Mortgage & finance brokers

The caller knows the loan details. That does not make them the client.

After a data breach, a scammer can call mid-settlement with the property, lender and payout details already in hand. Verify the person behind a high-risk instruction before money or information moves.

Why broking is exposed

A genuine detail can carry a fraudulent instruction.

Brokers sit at the junction of identity documents, credit data, property transactions and urgent payment decisions. Public warnings from the MFAA, ASIC and the ACSC show that the threat is recognised across the sector. Those sources do not endorse or have any affiliation with Vericode.

01

A convincing pretext

A breached aggregator or client mailbox can expose lender, property and settlement details that make an impersonator sound legitimate.

02

Two directions of fraud

A criminal can pose as the broker to redirect a client deposit—or pose as the client to change payout or bank details.

03

Evidence after the call

A file note says what someone remembers. A timestamped verification record shows who initiated the check, the masked target and the outcome.

Fits the workflow

Add a check without replacing the CRM.

Highlight a phone number or email visible in your browser-based CRM, lender portal or email client. Right-click to send a one-time verification code by SMS or email; the client reads the code back on the call.

That generic browser-extension mechanic works with whatever is already on screen—Salestrekker, BrokerEngine or another browser-based system. It is not a claimed direct integration with those products.

A practical trigger

Require verification before accepting changed payout details, disclosing loan information, resending documents or acting on a time-critical deposit instruction.

Evidence, not just a good intention

Make the callback procedure provable.

Audit trail

Each verification creates a timestamped, hash-chained record, exportable in PDF or CSV for compliance officers, insurers and auditors.

Recognisable message

SMS is sent through Australian carriers MobileMessage or ClickSend using Vericode's ACMA-registered sender ID, VERICODE.

Residency disclosed

Customer and verification data—recipient details, messages and verification records—is hosted in Azure Australia East. Staff sign-in is handled by our identity provider, WorkOS, in the United States.

Industry reading

The warning signs are already public.

MFAA practical scam resource

The MFAA launched a member scam resource in August 2025, reflecting an industry-wide need for practical controls.

Read source

Guidance after the youX breach

Broker Daily reported MFAA guidance following the youX data breach and the risks exposed for brokers and their customers.

Read source

Fraud risk across broking

Broker Daily reported that 15% of Australians had been hit by fraud as broking-sector risks continued to rise.

Read source

Settlement-week BEC warning

The ACSC warns that property transactions are targeted through compromised email accounts and changed payment instructions.

Read source
Set the rule before settlement day

Give every broker a simple answer to “how did you know it was them?”

Start with high-risk changes, document the trigger in your procedure, and retain the verification result beside the client file.