Sun. Jul 19th, 2026

ASIC Secures $830 Million in Penalties During Record Enforcement Year

ByShane Neagle

July 19, 2026 #ASIC
The Australian Securities and Investments Commission (ASIC)The Australian Securities and Investments Commission (ASIC)

ASIC’s $830 Million Penalty Year Puts Banks, Super Funds and Market Firms on Notice

The Australian Securities and Investments Commission has delivered one of its strongest enforcement periods on record, securing $830 million in court-ordered civil penalties during the 2025-2026 financial year and linking its work to almost $644 million in remediation, refunds and other payments to customers and investors.

Australia’s corporate regulator secured $480 million in civil penalties between January and June 2026, following $350 million ordered during the first half of the financial year.

The latest enforcement actions targeted misconduct across banking, superannuation, contracts for difference, consumer credit and securities markets. Union Standard International Group, HSBC Bank Australia, Westpac, Macquarie Securities and Mercer Super were among the companies penalised.

ASIC also launched more than 250 investigations during the year, filed 32 new civil proceedings and began 18 criminal prosecutions. The regulator recorded 25 criminal convictions, including 21 custodial sentences and 11 cases in which individuals were sentenced to imprisonment.

ASIC Chair Sarah Court said the regulator was concentrating its resources on misconduct that caused direct harm to consumers, investors and the integrity of Australian financial markets.

“Our enforcement work is focused on misconduct that causes real harm and we are delivering results, forcing change, strengthening accountability, and returning money to consumers and investors,” Court said.

She said ASIC was pursuing failures involving scams, financial hardship, market infrastructure, superannuation, private credit, financial reporting and digital assets.

The financial penalties were led by a record $300 million order against Union Standard International Group over serious misconduct involving contracts for difference, or CFDs, and failures affecting retail investors.

The Union Standard penalty accounted for more than one-third of ASIC’s full-year civil penalty total and nearly two-thirds of the $480 million ordered during the first half of 2026.

ASIC also secured close to $40 million in refunds for CFD investors in connection with its work.

CFDs allow traders to speculate on price movements in currencies, commodities, shares, indices and other assets without owning the underlying instrument. The products can expose retail customers to rapid losses, particularly when leverage allows positions to exceed the amount initially deposited.

ASIC has repeatedly identified retail derivatives as an area of concern because of the combination of leverage, complex pricing and business models that can place providers’ commercial interests in conflict with those of customers.

The $300 million Union Standard order shows how heavily a single major case can influence annual enforcement totals. It also reflects ASIC’s willingness to seek penalties large enough to change the economics of misconduct rather than treating regulatory fines as a routine cost of business.

Banks Penalised Over Scams and Hardship Failures

HSBC Bank Australia admitted failures in its systems for protecting customers from scams, resulting in a $35 million penalty.

Following ASIC’s investigation, HSBC established a remediation program that had paid around $21.5 million in compensation by the time of ASIC’s announcement. Further payments were expected before the end of July 2026.

HSBC also recovered $6.5 million and returned those funds to customers.

The case reflects growing pressure on Australian banks to identify suspicious activity, respond quickly when customers report fraud and avoid leaving scam victims trapped in slow or fragmented complaint processes.

Scam losses have become a central regulatory issue as criminals use impersonation, investment promotions, payment redirection and social engineering to persuade victims to transfer money voluntarily. Those cases can be difficult to reverse because the customer technically authorises the transaction, even when the authorisation was obtained through deception.

ASIC’s action against HSBC indicates that banks may face penalties not only when their own employees engage in misconduct, but also when internal systems fail to respond properly to external criminal activity affecting customers.

Westpac was separately ordered to pay a $26 million penalty for widespread failures in handling customer financial hardship requests.

Hardship arrangements can include reduced repayments, temporary pauses, changes to loan terms or other support for borrowers who are unable to meet existing obligations because of job loss, illness, income disruption or higher living costs.

Failures in that process can leave vulnerable customers facing added interest, collection activity or damaged credit records while their requests remain unresolved.

The Westpac case shows that operational failures in customer service can become major enforcement matters when they occur across a large institution and affect people already under financial pressure.

