In 2023, Australians reported losing $2.74 billion to scams — and that figure captures only what was reported. The real total is almost certainly higher. On 20 February 2025, Australia became the first country in the world to pass legislation specifically requiring banks, telecommunications providers, and digital platforms to take active steps to prevent scams — or face fines of up to $50 million per offence. The Scams Prevention Framework Act 2025 (Cth) is not just a corporate compliance exercise. It changes what Australian consumers are entitled to when they lose money to a scam and the relevant business failed to do its job. Here is what the new law means for you.
20 Feb 2025
Royal Assent
$2.74B
Reported losses (2023)
$50M
Max corporate fine per offence
3 sectors
Banking, telco, digital platforms
📋 Laws and Official Sources
- Scams Prevention Framework Act 2025 (Cth) — Federal Register of Legislation
- Competition and Consumer Act 2010 (Cth) — Part IVF (new Scams framework)
- Australian Competition and Consumer Commission — Scams information
- Australian Financial Complaints Authority — SPF dispute resolution
- Treasury — Scams Prevention Framework consultation materials
What Is the Scam Prevention Framework?
The Scams Prevention Framework Act 2025 amended the Competition and Consumer Act 2010 (Cth) by inserting a new Part IVF. This framework is the first of its kind in the world — no other country had, at the time of its passage, enacted legislation that places binding, enforceable obligations on private sector entities to actively prevent consumer scams.
The framework operates on a simple premise: the businesses through which scams reach consumers — banks that process fraudulent transfers, telecommunications companies whose networks carry scam calls and texts, and digital platforms whose services host scam advertisements and communications — have both the power and the responsibility to disrupt scams before they cause harm. When they fail to take reasonable steps to do so, they should share liability for the consumer’s loss.
This represents a fundamental shift from the status quo, under which Australian consumers who lost money to scams generally had no recourse against their bank, their telco, or the platform that delivered the scam — even when those entities had clear warning signs they chose to ignore.
Australia’s framework was explicitly modelled in part on the United Kingdom’s Authorised Push Payment (APP) fraud reimbursement scheme, which came into force in October 2023 and requires UK banks to reimburse most APP scam victims. Australia went further by covering telecommunications companies and digital platforms in addition to banks — a broader scope than any comparable legislation elsewhere.
Which Businesses Are Covered?
The framework initially applies to three designated sectors, selected because of their central role in scam delivery and the transfer of scam proceeds:
| Sector | Who Is Covered | Why This Sector? |
|---|---|---|
| Banking | Authorised deposit-taking institutions (ADIs) — banks, credit unions, building societies that provide payment services to consumers | Scam proceeds move through payment systems. Banks can detect unusual transfer patterns and delay or block suspicious transactions. |
| Telecommunications | Carriers and carriage service providers operating in Australia — mobile and fixed-line providers, ISPs | Scam calls, SMS messages, and robocall campaigns reach consumers through telco infrastructure. Telcos can identify and block scam traffic. |
| Digital platforms | Social media platforms, search engines, and other online services — designated entities will be specified in regulations | Scam advertisements are delivered through social media and search results. Platforms have tools to screen advertising and remove fraudulent accounts. |
The framework is designed to expand to additional sectors over time. The legislation creates the architecture — sector-specific codes and rules will add detail for each sector as they are developed in consultation with industry and consumer groups.
Critically, the framework applies to both domestic and overseas entities that operate regulated services to Australian consumers. A foreign social media company serving Australian users is covered — a significant enforcement challenge, but an important jurisdictional statement.
The Six Obligations Businesses Must Meet
At the core of the framework are six SPF Principles — overarching obligations that all regulated entities must embed in their operations. Sector-specific codes will add more detailed requirements on top of these principles.
| Principle | What It Requires |
|---|---|
| 1. Governance | Implement policies, procedures, metrics and targets for combating scams. Scam prevention must be actively managed at a governance level, not left to customer service teams. |
| 2. Prevent | Take reasonable steps to prevent scams connected with, or using, their regulated services. “Reasonable steps” will be defined in sector codes — the standard is proportionate to the risk. |
| 3. Detect | Take reasonable steps to detect scam activity in their systems — including investigating suspicious activities that suggest fraud is occurring through their services. |
| 4. Report | Report scam activity and attempted scams to relevant authorities (including the National Anti-Scam Centre), enabling intelligence to be shared across the system. |
| 5. Disrupt | Take reasonable steps to disrupt scams — blocking payments, removing scam accounts, deregistering fraudulent domain names, blocking scam SMS traffic. |
| 6. Respond | Respond to consumers who have been scammed — with internal dispute resolution processes that are accessible, fair, and timely. |
Failure to comply with these principles — or the sector-specific codes built on them — exposes regulated entities to fines of up to $50 million per contravention (for large corporations), or three times the benefit gained, or 30% of their adjusted turnover for the relevant period — whichever is highest. These are among the largest corporate penalties available under Australian consumer law.
