By Viktor Ha | July 2026 | AML-CAMS Blog
TL;DR: On 18 June 2026, the Federal Court ordered HSBC Bank Australia to pay a $35 million penalty after the bank admitted to systemic failures in protecting customers from scams. The case was brought under the ePayments Code, not the AML/CTF Act, but the underlying failure pattern will be instantly familiar to anyone who has worked in financial crime compliance. HSBC built scam controls on some of its payment rails and left the busiest one, its internal transfer system, largely unprotected. That is not a resourcing problem or a technology gap. It is a compliance program gap: the failure to test whether protection is actually complete, rather than assuming it is because controls exist somewhere in the system. This post examines what went wrong, the human cost behind the numbers, and why this case belongs in the same conversation as every AML enforcement action this blog has covered this year.
A $35 Million Wake-Up Call, and Not the Kind You’d Expect
Most of the enforcement stories on this blog involve institutions that ignored known risks, ignored audit findings, or failed to build the compliance infrastructure the law required. HSBC Australia’s case is different, and that difference is exactly what makes it worth examining closely.
HSBC did build scam controls. It simply didn’t build them everywhere.
On 18 June 2026, sitting in Melbourne, Justice Bennett of the Federal Court ordered HSBC Bank Australia Limited to pay a $35 million penalty after the bank admitted to serious failures in protecting customers from scams. ASIC Chair Sarah Court described the outcome as “one of the first cases of its kind globally” and “the strongest scam wake-up call yet to the banking industry.”
Between January 2020 and August 2024, HSBC received more than 1,000 reports of unauthorised transactions, totalling approximately $34.6 million. Those reports surged roughly 380% across 2023 and 2024 as impersonation scams escalated, and HSBC had been aware of the growing risk since May 2021. The bank has since paid around $21.5 million in compensation to affected customers, with further payments due by the end of July 2026, and has separately recovered and returned $6.5 million.
This case was brought under the ePayments Code, which ASIC administers, not the AML/CTF Act. But the failure pattern underneath it is one every AML/CTF practitioner will recognise immediately, because it is structurally identical to the failure patterns that have driven enforcement action after enforcement action across the sector this year.

Three People Behind the Numbers
Before getting into the mechanics of what went wrong, it’s worth pausing on who this actually happened to. ASIC’s release named specific cases, and they are worth sitting with.
A 51-year-old dental technician from New South Wales lost $47,000, almost all her savings. A 25-year-old part-time architectural assistant, also from New South Wales, lost $50,000, his life savings. A Victorian couple in their fifties lost $48,000 that was transferred out of their home loan.
ASIC Chair Sarah Court put it plainly: “Individual customers lost tens of thousands of dollars which, for some, were their life savings, causing them real stress and uncertainty.” Some customers reported borrowing money elsewhere, taking on extra shifts at work, or fearing they would struggle to meet their home loan repayments, while they waited an average of 144 days for HSBC to finalise its investigation into what had happened to their money.
That number, 144 days, is not a footnote. It is nearly five months of uncertainty for someone who has just lost their savings, layered on top of the original harm.
The Specific Failure: A Door Left Unlocked
Justice Bennett’s findings, and HSBC’s own admissions, point to a precise and instructive failure. HSBC had implemented scam controls on some of its payment systems. It did not implement the key controls on its internal (IAT) payment rail, which is where the majority of customer losses occurred.
Read that carefully. HSBC did not lack scam controls as a concept. It had them, deployed them, and presumably reported internally that scam protection measures were in place. What it failed to do was ensure those controls covered the channel customers were actually being defrauded through.
This is the detail that separates this case from a simple resourcing or awareness failure. HSBC knew impersonation scams were rising sharply from at least May 2021. It had already built some infrastructure to respond. The gap was not ignorance. It was an incomplete implementation that nobody caught, tested, or escalated before the harm compounded across a thousand-plus victims and $34.6 million in losses.
Justice Bennett held that HSBC’s failures in respect of the ePayments Code were “widespread and systemic.” Two further admissions compound the picture. HSBC took an average of 144 days to investigate scam reports, a delay ASIC found breached the bank’s financial services licence obligations. And HSBC lacked adequate systems to help customers regain access to accounts that had been locked after a scam was reported, meaning customers who had already lost money were then locked out of what remained of their banking access, with no clear pathway back in.
