Authorised push payment (APP) fraud has become one of the most challenging problems in modern payments. Unlike card fraud, where a criminal uses stolen credentials, APP fraud relies on deception: the victim is manipulated into authorising a payment themselves, often to an account they believe is legitimate. Because the customer authenticates the transaction, traditional fraud controls built around “unauthorised” activity struggle to catch it. For fintech and compliance professionals, understanding APP fraud typologies—and the regulatory response now reshaping liability—is essential to protecting customers and the business.
This article is general information for compliance and product professionals and is not legal advice. Reimbursement obligations, thresholds, and regulatory requirements vary by jurisdiction and change over time; confirm current rules with qualified counsel and your regulator.
What Makes APP Fraud Distinct
In an APP scam, the payer initiates and approves the transfer. The fraud lies not in a breached credential but in a manipulated decision. This distinction matters enormously: the payment passes authentication checks cleanly, it often originates from the customer’s usual device and location, and it may fall within normal spending patterns. The signal of fraud is behavioral and contextual rather than technical, which is why detection depends on understanding how the underlying scams actually work.
Common APP Scam Typologies
APP fraud is an umbrella term covering several distinct manipulation patterns. Recognising them is the foundation of both detection and customer education:
| Typology | How It Works |
|---|---|
| Purchase scam | Victim pays for goods or services that never arrive; often via marketplaces or social media listings. |
| Investment scam | Victim is lured into a fake investment—crypto, bonds, or “high return” schemes—frequently after building rapport over time. |
| Romance scam | A fraudster cultivates an online relationship, then engineers a financial emergency requiring transfers. |
| Impersonation scam | Fraudster poses as a bank, government body, or trusted brand, creating urgency to “protect” funds by moving them. |
| Invoice and mandate scam | A legitimate invoice is intercepted or spoofed; payment details are altered to divert funds, often targeting businesses. |
| CEO / business email compromise | An employee is instructed by a spoofed executive to make an urgent payment. |
| Advance fee scam | Victim pays an upfront “fee” to unlock a promised larger sum, loan, or prize that never materialises. |
The Regulatory Shift: From “Buyer Beware” to Shared Liability
For years, victims who authorised a payment had limited recourse, since they had technically consented. That framing has changed materially in some markets. In the United Kingdom, the Payment Systems Regulator introduced a mandatory reimbursement requirement that took effect on 7 October 2024 for payments made over the Faster Payments system, obliging payment service providers to reimburse most victims of APP scams, with the cost typically shared between the sending and receiving firms. This reallocates the incentive: institutions on both the paying and receiving side now have a direct financial stake in preventing fraud, not just detecting it after the fact.
Early evidence suggests the policy is having an effect. The regulator’s first-year assessment, published in mid-2026, reported that APP fraud losses sent over Faster Payments fell by roughly a fifth following implementation, and that the share of claimed losses returned to victims rose substantially compared with the period before the rules. Reported figures also indicated that firms were resolving the large majority of claims within days rather than weeks. At the same time, the assessment flagged a persistent gap in consumer awareness, with many victims unaware that reimbursement protection exists—meaning operational success does not automatically translate into public understanding.
Why Receiving Accounts Matter
A defining feature of APP fraud is the role of the receiving institution. The stolen funds land somewhere—frequently in accounts opened or exploited specifically to receive and quickly disperse fraudulent proceeds, sometimes controlled by money mules. Shared-liability regimes make this the receiving firm’s problem too, sharpening the importance of controls at onboarding and on inbound flows: detecting accounts that behave like collection points, monitoring rapid pass-through activity, and acting on patterns consistent with mule networks. Fraud prevention, under this model, is a two-sided obligation.
Detection Signals
Because the payment itself is authenticated, detection leans on context and behavior rather than credential checks. Useful signals include a first-time payment to a new payee for an unusually large amount; a payment made during or shortly after a long phone call; transaction values that deviate sharply from the customer’s history; hesitation or unusual session behavior suggesting the customer is being coached; and destination accounts that display characteristics of collection or mule activity. On the inbound side, sudden receipt of funds followed by rapid dispersal is a classic red flag. None of these is conclusive alone, but combined they form the basis of effective real-time intervention.
Prevention Beyond Detection
Detecting a suspicious payment is only valuable if the institution can act in the moment. Increasingly, prevention combines several layers: confirmation-of-payee style checks that warn a customer when a name does not match the account they are paying; dynamic, contextual warnings tailored to the specific scam risk rather than generic disclaimers; friction introduced selectively—a pause, an additional question, or a cooling-off step—when risk indicators are high; and customer education that helps people recognise manipulation before they act. The aim is to interrupt the scammer’s script without burdening the vast majority of legitimate payments.
Considerations for Fintech Decision-Makers
For firms evaluating their APP fraud posture, several questions are worth asking. Does your monitoring account for authorised as well as unauthorised activity? Can your systems assess inbound risk, not just outbound? Are your customer warnings specific and timely, or generic and ignored? Do you have a defensible, documented approach to reimbursement decisions where such regimes apply? And is fraud prevention coordinated with your broader financial crime program, rather than siloed away from AML and sanctions functions? APP fraud sits at the intersection of fraud operations and regulatory compliance, and treating it as purely one or the other tends to leave gaps.
Frequently Asked Questions
Is APP fraud the same as unauthorised fraud? No. In unauthorised fraud a criminal makes a payment without the customer’s consent; in APP fraud the customer is deceived into authorising it themselves. The controls and, increasingly, the liability rules differ.
Does mandatory reimbursement apply everywhere? No. Reimbursement regimes are jurisdiction-specific. The UK’s Faster Payments requirement is a prominent example, but obligations, scope, and thresholds differ across markets and continue to evolve.
Whose responsibility is preventing APP fraud? Under shared-liability models, both the sending and receiving institutions. This is a shift from earlier approaches that placed most of the burden on the payer.
Conclusion
APP fraud is difficult precisely because it turns the customer into the instrument of the crime, bypassing controls designed for stolen credentials. The regulatory response in leading markets has begun to realign incentives, making prevention a shared obligation between paying and receiving firms and rewarding institutions that can detect manipulation in real time. For fintech and compliance teams, the path forward combines typology awareness, behavioral detection, two-sided monitoring, well-designed friction, and clear customer communication—supported by governance that ties fraud prevention to the wider financial crime framework.
Related resources: Explore how scoring models support detection in Fraud Analytics and Scoring in Fintech, operational recovery in Fraud and Chargeback Management, and rule optimisation in Transaction Monitoring Tuning and Governance. To discuss your financial crime program, contact our team.