info This content is available in English only.
close

What Is Authorized Push Payment Fraud?

Authorized push payment (APP) fraud tricks victims into sending money to scammers. Learn how it works and how AI-driven solutions detect and prevent it.

Understanding Authorized Push Payment Fraud

Authorized push payment (APP) fraud, also known as a scam, occurs when a fraudster deceives a consumer or an individual at a business into knowingly sending a payment, under false pretenses, to a bank account controlled by the fraudster. Because the victim authorizes and initiates the transfer themselves, and because payments made through real-time payment schemes are typically irrevocable, victims often cannot reverse the payment once they realize they have been deceived. 

This type of fraud has become more attractive to criminals since the advent of real-time payment schemes. In the UK, Faster Payments were launched in 2008 and enabled the first wave of APP scams, but today real-time payment schemes are a reality worldwide. Schemes such as PIX in Brazil, the New Payments Platform in Australia, and the use of Zelle and Venmo in the USA make real-time payments, and unfortunately real-time payments fraud, a reality.


Key Takeaways

  • Authorization Makes APP Fraud Irreversible. Because the victim knowingly authorizes the payment, and real-time transfers are typically irrevocable, recovery of funds is rarely possible once the fraud is discovered.
  • Standard Bank Authentication Cannot Stop It. Because the legitimate accountholder, rather than an impostor, initiates the transfer, standard identity verification is not a good tool for detecting APP fraud.
  • Regulation Varies Significantly by Market. The UK mandates a 50/50 liability split up to GBP 85,000, effective October 2024, while Australia, Singapore, and the European Union have each introduced distinct liability and oversight frameworks. Many markets are still grappling with regulatory approaches and have no formal standards. 
  • Both Individuals and Businesses Are Targeted. Individual consumers are most often targeted through investment, job and romance scams, while businesses are targeted through property transaction fraud, false invoices and fake supplier payment schemes.
  • No Single Signal Can Detect APP Fraud Alone. Effective detection depends on AI models operating in parallel, complemented by network analytics that identify coordinated fraud rings rather than isolated accounts.

How Do Fraudsters Carry Out APP Fraud?

The approach taken by the fraudsters is not new. They use social engineering techniques and may hack into email and other systems to set up their victims. These methods are used to perpetrate a wide range of attacks; however, with authorized push payment fraud scammers can trick victims into using real-time payment schemes to transfer the money to them. Real-time payments also lower the risk for fraudsters. As money is transferred instantly, fraudsters can move payments through multiple accounts to launder the proceeds of the fraud and make tracing them more difficult.

Why Is APP Fraud on the Rise?

As more consumers continue to evolve into digital-first interactions, both individuals and businesses adopt simple ways to send money in real time, the pool of potential victims increases. 

Debbie Cobb on Authorized Push Payment Fraud

These criminals are devious and clever, and fraud victims cannot simply be written off as gullible fools. As real-time payment schemes can be used to transfer large sums of money, there is a need to employ layered fraud protection across all products and channels used to manage real-time payments.

What Are the Different Types of APP Scams?

Authorized push payment fraud schemes are many and varied, some common attack types include:

Attacks on Individuals

  • Paying an invoice that looks exactly like one from their child’s school – but turns out to be from a fraudster and sends the money to the fraudster’s bank account.
  • Sending payment for work done by a tradesperson such as a carpenter or a builder who’s been working on your house, only to find that you have acted based on an email that came from a fraudster pretending to be your legitimate contractor.
  • Confidence tricks such as romance scams, or the infamous ‘Hey Mum’ scam, where people are tricked into sending money to criminals they believe they have a personal relationship with.

Scams Targeting Property Transactions

This kind of fraud can affect any property purchase, whether by an individual or a business. In fact, the conveyancing solicitors may also end up as victims of payment fraud. Property purchase fraud occurs when criminals intercept the email chain between sellers, buyers, estate agents and solicitors. Once the communications are intercepted, the fraudsters change the payment information related to transfer of funds so that payments are diverted to the fraudsters’ account. With property transactions, the sums involved are likely to be large and falling victim can be life-changing.

Fraudsters Intercepting Supplier Payments

Also known as fake invoice fraud, this scheme is similar to the APP attacks made on individuals, but the victims are businesses. Using a combination of interception and social engineering techniques to obtain information, fraudsters are able to convince businesses to change bank account details, getting their victims to replace the account number of the legitimate suppliers with their own. When the business later goes to pay an invoice from their supplier, they are instead sending it to a fraudster.

Why Is APP Fraud So Difficult for Banks to Prevent and How do Countries Regulate It? 

Authorized push payment fraud is notoriously difficult for banks to prevent. Because the victim is sending the money themselves, the steps that banks take to authenticate customers are ineffective, as the customer will of course pass any identity check. 

