Authorized push payment fraud occurs when a scammer tricks you into willingly transferring money from your bank account to an account they control. Unlike card fraud, where criminals steal your details and pull funds without permission, APP fraud relies entirely on deception: you log in, you approve the transfer, and you push the money yourself.
That distinction creates a serious problem for victims. Because you initiated the payment, your bank’s standard fraud protections often don’t apply, and recovery rates remain stubbornly low. This guide breaks down how APP scams work, the most common tactics fraudsters use, and the practical steps that actually prevent losses before they happen.
What Is Authorized Push Payment Fraud?
Authorized push payment fraud happens when a scammer tricks you into willingly transferring money from your bank account to an account they control. The key word here is authorized. Unlike card fraud where criminals steal your details and pull funds without permission, APP fraud relies entirely on deception. You log in, you approve the transfer, and you push the money yourself.
That distinction matters more than you might think. Because you initiated the payment, your bank’s standard fraud protections often don’t kick in. The transaction looks completely normal from their end, just another customer sending money.
APP fraud has grown alongside faster payment systems. When transfers settle in seconds rather than days, there’s almost no window to catch a mistake or recall the funds. By the time you realize something’s wrong, the money has typically moved through several accounts and left the banking system entirely.
How Does APP Fraud Work?
Every APP scam follows a similar playbook, even when the specific story changes. Understanding the mechanics helps you spot an attack before you hit send.
1. Social Engineering Creates Urgency or Trust
The scam starts with manipulation. Fraudsters use urgency, fear, or trust to override your normal decision-making. They might pose as your bank warning about suspicious activity, a supplier requesting an urgent payment, or a romantic interest facing an emergency.
The goal is to create a scenario where sending money feels like the right, or only, option. Scammers often research their targets beforehand, pulling details from social media, data breaches, or prior interactions to make their story believable. A call that references your actual bank, your real supplier’s name, or details about your recent purchases feels much more convincing than a generic request. Many of these approaches rely on the same phishing scam groundwork used to harvest personal details before the payment request ever arrives.
2. The Victim Initiates the Payment
Here’s what separates APP fraud from other payment fraud: you do the work. You log into your banking app, enter the recipient’s details, and authorize the transfer. From the bank’s perspective, this looks like a normal, legitimate transaction.
Fraudsters typically provide account details that appear plausible, sometimes even using account names that match the supposed recipient. Some scams involve multiple calls or emails over days or weeks, building trust before the payment request arrives.
3. Funds Disappear Through Mule Networks
Once you send the money, it moves fast. Fraudsters route funds through multiple accounts, often belonging to unwitting money mules recruited through fake job offers, before withdrawing cash or converting to cryptocurrency.
This layering happens within minutes or hours. The speed of modern payment rails works against victims here. By the time you contact your bank, the money has typically passed through several accounts and exited the banking system.
Common Types of APP Fraud
APP fraud takes many forms, but certain eCommerce scam types appear repeatedly. Recognizing the patterns is your first line of defense.
1. Invoice and Mandate Fraud
A fraudster intercepts or impersonates a legitimate supplier, contractor, or vendor. They send an email, often from a spoofed or compromised account, requesting that future payments go to updated bank details. Businesses lose significant sums this way, sometimes hundreds of thousands of dollars in a single transaction.
This scam works because it exploits existing relationships. The email looks like it’s from someone you already do business with, and the request seems routine. It’s a close cousin of business email compromise, where attackers hijack or spoof a trusted inbox to redirect company payments.
2. Impersonation Scams
Criminals pose as trusted institutions: your bank, the police, a government agency, or a utility company. They claim your account is compromised or you owe money urgently. The pressure to act immediately is intense, and victims often don’t realize they’ve been scammed until days later.
A common version involves a caller claiming to be from your bank’s fraud department, warning that your account is under attack and you need to move your money to a safe account. That safe account, of course, belongs to the scammer. This tactic sits alongside other forms of account takeover fraud, since the end goal is the same: gaining control over funds the victim believes are still secure.
