After $1.25 million loss over deceptive text messages, scam victims take banking giant to task

A group of HSBC Australia customers have found themselves at the mercy of a sophisticated scam, losing a staggering total of $1.25 million.

Now, they're fighting back, demanding the global banking giant address what they believe are significant flaws in its digital security.



The scam, which has affected at least 24 individuals across Australia since April 2023, began with a seemingly innocuous text message.

The message appeared to come from HSBC, even showing up in the same thread as previous legitimate alerts from the bank.


compressed-shutterstock_2103328010.jpeg
More HSBC customers have fallen prey to scams. Credit: Shutterstock


Scamwatch, the federal government-backed agency established as its anti-scam advocacy arm, warned everyone that ‘scammers are targeting HSBC customers with calls and texts that appear to be from their bank’, known as spoofing.

Customers have been called from a number that ‘looks to be the genuine HSBC phone line’.

Gerald Chin, a Sydney resident and one of the victims, lost $50,000 to this scam last year.

He received a text message that appeared to be from HSBC, warning him of a potential breach in his account.

When he called the number provided in the message, a scammer posing as an HSBC representative convinced him to share his username, personal details, and bank codes.

The fraudster then accessed his account and drained his savings, shattering his plans of surprising his parents with an overseas holiday.



The victims, who have each lost between $50,000 and $100,000, have banded together in a coordinated effort to recover their stolen funds and compel HSBC to address the alleged security gaps.

They have written a joint letter to HSBC Australia's CEO, Antony Shaw, and Group Chief, Noel Quinn, but have only received a ‘boilerplate response’ from the bank's advocacy team.

Chin, set for mediation through the Australian Financial Complaints Authority (AFCA) in March, said ‘he will be considering all possible options’ if he does not secure a full refund.

So far, HSBC has only been able to recover $1 of his stolen money.



Chin said the situation left him struggling to service his mortgage and ‘infuriated’ that he never received a transaction notification, which ‘could have prompted me to act earlier’.

‘I think it’s disgusting how the bank has dealt with the whole saga,’ he said.

‘Similar incidents were reported to HSBC early on, but the bank has not taken any concrete actions.

Chin also labelled the bank’s attempts to mitigate concerns ‘deplorable’.

‘Generic information on how to protect yourself from scams was unhelpful and failed to raise awareness about how the scammers operated.’

‘(HSBC) continues to use SMS knowing that this has been compromised, and I have got a scam text only a few weeks back on a new HSBC number used to reset my account.’

Another customer complained that this situation would not have happened anywhere else because of the longer holds on money transfers to new recipients.

‘Had we banked at another bank, this would have been blocked,’ they said.

‘HSBC [is] the only [one] that can prevent these scams, as other banks have, and are therefore responsible.’


compressed-shutterstock_398067394.jpeg
Customers said HSBC is responsible for the loss of their savings. Credit: Shutterstock


In response, HSBC stated that it would not discuss individual cases for privacy reasons but stressed action was being taken on their end.

‘HSBC takes customer security seriously, and we investigate all reported customer issues, with the outcome dependent on each set of circumstances,’ the bank said.

‘The bank is investing heavily to protect our customers and play our part in supporting the wider financial services industry on this issue.’

HSBC has educational tools on its app, website, online banking, and inside its branches on how to protect a customer from scams. It has also been working with the Australian Banking Association in a bid to win the ‘war’ against scams.



The victims' plight has caught the attention of Scamwatch, which issued a warning about scammers targeting HSBC customers with spoofing calls and texts.

‘They claim there was an attempt to gain access to your account or fraudulent activity,’ Scamwatch warned.

‘The scammer asks for your username, personal details and bank codes to gain access to your account.’



In 2023, the Australian Financial Complaints Authority (AFCA) reported a record number of complaints against banks, surpassing 100,000 reports.

This marked a 23 per cent rise from the previous year and included grievances from individuals and businesses unable to resolve disputes with their banks.

‘The volume of complaints escalated to AFCA has been increasing at an unsustainable rate,’ AFCA’s Chief Ombudsman and Chief Executive Officer David Locke said.

‘Scam-related complaints to AFCA have nearly doubled between 2022 and 2023. They continue to be of great concern to us.’

‘We are also seeing the impact of increased interest rates and cost of living pressures, with complaints involving financial hardship also significantly higher.’
Tip
If you think you or someone you know may have been scammed, please call your bank immediately or report your experience to ACCC here.

You can also visit our Scam Watch forum to stay updated with the latest tricks scammers use to deceive people out of their money and sensitive details.
Key Takeaways

  • A group of HSBC Australia customers has fallen victim to a bank impersonation scam, with losses totalling $1.25 million.
  • The scam operated through spoofing, where scammers sent texts or made calls appearing to come from HSBC, asking for personal details and bank codes.
  • The victims have joined forces and are seeking to recover their money, alleging that HSBC has serious gaps in its digital security.
  • HSBC insists on taking customer security seriously and is investing in prevention measures, but the affected customers are dissatisfied with the bank's response to their situation.
Have you or someone you know been a victim of a similar scam? Share them with us in the comments below.
 
