Learn more about the latest security and privacy threats
Editorial illustration for the article "AUSTRAC mortgage fraud findings: Operation Claw puts lenders on notice".

AUSTRAC's Operation Claw found suspected mortgage fraud across 10 major Australian banks. What the findings mean for lender due diligence and SMR duties.

Table of contents

AUSTRAC said on 19 August 2026 that its Fintel Alliance found coordinated mortgage fraud across 10 major Australian banks, with potentially hundreds of millions of dollars in suspected fraudulent loans. Most were tied to Sydney property. AUSTRAC urged every lender to review its book, and a suspicious matter report is due three business days after the day suspicion forms.

  • AUSTRAC's Fintel Alliance project Operation Claw pooled data from 10 major Australian banks and found the same mortgage fraud warning signs across the ten, not one rogue lender or one borrower group.
  • The typologies were inflated incomes, misrepresented employment, fabricated or unverifiable business activity, and offshore or third-party funds used to settle and repay.
  • The same mortgage brokers, accountants and law firms were used repeatedly across multiple loan applications.
  • Fintel Alliance referred individuals and entities potentially involved in submitting false loan documents to law enforcement and regulators including the Australian Securities and Investments Commission (ASIC), the Australian Taxation Office and the Tax Practitioners Board, for intelligence purposes.
  • Some banking relationships have already been ended, and AUSTRAC says further action is expected.
  • No penalty has been announced, AUSTRAC did not identify evidence of widespread money laundering, and the findings land nearly five months after the reformed AML/CTF obligations began for existing reporting entities.

What did AUSTRAC find in Operation Claw?

AUSTRAC published the findings of Operation Claw on 19 August 2026. The project ran through Fintel Alliance, the public-private partnership AUSTRAC established in 2017, and analysed loan data contributed by 10 major Australian banks. It identified suspected fraudulent loans worth potentially hundreds of millions of dollars, and the mortgage fraud was concentrated on properties in Sydney.

AUSTRAC CEO Brendan Thomas framed the result as a sector problem rather than a set of isolated cases. "The scale of this activity should be a wake-up call for every lender," Thomas said. He said the same warning signs turned up at banks covering the vast majority of the national mortgage market.

The gaps in the release matter as much as the headline. AUSTRAC did not publish a loan count, a file volume or a date range for the loans reviewed, and it set no deadline by which lenders must complete their own reviews. Anyone quoting a precise exposure figure here is extrapolating beyond what the regulator said. The significance of the sum is what it reveals about controls, which is how AUSTRAC framed it, as a warning rather than a loss event. Every figure and provision reference here comes from AUSTRAC's release and its published guidance, with responsible lending from ASIC and the penalty figures from the pages linked below, checked on 24 August 2026. We will update this page if AUSTRAC publishes a loan count, a date range or an enforcement step.

Operation Claw detailAs published by AUSTRAC, 19 August 2026
Partner agenciesAustralian Taxation Office, NSW Police Force, NSW Crime Commission, Australian Criminal Intelligence Commission (ACIC), Australian Prudential Regulation Authority (APRA), ASIC
Loans or files reviewedNot published
Date range of loans reviewedNot published
Deadline for lender self-reviewNone specified
Penalty proceedings against lendersNone announced

One nuance shapes how compliance teams should read this. Thomas was explicit that the project "did not identify evidence of widespread money laundering". The finding is mortgage fraud at the application stage and the professional networks that enable it, with laundering exposure sitting downstream as a vulnerability rather than a proven pattern.

How did the loans get through onboarding controls?

The pattern AUSTRAC describes is documentary. The mortgage fraud ran through the paperwork: applications carried inflated income and misrepresented employment, supported by business activity that was fabricated or could not be verified. Settlements and repayments were funded in some cases from offshore or third-party sources, which breaks the link between the stated income and the money that actually moved.

That combination defeats any onboarding control that stops at inspecting a supplied document, which is why the durable fix is verification at source. A payslip renders correctly, an accountant's letter carries a real practice name, and a company appears in a registry. The pattern surfaces only when the same broker, accountant or law firm turns up across many applications at once, which is exactly what pooling data across 10 banks exposed.

Each artefact in a single loan file passes inspection alone, while the pooled view across ten banks shows five applications converging on the same broker.
Analysis by Zyphe, from AUSTRAC's published Operation Claw typologies.

