Customer failed to take reasonable care of banking by sharing security codes

Categories:
Fraud & scams, Bank accounts,
Summary:
In October 2025, Lucy received a call from someone claiming to be from her bank about suspected fraud on her accounts. The caller persuaded her to install remote-access software, log in to the bank’s business online banking service, and provide response codes generated by her security devices. The caller then moved money between accounts and set up two payments of $335,000 to Lucy’s currency transfer account. One payment was later recovered, leaving a loss of $335,000.

Lucy complained that the bank should have detected the activity sooner, that its security processes were inadequate, and that it did not tell her promptly about an earlier failed payment attempt.
Published:
August 2026

Our investigation

Our first task was to examine whether the bank was liable to reimburse Lucy for the loss under the Code of Banking Practice online fraud guarantee. The payments were unauthorised, but the bank did not have to reimburse the loss if Lucy had failed to take reasonable steps to protect her banking.

We found the bank had displayed a clear warning on its business banking log-in page not to grant remote access, log in on instruction from callers or share response codes. In addition, the further clear warnings in the authentication app said response codes must never be shared, including with people claiming to be bank staff.

Because Lucy granted remote access, logged in while the caller controlled her device, and then disclosed several response codes, we found she had not taken reasonable steps to protect her banking.

Next, we considered Lucy’s complaint that the bank should have treated the payments as suspicious before processing them. We found there was nothing about the transactions that should have prompted the bank to suspect the possibility of fraud. The instructions were given using Lucy’s genuine credentials and confirmed through the bank’s two-factor processes. The payments were also directed to a payee Lucy had used before.

We also examined the bank’s security arrangements for business banking. We found it was entitled to let a business choose to give a “super-user” authority to change domestic payment limits on that business' internet banking site. All transactions were nonetheless required to be confirmed using two-factor authentication (with clear alerts and warnings about scams) using either a physical security device or an authentication app.

In examining what the bank did after Lucy reported the scam, we found it took reasonable steps to recover the money by contacting the receiving bank, after Lucy had already reported the matter to the currency provider.

We also found the bank handled Lucy’s complaint effectively. The bank stayed in regular contact, gave its findings within a reasonable time, and explained the failed payment attempt when Lucy raised the matter.

Outcome

We did not uphold Lucy complaint.

Print this page