Last edited:
  • Like
Reactions: Chicky and Ezzy
Sponsored
How often do people have to be told about scams & their methods of getting your money. I have read so many times "Do not ring the number they give. Get the number from you a/c (or some other legit place) & ring to check if the SMS or phone call is genuine.
 
Once again why would anyone ring a number or click on any link on a text or email!
If you do You deserve to lose everything!
No sympathy whatsoever.
Simply ring the organisation on their proper number and check!
Sick of people complaining about their own stupidity!
 
Simple. Trust no email or text message, even from your well-used bank or accountant or ATO or telephone company or whoever is billing you via the internet. Unless it is a in a letter posted to your address delete it or ignore it. Then pay by cheque as that gives you a few days to stop the cheque if you get suspicious in the next couple of days. THAT IS SECURITY. The internet should be called the ScammerNet.

The internet is wonderfully convenient for both we, the punters, and scammers.
 
I don't see why the banks should refund the money. People have been told not divulge personal information. They should look up the phone number on their bank statement and ring that number.
There are time when you cannot avoid divulging personal information and once that is in someone's computer or server, then it is vulnerable to being hacked. Which is why it is illegal for personal medical information to be stored on an overseas server and doctors ,who use applications that record such data and they are applications that depend on an overseas server for their storage, are breaking the law.

Once one had to burgle an office to get hold of such information, which was on paper in a filing system; now, just learn the skills to hack a server remotely. I have no doubt every national "intelligence" agency teaches members of staff how to do this; it involves a form of code-breaking.. It's how Bletchley Park in the UK managed to learn where German U-boats were lying in wait for the trans-Atlantic convoys and thus won the Battle of the Atlantic.
 
There are time when you cannot avoid divulging personal information and once that is in someone's computer or server, then it is vulnerable to being hacked. Which is why it is illegal for personal medical information to be stored on an overseas server and doctors ,who use applications that record such data and they are applications that depend on an overseas server for their storage, are breaking the law.

Once one had to burgle an office to get hold of such information, which was on paper in a filing system; now, just learn the skills to hack a server remotely. I have no doubt every national "intelligence" agency teaches members of staff how to do this; it involves a form of code-breaking.. It's how Bletchley Park in the UK managed to learn where German U-boats were lying in wait for the trans-Atlantic convoys and thus won the Battle of the Atlantic.
A company getting “hacked” is totally different to a scam.
We have no control on a business being hacked.
But only a fool will respond to an email by clicking a link or ringing a number and the handing over personal details.
I have no sympathy for these idiots and they deserve to lose ever!
But I do sympathise with anyone who has been affected by a company who has been hacked.
If you use Amazon or any online business to purchase goods make sure your credit card details are removed immediately after purchase!
 
  • Like
Reactions: Tervueren
'A company getting “hacked” is totally different to a scam'. Yes; and that, the theft of personal information from a server, is what may lead to one being scammed.
 
'A company getting “hacked” is totally different to a scam'. Yes; and that, the theft of personal information from a server, is what may lead to one being scammed.
Not at all if you are diligent and don’t respond to any emails or texts directly!
 
Simple. Trust no email or text message, even from your well-used bank or accountant or ATO or telephone company or whoever is billing you via the internet. Unless it is a in a letter posted to your address delete it or ignore it. Then pay by cheque as that gives you a few days to stop the cheque if you get suspicious in the next couple of days. THAT IS SECURITY. The internet should be called the ScammerNet.

The internet is wonderfully convenient for both we, the punters, and scammers.
Unfortunately, there are no more cheques.
 
NEVER EVER REPLY TO A MESSAGE
on your phone or computer....
Ring the bank !! EASY !
 
I treat everything as a scam until I know 100% otherwise. I never keep money in my card account and only transfer from a different account when I need to go shopping. If my card number is compromised there is no money for the scammer to steal.
 
Juse thinking to myself: how easy would it be for the banks themselves to be the actual scammers in most cases!!..they investigate them selves with maybe like minded outside of them investigaters. They then reply with: "its the customers own fault for falling for the so-called scam" but then seem to leave these scam avenues wide open for them to be repeated. I'm thinking!! When thousands of people are scammed out of millions of dollars and only a small percentage are reimburse, then the scammers whoever they are, walk away with a very tiedy sume of money
 

Join the conversation

News, deals, games, and bargains for Aussies over 60. From everyday expenses like groceries and eating out, to electronics, fashion and travel, the club is all about helping you make your money go further.

Seniors Discount Club

The SDC searches for the best deals, discounts, and bargains for Aussies over 60. From everyday expenses like groceries and eating out, to electronics, fashion and travel, the club is all about helping you make your money go further.
  1. New members
  2. Jokes & fun
  3. Photography
  4. Nostalgia / Yesterday's Australia
  5. Food and Lifestyle
  6. Money Saving Hacks
  7. Offtopic / Everything else

Latest Articles

  • We believe that retirement should be a time to relax and enjoy life, not worry about money. That's why we're here to help our members make the most of their retirement years. If you're over 60 and looking for ways to save money, connect with others, and have a laugh, we’d love to have you aboard.
  • Advertise with us

User Menu

Enjoyed Reading our Story?

  • Share this forum to your loved ones.
Change Weather Postcode×
Change Petrol Postcode×