Australia's proposed Scams Prevention Framework has come under scrutiny for omitting several critical scam-enabling entities from its regulatory scope. While the framework aims to impose mandatory prevention, detection, and response obligations on banks, telecom providers, and major digital platforms, stakeholders have raised concerns that non-bank payment service providers, cryptocurrency platforms, email services, and VoIP communications are not included. Treasury submissions argue that these channels are central to how scams are initiated and monetized, with the National Anti-Scam Centre highlighting email as a major entry point for scammers and noting that 46% of fraudulent calls originate from VoIP-enabled devices. The exclusion of these entities is seen as a significant gap that could undermine the effectiveness of the framework in protecting consumers from evolving scam tactics.
The debate reflects broader concerns about the adequacy of regulatory responses to modern, industrialized fraud, which increasingly leverages advanced technology and global infrastructure. Experts warn that without comprehensive coverage, regulatory frameworks risk leaving critical vulnerabilities unaddressed, allowing fraudsters to exploit gaps in oversight. Calls for expanding the framework underscore the need for a holistic approach to fraud prevention that keeps pace with the rapidly evolving threat landscape and the sophisticated methods used by cybercriminals to target individuals and organizations alike.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
Industry stakeholders and critics warned that excluding non-bank payment providers, cryptocurrency platforms, email services, and VoIP providers leaves major gaps in Australia's anti-scam regime. They also called for clearer liability and reimbursement rules and stronger intelligence-sharing requirements to disrupt scam networks and mule accounts.
Australia's proposed Scams Prevention Framework was introduced to impose mandatory anti-scam obligations on banks, telecommunications providers, and major digital platforms. The proposal aims to reduce scam-related harm but does not cover several other service categories critics consider important.
The National Anti-Scam Centre reported that investment scams caused $34.9 million in losses in the fourth quarter of 2024. One source said cryptocurrency accounted for $10 million of those losses, underscoring the role of crypto in scam monetization.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.