3. Romance Scams
After weeks or months of building an online relationship, the scammer invents an emergency, medical bills, travel costs, a business crisis, and asks for money. Victims often send multiple payments before recognizing the pattern.
Romance scams tend to involve larger total losses because the relationship-building phase creates genuine emotional investment. The victim wants to help someone they believe they care about.
4. Investment and Cryptocurrency Scams
Fraudsters promote fake investment opportunities promising high returns. They may create professional-looking websites, fake testimonials, and even show fabricated account balances. Victims transfer funds believing they’re building wealth, only to discover the platform was entirely fraudulent.
Cryptocurrency fraud adds another layer of difficulty here. Once funds convert to crypto and move to an external wallet, recovery becomes nearly impossible.
5. Purchase Scams
A seller advertises goods, often on social media or marketplace platforms, at attractive prices. The buyer pays via bank transfer, and the goods never arrive. Because the payment was authorized, recovery is difficult.
APP Fraud vs. Other Payment Fraud Types
Understanding how APP fraud differs from other fraud categories clarifies why it’s so challenging to prevent and recover from.
| Fraud Type | Who Initiates Payment | Typical Recovery | Detection Difficulty |
|---|---|---|---|
| APP fraud | Victim (authorized) | Low, victim approved transfer | High, looks like normal transaction |
| Card-not-present fraud | Fraudster (unauthorized) | Higher, chargeback rights apply | Moderate, fraud signals detectable |
| Account takeover | Fraudster (unauthorized) | Moderate, depends on detection speed | Moderate, behavioral anomalies visible |
With card fraud, the cardholder didn’t authorize the transaction, so chargeback rights and liability protections apply. With account takeover, someone else accessed your account without permission, again, unauthorized.
APP fraud sits in a gray area. You authorized the payment, even though you were deceived. Traditional fraud detection tools look for unauthorized activity, which means APP fraud often slips through undetected. The transaction itself appears completely legitimate, unlike friendly fraud, where a legitimate cardholder disputes a charge they actually made.
Warning Signs of an APP Scam
Fraudsters rely on speed and emotion. Slowing down and watching for red flags can prevent significant losses.
- Unexpected contact: A call, email, or message you didn’t initiate, especially one requesting payment or account changes
- Urgency or pressure: Claims that you’ll lose money, face legal action, or miss an opportunity if you don’t act immediately
- Requests to bypass verification: Instructions to ignore security warnings, avoid telling anyone, or use specific payment methods
- Changed payment details: A supplier or contact suddenly providing new bank account information, especially via email
- Too-good-to-be-true offers: Investment returns, prices, or opportunities that seem unusually favorable
If something feels off, it probably is. Legitimate organizations won’t pressure you to transfer money immediately or ask you to keep the transaction secret from family members or colleagues.
How to Prevent APP Fraud
Fraud prevention requires a combination of personal vigilance and, for businesses, systematic controls. Neither technology nor awareness alone is sufficient.
1. Verify Payment Requests Independently
Never use contact information provided in a suspicious message. Look up the organization’s official number from their website or your records, then call to confirm the request. This single step stops most invoice and impersonation scams.
Even if an email appears to come from someone you know, pick up the phone and verify. Email accounts get compromised, and spoofed addresses can look nearly identical to legitimate ones.
2. Slow Down Before Sending Money
Fraudsters manufacture urgency because it works. Taking even a few minutes to consult a colleague, family member, or friend can break the spell. Legitimate requests can wait for verification.
If someone is pressuring you to act immediately and telling you not to discuss the situation with anyone else, that’s a major red flag. Real emergencies rarely require secrecy.
3. Use Confirmation of Payee Services
Many banks now offer confirmation of payee, which checks whether the account name matches the details you’ve entered. A mismatch warning is a strong signal to stop and verify before proceeding.
This service isn’t available everywhere yet, but where it exists, it adds a valuable layer of protection against misdirected payments.
4. Enable Transaction Alerts and Limits
Real-time notifications for outgoing payments help you catch unauthorized activity quickly. Setting transfer limits adds friction that can prevent large losses from a single transaction.