Your New Rights as a Scam Victim
The framework creates new rights for consumers that did not exist before February 2025. The key ones are:
- Right to internal dispute resolution: Every regulated entity must have an accessible, fair, and timely internal dispute resolution (IDR) process for scam-related complaints. You have the right to complain to the business that failed to prevent the scam and receive a substantive response.
- Right to external dispute resolution: If you are dissatisfied with the outcome of an internal complaint, from 31 March 2027 you can escalate scam-related complaints under the SPF to the Australian Financial Complaints Authority (AFCA) — a free, independent external dispute resolution scheme. AFCA can award compensation against regulated entities.
- Right to court action: Consumers and small businesses can also bring a claim directly in court to recover losses or damages where a regulated entity failed to meet its SPF obligations. This right exists independently of the IDR and AFCA processes.
The AFCA’s jurisdiction to handle SPF scam complaints only applies to matters that occur on or after 31 March 2027. For scams that occurred before that date, existing pathways apply — such as the AFCA’s general financial services jurisdiction (for bank-related complaints) and the Telecommunications Industry Ombudsman (for telco complaints). Don’t wait if you’ve already been scammed — pursue existing remedies now.
Lost Money to a Scam? You May Have Legal Recourse.
Under Australia’s new Scam Prevention Framework, banks and telcos may be liable for losses caused by scams they failed to prevent. A consumer rights solicitor can assess whether you have a claim against the business that let the scam through.
When Can You Get Your Money Back?
This is the question most scam victims ask first. The honest answer is: the framework creates the conditions under which reimbursement can be sought, but it does not guarantee it. The key question in any individual case is whether the regulated entity failed to meet its obligations under the SPF — and whether that failure was connected to your loss.
Consider two scenarios:
Scenario A: You receive a text message that appears to come from your bank (“CommBank”), directing you to a fake website where you enter your banking credentials. Your bank later shows that the SMS came through a network that had been flagged by the telco’s own monitoring system as a high-risk scam source — but no action was taken. The telco failed to meet its obligation to disrupt known scam traffic. You have a strong factual basis for a complaint against the telco (and potentially the bank, for failing to block the resulting fraudulent transaction).
Scenario B: You voluntarily transfer money to someone you met on a social media platform after weeks of interaction, because you genuinely believed they were a romantic partner in financial difficulty. The platform had no flagged history of the account before the transfer. The platform met its reasonable steps obligations. Your loss may be harder to pursue against the platform — though internal complaint processes and AFCA review are still available.
The SPF does not eliminate consumer responsibility. If a consumer took unreasonable risks — ignoring explicit fraud warnings, overriding security prompts — a court or AFCA may reduce or deny compensation on contributory negligence grounds. But the framework shifts the burden: regulated entities must now affirmatively demonstrate they met their obligations, rather than consumers proving the entity did something wrong from scratch.
How to Complain Under the New Framework
Key Dates: When the Rules Come Into Full Effect
| Date | What Changes |
|---|---|
| 13 February 2025 | Parliament passes the Scams Prevention Framework Bill 2025 |
| 20 February 2025 | Act receives Royal Assent — the SPF becomes law |
| 2025–2026 | Sector-specific codes developed for banking, telecommunications, and digital platforms in consultation with industry and consumer groups |
| 1 July 2026 | AFCA designated as the authorised external dispute resolution scheme for SPF scam complaints |
| 31 March 2027 | AFCA can begin accepting SPF scam complaints — consumers can bring scam-related disputes under the full SPF framework to AFCA for adjudication |
The staged implementation reflects the practical reality that building sector codes, training AFCA staff, and establishing industry compliance systems takes time. But the law itself — and the corporate penalty regime — is already in force. Regulated entities cannot wait for sector codes to be finalised before beginning to implement reasonable scam prevention measures.
Which Scams Are Most Commonly Reported?
Understanding what the most prevalent scams look like helps you recognise them — and helps establish where a regulated entity’s obligation to prevent them was most clearly applicable.
According to the ACCC’s Scamwatch data, the categories generating the highest total losses in Australia include:
- Investment scams: Fake investment platforms, cryptocurrency fraud, “pig butchering” schemes involving months of relationship-building before directing victims to sham investment portals. These typically involve significant losses per victim and often use social media and messaging apps as initial contact.
- Remote access scams: Criminals convincing victims to install software (AnyDesk, TeamViewer) that gives the scammer control of the victim’s device and bank account. Often delivered via phone call pretending to be from a bank’s fraud team or a technology company.
- Phishing (bank impersonation): SMS or email messages using spoofed sender IDs that appear to come from a victim’s own bank, directing them to fake login pages. The telco and bank are directly in the delivery chain.
- Romance scams: Long-running deceptions via dating apps or social media, building emotional attachment before requesting money transfers. Average losses per victim in this category are among the highest of any scam type.
