General information only. This article is not legal, financial or professional advice. Rules and provider terms can change; check the linked primary sources.

Bank annual reports contain plenty of numbers designed for investors. Commonwealth Bank included a few that should interest anyone who moves money.

CBA says it monitors more than 80 million customer account activities each day, sends about 40,000 fraud alerts through its app daily and has delivered more than 5.9 million intelligent warnings for first-time payments since September 2024. It invested more than $1 billion during the year in fraud, scams, cyber threats and financial-crime capabilities.

Those are enormous numbers. They also explain why scam prevention is an awkward product problem.

A warning can be accurate and still fail

A customer making a legitimate first payment wants it to work. A customer being coached by a scammer has often been told what the bank will ask and how to answer. The bank has seconds to identify risk, explain it without sounding generic and introduce enough friction to change a decision.

If warnings appear too often, customers learn to dismiss them. If they appear too rarely, the bank misses the moment when intervention could matter. Forty thousand alerts a day is therefore not just a security statistic. It is forty thousand daily tests of wording, timing and trust.

CBA also says its AI-enabled bots have conducted more than 350,000 conversations with scammers since August 2025. That is clever disruption: waste the criminal’s time and collect intelligence without exposing a real customer. But the most valuable result is not a funny recording. It is whether phone numbers, scripts, URLs and payment patterns reach controls across the ecosystem quickly enough to stop the next attempt.

The beneficiary is part of the product

Real-time payments changed customer expectations. They also shortened the window for recovering money once it reaches a mule account. That makes beneficiary checks, first-payment warnings and post-transaction monitoring parts of the payment experience, not security features bolted onto it.

There is a reconciliation angle as well. Scam response teams need to join the customer report, payment instruction, account ledger, receiving institution, device data and any recovery into one case. A payment can be technically successful and still be the wrong outcome. Operations systems have to preserve both facts.

Banks should publish more outcome data alongside activity data: losses prevented, false-positive rates, customer abandonment and the proportion recovered. Volume tells us the machinery is busy. Outcomes tell us whether it works.

The Payment Nerd view

There is no single scam fix coming. Confirmation prompts, intelligence sharing, call blocking, mule-account detection and customer education each catch a different part of the problem.

The encouraging part of CBA’s numbers is the scale of investment and intervention. The uncomfortable part is that scammers still get a vote. They adapt their scripts to the controls and move customers onto channels where the bank sees less context.

A safe payment is not merely authorised and settled. It is a payment the customer actually intended after understanding who was on the other side. That is a much higher bar, and it is where modern banking has landed.

Source: Commonwealth Bank 2026 Annual Report.