ASIC v HSBC Bank Australia — Federal Court imposes $35 million penalty for systemic failures in fraud controls and ePayments Code compliance

Case
Australian Securities and Investments Commission v HSBC Bank Australia Limited
Court
Federal Court of Australia
Date Decided
18 June 2026
Citation
[2026] FCA 847
Topics
Financial services regulation, fraud prevention, ePayments Code compliance, consumer protection
Source
Read the full opinion

Background

HSBC Bank Australia Limited, a major financial institution holding Australian Financial Services and Credit Licences, offered deposit and loan accounts to customers with payment functionality through mobile and online banking platforms. The internal account transfer (IAT) payment rail allowed near real-time transfers between HSBC accounts, creating an elevated fraud risk. Between 2020 and 2024, customers were exposed to unauthorized payments through account compromise and social engineering attacks. ASIC alleged that HSBC failed to meet statutory obligations to provide financial services and credit activities “efficiently, honestly and fairly” under the Corporations Act 2001 (Cth) and National Consumer Credit Protection Act 2009 (Cth).

HSBC admitted to three categories of systematic contraventions spanning from January 2020 to November 2024. The parties proceeded by agreed statement of facts and joint submissions regarding both liability and penalty. Justice Bennett found the contraventions serious and within the agreed penalty range.

The Court’s Holding

The Federal Court declared that HSBC breached its statutory obligations through three distinct failures. First, from May 2023 to May 2024 (mobile banking) and December 2023 (online banking), HSBC failed to implement adequate prevention and detection controls on the IAT payment rail, specifically real-time interception capabilities and fraud rules using behavioral biometrics and device-based identification technology. HSBC was aware these controls were available and necessary but failed to implement them, leaving customers exposed to elevated fraud risk.

Second, between January 2020 and August 2023, HSBC lacked adequate systems and processes to ensure compliance with ePayments Code requirements for investigating unauthorized transaction reports and applying liability rules. The court found widespread and systemic non-compliance with prescribed investigation timeframes and failures to properly advise customers of investigation outcomes. Third, from January 2020 to April 2024, HSBC failed to establish adequate systems to inform customers within a reasonable time about how to reinstate full account access after restrictions or digital blocks were applied following fraud reports.

Key Takeaways

  • Major banks must implement contemporaneous fraud controls—HSBC’s delay in deploying available technology (behavioral biometrics and device identification) on high-risk payment rails violated statutory duties despite prior knowledge of vulnerabilities.
  • ePayments Code compliance requires not just investigation of fraud reports but systematic tracking, timely processing, and proper application of liability rules; wholesale failures trigger substantial penalties.
  • Regulatory obligations extend to customer communication; banks must proactively advise customers how to restore account access after fraud-related restrictions, not simply maintain restrictions indefinitely.
  • The $35 million penalty ($10M for fraud controls, $22.5M for ePayments Code failures, $2.5M for back-to-banking failures) reflects that systemic regulatory lapses at major institutions warrant penalties exceeding $2M for individual breaches.

Why It Matters

This decision demonstrates ASIC’s enforcement willingness against systemically important financial institutions and establishes measurable standards for fraud prevention obligations. HSBC’s admission that it identified but failed to implement necessary controls—despite prior awareness of fraud risks and availability of solutions—shows that regulatory breach liability does not require gross negligence; failure to deploy known, available protections suffices. The $35 million penalty, combined with $2.3 million in costs and mandatory adverse publicity notices, signals that banks cannot postpone fraud control investments without facing significant enforcement consequences.

The decision also clarifies that ePayments Code obligations are substantive and enforceable through both declarations and substantial penalties. The court’s emphasis on HSBC’s awareness of control gaps prior to May 2023 suggests regulators will scrutinize internal compliance reviews and fraud risk assessments to establish constructive notice of vulnerabilities. For the banking sector, this case underscores that statutory duties to provide services “efficiently, honestly and fairly” require proactive investment in emerging fraud technologies, systematic monitoring of regulatory compliance, and clear communication with customers—not merely reactive responses after breaches occur.

✉️ Get tomorrow’s cases before your first coffee
Daily Case Law is our free morning digest — the most substantive new decisions, filtered to your jurisdictions and topics, each linking back here for the full analysis.
Subscribe free →

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top