AUSTRAC's Operation Claw found suspected mortgage fraud across 10 major Australian banks. What the findings mean for lender due diligence and SMR duties.
Table of contents
AUSTRAC said on 19 August 2026 that its Fintel Alliance found coordinated mortgage fraud across 10 major Australian banks, with potentially hundreds of millions of dollars in suspected fraudulent loans. Most were tied to Sydney property. AUSTRAC urged every lender to review its book, and a suspicious matter report is due three business days after the day suspicion forms.
- AUSTRAC's Fintel Alliance project Operation Claw pooled data from 10 major Australian banks and found the same mortgage fraud warning signs across the ten, not one rogue lender or one borrower group.
- The typologies were inflated incomes, misrepresented employment, fabricated or unverifiable business activity, and offshore or third-party funds used to settle and repay.
- The same mortgage brokers, accountants and law firms were used repeatedly across multiple loan applications.
- Fintel Alliance referred individuals and entities potentially involved in submitting false loan documents to law enforcement and regulators including the Australian Securities and Investments Commission (ASIC), the Australian Taxation Office and the Tax Practitioners Board, for intelligence purposes.
- Some banking relationships have already been ended, and AUSTRAC says further action is expected.
- No penalty has been announced, AUSTRAC did not identify evidence of widespread money laundering, and the findings land nearly five months after the reformed AML/CTF obligations began for existing reporting entities.
What did AUSTRAC find in Operation Claw?
AUSTRAC published the findings of Operation Claw on 19 August 2026. The project ran through Fintel Alliance, the public-private partnership AUSTRAC established in 2017, and analysed loan data contributed by 10 major Australian banks. It identified suspected fraudulent loans worth potentially hundreds of millions of dollars, and the mortgage fraud was concentrated on properties in Sydney.
AUSTRAC CEO Brendan Thomas framed the result as a sector problem rather than a set of isolated cases. "The scale of this activity should be a wake-up call for every lender," Thomas said. He said the same warning signs turned up at banks covering the vast majority of the national mortgage market.
The gaps in the release matter as much as the headline. AUSTRAC did not publish a loan count, a file volume or a date range for the loans reviewed, and it set no deadline by which lenders must complete their own reviews. Anyone quoting a precise exposure figure here is extrapolating beyond what the regulator said. The significance of the sum is what it reveals about controls, which is how AUSTRAC framed it, as a warning rather than a loss event. Every figure and provision reference here comes from AUSTRAC's release and its published guidance, with responsible lending from ASIC and the penalty figures from the pages linked below, checked on 24 August 2026. We will update this page if AUSTRAC publishes a loan count, a date range or an enforcement step.
| Operation Claw detail | As published by AUSTRAC, 19 August 2026 |
|---|---|
| Partner agencies | Australian Taxation Office, NSW Police Force, NSW Crime Commission, Australian Criminal Intelligence Commission (ACIC), Australian Prudential Regulation Authority (APRA), ASIC |
| Loans or files reviewed | Not published |
| Date range of loans reviewed | Not published |
| Deadline for lender self-review | None specified |
| Penalty proceedings against lenders | None announced |
One nuance shapes how compliance teams should read this. Thomas was explicit that the project "did not identify evidence of widespread money laundering". The finding is mortgage fraud at the application stage and the professional networks that enable it, with laundering exposure sitting downstream as a vulnerability rather than a proven pattern.
How did the loans get through onboarding controls?
The pattern AUSTRAC describes is documentary. The mortgage fraud ran through the paperwork: applications carried inflated income and misrepresented employment, supported by business activity that was fabricated or could not be verified. Settlements and repayments were funded in some cases from offshore or third-party sources, which breaks the link between the stated income and the money that actually moved.
That combination defeats any onboarding control that stops at inspecting a supplied document, which is why the durable fix is verification at source. A payslip renders correctly, an accountant's letter carries a real practice name, and a company appears in a registry. The pattern surfaces only when the same broker, accountant or law firm turns up across many applications at once, which is exactly what pooling data across 10 banks exposed.

