
For years, Australia’s scam story only moved in one direction: up. Losses climbed, tactics sharpened, and every quarter brought a grimmer headline. That trend has finally cracked — and one deceptively simple piece of infrastructure is about to press the advantage.
The centrepiece is Confirmation of Payee: a name-checking system that, for the first time, tells you whether the account you are about to pay actually belongs to who you think it does. It sounds obvious. Its absence has quietly cost Australians a fortune.
Why paying someone has been a leap of faith
Here is a fact that surprises people outside the industry. When you send money in Australia today, the bank matches only the BSB and account number. The name you type in is, for verification purposes, largely decorative. If a scammer tells you their account is under “ATO Recovery Team” and gives you a number, your bank will happily send funds to whatever account that number points to — no matter whose name is really attached.
That gap is the engine room of the most damaging scam category: authorised push-payment fraud, where the victim is manipulated into sending the money themselves. Because the customer clicked “confirm,” traditional fraud controls barely register it. Confirmation of Payee closes the gap by checking the name against the account before the payment leaves.
The $100 million backbone
This is the flagship commitment of the banking industry’s Scam-Safe Accord, a coordinated program to harden the whole system rather than leave each bank to fend for itself.
By the numbers:
- A $100 million industry investment is funding a shared Confirmation of Payee capability across Australian banks.
- The Accord also brings in biometric checks for new account openings, enhanced payment warnings and delays, and expanded intelligence-sharing between banks.
- The Federal Budget committed $37.3 million toward implementing mandatory, industry-wide scams codes.
The design detail that matters most is that Confirmation of Payee works best when it is universal. A name-check that only some banks run is a name-check scammers route around. By funding it as shared infrastructure across the sector, the Accord aims to leave no easy back door — which is precisely why it needed to be an industry program rather than a feature race.
The numbers are finally moving the right way
The early data suggests the layered approach is working. Reported scam losses have started falling — a genuine reversal after years of relentless increases — with double-digit percentage declines recorded across key reporting channels and even steeper drops in some financial-crime datasets. It is the first sustained evidence that coordinated defence, rather than isolated bank-by-bank effort, actually bends the curve.
A note of realism belongs here. Losses falling is not losses gone, and scammers adapt fast. As name-checking closes the bank-transfer route, expect pressure to shift toward channels with weaker friction — cryptocurrency on-ramps, gift cards, and social-engineering that pushes victims off the regulated rails entirely. A win in one lane tends to redirect traffic, not end the journey.
That is exactly why the policy response has widened beyond banks. The mandatory scams-code framework is built on a simple insight: a scam is rarely just a banking failure. It usually begins with a text message or a social-media ad and ends with a bank transfer, which means telcos and digital platforms sit upstream of the loss. By placing enforceable obligations on all three sectors — and creating a pathway for victims to seek redress when an obligation is breached — the framework tries to close the seams between industries that scammers have always exploited. Confirmation of Payee hardens the last step; the codes are aimed at the whole chain.
The rail nobody is talking about: PayTo
There is a structural angle worth flagging for anyone building payment flows. As Australia migrates away from the legacy direct-debit system toward PayTo on the New Payments Platform, the security model changes underneath the surface. PayTo puts the customer in control of a pre-authorised agreement — they see and approve exactly who can pull funds, how much, and how often, inside their banking app. That is a fundamentally harder target for the “just set up a direct debit for me” style of fraud than the paper-and-trust world it replaces.
Confirmation of Payee protects the money you push out. PayTo’s mandate model brings similar visibility to the money that gets pulled from you. Together they represent a quiet re-architecting of Australian payments around a single principle: verify before value moves.
What businesses and consumers should do now
For consumers, the habit to build is patience. When Confirmation of Payee flags a name mismatch, treat it as a stop sign, not a speed bump — that warning is the system doing exactly what $100 million bought it to do.
For businesses, two things. First, make sure your payment details are consistent everywhere a customer might find them, because a name that does not match your registered account will now trigger warnings that cost you sales and trust. Second, if you collect recurring payments, understand where PayTo fits — the businesses that adopt it early will look markedly more trustworthy to a public that has been trained, at last, to check.
Share this one widely. A single forwarded message about checking the name before you send has stopped more scams than any regulator. Send it to the family member most likely to be targeted — that is the highest-value share you’ll make this week.