my bank?

It is ASIC's code covering consumer electronic payments — ATM, EFTPOS, card, online, internet and mobile banking and BPAY. It sets the rules for who pays for unauthorised transactions and establishes a regime for recovering mistaken internet payments. It is voluntary, but most banks, credit unions and building societies subscribe. ASIC publishes a list of subscribers you can check.

My bank says I authorised the payment so it will not refund me. What now?

Ask for the decision and its reasons in writing, then lodge a formal internal dispute resolution complaint setting out which of the bank's own scam controls should have operated and did not. If that fails, take it free to AFCA on 1800 931 678. Name the receiving bank as well — AFCA's Rules have covered receiving banks and mule accounts since 12 March 2026.

Does the Scams Prevention Framework mean banks have to refund me now?

Not yet, and the dates matter. The Scams Prevention Framework Act 2025 imposes prevent, detect, report, disrupt and respond obligations on banks, telcos and digital platforms, and AFCA became the authorised external dispute resolution scheme for it on 1 July 2026. But consumers can only bring SPF complaints to AFCA from 31 March 2027, and only about matters occurring on or after that date.

Can I complain about the bank that received my money rather than my own?

Yes. Moneysmart states you can complain about your bank or a receiving bank if you think they contributed to your loss, and AFCA's Rules were expanded on 12 March 2026 to let it consider scam complaints involving receiving banks and mule accounts. Identify the receiving institution from your transaction record or your bank's trace and name it in the complaint.

Is there any way to recover cryptocurrency sent to a scammer?

Rarely. Report it immediately to the exchange or virtual asset service provider you used, which is what Moneysmart advises, and keep the transaction hash. A registered exchange can sometimes freeze a wallet still holding the funds. The Australian Banking Association describes recovery once money leaves the regulated banking system as virtually impossible, which is why banks now limit payments to some crypto platforms.

Someone has offered to recover my scam losses for a fee. Is that legitimate?

No. Moneysmart lists recovery offers as a standard follow-up scam, along with offers to swap your investment, to buy your shares if you pay a fee to lift restrictions, or to recover losses for a percentage or a payment called a tax, deposit, retainer or refundable insurance bond. Legitimate routes — your bank, AFCA, the courts — never approach you first.