We covered the same failure mode when deepfake artefacts began appearing in identity checks: the artefact improves faster than the inspection of it, and closer scrutiny of what the applicant hands over never closes that gap. AUSTRAC named the typologies below. The mapping to where detection belongs, and what actually tests it, is ours.
| Typology AUSTRAC observed | Where detection should sit | Control that actually tests it |
|---|---|---|
| Inflated income | Application intake | Verified income at source rather than a supplied document |
| Misrepresented employment | Application intake | Independent employer confirmation, not employer-supplied paper |
| Fabricated or unverifiable business activity | Credit assessment | Registry and tax data checks on the trading entity |
| Offshore or third-party settlement funds | Settlement and repayment | Source of funds and source of wealth evidence |
| Falsified or misleading documents | Document handling | Authenticity checks and cross-application document matching |
| Repeated intermediaries across files | Portfolio analytics | Network analysis across brokers, accountants and firms |
Thomas made the timing point plainly: "The most effective way to stop mortgage fraud is before a loan is approved." He added that once the funds have moved, "recovering the money becomes significantly harder."
What does this change for your AML obligations?
Operation Claw creates no new duty. It sharpens three existing ones, plus one transition deadline, under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, and the reformed regime is now the baseline: changed obligations for current reporting entities started on 31 March 2026, and newly regulated professions come in from 1 July 2026. The provision references below follow AUSTRAC's own published guidance.
| Obligation | Legal source per AUSTRAC guidance | Trigger in Operation Claw terms | Deadline |
|---|---|---|---|
| Suspicious matter report (SMR) | Act section 41 | Falsified payslips, fabricated or unverifiable trading activity | 3 business days after the day the suspicion is formed, 24 hours for terrorism financing, 5 business days where legal professional privilege is claimed |
| Enhanced customer due diligence | Act section 32, Rules section 6-20 | An SMR is required and you keep providing the service, or funding is unusually complex or has no apparent purpose | Applies once the trigger is met, not after the report is filed |
| Ongoing customer due diligence | Act section 30(2)(a) | Repayments arriving from parties never disclosed at origination | Continuous |
| SMR form transition | Rules sections 12-1 and 12-2 | Which SMR form you must use | Enrolled after 30 March 2026: the new form from 1 July 2026. Enrolled on or before 30 March 2026: any time between 1 July 2026 and 30 March 2029 |
AUSTRAC's suspicious matter report guidance is unusually direct about the standard it will apply. "Reasonable grounds is an objective standard," the guidance states. Our reading is that this measures the grounds for a suspicion against what a reasonable person would conclude, not against how cautious the individual analyst happened to be.
The enhanced due diligence obligation is the one most likely to be missed here. It bites automatically once an SMR is required and you intend to keep providing the designated service, and separately where transactions are unusually complex, lack apparent economic or legal purpose, or form an unusual pattern. Offshore third-party settlement funding sits inside that trigger, and collecting and verifying source of funds and source of wealth is one of the enhanced measures AUSTRAC lists for exactly this situation.
A mortgage is also a multi-decade relationship, so undisclosed repayers are a change in know your customer information and the risk rating should move with it, which is the practical case for perpetual review over a fixed refresh cycle.
Read the ASIC referrals as a second front. For an Australian credit licensee, the same falsified income evidence engages the responsible lending conduct obligations in Chapter 3 of the National Consumer Credit Protection Act 2009, which require reasonable inquiries about, and reasonable steps to verify, a consumer's financial situation.
What is still uncertain after the mortgage fraud findings?
AUSTRAC's Operation Claw release leaves four questions unresolved.
Who carries the liability. Fintel Alliance referred those names to law enforcement and regulators, for intelligence purposes, which points to professional conduct and tax exposure for brokers and accountants. It does not settle what a lender owes when it accepted paperwork a third party forged. No penalty proceedings have been announced.
The regulatory hook is fraud, not laundering. Because the project did not find widespread money laundering, the Act is engaged through the reporting and due diligence duties rather than through a proven laundering typology. That makes the enforcement path less predictable than a conventional programme failure case.
Retrospective review is expensive and slow. Testing an existing book for mortgage fraud means revisiting files approved years ago. Doing that at scale, while managing tipping off constraints on customers who remain in the relationship, is a material programme of work with no fixed deadline attached.