5. Train Staff on Payment Verification Procedures
For businesses, documented procedures for verifying payment changes, especially for high-value transactions, reduce reliance on individual judgment. Dual authorization for large transfers adds another layer of protection, and these habits fold naturally into broader payment fraud detection practices and ongoing fraud monitoring routines.
Tip: Create a simple verification checklist for any payment request involving new or changed bank details. Even a two-minute callback can prevent a six-figure loss.
Regulations and Reimbursement for APP Fraud Victims
The regulatory landscape for APP fraud is evolving, with significant differences between jurisdictions.
In the UK, the Payment Systems Regulator introduced mandatory reimbursement rules in October 2024. Most APP fraud victims can now expect reimbursement from their bank within five business days, up to £85,000, unless they acted with gross negligence. This represents a major shift in liability from consumers to financial institutions.
In the US, the picture is less favorable. Regulation E, which governs electronic fund transfers, generally doesn’t cover authorized transactions, even if you were deceived. Some banks offer voluntary protections, but there’s no consistent standard. Victims often find themselves with limited recourse beyond filing a report with the FBI’s Internet Crime Complaint Center.
For merchants and payment professionals, regulatory shifts matter. As liability moves toward banks and payment providers, expect increased scrutiny on transaction monitoring and customer warnings.
The Cost and Scale of APP Fraud
APP fraud losses are substantial and growing. In the UK, losses exceeded £459 million in 2023, with only about 62% reimbursed to victims. In the US, Zelle alone saw over $166 million in reported scam losses in 2023, though actual figures are likely higher since many cases go unreported to the FTC’s Consumer Sentinel Network.
For businesses, the risk extends beyond direct losses. Invoice fraud can disrupt supplier relationships, damage reputation, and create operational chaos. Real-time payment adoption is accelerating globally, and APP fraud is following.
The Bottom Line
APP fraud exploits trust and speed, two features that make modern payments convenient but also vulnerable. Because victims authorize the transfer themselves, traditional fraud protections often don’t apply, and recovery rates remain low.
The most effective defense combines skepticism, verification habits, and systematic controls. For individuals, that means pausing before any urgent payment request and confirming details through independent channels. For businesses, documented procedures and staff training are essential.
Regulatory changes are shifting some liability toward financial institutions, but prevention remains your best protection. A few minutes of verification can save months of recovery efforts.
Frequently Asked Questions
What is the difference between authorized and unauthorized payment fraud?
Unauthorized fraud occurs when someone accesses your account or card without permission and initiates a transaction. Authorized fraud, like APP fraud, happens when you initiate the payment yourself, even though you were deceived into doing so.
Can businesses be targeted by APP fraud?
Yes, businesses are frequent targets, especially through invoice and mandate fraud. Scammers impersonate suppliers or intercept legitimate invoices, redirecting payments to fraudulent accounts.
Does using real-time payment rails make APP fraud harder to reverse?
Real-time payments settle within seconds, leaving almost no window to recall funds. This speed is a key reason APP fraud recovery rates are so low compared to card-based fraud.
Are cryptocurrency transfers considered APP fraud?
If you're tricked into sending cryptocurrency to a scammer, the mechanics are similar to APP fraud, you authorized the transfer. However, crypto transactions fall outside traditional banking regulations, making recovery even more difficult.
Who investigates APP fraud complaints?
Your bank typically handles the initial complaint and investigation. In some cases, law enforcement or financial regulators may become involved, particularly for large-scale or organized fraud operations.
What is the average financial loss per APP fraud case?
Losses vary widely by scam type. Romance and investment scams often result in losses exceeding $10,000 per victim, while purchase scams may involve smaller amounts. Business invoice fraud can reach six figures in a single incident.
Charity Amancio
Charity Amancio specializes in SaaS solutions for global eCommerce businesses, including payments and risk management applications. She bridges the gap between technology and merchant needs, offering practical perspectives on the tools shaping eCommerce. Her insights appear regularly in B2B publications covering the digital commerce space.