Market Data Failures Draw $35 Million Macquarie Penalty

Macquarie Securities was ordered to pay $35 million after systemic failures led to millions of short sales being misreported and inaccurate information entering the market.

Short selling involves selling securities that the trader does not own at the time of the transaction, usually with the intention of buying them back later at a lower price.

Accurate reporting matters because regulators rely on market data to monitor trading activity, identify unusual patterns and assess whether participants are complying with market rules.

The Macquarie case was not built around a single rogue transaction. It involved systems capable of producing inaccurate information on a large scale.

That distinction matters.

A financial market can tolerate occasional human error. It cannot function properly when the infrastructure used by major participants repeatedly sends incorrect data into reporting systems.

The $35 million penalty places market reporting failures alongside consumer misconduct as a serious enforcement priority. It also suggests that ASIC is paying closer attention to the technology, governance and control frameworks behind trading operations rather than waiting for a visible market disruption before acting.

Mercer Super and Snaffle Cases Expand ASIC’s Reach

Mercer Super was ordered to pay $10.3 million for systemic reporting failures, including failures to report significant breaches to ASIC.

Financial services firms are required to notify the regulator when serious compliance breaches occur. Those reports allow ASIC to detect patterns, assess risks and decide whether broader intervention is needed.

When a company fails to report its own misconduct, the regulator may be left unaware of consumer harm until the problem grows.

The Mercer penalty therefore reaches beyond paperwork. Breach reporting is part of the early-warning system on which financial supervision depends.

Walker Stores, which traded under the Snaffle brand, received a $33.5 million penalty for unlawful credit practices that resulted in consumers being charged almost $20 million in excess interest.

The case added consumer lending to a list of enforcement targets that also included global banks, trading firms, superannuation trustees and leveraged product providers.

Together, the cases show a regulator willing to pursue misconduct across different corners of the financial system rather than concentrating only on the country’s largest banks.

Almost $644 Million Linked to Consumer Payments

ASIC said $643.5 million was being delivered to tens of thousands of customers and investors through remediation, refunds and payments connected to its work.

More than $61 million was announced during the first half of 2026, on top of $583 million announced between June and December 2025.

The figure reflects payments announced in connection with ASIC’s work rather than money collected directly by the regulator. Some payments may occur before or after the reporting period, and totals can change as remediation programs progress.

That distinction separates penalties from consumer recovery.

Civil penalties are generally imposed by courts as punishment and deterrence. Remediation is intended to restore money to customers or investors who suffered loss.

ASIC’s results suggest it is trying to pursue both outcomes at once: penalising institutions while pressing them to compensate affected customers.

“ASIC has delivered record penalties and strong criminal outcomes, but enforcement is not just about punishment,” Court said. “It is about detecting misconduct sooner, preventing harm where we can, and securing remediation for those affected.”

Criminal Cases Produce Longer Prison Sentences

ASIC also reported stronger criminal enforcement results, with 25 convictions during the financial year.

Twenty-one involved custodial sentences, including 11 individuals sentenced to imprisonment. Four convictions resulted in non-custodial sentences.

Among the most prominent cases was that of former Sydney fund manager Rodney Forrest, who was resentenced by the Full Federal Court in May to five years and three months in prison over a $3 million insider trading scheme involving shares in Platinum Asset Management.

Former financial adviser Anthony Torre was sentenced in January to six years in prison for fraud involving the misappropriation of superannuation funds.

Remedy Housing officials Brent Smith, Mahmoud Khodr and Fue Mano also received lengthy prison sentences in March for dishonesty offences.

ASIC recorded $137,315 in criminal fines alongside $12 million in infringement notices.

The figures indicate that the regulator is using several enforcement channels simultaneously. Civil proceedings target companies and financial institutions. Criminal prosecutions focus on individuals accused of fraud, dishonesty or market offences. Infringement notices allow ASIC to respond to certain breaches without a full court process.

Court said ASIC would continue using its full range of regulatory and enforcement powers when it identified serious harm or threats to market integrity.

“Our focus is on protecting investors, returning money where possible, and holding lawbreakers to account,” she said.