- Job offer scams: Fake job advertisements, often through legitimate job platforms, that request upfront payments or identity documents as part of a sham employment process.
Frequently Asked Questions
What is the Scams Prevention Framework Act 2025?
The Scams Prevention Framework Act 2025 (Cth), which received Royal Assent on 20 February 2025, is world-first legislation that amends the Competition and Consumer Act 2010 to impose mandatory obligations on banks, telecommunications providers, and digital platforms to prevent, detect, disrupt, report, and respond to scams. Entities that fail to meet these obligations face fines of up to $50 million per contravention and can be required to compensate consumers for losses.
Can I get my money back from the bank if I was scammed?
It depends on the circumstances. If your bank failed to take reasonable steps required under the SPF — for example, failed to detect a suspicious outgoing transfer pattern that their systems flagged — you may have a claim for reimbursement. If you authorised the transfer and the bank met its obligations, recovery is less certain. Under the AFCA’s general jurisdiction (available now), you can already complain about bank conduct in relation to scam transactions. The full SPF complaint pathway through AFCA starts 31 March 2027.
Which businesses must comply with the Scam Prevention Framework?
Initially, the framework covers three sectors: banking (authorised deposit-taking institutions providing payment services), telecommunications (mobile and fixed-line providers), and digital platforms (social media, search engines — specific entities to be designated in regulations). The framework can be extended to additional sectors by regulation. It applies to both Australian and overseas entities serving Australian consumers.
What is the maximum fine for a business that fails to prevent scams?
For a body corporate, the maximum penalty is the greater of: $50 million; three times the value of the benefit obtained from the contravention; or 30% of the entity’s adjusted turnover for the relevant period. These are among the highest civil penalties available under Australian consumer law.
When can I complain to AFCA about a scam under the SPF?
AFCA’s Scam Prevention Framework jurisdiction commences on 31 March 2027, and only applies to SPF scam-related matters that occur on or after that date. For scams that have already occurred, you can use AFCA’s existing jurisdiction for bank-related complaints, or the Telecommunications Industry Ombudsman for telco complaints.
Does the framework cover cryptocurrency scams?
The SPF covers entities in the designated sectors — banks, telcos, and digital platforms — not cryptocurrency exchanges directly. However, if a scam reaches you through a social media platform or a bank processes the relevant payment, those entities’ obligations under the SPF are engaged. Cryptocurrency exchanges may be brought into the framework as an additional designated sector in future.
What should I do immediately after being scammed?
Act immediately: (1) call your bank’s fraud line and ask them to recall or freeze the payment; (2) report to Scamwatch at scamwatch.gov.au; (3) report to the Australian Cyber Security Centre if the scam involved your devices; (4) lodge a formal written complaint with each regulated entity you believe failed to prevent the scam; (5) keep all records — screenshots, texts, emails, bank statements. Time is critical — the faster you act, the higher the chance of recovering funds.
Can a small business claim under the Scam Prevention Framework?
Yes. The SPF protections and the AFCA complaint pathway are available to both consumers and small businesses. Small businesses that lose money to scams delivered through regulated entities — particularly banking and telco services — have the same rights as individual consumers to lodge complaints and seek reimbursement where the regulated entity failed to meet its obligations.
The Shift That Changes Everything
Before February 2025, being scammed in Australia was almost entirely your own problem. Banks returned funds in some cases — voluntarily, inconsistently, with no legal obligation. Telcos had codes of practice, but breaching them carried no meaningful penalty for the consumer’s loss. Platforms hosted scam advertisements under general terms that effectively disclaimed all responsibility.
The SPF changes the legal landscape fundamentally. It does not eliminate scams — nothing could do that — but it tells the private sector that the cost of failing to prevent them will no longer fall entirely on the people who were targeted. That is a significant shift. And it means that if you lose money to a scam from now on, the first question to ask is not just “what did I do wrong?” but “did the systems I trusted to protect me fail to do what the law now requires?”
Scammed? You Have More Rights Than You Think.
Australia’s new scam prevention laws give consumers real recourse against banks, telcos, and platforms that failed to protect them. A consumer rights solicitor can assess whether you have a claim and guide you through the complaint and recovery process.
Sources
- Scams Prevention Framework Act 2025 (Cth) — Federal Register of Legislation
- Competition and Consumer Act 2010 (Cth) Part IVF — Federal Register of Legislation
- ACCC Scamwatch — scamwatch.gov.au
- AFCA — Scams Prevention Framework information
- Treasury — Scams Prevention Framework fact sheet (January 2025)
This article provides general information only and is not legal advice. The Scams Prevention Framework Act 2025 is new legislation — sector-specific codes and regulatory details are still being developed. Information was current as at August 2026 but may change. If you have been scammed, contact your bank immediately and report to Scamwatch. For legal advice about your specific situation, consult a qualified consumer rights solicitor.