We covered the same failure mode when deepfake artefacts began appearing in identity checks: the artefact improves faster than the inspection of it, and closer scrutiny of what the applicant hands over never closes that gap. AUSTRAC named the typologies below. The mapping to where detection belongs, and what actually tests it, is ours.

Typology AUSTRAC observedWhere detection should sitControl that actually tests it
Inflated incomeApplication intakeVerified income at source rather than a supplied document
Misrepresented employmentApplication intakeIndependent employer confirmation, not employer-supplied paper
Fabricated or unverifiable business activityCredit assessmentRegistry and tax data checks on the trading entity
Offshore or third-party settlement fundsSettlement and repaymentSource of funds and source of wealth evidence
Falsified or misleading documentsDocument handlingAuthenticity checks and cross-application document matching
Repeated intermediaries across filesPortfolio analyticsNetwork analysis across brokers, accountants and firms

Thomas made the timing point plainly: "The most effective way to stop mortgage fraud is before a loan is approved." He added that once the funds have moved, "recovering the money becomes significantly harder."

What does this change for your AML obligations?

Operation Claw creates no new duty. It sharpens three existing ones, plus one transition deadline, under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, and the reformed regime is now the baseline: changed obligations for current reporting entities started on 31 March 2026, and newly regulated professions come in from 1 July 2026. The provision references below follow AUSTRAC's own published guidance.

ObligationLegal source per AUSTRAC guidanceTrigger in Operation Claw termsDeadline
Suspicious matter report (SMR)Act section 41Falsified payslips, fabricated or unverifiable trading activity3 business days after the day the suspicion is formed, 24 hours for terrorism financing, 5 business days where legal professional privilege is claimed
Enhanced customer due diligenceAct section 32, Rules section 6-20An SMR is required and you keep providing the service, or funding is unusually complex or has no apparent purposeApplies once the trigger is met, not after the report is filed
Ongoing customer due diligenceAct section 30(2)(a)Repayments arriving from parties never disclosed at originationContinuous
SMR form transitionRules sections 12-1 and 12-2Which SMR form you must useEnrolled after 30 March 2026: the new form from 1 July 2026. Enrolled on or before 30 March 2026: any time between 1 July 2026 and 30 March 2029

AUSTRAC's suspicious matter report guidance is unusually direct about the standard it will apply. "Reasonable grounds is an objective standard," the guidance states. Our reading is that this measures the grounds for a suspicion against what a reasonable person would conclude, not against how cautious the individual analyst happened to be.

The enhanced due diligence obligation is the one most likely to be missed here. It bites automatically once an SMR is required and you intend to keep providing the designated service, and separately where transactions are unusually complex, lack apparent economic or legal purpose, or form an unusual pattern. Offshore third-party settlement funding sits inside that trigger, and collecting and verifying source of funds and source of wealth is one of the enhanced measures AUSTRAC lists for exactly this situation.

A mortgage is also a multi-decade relationship, so undisclosed repayers are a change in know your customer information and the risk rating should move with it, which is the practical case for perpetual review over a fixed refresh cycle.

Read the ASIC referrals as a second front. For an Australian credit licensee, the same falsified income evidence engages the responsible lending conduct obligations in Chapter 3 of the National Consumer Credit Protection Act 2009, which require reasonable inquiries about, and reasonable steps to verify, a consumer's financial situation.

What is still uncertain after the mortgage fraud findings?

AUSTRAC's Operation Claw release leaves four questions unresolved.

Who carries the liability. Fintel Alliance referred those names to law enforcement and regulators, for intelligence purposes, which points to professional conduct and tax exposure for brokers and accountants. It does not settle what a lender owes when it accepted paperwork a third party forged. No penalty proceedings have been announced.

The regulatory hook is fraud, not laundering. Because the project did not find widespread money laundering, the Act is engaged through the reporting and due diligence duties rather than through a proven laundering typology. That makes the enforcement path less predictable than a conventional programme failure case.

Retrospective review is expensive and slow. Testing an existing book for mortgage fraud means revisiting files approved years ago. Doing that at scale, while managing tipping off constraints on customers who remain in the relationship, is a material programme of work with no fixed deadline attached.

Detection depends on data nobody holds alone. A lender acting alone cannot reproduce the cross-institution view of mortgage fraud that made Operation Claw work. As Thomas put it, "Each bank may see only one fragment ... Mortgage fraud succeeds when those fragments remain disconnected." In practice the substitutes are Fintel Alliance membership and acting on the indicators and threat alerts AUSTRAC has issued, which carry the cross-institution picture no single lender holds.

