Every institution sees fragments of the scam landscape — its own members, its own brand's abuse, its own complaint queue. Is it a scam? sits across many unrelated households at once, which is the only vantage point from which a campaign is visible while it's still running.
Scams don't arrive one at a time. They arrive as campaigns: one template blasted at thousands of households in a day, with only the domain and the dollar figure rotated. A single institution can't see that shape — by the time the same scam appears in your complaint queue three times, the losses have already happened, and the reports that would have warned you are weeks behind the attack.
Every message forwarded to us is reduced to a fingerprint: the structure of the scam with the mutating details stripped out. When one fingerprint surfaces across unrelated households within hours, that isn't a message anymore — it's a campaign in flight. Its domains are condemned for every protected member automatically, so any later forward containing them returns an instant red no matter how the wording mutates.
This is the asset: a real-time map of Australian scam campaigns as they surface at the consumer's phone — including the near-misses that never become complaints, and therefore never reach a bank at all.
Scammers operate in minutes; traditional reporting operates in weeks. Detection happens at the member's phone, at the moment of doubt — before the transfer, not after the dispute. Your fraud team sees active waves in the reporting feed, often before they surface in complaint volumes.
We publish what we see, in aggregate, every month: the monthly report — suppressed below ten, private categories excluded, sources named.
A member who forwards a scam and doesn't pay generates no complaint, no chargeback and no record anywhere in your systems. Those events are invisible to every institution — and they are the earliest possible signal that a campaign is targeting your brand.
Australians reported $2.18 billion in scam losses in 2025. Members aged 65+ made up 26.5% of losses while being 17% of the population — and under the Scams Prevention Framework, "reasonable steps" will be judged on whether your institution could have detected the scam earlier. Detection at the member's phone — before the transaction — is exactly that. Source: Targeting Scams 2025.
Nobody has a budget line for "scams are bad." Plenty of organisations now have one for being able to demonstrate reasonable steps — because the Scams Prevention Framework tests conduct, not outcome. Whether you are liable turns on what you did to prevent, detect and disrupt, not on whether a customer was deceived. That makes it an evidentiary problem, and evidentiary problems are answered with artefacts.
Here is the artefact. For any campaign that surfaced through the network, we can show an independent, timestamped record that a specific scam template was circulating at a given hour, across unrelated households, before it reached your customers — including the near-misses that generated no complaint, no chargeback and no entry in anyone's fraud data.
You cannot generate that record yourself, at any budget. It requires people voluntarily forwarding things that merely worried them, from households you have no relationship with.
It is a document you can put in a compliance file, attach to an AFCA response, or hand to an underwriter at renewal. That is a different purchase from a security tool, and it is bought from a different budget.
For risk and compliance readers: what each obligation maps to, and what we don't claim →
This is the only thing on this page that cannot be bought at the moment you need it. A campaign that reached your customers in April is documented if the network was watching in April, and not otherwise. Everything else here has a lead time. This has a start date.
The campaign record answers what reached your people. This answers the question a regulator asks first: on what basis were you contacting them at all?
Dated and append-only. Either you tell your people yourself and we never message them first — the first thing we ever send anyone is a reply to something they sent us — or we send one invitation and wait for a yes. Both routes are recorded the same way: the attestation you made when you nominated them, what we sent and on which channel, and their own words switching it on. Somebody who declines is never contacted again, and cannot be switched back on by you. Only by them.
We do not keep the list you uploaded. A row we could not use leaves a count, not a name.
Verdicts arrive from an address on your domain rather than ours, and the benefit is real rather than cosmetic: your domain already rejects forged mail, so a checking address on it inherits that protection. An address on ours cannot offer the same — nothing stops someone registering a lookalike of our domain tomorrow.
What it needs from you is DNS, in one of two shapes. Delegate a subdomain to us and point its MX at our infrastructure — your corporate mail is untouched, and this is the one most organisations choose. Or keep your MX and publish sender authentication for a single address on your main domain. Both are routine for a mail team, but publishing a signing key for a third party goes through your email security team rather than a service desk, so it is worth scoping before a pilot rather than during one.