ASIC’s Record Penalties Look Tough, but the Real Test Is Whether Misconduct Gets Harder

The headline number is huge.

$830 million in civil penalties in one financial year. Another $643.5 million tied to refunds, remediation and payments. Twenty-five criminal convictions. More than 250 investigations.

On paper, ASIC has had a monster year.

But I wouldn’t stop at the total.

Big enforcement numbers can mean a regulator has become more aggressive. They can also mean the underlying financial system produced an ugly amount of misconduct before anyone managed to stop it.

Both things can be true.

And here, they probably are.

One Case Did a Lot of the Heavy Lifting

Start with the $300 million Union Standard penalty.

That single order made up more than 36% of ASIC’s full-year civil penalty total. It represented 62.5% of the $480 million secured between January and June.

Strip it out and the record suddenly looks less explosive.

Still strong. Just not as dramatic.

This matters because annual enforcement totals can be distorted by one giant judgment. A regulator can spend years building a case, win it in a particular reporting period, then look vastly more aggressive than it did the year before.

That does not make the result meaningless. A $300 million penalty is serious. It sends a message to every leveraged trading provider operating in Australia.

But I would not read the $830 million figure as proof that every corner of the market is now being policed with equal force.

It tells us ASIC landed several large punches.

It does not tell us how many harmful practices were stopped before customers lost money.

The CFD Case Is the Clearest Warning

The Union Standard outcome is probably the most important case in the entire batch.

CFD providers have operated for years around a basic commercial tension: the more customers trade, the more providers can earn, even though a large share of retail traders lose money.

Add leverage and the glass floor disappears fast.

A customer deposits a small amount. The platform offers exposure many times larger than that deposit. A modest market move then wipes out the account.

That setup can become even uglier when sales staff pressure customers to deposit more, trade more often or keep positions open after losses have started piling up.

ASIC securing nearly $40 million in refunds for CFD investors matters more to me than another press-release penalty total.

Why?

Because a fine hurts the company. A refund reaches the person who got burned.

The record $300 million order also raises a blunt question: how bad did the conduct have to be for the court to land there?

That is the uncomfortable bit behind record enforcement.

A giant penalty usually sits on top of giant failure.

HSBC’s Scam Case Changes the Responsibility Debate

The HSBC matter may have broader implications than the amount suggests.

A $35 million penalty is small next to $300 million. The principle is bigger.

Banks have often treated scams as transactions initiated by customers. The customer clicked. The customer transferred. The customer authorised the payment.

Legally neat.

Real life is messier.

A person can technically approve a transfer while being manipulated by someone impersonating a bank employee, investment adviser, government official or family member.

So where does responsibility sit?

ASIC’s HSBC case pushes banks further away from the old “the customer pressed send” defence. It says systems matter. Response times matter. Fraud controls matter. What the bank does after receiving a warning matters.

I think that direction is overdue.

Banks see transaction data at scale. They know the recipient accounts. They can spot unusual payment patterns. They can freeze or delay suspicious transfers in ways an individual customer cannot.

That does not mean banks should reimburse every scam loss automatically. Some cases will involve obvious customer negligence or attempts to bypass repeated warnings.

But when a bank’s own systems are slow, fragmented or badly designed, the loss should not sit entirely with the victim.

HSBC paying around $21.5 million in compensation and recovering another $6.5 million for customers makes that point better than the penalty itself.

Money came back.

That is the receipt.

Westpac’s Hardship Failures Are Less Flashy and More Human

The Westpac case will get less attention because hardship processing is not dramatic.

No insider trading chart. No leveraged trading blow-up. No scammer disappearing with millions overnight.

Just people asking their bank for help and not getting a proper response.

That is exactly why the case matters.

A customer applying for hardship support is already under pressure. Maybe they lost work. Maybe rent jumped. Maybe illness hit. Maybe mortgage repayments became unmanageable after rate increases.

Delay is not neutral in that situation.

Interest keeps running.

Arrears build.

Collection calls continue.

Credit records deteriorate.

A broken workflow inside a bank can quietly make thousands of lives worse without producing one spectacular headline.

ASIC imposing a $26 million penalty says operational neglect can be misconduct, not just bad service.