Read next

Sources & provenance

Facts verified

  1. 1.Unauthorised and mistaken transactions RegulatorMoneysmart (ASIC)Used for: Definitions of unauthorised and mistaken transactions, the lists of circumstances making reimbursement more or less likely, the ePayments Code reporting thresholds of 10 business days and seven months, and the internal dispute resolution then AFCA escalation path
  2. 2.What to do if you've been scammed RegulatorMoneysmart (ASIC)Used for: Payment-method-specific instructions for bank transfer, card, gift card, money transfer app, crypto and cash; the statement that you can complain about your bank or a receiving bank; the follow-up scam warning list; and the credit ban and IDCARE steps
  3. 3.Banking scams RegulatorMoneysmart (ASIC)Used for: Phishing, bank impersonation and remote access scam mechanics, spoofed caller ID, and the list of things a bank will never ask you to do
  4. 4.ePayments Code RegulatorASICUsed for: Scope of the Code across ATM, EFTPOS, card, online, internet and mobile banking and BPAY; that it sets the rules for who pays for unauthorised transactions and establishes a regime for recovering mistaken internet payments; and that subscription is voluntary with a published subscriber list
  5. 5.Scams Prevention Framework RegulatorAustralian Financial Complaints AuthorityUsed for: AFCA's authorisation as the single SPF external dispute resolution scheme from 1 July 2026, membership from 1 September 2026, consumer complaints from 31 March 2027 with no jurisdiction over earlier matters, and the 2023 figure that 65% of victims received no refund or remedy
  6. 6.2025 Rules Consultation RegulatorAustralian Financial Complaints AuthorityUsed for: ASIC-approved Rules changes effective 12 March 2026: expanded jurisdiction over receiving banks and mule accounts in scam complaints, and the ability to publish the names of firms that fail to comply with Determinations
  7. 7.Make a complaint RegulatorAustralian Financial Complaints AuthorityUsed for: That AFCA is free, fair and independent; the banking deposits and payments category; the 30–50 minute online form; agent authority; interpreter access on 131 450 and the National Relay Service; and the circumstances in which AFCA cannot help, including time limits and non-member firms
  8. 8.Outcomes AFCA provides RegulatorAustralian Financial Complaints AuthorityUsed for: The remedies available — payment of money, debt forgiveness or variation, fee repayment or waiver, contract variation or setting aside, apology — the requirement that loss was caused by the firm's conduct, and the exclusion of punitive or exemplary damages
  9. 9.Scams Prevention Framework Act 2025 (No. 15, 2025) LegislationFederal Register of LegislationUsed for: The Act as made on 20 February 2025 and its Schedule 1 amendments to the Competition and Consumer Act 2010, the ASIC Act, the Corporations Act and the ACMA Act
  10. 10.Scams Prevention Framework — exposure draft legislation OfficialThe TreasuryUsed for: The framework's design as an economy-wide, whole-of-ecosystem reform; ministerial sector designation beginning with banks, telecommunications and digital platform services covering social media, paid search advertising and direct messaging; the prevent, detect, report, disrupt and respond obligations; and the inclusion of consumer dispute resolution pathways
  11. 11.Targeting scams: report of the National Anti-Scam Centre on scams data and activity 2025 StatisticsACCC / National Anti-Scam CentreUsed for: Combined 2025 losses of $2.18 billion across Scamwatch, ReportCyber, IDCARE, the AFCX and ASIC, 481,523 reports, and payment redirection losses of $166.8 million
  12. 12.Scam-Safe Accord IndustryAustralian Banking AssociationUsed for: The confirmation-of-payee name-checking system, biometric checks on new online accounts, increased warnings and payment delays on new payees and raised limits, ABA and COBA members joining the AFCX and the Fraud Reporting Exchange used to recover money paid to another account, and limits on high-risk payment channels including some crypto platforms
  13. 13.Minor debt disputes OfficialQueensland Civil and Administrative TribunalUsed for: That QCAT hears debt disputes about a fixed or agreed sum of money up to and including $25,000 as minor debt disputes
  14. 14.Civil matters OfficialMagistrates Court of TasmaniaUsed for: That a Tasmanian civil claim up to and including $15,000 proceeds as a minor civil claim

Not a source — AI-assisted analysis on this page

  • AI-assisted analysis — classify the payment before you tell the storyThe recommendation to decide and state which of the three categories your payment falls into before contacting the bank, and the observation that an unstructured chronological account tends to be triaged into the weakest pathway, are our reasoning over how Moneysmart and ASIC define the categories. Neither publisher gives consumers advice about how to frame a claim.
  • AI-assisted analysis — the Scams Prevention Framework gap in 2026The conclusion that a scam victim in mid-2026 has no personal remedy under the Scams Prevention Framework, and that the working routes in the interim are the ePayments Code, AFCA's ordinary jurisdiction over a bank's conduct and the 12 March 2026 receiving-bank Rules change, is our synthesis of separately published AFCA and Treasury material. Neither AFCA nor Treasury draws that conclusion or describes an interim gap.

The three-category framework, the ePayments Code liability lists, the 10-business-day and seven-month reporting thresholds and the payment-method instructions are taken from ASIC's Moneysmart and ASIC's ePayments Code page. The Scams Prevention Framework dates, AFCA's authorisation and the 12 March 2026 Rules change covering receiving banks and mule accounts come from AFCA and Treasury; the loss figures come from the National Anti-Scam Centre's Targeting scams report 2025; the recall machinery comes from the Australian Banking Association's Scam-Safe Accord. Two passages are marked as AI-assisted analysis. Loss figures, the small claims thresholds in the table, AFCA time limits and the Framework's commencement dates all change — confirm the current position with the body named beside each before you rely on it. Nothing here is legal or financial advice.

Facts on this page are taken from the sources listed above — Australian government departments, regulators, statutory bodies and official statistical releases. Comparisons, judgements and "which option suits whom" conclusions are AI-assisted analysis written over those sources; they are marked in the text and listed as an AI-analysis entry in the sources, not attributed to any authority. Rates, thresholds, fees and processing times change, often at the start of a financial year; figures are current as at the review date shown and should be confirmed with the responsible agency before you rely on them for money or legal decisions.