Authorized Push Payment Scams: When the Victim Sends the Money Themselves
Almost everything this site covers defends against an attacker acting without the account holder: stolen cards, hijacked accounts, forged credentials. Authorized push payment fraud inverts the threat model completely. In an APP scam, the victim performs every security step flawlessly — correct app, correct passcode, correct biometric — and sends their own money to a criminal, because a story convinced them to. No control that verifies who is paying can stop a payment the right person genuinely makes. As instant transfers spread (the rails whose speed-and-irreversibility problem we examined in real-time payments, real-time fraud), APP scams have become the fastest-growing loss category in several markets, and the first to trigger mandatory reimbursement regulation. This guide covers the playbook, why banks struggle, the UK’s landmark rules, and the defenses that actually bite.
Quick answer: Authorized push payment fraud occurs when a victim is deceived into willingly transferring money to an account controlled by criminals — through impersonation, invoice redirection, purchase, investment, or romance scams. Because the victim authorizes the payment, traditional fraud controls don’t trigger; defenses center on manipulation detection, payee verification, transaction friction at warning signs, and — increasingly — regulated reimbursement.
The main scam patterns
- Impersonation (“safe account”) scams. A call, ostensibly from the bank’s fraud team or police: your account is compromised, move funds to a “safe account” immediately. Every element is engineered — spoofed caller ID, personal details from breaches, urgency, secrecy (“don’t tell the branch staff, they may be involved”). The cruelest variant follows a real security event the victim knows about, sometimes set up by the same gang via a smishing text or SIM-swap attempt days earlier.
- Invoice redirection and BEC. The business-scale version: a compromised or spoofed email account sends a plausible “our bank details have changed” note before a genuine invoice falls due. Accounts payable updates the record; the real supplier calls weeks later asking where the money is. Law-enforcement reporting has ranked business email compromise among the costliest cybercrime categories for years running, and construction, legal conveyancing, and any business with large scheduled payments are standing targets.
- Purchase scams. Goods that don’t exist — cars, concert tickets, rental deposits, puppies — advertised at compelling prices, payable only by bank transfer. Small individually, enormous in aggregate, and the highest-volume APP category by count in most reporting.
- Investment and romance scams. The long-game categories with the largest per-victim losses: months of relationship-building or fake trading-platform “returns” before the extraction phase. Modern operations run from industrial-scale compounds, use deepfaked video calls and cloned voices, and increasingly cash out through crypto ramps.
- Advance-fee and job scams. Pay a small “release fee,” “customs charge,” or “training kit” cost to unlock something larger that never arrives — often the entry-level tier that identifies compliant victims for bigger schemes.
Across all five, the mechanics rhyme: manufactured urgency, invoked authority or intimacy, a reason secrecy is essential, and a payment method that settles instantly and irrevocably.
Why is APP fraud so hard for banks to stop?
- Authentication is satisfied — genuinely. The payment passes every test strong customer authentication can pose, because the authentic customer is authentically paying. Even passkeys, which end phishing of credentials, verify the person — not the person’s judgment.
- Speed forecloses recovery. Instant rails settle in seconds; mule networks fan the money across accounts and borders within minutes. The recovery window is measured in phone-call durations.
- Coaching defeats warnings. Scammers pre-brief victims on the bank’s questions: “they’ll ask if anyone told you to make this payment — say no, it’s a security procedure.” The bank’s friction becomes part of the script.
- The signal is behavioral, not transactional. The tell isn’t the payment’s size but its context: a first-time payee, an unusually long phone call in progress, hesitation patterns in the app, a customer segment that never sends transfers suddenly sending one. Detecting manipulation means modeling the customer, not just the transaction — a harder problem than the one transaction-scoring models were built for, and the current frontier of bank-side fraud ML.
The regulatory turn: the UK experiment
The United Kingdom — an early adopter of instant payments and consequently of APP fraud — became the first market to mandate reimbursement. Since October 2024, under Payment Systems Regulator rules, victims of APP scams on the Faster Payments system are generally entitled to reimbursement, with the cost split 50/50 between the sending and receiving institutions, a claim excess option, a per-claim cap, and a gross-negligence exception that is deliberately narrow. The design logic deserves attention beyond the UK, because it rewired incentives on both ends: sending banks now invest in manipulation detection and payment friction, while receiving banks — half-liable for money landing in mule accounts — finally carry a price for lax account opening and mule tolerance. Complementing it, Confirmation of Payee name-checking lets senders verify the recipient’s account name matches who they think they’re paying — a simple control that guts invoice-redirection scams when actually consulted. Other jurisdictions are watching the loss-shifting experiment closely, and several are moving in the same direction on payee verification. (Regimes evolve; verify current rules in your market.)
Defenses that actually work
For businesses
- Callback verification, without exceptions. Any change to supplier bank details is confirmed by phone to a number from your own records — never from the email requesting the change. This one control, enforced absolutely, defeats the core of invoice redirection.
- Dual authorization on payments above a threshold, with the second approver structurally encouraged to question, not rubber-stamp.
- Drill the finance team on the current scripts — urgency, CEO-impersonation “confidential acquisition” payments, Friday-afternoon timing — the same rehearsal logic as a tabletop exercise, aimed at accounts payable.
- Pre-agree a recall procedure with your bank: who to call, what reference to quote. Minutes decide recoveries.
For banks and PSPs
- Behavioral and session analytics tuned to manipulation markers; dynamic, scenario-specific warnings (generic warnings are scenery); payee name verification; inbound mule detection with real consequences; and staff empowered to delay a payment when the customer is visibly mid-script — the “banking protocol” pause that has saved real money in branch settings.
For individuals
- Adopt one rule with no exceptions: a genuine bank, police force, or government agency will never instruct you to move money to a new account. Hang up; call back on the number from your card or statement. Urgency plus secrecy equals scam — every time, regardless of how much the caller knows about you.
Frequently asked questions
How is APP fraud different from card fraud?
Card fraud is unauthorized — someone else uses your credentials, and chargeback rights protect you. APP fraud is authorized — you initiate the payment — so card dispute machinery doesn’t apply, and protection depends on your market’s rules and your bank’s policies.
Can an APP payment be recalled?
Sometimes, if reported within minutes and the receiving account still holds funds; banks operate recall and repatriation processes. In practice mule networks disperse money fast — treat recall as a sprint you’ll probably lose, and reimbursement rules as the real safety net where they exist.
Does Confirmation of Payee stop these scams?
It reliably wounds redirection-type scams (wrong-name warnings are hard to script around) and helps less against purchase and romance scams, where victims believe the name is legitimate. Necessary, not sufficient.
Who pays when a business falls for invoice fraud?
Outside consumer reimbursement schemes, usually the business — which still legally owes its real supplier. Insurance may respond depending on policy wording (crime vs. cyber coverage is a genuine minefield worth resolving before an incident, not after).
Are AI voice clones really being used?
Yes — cloned voices of executives and family members are documented in impersonation scams, and video deepfakes have appeared in high-value corporate cases. The countermeasure is procedural, not technological: verification callbacks and code words don’t care how good the audio is.
The payment system has spent two decades making unauthorized fraud hard, and criminals responded by industrializing persuasion. The defenses that work share one property: they interrupt the story — a callback, a name-check, a pause — because the story, not the payment, is the attack.