Customer loses AUD41,600 after her bank account was apparently compromised.
New South Wales small business owner Thuy Le received a "telephone call" - it is not clear if that was an actual call or through a messaging service such as WhatsApp - saying that the caller had accidentally paid, on behalf of his wife, AUD60 into Le's primary business bank account and asking that she refund it.
She checked her account, saw the credit and transferred the amount, via her bank's mobile phone app NetBank, to account details provided by the caller.
Within 24 hours, a series of transactions had taken place, without her knowledge or involvement, totalling some AUD41,600, her entire savings for her children's education and her husband's medical bills. All were made through NetBank.
It's easy to point fingers, to ask why she would keep such a large sum in an account accessible by a mobile app, for example but the point is, surely, that it's got the bank's logo on it, the bank says it's safe and, well, it's a bank.
But the bank has consistently denied responsibility, insisting that Le must have allowed the fraudster to have access to her account. That doesn't explain how Two-Factor Authentication didn't alert her or prevent payments after the first AUD60.

There are many theories flying around as to how the fraudster was able to get her banking credentials. If that's what actually happened.
The transfers were all for round figures: 2,200, 200, 25,000, 9,800 and 4,100 on 24th and 25th November last year. These transfers appear to be very much out of the ordinary pattern of expenditure on the account but, for fraud-related purposes at least, did not trigger alerts. Even so, her account was not accessible after the transaction on 25th November.
Commonwealth Bank, which owns the NetBank service, investigated and established that each of the transactions was successful at the first attempt. It would be “very remote and nearly impossible for an unauthorised third party to guess” the credentials, the bank said.
The bank went on to say “the only reasonable explanation for these logins would be that your online banking credentials were known to the unauthorised third party, which would be in breach of the passcode security requirements.”
It also said that even if she did not make the transactions, she should have known about them and contacted the bank "“Had you reported the transactions immediately after the login ... the chances of successfully recovering some of the funds would have been much higher. On the balance of probabilities, if you did not complete transactions yourself, you have provided NetBank credentials to a third party, who has gone on to perform the transactions.”
The bank's position seems reasonable. Or it would if it were the first time this had happened but it isn't. Exactly the same happened to a customer of the same bank in Melbourne. Donna Brain refunded a supposedly mistaken payment for AUD210 in 2022 - and about AUD200,000 was drained from her account.

