What Is Authorized Push Payment Fraud?
Authorized push payment (APP) fraud happens when someone is tricked into willingly sending money to a fraudster’s account. Unlike most payment fraud, the victim authorizes the transaction themselves — which makes it one of the hardest fraud types for both individuals and financial institutions to catch and reverse.
How APP Fraud Works and Why It’s Hard to Stop
APP fraud is a financial crime in which a fraudster deceives a victim into sending money directly from their own account to one the fraudster controls. The key distinction is consent: the victim believes the payment is legitimate and approves it themselves.
This sets APP fraud apart from unauthorized payment fraud — such as card fraud or account takeover — where a criminal completes a transaction without the victim’s knowledge. The table below shows the core differences between the two fraud types.
| Characteristic | APP Fraud (Authorized) | Unauthorized Payment Fraud
|
|---|---|---|
| Victim’s role | Victim initiates and approves the payment | Victim has no involvement in the transaction |
| Bank’s role | Processes a technically valid, customer-authorized instruction | Processes a fraudulent instruction without customer consent |
| Primary fraud mechanism | Social engineering — manipulating the victim’s behavior | Technical compromise — hacking, card skimming, credential theft |
| Default bank liability | Limited; the bank followed a legitimate instruction | Higher; the bank processed an unauthorized transaction |
| Recovery likelihood | Low; funds are often moved quickly through multiple accounts | Higher; stronger regulatory protections typically apply |
| Transaction reversibility | Difficult; fast payment systems are often instant and irrevocable | More reversible; chargeback and dispute mechanisms commonly available |
Because the victim’s bank processed a legitimate instruction, it carries less automatic liability than it would in an unauthorized fraud case. This creates a significant recovery gap for victims.
Fast payment systems make things worse. They operate instantly, around the clock, with no way to recall funds once sent. By the time a victim realizes what happened, the money has typically moved through a chain of accounts — often across borders.
Social engineering, not technical hacking, is the engine behind APP fraud. Fraudsters invest time building trust, manufacturing urgency, or projecting authority to convince victims that a payment is not only legitimate but necessary.
The Most Common APP Fraud Schemes
APP fraud takes many forms, but each variant follows the same logic: the victim is persuaded that the payment is genuine. The table below summarizes the most common schemes, how they work, and how to spot them.
| Fraud Type | How It Works | Common Target | Typical Scenario | Key Warning Sign
|
|---|---|---|---|---|
| Invoice and Supplier Fraud | Fraudsters intercept business communications or impersonate a known supplier to redirect legitimate payments to a fraudster-controlled account | Businesses, finance teams, accounts payable staff | A company receives an email appearing to be from a regular supplier, notifying them of a new bank account number for future payments | Unexpected change to payment details received by email, especially close to an invoice due date |
| Impersonation Scams | Fraudsters pose as trusted authorities — banks, HMRC, the IRS, police, or utility companies — to create urgency and pressure victims into transferring funds | Individuals of all ages, particularly those who respond to authority | A caller claims to be from the victim’s bank fraud team, warning that their account is compromised and funds must be moved to a “safe account” immediately | Unsolicited contact from an authority figure demanding urgent fund transfers, especially to a new account |
| Romance Scams | Fraudsters build a long-term online relationship with a victim over weeks or months before requesting money, often citing an emergency or investment opportunity | Individuals using dating platforms or social media, often older adults | After months of daily contact, an online partner claims to be stranded abroad and urgently needs money wired to cover medical or travel costs | A person you have never met in person requests a financial transfer, regardless of how well you feel you know them |
| Purchase Scams | Victims pay for goods or services — often advertised at attractive prices on online marketplaces — that are never delivered | Online shoppers, individuals seeking high-demand or discounted items | A buyer pays a deposit for a used car advertised on a marketplace platform; the seller disappears after receiving payment | Sellers who insist on bank transfer rather than a protected payment method, or who pressure for quick payment |
| Investment Scams | Fraudsters promote high-return investment opportunities through social media, cold calls, or fake websites to solicit large transfers | Individuals seeking investment returns, often approached via social media | A victim is shown fabricated account dashboards showing strong returns, then transfers increasing sums before the platform becomes inaccessible | Unsolicited investment offers promising guaranteed or unusually high returns, especially with pressure to act quickly |
| CEO / Executive Fraud | Fraudsters impersonate a senior executive via email or messaging to instruct an employee to make an urgent, confidential payment | Finance staff in businesses of all sizes | An employee receives an email appearing to be from their CEO requesting an urgent wire transfer for a confidential acquisition | Payment requests from senior figures that bypass normal approval processes and emphasize secrecy |
Each scheme relies on the same core principle: the victim is made to believe the payment is both legitimate and urgent. Learning to recognize the pattern — not just the specific scenario — is the most reliable form of protection.
How to Detect, Prevent, and Respond to APP Fraud
Knowing what APP fraud looks like is only useful if it leads to action. This section covers the warning signs to watch for, the steps individuals and institutions can take to reduce exposure, and what to do immediately after a fraudulent payment has been made.
