APP Fraud (Authorized Push Payment Fraud)
TL;DR
- APP fraud is a scam where a fraudster tricks a victim into authorizing a payment to an account the fraudster controls.
- Because the victim authorizes the transfer with their own credentials, the payment looks legitimate to the bank, making it hard to detect and recover.
- UK mandatory reimbursement rules now shift much of the liability from victims onto banks and payment providers.
- Funds move within hours, so real-time detection and intervention matter more than after-the-fact investigation.
What Is APP Fraud (Authorized Push Payment Fraud)?
APP fraud is a scam where a fraudster tricks a victim into authorizing a payment to an account the fraudster controls. The fraudster often impersonates a business, investment opportunity, romantic partner, or authority figure.
What sets APP fraud apart is that the victim authorizes the transaction using their own credentials. The bank’s systems see a normal payment, not an unauthorized transaction initiated by a criminal who stole account access.
That distinction makes APP fraud hard to stop. Traditional fraud controls focus on catching unauthorized access, so they often miss a payment the customer intends to make. Recovery is difficult once funds move because the receiving account frequently empties through a chain of transfers within hours. Common categories include investment scams, romance scams, impersonation scams, and purchase scams.
Because the payment looks legitimate to the sending bank, prevention increasingly depends on behavioral and contextual signals such as unusual payment patterns, new payees, and anomalies relative to the customer’s typical activity.
Why It Matters
APP fraud is one of the most damaging categories of financial crime because it exploits trust and manipulation rather than technical vulnerabilities. Passwords and two-factor authentication can stop unauthorized fraud, but they do nothing when the victim initiates the payment.
UK Finance reported £576.4 million in APP fraud losses across 248,070 cases in 2025, up 19% year over year.
The UK’s mandatory reimbursement framework for APP fraud victims has shifted much of the financial liability onto banks and payment providers. Institutions now have a direct incentive to invest in detection and prevention rather than treating APP fraud mainly as a customer education problem. The Payment Systems Regulator reported that 89% of in-scope APP fraud was reimbursed in the first 15 months of the rules introduced in October 2024.
Because funds move with the victim’s authorization, recovery windows are short, often measured in hours. Real-time detection and intervention are more valuable than after-the-fact investigation.
How APP Fraud (Authorized Push Payment Fraud) Works
- Victim manipulation: a fraudster contacts the victim, posing as a business, investment opportunity, romantic interest, or authority figure to build trust and urgency.
- Authorized transfer: the victim, believing the transaction is legitimate, authorizes a payment using their own banking credentials.
- Fund movement: funds move quickly through the receiving account, often across a chain of transfers, to make recovery difficult.
- Detection and reporting: the victim or bank identifies the fraud, typically after the supposed recipient fails to deliver goods, services, or the promised relationship.
- Reimbursement and investigation: under mandatory reimbursement regimes, the sending bank evaluates the claim and reimburses the victim within a defined timeframe while investigating the receiving account and associated networks.
Regulatory and Compliance Considerations
APP fraud regulation has evolved rapidly in the UK. The Payment Systems Regulator (PSR) introduced mandatory reimbursement for eligible APP scam victims starting in October 2024, requiring sending payment service providers to reimburse victims within five business days for in-scope Faster Payments, subject to a cap of £85,000 per claim.
This is a major shift from the prior voluntary Contingent Reimbursement Model Code, under which only some institutions participated and reimbursement rates were lower. The policy gives banks a direct financial incentive to invest in fraud prevention and customer protection.
Other jurisdictions are watching the UK’s experience as they consider similar reimbursement mandates for authorized payment fraud and broader consumer protection rules.
How Firstsource Can Help
Firstsource runs fraud and financial crime operations end-to-end, combining trained financial crime analysts with AI-powered behavioral analytics to detect APP scam patterns in real time, triage alerts, and resolve cases while protecting the customer relationship. Explore how Firstsource can strengthen your fraud prevention and APP scam defenses.
FAQ
What is Authorized Push Payment (APP) fraud?
APP fraud occurs when a victim is deceived into willingly sending money to an account controlled by a fraudster, typically through impersonation, investment scams, or romance scams. Because the victim authorizes the payment themselves, it looks legitimate to the sending bank.
How is APP fraud different from unauthorized fraud?
Unauthorized fraud involves a criminal accessing an account without the owner's consent, such as through stolen card details. APP fraud involves the victim knowingly and willingly authorizing the payment, having been deceived about who they are actually paying.
Are UK banks required to reimburse APP fraud victims?
Yes. Since October 2024, UK payment service providers must reimburse eligible APP scam victims for in-scope Faster Payments claims within five business days, up to a cap of £85,000 per claim, under rules set by the Payment Systems Regulator.
Why is APP fraud hard to detect?
Because the victim authorizes the transaction themselves using their own credentials, the payment looks like a normal, legitimate transfer to the bank's systems, unlike unauthorized fraud, which often triggers account security alerts.