APP Fraud Regulation Around the World

The Which Super Complaint in 2016 was a wakeup call to the UK banking industry. Steps such as the contingent reimbursement model and the confirmation of payee service have led to improvements. However, authorized push payment fraud continues to regularly hit the UK headlines and now other countries are rapidly experiencing the same fraud issues.

How Is the UK and Europe Regulating APP Fraud?

The UK has the most comprehensive expectation of any market for receiving banks. The Authorized Push Payment (APP) Fraud Reimbursement Scheme launched in October 2024 by the Payment Systems Regulator (PSR) mandates a 50/50 split (up to GBP 85,000) between the sending and the receiving banks. The confirmation of payee service is also being expanded, and data sharing to detect more fraud is being explored by industry bodies such as UK Finance

It's notable that despite the long history of issues in the UK, new real-time payment schemes are still being launched in many countries without these safeguards in place. UK Faster Payments is a case study for both success in mass adoption of a real-time payments scheme and a salutary tale of the impact of fraud when necessary controls aren’t in place – will other countries learn from it?

The PSD3 regulation in Europe and the accompanying Payment Services Regulation (PSR) signal a new era of tighter oversight, increased liability, and elevated expectations for consumer protection.

APP Fraud Regulations in Australia 

Australia passed the Scams Prevention Framework in February 2025, requiring banks, telcos, and digital platforms to have defined controls in place. Institutions will be deemed liable if these controls are not in place, and the framework extends explicitly to receiving banks as well. Implementation is expected sometime in 2026.

How Is Singapore Regulating APP Fraud?

Singapore has introduced the Shared Responsibility Framework (SRF). Unlike the UK and Australian frameworks, the SRF has a narrower scope, covering phishing-related scams rather than all scam types, and it mandates liability only when the core control requirements have not been met.

Learn More About FICO’s Commitment to Detect and Preventing Fraud 

  • As financial institutions move beyond reactive fraud detection, AI decisioning is becoming central to identifying suspicious transactions and stopping scammers before funds are lost. Download FICO's white paper on fighting scams with AI decisioning to learn how a shared enterprise platform approach helps your teams stay ahead of emerging fraud behavior with greater speed and agility.
  • Combating APP scams in real time requires more than transaction data alone. Download the FICO Scam Signal solution sheet to see how combining telco network intelligence with contextual customer and payment data enables real-time scam detection, proactive intervention, and stronger regulatory compliance across your fraud program.
  • Effective scam prevention now demands a proactive, intelligence-driven strategy rather than reactive controls alone. Download FICO's seven-step framework for customer protection to learn how leading institutions are building customer-level context, proactive intervention, mule control, and industry-wide collaboration into a single, comprehensive scam prevention approach.

Note: This is an update of a post originally published in December 2017.


Frequently Asked Questions

Regulation is tightening globally, from the UK's mandatory reimbursement scheme to Australia's and Singapore's emerging frameworks, while fraud itself is shifting toward faster, more coordinated scams that exploit real-time payment rails. Effective mitigation is embracing AI models and every available data signal for a specific transaction and customer, combined with analytics that can identify suspicious transactions or coercion in action.

Beyond liability-sharing rules, regulators increasingly expect financial institutions to run a comprehensive, continuously monitored program rather than a single control. This typically spans onboarding verification, real-time transaction monitoring, network and graph-based investigation, cross-institutional intelligence sharing, and clear operational protocols for freezing, investigating, or releasing a flagged account, with organizational alignment to prevent duplicated or missed signals.

Industry research indicates that scam detection controls are widely expected to see the sharpest gains in innovation and adoption over the next five years. Rather than a fixed return figure, the business case rests on avoided liability under reimbursement schemes, reduced investigator workload through fewer false positives, and reputational protection in markets where regulation is only getting stricter. Though it can be hard to quantify, increased customer protection can result in higher customer satisfaction, leading to lower attrition rates and potentially higher cross-sell opportunities.

FICO combines an award-winning scams protection solution with Scam Signal, which layers telco network intelligence on top of transaction and customer data to identify social engineering in progress, and purpose-built financial AI in the form of dedicated detection models. These models are designed specifically for regulated financial decisions, delivering greater precision and explainability.

As liability-sharing reimbursement schemes take hold across markets, every scam that reaches completion becomes a potential dispute between sending and receiving institutions. Available in some markets, FICO's Scam Signal is built to intervene before that point, through actions such as blocking a payment, disabling the online session, or triggering personalized, omni-channel outreach that interrupts the scam while it is still underway. This reduces the number of completed scams that ever reach a liability dispute in the first place.

chevron_left Blog home
RELATED POSTS

Take the next step

Connect with FICO for answers to all your product and solution questions. Interested in becoming a business partner? Contact us to learn more. We look forward to hearing from you.