Greg's Take
There are two events in every scam, and almost everyone only looks at the first one
Event 1 is the deception. The customer was tricked. That is not in dispute, and it is not where the answer lies
Event 2 is the bank moving the money. That is the event nobody asks about, and it is the one that matters
"But how is that the bank's fault?" is the wrong question. The right question is: what did the bank do when the money moved?
Preamble
When someone hears that a person had money stolen by a scammer, the first reaction is almost always the same: how did they fall for it, and how is that the bank's fault? This page is about why that question, however natural, points in the wrong direction, and what happens when you separate the one event everyone stares at from the one event everyone ignores.
How Is That the Bank's Fault?
Tell someone that a customer had forty thousand dollars stolen by a scammer, and watch the first reaction. It is nearly always some version of the same thing:
How did they fall for that?
How is that the bank's fault?
The customer handed over the code.
The customer let someone onto their computer.
The customer made the payment.
Where is the bank in any of that?
It is a fair reaction. But nobody else was there in the moment.
It is also the exact point at which most people stop thinking, and it is the reason so many people who have had funds stolen are quietly told, in effect, that they brought it on themselves. That reaction is normal because it treats a scam as one event. It is not. It is two events
Event 1 is the deception.
A criminal manipulates a person into doing something, disclosing a code, allowing remote access to a computer, believing a lie about who they are speaking to. This is real, it is where the wrong is done, and it should be said plainly: the customer was deceived. There is no point pretending otherwise, and nothing on this page depends on pretending otherwise. Event 1 belongs to the scammer. The customer's part in it is the part a skilled criminal crafted.
Event 2 is the movement of the money.
After the deception, the stolen funds have to actually leave the account and travel through the banking system to the scammer. That is not done by the customer and it is not done by the scammer. It is done by the bank, through its own payment systems, under its own controls, subject to its own monitoring. Event 2 is the bank's event.
Almost every conversation about scams stops at Event 1. How did they fall for it. How could they be so careless. And once the conversation is stuck on Event 1, the answer is always the same, because Event 1 really was the customer's moment of deception. Ask only about Event 1 and you will always arrive at "the customer's fault", every time, because that is the only place that question can lead.
The questions that actually matter are all about Event 2, and they are never asked.
When the money moved, what did the bank's systems see?
Was the payment unusual for this customer?
Did it trip any alert?
If it did, what did the bank do?
If it did not, why not?
Did the money go somewhere the bank had been warned about before?
Being deceived at Event 1 tells you nothing about how the bank handled Event 2.
They are separate events, examined separately. One belongs to the scammer. The other belongs to the bank.
Think about how we treat security everywhere else. At an airport, passengers are told not to carry prohibited items, and most people try to comply. Nobody imagines that a warning sign at the entrance is the whole of airport security. There is a screening layer, run by the airport, precisely because human beings make mistakes, get distracted, get fooled, and because the consequences of a single failure are serious enough to justify a second line that does not depend on every individual getting it right every time. The screening layer exists because relying on people to be perfect is not a security system. It is the absence of one.
Banking has the same shape. The customer is the first line, and the customer can be deceived, because customers are human. The bank's payment monitoring is the screening layer, the line that is supposed to catch what gets through, precisely because the first line is fallible. When a bank's entire answer to a scam is "the customer authorised it, the customer was careless, the customer disclosed the code", it is pointing at the failure of the first line as though the second line was never its job.
It is holding up the warning sign and saying nothing about the screening.
A great deal of scam prevention advice is built on the assumption that the customer will not be fooled. Do not disclose your code. Do not allow remote access. Do not trust callers claiming to be from your bank. This is fine advice, but it is advice to a species that does not exist, one that never gets tired, never gets frightened, never trusts the wrong voice at the wrong moment. Real people get fooled. That is not a reason to abandon them at Event 2. It is the whole reason Event 2 protections have to exist.
This is not a fringe view of how these matters should be assessed. In a published decision, AFCA case 12-24-153284, the adjudicator said it was unclear why the bank processed a $40,000 transaction while a fraud detection alert was still unresolved, and why it then waited about two hours before acting to block the customer's online banking. As it happened, the customer was already protected, because the bank could not show the customer had breached the security requirements, so the Code placed the loss on the bank. That meant the adjudicator did not have to decide the fraud alert questions. But the questions were the right ones, and they are the questions this page is about: when the money moved, what did the bank do, and why did it let it through?
So when the reaction comes, and it always comes, that "but how is that the bank's fault", the answer is not to argue that the customer was clever, or blameless, or careful. The customer was deceived, and that is Event 1, and it is conceded. The answer is to ask the question nobody asked: when the money moved, what did the bank do?
What This Means If You've Had Funds Stolen
Separate the two events in your own matter.
Event 1 is how you were deceived.
Event 2 is how the bank moved the money.
They are different events and they are judged differently.
You do not have to prove you were not deceived. You were, and that is not the question. Concede it plainly and move the focus to Event 2.
The questions that carry weight are about the bank's conduct when the money moved: what its systems saw, whether the payment was unusual, whether it tripped an alert, and what the bank did about it.
If a bank's whole response is that you authorised the payment, disclosed a code, or were careless, notice that every one of those points is about Event 1.
None of them answers what the bank did at Event 2.
Being deceived is not the same as being at fault for what the bank's systems did or failed to do afterwards.
Those are two events, and you are entitled to have the second one examined.
Feedback and Right of Reply
Questions or comments?
This page reflects patterns observed in real complaint handling. If you have questions or comments, or your own experience to add, we would like to hear from you.
Right of reply.
Where a bank or organisation named or clearly identifiable on this page believes anything stated here is inaccurate or unfair, we invite that bank or organisation to contact us directly. Any correction that is factually substantiated will be published alongside the original material, so the public record reflects both sides.
This is not a request for legal argument, it is an open invitation to correct the record.
Authorised by Greg Williams, Lincoln Computer Centre, contact details below