How does this compare with earlier AUSTRAC actions?

AUSTRAC's best known interventions, including two against retail banks, arrived as civil penalty proceedings after the fact. This one arrives as a warning before any lender has been named.

MatterOutcomeDateNature
Commonwealth Bank of Australia700 million Australian dollars, agreed penalty4 June 2018Retail bank, deposit machine reporting and monitoring failures
Westpac1.3 billion Australian dollars, the highest civil penalty in Australian history when ordered21 October 2020Retail bank, international transfer reporting failures
Crown Melbourne and Crown Perth450 million Australian dollars over two years11 July 2023Casino operator, programme and monitoring failures
Operation ClawNo penalty announced, names referred to law enforcement and regulators19 August 2026Retail lending sector, Fintel Alliance intelligence project
AUSTRAC penalties of 700 million, 1.3 billion and 450 million dollars against Commonwealth Bank, Westpac and Crown, with Operation Claw at no penalty.
Analysis by Zyphe, from AUSTRAC's published penalty releases.

The precedent cuts both ways. Lenders that use the threat alerts to find and report their own mortgage fraud exposure are in a materially different position from lenders that wait. Participating banks have already ended some relationships on the strength of the intelligence, and AUSTRAC says further action is expected.

How should compliance teams respond?

Lenders responding to AUSTRAC's Operation Claw findings should start with one test: do origination controls verify facts, or do they only inspect the documents an applicant supplies? Then run AUSTRAC's mortgage fraud indicators across the existing book rather than only new applications, and treat recurring intermediaries as a portfolio signal.

Where suspicion crystallises, calendar the three business day clock from the day after the suspicion forms, and trigger enhanced customer due diligence in parallel rather than after filing. Evidence source of funds and source of wealth wherever settlement money arrives from a party who was not on the application. Finally, check that your file retention actually supports a retrospective review, because a control you cannot evidence later is a control you did not have.

One of the SMR triggers AUSTRAC names is a customer who is not who they claim to be, and that is the part of this problem identity verification does answer. Zyphe reads identity from the chip in a passport or ID card to ICAO 9303 and eIDAS standards, with two-step liveness and no image upload, so there is no supplied image to forge. The reusable credential lets the same verified identity be re-presented rather than re-documented at each institution, and the customer holds the key, so there is no central store of identity images to breach. If you are reviewing origination controls after these findings, book a demo.

The bottom line

Operation Claw is a rare case of a financial intelligence unit publishing what it found before naming anyone. The useful signal is not the headline number but the shape of the failure: mortgage fraud survives where controls inspect supplied documents, run once at origination, in institutions that cannot see each other's files. Verifying identity and income at source, keeping the risk view live after approval, and treating recurring intermediaries as a portfolio-level signal are the changes that close the gap.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

Operation Claw is a Fintel Alliance intelligence project that pooled loan data from 10 major Australian banks and identified coordinated mortgage fraud worth potentially hundreds of millions of dollars, mostly linked to Sydney properties. AUSTRAC published the findings on 19 August 2026, and Fintel Alliance referred the names of individuals and entities potentially involved in submitting false loan documents to law enforcement and regulators including ASIC, the Australian Taxation Office and the Tax Practitioners Board, for intelligence purposes.

Yes, where you suspect on reasonable grounds that the information may be relevant to an offence such as tax evasion, or that a customer is not who they claim to be. AUSTRAC's guidance points to section 41 of the AML/CTF Act and sets the deadline at three business days after the day you form the suspicion, 24 hours where terrorism financing is involved, or five business days where legal professional privilege is claimed.

Enhanced CDD is mandatory once you are required to submit a suspicious matter report about a customer and intend to keep providing the designated service. It is also mandatory where transactions are unusually complex or large, lack an apparent economic or legal purpose, or form an unusual pattern. Collecting and verifying source of funds and source of wealth is one of the enhanced measures AUSTRAC lists.

Not on a widespread basis. AUSTRAC CEO Brendan Thomas said the project did not identify evidence of widespread money laundering, but warned that the weaknesses exposed could be exploited by criminals seeking to abuse the Australian financial system. The finding is loan application fraud and the professional networks enabling it.

AUSTRAC directed its message at every mortgage lender in Australia, not only the 10 banks that contributed data. It urged lenders to examine their mortgage books for signs of fraud, report suspicious activity and implement strong controls, and it has issued multiple threat alerts setting out indicators of mortgage fraud to support that work.

See privacy-first KYC in action

Verify identity without storing a single document. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo