Regulatory Update

Operation Claw Exposed the Fraud. What Happens When Staff See the Red Flags?

Published 21 August 2026

On 19 August 2026, AUSTRAC's Fintel Alliance released the findings of Operation Claw, a joint analysis of transaction data from ten major Australian banks. The investigation identified potentially hundreds of millions of dollars in suspected fraudulent home loans, the majority linked to properties in Sydney. Applications had been built on inflated incomes, misrepresented employment, and fabricated or unverifiable business activity. In some cases, offshore or third-party funds were used to settle properties and keep up repayments.

"The scale of this activity should be a wake-up call for every lender," said AUSTRAC CEO Brendan Thomas.

It's easy to read this as a banking problem. But the risks don't stop at the bank. Operation Claw is a live example of the kind of financial crime activity that can sit around property transactions, and why businesses involved in the broader transaction need to understand what they are seeing and what they should do about it.

If your business provides designated services in or around property transactions, Operation Claw is not background noise. It's a live case study in the kinds of activity your AML/CTF controls and trained staff need to be able to recognise and escalate.

Where this gets sharp: tipping off

Most AML/CTF conversations focus on detection: verifying who your client is, watching for red flags and filing the right reports.

But there is another responsibility that staff need to understand: what they can and can't say when concerns arise.

If your business has submitted a Suspicious Matter Report (SMR), or information protected by the tipping off provisions, staff need to understand the limits on what they can disclose. The offence isn't simply about mentioning an SMR. The issue is whether a disclosure would or could reasonably be expected to prejudice an investigation.

Good intentions don't necessarily protect a staff member if a disclosure meets that legal test.

A staff member reassuring a nervous client, casually explaining why additional checks are being undertaken, or making a comment that reveals information has been reported or that authorities may be taking an interest could create a tipping-off risk, depending on the circumstances.

This is precisely why regtech isn't enough on its own.

Regtech can flag a suspicious file. It can't stop a receptionist, a graduate accountant or a junior property manager from saying the wrong thing.

That gap isn't automated. It's trained.

Wherever you're starting from, this applies

STATUS: NOT ENROLLED

Haven't enrolled or started your program yet.

Operation Claw is a reminder that AUSTRAC is actively using transaction data and intelligence to identify financial crime risks, this isn't a theoretical framework.

Enrolment is only the starting point. Your business also needs an effective AML/CTF program, appropriate controls and trained staff.

STATUS: ENROLLED

Enrolled, but haven't implemented anything since.

A completed AUSTRAC enrolment doesn't make an AML/CTF program effective. If staff don't understand their responsibilities, your business can still have a significant frontline compliance gap.

Your paperwork might be in order. Your frontline isn't covered yet.

STATUS: SYSTEMS READY

Systems sorted, staff not trained.

If you've invested in verification tools or regtech but haven't trained the people using them, you may still have a significant human-risk gap.

Tipping off is a good example. It's not simply a system problem. It's a conversation risk.

Your systems can identify a concern. Your people need to know what happens next.

The takeaway

Operation Claw is a fraud story about banks. But it also provides a timely reminder of the financial crime risks that can sit around property transactions, and the importance of effective AML/CTF controls and informed staff.

Tipping off is one part of staff awareness training, not the whole of it.

Staff need to understand the red flags, know when to escalate concerns, understand what information is protected, and know what they should and shouldn't say to a client.

↓ Get started today

For accounting practices: The GET-READY Bundle.

$250 for a practice of up to three staff, $50 per additional seat.

  • AMLCO Support Kit — risk assessment templates, policies, and procedures
  • Client communications pack and Customer IDV Guide included
  • Staff awareness training with individual certificates of completion
  • 3 seats included — $50 per additional seat
Buy the GET-READY Bundle — get started now

Questions? Visit our FAQ or get in touch.

↓ Register your interest

For real estate agencies: Register your interest.

Our real estate program is in development. Register your interest and we'll let you know the moment training opens — no cost, no obligation.

Register your interest

We'll be back again later with a look at the parts of Tranche 2 most businesses don't realise are in there.

Back to Issue 1: Do the new AUSTRAC laws actually apply to your accounting practice?
Back to Issue 2: What even is a 'designated service'?
Back to Issue 3: DIY, consultant, or head in the sand
Back to Issue 4: Enrolment Closes 29 July. Your Obligations Started 1 July. Is Your Program Underway?

This article provides general information only and is not legal advice. Businesses should obtain professional advice about how the AML/CTF Act applies to their particular circumstances.