I agree with that.

When a financial institution serves millions of customers, sloppy systems are not small mistakes. They scale.

Macquarie’s Reporting Failure Is a Market Plumbing Problem

The Macquarie Securities penalty looks technical.

Millions of short sales were misreported. Market data became inaccurate. Systems failed.

Easy to skim past.

Don’t.

Markets run on information. Regulators need accurate reporting to know who is selling, what positions are building and where unusual activity is occurring.

When a major market participant feeds bad data into that system, everyone else is operating with a dirtier picture.

This is not the same as manipulating a stock price. But it weakens the surveillance layer that is supposed to catch manipulation.

That is why the $35 million penalty makes sense.

The real red flag is the word “systemic.”

A single employee selecting the wrong code is an error. Millions of misreported transactions point to design, testing, oversight and governance failures.

That chain normally runs upward.

Someone approved the system.

Someone accepted the controls.

Someone received reports saying things were fine.

Someone failed to ask the next question.

When ASIC says it is focusing on governance and systems, this is what that means in practice.

Breach Reporting Fails When Firms Police Themselves

Mercer Super’s $10.3 million penalty is another plumbing case.

Financial firms are required to report serious breaches to ASIC. That system assumes institutions will recognise their own failures, classify them correctly and tell the regulator.

A lot can go wrong there.

Management may underestimate the seriousness.

Legal teams may argue over definitions.

Business units may delay escalation.

Nobody wants to be the person who tells ASIC the firm has a major problem.

So breach reporting becomes a test of culture, not paperwork.

If a company reports only after the regulator finds the issue, the early-warning system is useless.

I suspect ASIC will keep pressing this area because it gives the regulator leverage before harm becomes enormous. A company that hides or delays reporting can turn a manageable problem into a customer-remediation monster.

The Remediation Figure Needs Careful Reading

Almost $644 million going back to Australians sounds like ASIC recovered that money directly.

That is not exactly what the figure says.

It covers payments announced in connection with ASIC’s work. Some may be paid before the reporting period. Some after it. Programs can change as more customers are identified.

That does not weaken the result, but the distinction matters.

Regulators love aggregate figures because they are easy to communicate. Consumers care about something simpler: did the money reach my account?

The real scorecard should track completed payments, average waiting times, how many customers were contacted and how many had to fight through another complaints process to receive compensation.

A remediation program can look generous in an announcement and still become a bureaucratic maze.

I have seen enough financial compensation schemes to be cautious here.

Announced money is not paid money.

Prison Sentences Change the Tone

The criminal results give ASIC’s enforcement year more weight.

Twenty-five convictions. Twenty-one custodial sentences. Eleven people sent to prison.

That hits differently from corporate penalties.

A company fine is paid from corporate funds. Shareholders may ultimately absorb part of it. Senior executives can leave while the institution continues operating.

A prison sentence lands on the individual.

Rodney Forrest received five years and three months over a $3 million insider trading scheme. Anthony Torre received six years for fraud involving misappropriated superannuation money.

Those sentences tell advisers, fund managers and market insiders that certain conduct will not end with a banning order and a settlement.

That deterrent matters.

But again, conviction totals tell us about cases ASIC completed. They do not reveal how much misconduct remains undetected or how long investigations took while victims waited.

$830 Million Is Not the Finish Line

I think ASIC deserves credit for this year.

The regulator took on banks, a super trustee, a major securities firm, a credit provider and a CFD business. It secured prison sentences. It pushed money back toward affected customers.

That is real enforcement.

Still, record penalties should not become the goal by themselves.

The best regulatory year would not necessarily produce the biggest fine total. It would produce fewer customers being harmed in the first place.

Earlier detection.

Faster intervention.

Smaller remediation programs because losses never reached hundreds of millions.

Executives fixing systems before a court forces them to.

That is harder to put in a headline.

It is also the only metric that really matters.

For now, ASIC has shown it can punish misconduct after the damage appears.

The next test is nastier.

Can it make firms believe they will be caught early enough that the misconduct is not worth trying?

ByShane Neagle

Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms. He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments. Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

Leave a Reply

Your email address will not be published. Required fields are marked *