Insights for consumers
Never share one-time passcodes with anyone. One-time codes are the final security check before a payment is processed. Once entered, they confirm that a transaction is authorised and cannot be reversed. If someone asks for your one-time passcode, stop.
Insights for providers
When a scam is reported, act quickly. We expect clear explanations and empathy. Even if recovery is unlikely, consider taking practical steps to support your customer.
Scam responsibility while travelling overseas
Aria* was travelling in Bali and checked into a hotel on 9 December 2025. As part of the process, she shared her passport and card details with the hotel’s reception staff. She paid for her stay and made a small purchase at the hotel bar. Soon after, Aria received a phone call from her credit card provider. The caller knew Aria’s date of birth and described her recent transactions at the hotel as well as two payments she knew nothing about. One payment was for $1,445.47 and the other was for $3,703.42.
Aria asked the caller to reverse the two unknown transactions, to which they agreed. The caller asked for the last four digits of Aria’s card number and email address, which she provided. Then they told Aria to expect some one-time passcodes which were needed to reverse the transactions. Aria received the codes and read them out, as instructed.
About an hour later, Aria realised she had been scammed. She contacted the credit card provider straight away and the card was cancelled. Aria was told the payments could not be reversed as they had been authorised using one-time passcodes. Aria felt distressed and confused.
Aria complained to FSCL.
Was it fair to hold the customer responsible?
Aria said she was deceived by a convincing scam, when she thought she was stopping fraudulent transactions. She acted quickly after realising what had happened and felt it was unfair to be held responsible. She thought that the credit card provider should have done more to support her.
The credit card provider said the payments were authorised even though one payment was still pending at the time they were notified. This is because once the one-time passcodes are entered, the transactions cannot be reversed.
How FSCL assesses responsibility for scams
We looked at the card’s terms and conditions, the law, and industry best practice. We reviewed what happened after the scam was reported, and whether the response was fair and reasonable.
We focused on two questions.
- Who was responsible for the transactions?
- Did the provider respond appropriately after the scam?
Responsibility for authorised transactions
We accepted that Aria was the victim of a scam. However, by sharing the passcodes with the scammer, she had approved the payments.
The card provider’s terms and conditions required Aria to protect security information and keep her card safe, including not sharing one-time security codes or account information with anyone else. We found Aria was responsible for the payments, because she had provided the one-time security passcodes to the scammer.
One-time passcodes are the final security check before a payment is processed. Once entered, they confirm that a transaction is authorised and cannot be reversed, even if they briefly show as pending.
The provider’s response after the scam
Aria contacted the provider quickly, despite being overseas and distressed. The provider had correctly explained that the transactions could not be reversed. However, we found that the advice was limited, and there was little effort to reassure or guide Aria. The explanation lacked clarity and empathy.
We also considered whether more could have been done, such as a request to recall the funds. Even if unlikely to succeed, it shows an effort made.
We found a lost opportunity to support Aria, adding to her stress and frustration.
We did not hold the provider responsible for the payments, as Aria had approved the transactions under the terms and conditions. However, we partially upheld the complaint, as we found that the provider’s response after the scam was not fair.
We decided the provider should pay $500 to recognise Aria’s distress and the lost opportunity to offer her some support.
Both parties accepted our proposal, and the complaint was closed.