Detection depends on data nobody holds alone. A lender acting alone cannot reproduce the cross-institution view of mortgage fraud that made Operation Claw work. As Thomas put it, "Each bank may see only one fragment ... Mortgage fraud succeeds when those fragments remain disconnected." In practice the substitutes are Fintel Alliance membership and acting on the indicators and threat alerts AUSTRAC has issued, which carry the cross-institution picture no single lender holds.
How does this compare with earlier AUSTRAC actions?
AUSTRAC's best known interventions, including two against retail banks, arrived as civil penalty proceedings after the fact. This one arrives as a warning before any lender has been named.
| Matter | Outcome | Date | Nature |
|---|---|---|---|
| Commonwealth Bank of Australia | 700 million Australian dollars, agreed penalty | 4 June 2018 | Retail bank, deposit machine reporting and monitoring failures |
| Westpac | 1.3 billion Australian dollars, the highest civil penalty in Australian history when ordered | 21 October 2020 | Retail bank, international transfer reporting failures |
| Crown Melbourne and Crown Perth | 450 million Australian dollars over two years | 11 July 2023 | Casino operator, programme and monitoring failures |
| Operation Claw | No penalty announced, names referred to law enforcement and regulators | 19 August 2026 | Retail lending sector, Fintel Alliance intelligence project |

The precedent cuts both ways. Lenders that use the threat alerts to find and report their own mortgage fraud exposure are in a materially different position from lenders that wait. Participating banks have already ended some relationships on the strength of the intelligence, and AUSTRAC says further action is expected.
How should compliance teams respond?
Lenders responding to AUSTRAC's Operation Claw findings should start with one test: do origination controls verify facts, or do they only inspect the documents an applicant supplies? Then run AUSTRAC's mortgage fraud indicators across the existing book rather than only new applications, and treat recurring intermediaries as a portfolio signal.
Where suspicion crystallises, calendar the three business day clock from the day after the suspicion forms, and trigger enhanced customer due diligence in parallel rather than after filing. Evidence source of funds and source of wealth wherever settlement money arrives from a party who was not on the application. Finally, check that your file retention actually supports a retrospective review, because a control you cannot evidence later is a control you did not have.
One of the SMR triggers AUSTRAC names is a customer who is not who they claim to be, and that is the part of this problem identity verification does answer. Zyphe reads identity from the chip in a passport or ID card to ICAO 9303 and eIDAS standards, with two-step liveness and no image upload, so there is no supplied image to forge. The reusable credential lets the same verified identity be re-presented rather than re-documented at each institution, and the customer holds the key, so there is no central store of identity images to breach. If you are reviewing origination controls after these findings, book a demo.
The bottom line
Operation Claw is a rare case of a financial intelligence unit publishing what it found before naming anyone. The useful signal is not the headline number but the shape of the failure: mortgage fraud survives where controls inspect supplied documents, run once at origination, in institutions that cannot see each other's files. Verifying identity and income at source, keeping the risk view live after approval, and treating recurring intermediaries as a portfolio-level signal are the changes that close the gap.
Cited sources
- AUSTRAC, Fintel Alliance uncovers coordinated mortgage fraud across major lenders, 19 August 2026
- AUSTRAC, Suspicious matter reports guidance, submission deadlines under Act section 41
- AUSTRAC, Enhanced customer due diligence, Act section 32 and Rules section 6-20
- Federal Register of Legislation, Anti-Money Laundering and Counter-Terrorism Financing Act 2006, compilation in force
- AUSTRAC, Ongoing customer due diligence, what you must monitor for under Act section 30(2)(a)
- AUSTRAC and CBA agree $700m penalty, 4 June 2018
- ASIC, Responsible lending conduct obligations under the National Consumer Credit Protection Act 2009
- AUSTRAC, Risks and indicators of suspicious activity, including the banking sector
- AUSTRAC, Fintel Alliance, established 2017
- AUSTRAC, About the AML/CTF reforms and commencement dates
- AUSTRAC, Westpac ordered to pay $1.3 billion penalty, 21 October 2020
- AUSTRAC, Federal Court makes ruling in Crown matter, 11 July 2023
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.