P2P Fraud

P2P fraud is fraud carried out over peer-to-peer payment rails — Zelle, Venmo, Cash App and similar services that move money between individuals in seconds. The rails did not create new scams. They removed the delay and the reversibility that used to limit what older scams could take, and that is the whole of the problem.

Rails involved Zelle, Venmo, Cash App, and bank-operated instant transfer services
Defining characteristic Near-instant settlement and, in practice, irrevocable
Two categories Unauthorized transfers, and authorized transfers induced by deception
U.S. legal position — unauthorized Regulation E makes the institution liable
U.S. legal position — authorized No federal law requires reimbursement where the customer was deceived into sending
Common scam types Impersonation of a bank or utility, marketplace non-delivery, rental deposits, romance, overpayment
Why recovery fails Funds are moved out or converted within minutes of arrival
Enrollment weakness A recipient identity that was never properly verified

The distinction the whole subject turns on

Almost every argument about P2P fraud is really an argument about this line.

An unauthorized transfer is one the accountholder did not make — their credentials were stolen, their phone was taken, their account was seized. Regulation E covers this in the United States, and the institution generally bears the loss.

An authorized transfer is one the customer made themselves, having been deceived about who they were paying or why. The instruction was genuine. The consent was real. The customer was lied to. No federal law currently requires reimbursement for this category, and it is where the overwhelming majority of P2P scam losses sit.

That gap is the live policy question. The CFPB sued Zelle’s operator and three large banks in December 2024 over their handling of it, and voluntarily dismissed the case with prejudice in March 2025. In August 2025 the New York Attorney General filed a state suit against Early Warning Services making a related claim, and in July 2026 a New York judge ruled that case must proceed to trial. The position is unsettled and moving, so anyone relying on it should check where it stands rather than assume.

Why identity verification is central here

The New York complaint is worth noting for a specific reason: its core allegation is that weak identity verification at enrollment allowed scammers to register accounts and take more than a billion dollars over several years. Whatever the case’s outcome, that frames the problem correctly.

Trace a P2P scam and the identity failure is at the receiving end, not the sending one. The victim did authorize the payment, so nothing at their end was compromised. What made the scam workable was that the recipient account could be opened quickly, operated anonymously enough to be untraceable, and abandoned once the money moved on.

Two consequences follow. Verifying the recipient at enrollment — an authenticated document plus a biometric comparison binding it to a real person — makes an account that costs something to create and leads somewhere when investigated. And accounts opened with synthetic identities or by money mules are the infrastructure this fraud runs on; both are onboarding problems, not transaction problems.

That is why identity document verification at account opening does more for P2P fraud than any control applied at the moment of transfer, and why payment fraud defenses that only examine transactions are looking at the wrong end of the scam.

P2P fraud compared with adjacent categories

What happened Who bears the loss (U.S.)
Unauthorized P2P transfer Account taken over or credentials stolen The institution, under Regulation E
Authorized push payment scam The customer was deceived into sending The customer, absent a voluntary policy
Card-not-present fraud A card was used without the holder’s authority Merchant or issuer, via chargeback
Money mule activity A genuine accountholder moves criminal funds The original victim; the mule faces liability

Authorized push payment fraud is the technique; P2P is the channel it most commonly runs on. The two pages cover different halves of the same problem — that one explains the deception, this one explains why the rails make it so effective.

What controls can’t do

Nothing reverses a completed transfer. These systems were built to settle instantly, and instant settlement means no window in which to stop it.

Transaction monitoring sees a legitimate payment. The customer is who they say they are, using their own device, sending an ordinary amount. There is no anomaly, because nothing anomalous happened at the sender’s end.

Warnings have limited effect. A customer in the middle of a convincing impersonation call has already been given a reason to ignore the warning, usually by the person on the phone.

Verifying the sender does not help. The sender is genuine. The identity question is about the account receiving the money.

Frequently asked questions

Is P2P fraud covered by Regulation E?

It depends on the category. Regulation E covers unauthorized electronic fund transfers — those the accountholder did not make — and the institution generally bears that loss. Transfers the customer authorized while being deceived are not covered by any federal reimbursement requirement, and that is where most P2P scam losses fall.

Why can’t a P2P payment be reversed?

Because the rails were designed for instant, final settlement, which is the feature customers want. By the time a victim realizes what happened, the funds have usually been moved on or converted. There is no clearing window of the kind that makes card chargebacks possible.

What is the difference between P2P fraud and authorized push payment fraud?

Authorized push payment fraud describes the technique — deceiving someone into sending money willingly. P2P fraud describes fraud on peer-to-peer payment rails, which is the channel APP scams most often use because settlement is instant and effectively irreversible.

How does identity verification reduce P2P fraud?

By attacking the receiving end. The sender is genuine and the payment is authorized, so the exploitable weakness is an account that was opened without the recipient being properly identified. Verifying an authenticated document against a live biometric at enrollment makes those accounts costly to create and traceable afterwards.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data