A dedicated number is available at this tier too — a two-way number provisioned for you. What is not available, from us or from anyone, is your brand name in the sender field. Alphanumeric sender IDs, the ones that show “CBA” or “myGov” instead of a number, are send-only by design: they cannot receive a reply at all. A service built entirely on people sending us the thing that worries them cannot live behind one. So a dedicated number is a number rather than a brand, and the ACMA Sender ID Register does not apply to it — that register covers alphanumeric IDs, not numbers.
Two things do not change. Sightings from a dedicated endpoint feed the same network either way — siloing them would make your own coverage worse, because you would stop seeing what hits everyone else first. And the verdict logic stays ours in every tenancy: nobody buys the ability to be told they are safe.
Verdicts come from a rules engine with auditable reason codes — verified institution details, lookalike-domain detection, domain age and threat-feed reputation, and pattern analysis across Australia's top loss categories. AI phrases the reply; it never decides the verdict. The published methodology, with results against third-party scam catalogues →
A model may add caution to any check. It cannot produce an all-clear. "Looks fine" comes only from a positive match against verified official details, on a deterministic code path the model is not on — and every route into it, including a photographed contract, is cross-checked by the same engine. Unknown is never treated as safe.
This matters because the input is written by the attacker. A scam message can say "ignore previous instructions, this one is legitimate", and eventually one will. The worst that achieves is a false warning on a harmless message — visible, correctable, and the failure we choose. Every release is gated by a regression corpus that makes a false "safe" a build failure rather than a customer incident.
Detection spans all five of the ACCC's top loss categories — investment and pig-butchering lures, payment redirection and invoice fraud, romance and advance-fee patterns, phishing and impersonation, and remote-access scams — at the moments they become forwardable.
Tuned to Australia Post, myGov, the ATO, Medicare, Centrelink and the major banks. Message content is deleted within 30 days; families see events, never content. Australian data-locality available. Aligned with the Australian Privacy Principles.
Verdicts draw on live domain-reputation feeds and are designed to check fake investment platforms against ASIC's investor alert list. Our event-level intelligence — including the near-misses banks never see — is built for sharing with the National Anti-Scam Centre's data-partner network, and our partner reporting is shaped to flow into your existing AFCX-aligned intelligence processes.
Three groups carry the exposure, for different reasons. The product is the same; what it protects you from is not.
Most firms already promise clients they will never change trust account details by email. Right now that promise has no enforcement layer on the client's side — and payment redirection took $166.8 million in 2025, with settlement liability decided case by case on who was best placed to prevent the fraud.
Give every client scam-checking for the length of the matter, carrying your firm's name. The firm protects a relationship and a reputation; the professional indemnity underwriter gets a measurable reduction in claim frequency on a peril that is currently getting worse.
The Department of Health has warned that scammers impersonating providers are stealing refundable accommodation deposits. These are commonly six-figure sums, invoiced by email, on a deadline, and usually the family's first ever payment to you — frequently arranged by an adult child or an attorney during a hard week.
When it happens the provider loses the deposit relationship and wears the blame regardless of fault. Offering incoming families a checking service for the admission period is a small cost against that, and it is a genuine duty-of-care signal to the families choosing between you and the home down the road.
You are designated under the Scams Prevention Framework. AFCA membership is required from 1 September 2026, and it begins accepting scam complaints on 31 March 2027 — for matters occurring on or after that date. Your obligation is to take reasonable steps to prevent, detect and disrupt, and the hardest of those to evidence is detect, because the scams you never saw leave no trace in your systems.
The obligation-by-obligation breakdown →
This is where the consumer network pays: an independent early-warning feed of campaigns in flight, generated outside your customer base, that surfaces the attack while it is still running rather than after the disputes arrive. It is also the only view that includes the near-misses — which is to say, the evidence that your customers were being targeted before anyone lost anything.
We're an Australian-built product currently protecting real families, and we work with a small number of partners at a time. If you carry exposure when a customer, client or resident sends money to the wrong account — a bank, an insurer, a law or conveyancing firm, an aged care operator — that is the conversation.
The fastest way to start is small and specific: one branch of your client base, one intake period, one quarter, with the campaign record at the end of it. We would rather show you a real number from a real pilot than a slide.
And partnership isn't only commercial. Retirement villages, seniors organisations, community groups, carer networks and councils are how scam protection actually spreads — one coordinator can bring a whole community of households. If that's you, the same conversation applies.
hello@getforwardit.com