Macquarie Bank began trialing expanded step-up prompts in its Authenticator app this month after wealthy clients approved high-value transfers during phone calls that carried synthetic voices resembling known relationship managers, a scam pattern the bank said now outpaces classic SMS code theft in reported losses.
What broke
Fraud investigators described at least six cases since July in which callers spoofed Macquarie switchboard numbers, recited partial account details gathered from data breaches, and played AI-cloned voices to insist that “security teams” needed immediate approval of outbound payments. Victims who were already on the phone tapped approve on Authenticator pushes because the notification lacked plain-language warnings that the request conflicted with an active call.
Macquarie’s trial adds a mandatory pause screen listing payee, amount, channel, and a bold note that the bank never asks customers to approve transfers to “safe accounts” during unsolicited calls. Clients must type a short denial phrase to dismiss a request while a call is in progress—a friction step modeled on wire-transfer holds U.S. banks adopted after voice-cloning fraud spiked.
Who is liable
Australian Financial Complaints Authority guidance still treats in-app approval as strong customer authentication when the device is under the customer’s control. Macquarie argues enriched prompts restore informed consent; consumer lawyers counter that banks must also block approvals when telemetry shows an active call to a flagged scam hotline range. The pilot will feed into AFCA test cases expected later this year.
Macquarie’s public scam alerts already warn that criminals harvest Authenticator codes by impersonating fraud desks. The new prompts do not replace that advice: customers who receive unexpected pushes should deny, change passwords, and call the number on the back of their card—not the caller ID on the incoming scam.
Why SMS is not enough
Macquarie Authenticator replaced SMS one-time codes for most retail and adviser flows after scammers exploited SIM swap and spoofing weaknesses. Push notifications show transaction context, but until this trial they did not surface social-engineering cues such as concurrent phone contact.
Rivals including Westpac and CBA have emphasized name-matching payee checks rather than voice-aware step-ups. Macquarie’s experiment is narrower—focused on clients above $1 million in investable assets—but fraud chiefs said they will open enrollment to mortgage offset customers if decline rates stay manageable.
What Macquarie will measure
The bank will track how often users abandon approvals after the pause screen, how many deny legitimate adviser-initiated trades, and whether scam reports tied to “bank impersonation” calls fall quarter-on-quarter. Early data are not public; Macquarie Authenticator enrollments passed one million users in 2025, giving the pilot a large denominator.
ASIC has asked all major banks for quarterly updates on deepfake-enabled scams since Westpac’s April 2026 warning about AI-driven impersonation. Macquarie’s trial response will likely set expectations for whether regulators mandate call-aware authentication or treat voice fraud as purely a customer-education problem.
Practical defenses
Relationship managers are telling clients to establish a verbal passphrase for any phone-initiated money movement and to refuse “co-approval” sessions where a stranger stays on the line while you tap Authenticator. Macquarie’s help pages reiterate that actionable pushes should match activity the customer or adviser initiated; anything else is a deny-and-call event.
Synthetic voice tools remain legal for many commercial uses, which means banks cannot rely on voice biometrics alone. Macquarie’s bet is that slowing the last mile—forcing eyes on payee details while a scammer is still talking—buys enough doubt to keep funds in the account.
Until the trial ends, Macquarie said it will reimburse select victims where call metadata and push timestamps show clear impersonation, preserving goodwill while lawyers debate how much friction regulators will ultimately require.
Wealth advisers told InfoHandle they are rehearsing client drills: hang up, call back on Macquarie’s listed fraud line, and only then open Authenticator. The bank’s trial adds a fifth second of delay to each high-value push—small in UX terms, large when a synthetic voice is still urging haste on the other line.
Telecommunications firms said they are testing network-level flags for calls that spoof financial institution numbers, but rollout remains patchy outside major cities. Until carriers block those routes, in-app friction is Macquarie’s primary lever.
Consumer groups welcomed the pilot while noting it does not help customers who still approve transfers inside legacy phone-banking flows; Macquarie said those channels represent a shrinking share of scam losses but will receive parallel warnings by year end.