Why This Belongs in an AML/CTF Conversation
It would be easy to treat this as a scam-prevention story that sits outside AML/CTF practice. That would be a mistake, and here’s why.
The compliance architecture that governs scam prevention and the compliance architecture that governs money laundering detection are built from the same components: risk-based control design, transaction monitoring calibrated to actual threat patterns, timely investigation and escalation, and governance oversight that tests whether controls are functioning as intended rather than simply existing on paper. A regulator assessing either domain is asking fundamentally the same question: does this program actually work, end to end, or does it only work in the parts that were easiest to build?
HSBC’s gap, controls on some payment rails but not the one carrying the highest volume of actual risk, is the same failure mode this blog has documented across the AML/CTF landscape all year. Airwallex’s transaction monitoring was found not to be calibrated to the platform’s actual cross-border risk profile. Sportsbet’s five-area remediation program existed specifically because its original controls didn’t extend consistently across its risk surface. Tabcorp’s compliance program was found in 2017, and again under investigation in 2026, to exist in form without functioning in practice across the full scope of the business.
The lesson HSBC’s case adds to that pattern is specific and useful: a compliance program is not “complete” because it addresses the risks that were easiest to identify or the channels that received attention first. It is complete when someone has deliberately tested whether every material channel is covered, and has been willing to ask an uncomfortable question: where haven’t we looked yet?
The Governance Question Nobody Wants to Ask
Every enforcement case in the AML and financial crime space eventually comes down to a governance question, and HSBC’s is no exception: how did a gap this significant, controls present on some payment rails but absent on the highest-risk one, go unnoticed or unescalated for years while impersonation scam reports surged 380%?
That is not a technology question. Building the additional controls, once someone decides to build them, is usually the easier part. The harder part is the internal process that is supposed to catch a partial implementation before it becomes a four-year, thousand-victim, $35 million problem. Someone needed to ask whether scam protection had actually been extended across every channel customers used, not just the channels where it was first deployed. That question either wasn’t asked, or the answer wasn’t escalated to a level where action followed.
This is the same governance failure that has appeared, in different forms, across nearly every major AML enforcement action in Australia over the past several years: information existed somewhere in the institution that would have prevented or limited the harm, and it did not reach the people who could act on it in time.
What This Means at the Desk
For AML and financial crime practitioners, HSBC’s case offers three practical lessons that extend well beyond scam prevention.
Coverage audits need to be deliberate, not assumed. It is not enough to know that scam controls, or transaction monitoring, or customer due diligence measures exist within an institution. The relevant question is whether they exist across every channel and product where the actual risk sits, and whether anyone has recently and rigorously tested that coverage rather than assumed it from the last review cycle.
The channel carrying the least attention is often the channel carrying the most risk. HSBC’s internal transfer rail was where the majority of losses occurred, precisely the kind of channel that can be deprioritised in control design because it feels lower-profile than customer-facing, external-facing payment systems. The same logic applies to internal transfers, back-office processes, and lower-visibility product lines in an AML/CTF context. Risk does not concentrate where compliance teams find it most convenient to look.
Investigation timelines are a compliance metric, not just an operational one. HSBC’s 144-day average investigation time was treated by the Federal Court as a standalone breach, not a minor administrative delay. For AML practitioners, the equivalent lesson applies to SMR escalation timeframes and customer risk reassessment cycles: how long something takes to resolve is itself a measure of whether the program is functioning, independent of whether the right decision is eventually reached.
HSBC’s $35 million penalty and its extensive remediation programme, $21.5 million paid in compensation and counting, suggest a bank that responded seriously once the scale of the problem became clear. That is worth acknowledging. But the case’s real value for this audience is what it reveals about how a compliance gap this significant can exist inside a major, well-resourced institution for years without being caught by the institution itself.
The door was not left open by accident. It was left open because nobody had checked whether it had ever been locked.
Viktor Ha is a Senior Financial Crime Analyst with experience in AML/CTF compliance across the Australian banking sector. The views expressed here are his own.
Links referenced in this post:
External:
- ASIC media release 26-127MR — Federal Court orders $35 million penalty against HSBC
- ASIC media release 26-126MR — HSBC admits to scam protection failures
- ICLG — HSBC Australia hit with hefty penalty over scam protection failings
Internal:


Leave a Reply