The Facts
Man provides credit card number and PIN codes to fraudsters running phishing scam
The case of a man who fell victim to a phishing scam reads as a textbook example of cyber fraud. The man received an email inviting him to participate in an online cash survey. The email contained a web link and instructions to click on the link to complete the survey.
As part of the survey, the man was asked to provide his credit card number, which he did. Unbeknownst to him, by doing so, he made this information available remotely to the scammers who had sent him the email.
The fraudsters then asked the man to enter one-off PIN codes sent by his financial services provider to his mobile phone, which he did.
Transactions made using customer's credit card
This enabled the scammers to make transactions using the man’s credit card. These transactions totalled over $5,000 and were with merchants outside Australia.
When the man’s financial services provider denied liability for the losses, he lodged a dispute with the Australian Financial Complaints Authority (AFCA), which had to determine whether he was liable.














Expert commentary on the court's decision
AFCA finds customer not liable for his losses
After reviewing the dispute, AFCA (then operating under its old name, the Financial Ombudsman Service) decided in favour of the customer.
Disputes over electronic transactions under ePayments Code
The ePayments Code stipulates that if there is a dispute over an electronic transaction, it is up to the financial services provider (FSP) to prove one of two things.
The first is that the customer authorised the payment by making the payment himself or herself, or by having someone else carry out the transaction with his or her knowledge or consent.
The second is that if the customer claims not to have authorised the payment, the FSP has to prove that he or she breached certain security provisions of the ePayments Code and is therefore liable for the transaction.
Customer found to be not in breach of ePayments Code
AFCA found that the customer, identified only as “Mr H”, did not intend to divulge his passcodes to anyone and that he did not know they were meant to be kept secret. Mr H’s argument that he thought he was merely responding to a survey was found to be valid and convincing.
Because Mr H was found not to have disclosed his passcodes voluntarily, it was determined that he did not contribute to his losses under the ePayments Code.
Additional compensation for stress and inconvenience
Mr H had limited liability of $150 for his losses. The FSP was liable to reimburse him for the remaining sum.
In addition, the FSP had to pay Mr H $250 to compensate him for the stress and inconvenience he experienced due to the FSP sending him several text messages referring to his “liability” for the transactions after he referred the dispute to AFCA.
What is a phishing scam?
A phishing scam is an attempt by a criminal to trick you into divulging personal information, such as credit card numbers, passwords and PIN codes, in order to steal your money. The tale of Mr H is a classic case of a successful phishing scam.
Many phishing scams target their intended victims via email, although other approaches are also used, such as text messages, phone calls and social media.
Some phishing emails claim to be from a legitimate organisation, like a bank or internet service provider. Some, like the one that duped Mr H, claim to be offering a prize for participating in a survey.
How can you avoid being caught by a phishing scam?
The way to minimise your chances of being “phished” is to remain vigilant and be aware of the techniques that scammers use to try to trick you into divulging details they can use to rob you.
How can you tell when an email you receive is part of a phishing scam?
There are several details that could alert you that you have received an email which is part of a phishing scam.
The most important thing to remember is not to click on any links or download any attachments from an email if you have even the faintest shadow of a doubt about its validity.
If in doubt, ring the sender of the email
If you receive an email claiming to be from your bank, telephone company, internet service provider, lawyer, accountant or conveyancing company, and you’re not 100 per cent confident that the email is genuine, there is a simple way to verify its legitimacy.
To eliminate any doubt, just pick up the phone and give them a call on the phone number that you would usually use to call them (don’t use a phone number that appears in the email).
Australians losing increasing sums to scammers
Despite the efforts of the government to warn us, many Australians continue to fall victim to scams. Collectively we lost $2.18 billion during 2025, an increase of 7.8% on the previous year.
In 2025 the scams most commonly reported to Scamwatch were phishing scams, with 65,361 reports.
As technology advances and systems become ever more sophisticated in the attempt to prevent fraud, scammers become increasingly ingenious in their efforts to rob us.
Human error remains the weakest link in the chain. Mr H was fortunate. He was compensated for his losses because the adjudicator found in his favour. Others in a similar position may not be so lucky.
Being aware of scams and remaining vigilant is your best defence.
For more information please see the articles below.
Protect yourself against payment redirection scams
Business email compromise scams conning Australians out of millions
“I lost my money in a cryptocurrency scam. My financial firm should have warned me.” Which case won?
Useful resources about scams
Get Online Week – this initiative is designed to support everyone to feel safer and more confident online. It is being run from 19-25 October 2026.
Scamwatch – website run by the Australian Competition and Consumer Commission (ACCC) which publishes regular updates about scams. You can sign up for email alerts about new and current scams.
The Australia Cyber Security Centre, run by the Australian Signals Directorate, is the Australian government’s technical authority on cyber security. Its Cyber health check tool is a free tool for individuals, small businesses and not-for-profits wanting to do a basic cyber security assessment to improve their cyber security.
Phishing – this page describes in detail what phishing is and how it works.
Whaling and spear phishing – this page describes phishing scams that target businesses.