Warning Signs That a Payment Request May Be Fraudulent
APP fraud relies on predictable psychological tactics. The table below organizes the most common warning signs by category to help you quickly assess whether a situation matches a known fraud pattern.
| Red Flag Category | Specific Warning Sign | Why Fraudsters Use This Tactic | Applies To
|
|---|---|---|---|
| Unsolicited Contact | You receive an unexpected call, email, or message from someone claiming to be a bank, government body, or business | Initiating contact gives the fraudster control over the narrative before the victim has time to verify | Individuals and businesses |
| Artificial Urgency | You are told you must act immediately or risk losing money, facing legal consequences, or missing an opportunity | Time pressure prevents victims from pausing to verify or seek a second opinion | Individuals and businesses |
| Secrecy Instructions | You are asked not to tell your bank, family, or colleagues about the transaction | Isolation prevents victims from receiving advice that might expose the fraud | Individuals and businesses |
| Safe Account Requests | You are instructed to move money to a new or “safe” account for protection | No legitimate bank or authority will ever ask a customer to transfer funds to a different account for security reasons | Individuals |
| Unverified Payment Details | You receive new or changed bank account details without being able to independently verify them | Fraudsters intercept or fabricate payment details, relying on victims not to double-check through a separate channel | Businesses |
| Pressure to Bypass Verification | You are discouraged from using your bank’s standard security checks or told they are unnecessary | Standard verification processes are the primary obstacle to a successful fraud; fraudsters work to circumvent them | Individuals and businesses |
| Too-Good-To-Be-True Offers | A price, return, or opportunity appears significantly better than comparable alternatives | Attractive offers lower a victim’s critical judgment and create motivation to act quickly | Individuals |
Steps Individuals and Businesses Can Take to Reduce Risk
Both individuals and financial institutions can take concrete steps to reduce APP fraud exposure.
For individuals and businesses, a few habits make a real difference. Always verify independently: if you receive new payment details or an urgent request, call the organization back using a number from their official website — not one provided in the message. Where supported, use Confirmation of Payee (CoP) tools, which check that the account name matches the sort code and account number before a payment is sent. Always review CoP results before proceeding. And never act under pressure. Legitimate organizations will not penalize you for taking time to verify a request. Urgency is a manipulation tactic, not a genuine operational requirement. Businesses should also implement dual-authorization controls for high-value payments and require verbal confirmation of any changes to supplier payment details.
For financial institutions, the approach is different but equally concrete:
- Transaction monitoring using AI and machine learning. Behavioral analytics and anomaly detection can flag authorized payments that deviate from a customer’s established patterns — for example, a first-time large transfer to an unknown payee.
- Targeted friction at high-risk moments. Warnings, cooling-off periods, and prompts at the point of payment can interrupt the social engineering process before funds leave the account.
- Customer education programs. Communicating clearly about current fraud schemes reduces victim susceptibility over time.
What to Do Immediately After a Fraudulent Payment
Speed is the single most important factor in recovering funds after an APP fraud incident.
- Contact your bank immediately. Report the fraud as soon as possible and ask the bank to attempt a recall of the payment. Many banks participate in voluntary or mandatory recall schemes that can freeze funds if acted upon quickly.
- Report to the relevant authority. In the UK, report to Action Fraud. In the US, file a report with the FTC and IC3. In other jurisdictions, contact the national financial crimes reporting body.
- Preserve all evidence. Retain all communications, transaction records, and any information about the fraudster’s account or contact details. This supports both the bank’s investigation and any law enforcement action.
- Request a formal complaint process. If your bank declines to reimburse, escalate through the formal complaints process and, where applicable, to the relevant financial ombudsman or regulator.
What APP Fraud Victims Are Entitled to by Region
Consumer protections for APP fraud victims vary significantly by jurisdiction. The table below summarizes the current landscape across major regions.
| Region / Jurisdiction | Governing Framework | Reimbursement Obligation | Key Conditions or Exceptions | Status
|
|---|---|---|---|---|
| United Kingdom | PSR Mandatory Reimbursement Rule | Mandatory reimbursement up to £85,000 for most APP fraud cases, shared equally between sending and receiving banks | Exceptions apply for gross negligence, first-party fraud, and claims below a £100 excess threshold | In effect from October 2024 |
| United States | Regulation E (Electronic Fund Transfer Act) | No federal mandate for authorized push payments; reimbursement is at the bank’s discretion for payments the customer approved | Regulation E protections apply to unauthorized transactions only; authorized transfers have very limited federal coverage | Current; ongoing legislative discussion |
| European Union | PSD2 / PSD3 (Payment Services Directive) | PSD2 provides limited protection for authorized payments; PSD3 proposes stronger obligations on payment service providers to detect and prevent fraud | Liability can shift to the payer’s institution if it failed to apply strong customer authentication | PSD3 in legislative process as of 2024 |
| Australia | Scam-Safe Accord / proposed Scams Prevention Framework | Industry-led commitments under the Scam-Safe Accord; mandatory framework under legislative development | Proposed framework would require banks, telcos, and digital platforms to share liability | Legislation in progress as of 2024 |
Note: Regulatory frameworks in this area are evolving rapidly. Readers should verify current rules with their financial institution or national regulator.
Final Thoughts
APP fraud is a social engineering threat, not a technical one — and that distinction shapes everything from how it is detected to how victims are protected. The combination of fast, irrevocable payment systems and sophisticated impersonation tactics makes APP fraud both highly effective for criminals and uniquely difficult to reverse. Awareness of the common fraud types, recognition of the warning signs, and prompt action after an incident are the most reliable defenses available to individuals and businesses.
For financial institutions, the AI-driven transaction monitoring described in this article represents one layer of a broader defense strategy. The identity verification layer — encompassing document authentication, synthetic identity detection, and deepfake detection — has become an increasingly important complement to transaction monitoring, addressing the impersonation mechanics that APP fraud depends on at the point of onboarding and payment authorization. Identity verification platforms such as Microblink, which has built these capabilities specifically for banking and fintech environments over more than a decade, represent one category of solution that financial institutions may consider when evaluating their fraud prevention infrastructure.