Authorized Push Payment (APP) Fraud
Authorized push payment fraud, usually shortened to APP fraud, happens when a person or business is deceived into sending money to a fraudster from their own account. The payment is authorized by the victim, but the decision is manipulated through impersonation, pressure, or other social engineering tactics.
That distinction matters. In APP fraud, the bank may see a valid login, a known device, and a correctly approved payment. What the bank cannot assume is that the customer is acting freely and with full context. This is why APP fraud sits at the intersection of payment risk, scam prevention, authentication, and customer experience.
For financial institutions, APP fraud is hard to control with static payment checks alone. For customers, it can be financially and emotionally devastating because funds are often moved quickly through mule accounts and become difficult to recover.
At Entersekt, APP fraud is treated as a problem of intent as well as identity. That perspective helps explain why older, one-time identity checks rarely stop modern payment scams.
Key facts about APP fraud
APP fraud is a scam-led payment crime, not a classic unauthorized account breach. The victim sends the money, even though the payment was induced by deception.
- APP stands for authorized push payment.
- It usually involves account-to-account transfers such as bank transfers, instant payments, and peer-to-peer payment flows.
- It commonly starts with impersonation, invoice manipulation, romance scams, investment scams, or fake urgent requests.
- It differs from card fraud because there is usually no chargeback model equivalent once the transfer settles.
- It differs from account takeover because the customer may still be the person logging in and approving the payment.
- It often relies on social engineering rather than stolen credentials alone.
How APP fraud works
APP fraud works by persuading the victim to initiate a real payment to a criminal-controlled account. The fraudster does not always need to break into the account. They need to control the story around the payment.
- Contact and pretext: The fraudster poses as a bank employee, supplier, family member, government authority, or investment contact.
- Pressure and persuasion: The victim is told there is urgency, secrecy, risk, or a time-sensitive opportunity.
- Payment initiation: The victim logs in and sends the funds, often to a new beneficiary or an account framed as safe or legitimate.
- Rapid movement of funds: The receiving account may be a mule account used to move money onward quickly.
- Recovery becomes difficult: Once the transfer settles, tracing and reclaiming funds may be slow, partial, or impossible.
This is why APP fraud often bypasses controls built only to verify identity at login. The customer may be genuine. The payment intent is not.
Why APP fraud is hard to stop
APP fraud is hard to stop because the payment can look technically valid at the point of execution. The institution may see a successful session, a recognized channel, and an approved instruction.
The real warning signs often sit elsewhere. They appear in behavior changes, unusual payment context, new beneficiary patterns, location anomalies, abnormal timing, or signals that the customer is being coached while transacting.
This is also why one-size-fits-all payment challenges can underperform. If every transaction gets the same treatment, low-risk payments absorb unnecessary delay while higher-risk scam journeys may still slip through.
APP fraud versus account takeover fraud
APP fraud and account takeover fraud are related, but they are not the same. The difference is who initiates the payment and how the fraudster gains influence.
| Question | APP fraud | Account takeover fraud |
|---|---|---|
| Who initiates the payment? | The victim | The fraudster |
| How does the attack work? | Deception and social engineering | Unauthorized access to the account |
| Is the login always compromised? | No | Usually yes |
| Primary control focus | Intent, transaction context, beneficiary risk | Identity, access control, session security |
In practice, the two can overlap. A scam may begin with impersonation and later include compromised credentials or device changes. That is one reason banks need linked controls rather than isolated point checks.
What types of scams lead to APP fraud?
Several scam types can end in APP fraud because they all aim to persuade the victim to move money voluntarily.
- Bank impersonation scams: The victim is told their account is under threat and funds must be moved to a supposedly safe account.
- Invoice and supplier fraud: Payment details are changed or spoofed so a legitimate business payment goes to a criminal account.
- Romance scams: Emotional trust is built over time and then used to request money.
- Investment scams: The victim is lured into sending funds to a fake or misrepresented investment opportunity.
- Purchase scams: The victim pays for goods or services that do not exist or are never delivered.
- Family emergency scams: The fraudster claims a relative needs urgent financial help.
These journeys differ in story, but they share the same operating model: manipulate trust, create urgency, and induce payment.
What controls help reduce APP fraud?
APP fraud is reduced through layered controls that evaluate the payment journey, not just the login event. No single control is enough on its own.
Adaptive authentication helps by varying the response to risk. A known customer performing a familiar transfer may pass quickly. A customer adding a new beneficiary, changing behavior, or making an unusual high-value payment may trigger stronger verification.
Scam prevention also depends on understanding payment context. That includes beneficiary changes, device trust, behavioral signals, transaction amount, payment timing, and indicators of coercion or manipulation.
Good APP fraud controls often include:
- Risk-based authentication tied to payment context
- Beneficiary and payee validation checks
- Behavioral analytics during the payment session
- Real-time transaction risk scoring
- Step-up verification for anomalous payment activity
- Targeted customer warnings that appear at the right moment
- Cross-channel intelligence sharing across digital banking, contact center, and payment environments
Entersekt’s authorized push payments approach focuses on authenticating intent as well as identity. Entersekt evaluates transaction context and customer behavior so banks can intervene before irrevocable payment loss occurs.
Why customer warnings often fail
Customer warnings often fail when they are generic, repetitive, or disconnected from the payment moment. A long warning shown on every transaction can quickly become background noise.
Warnings are more effective when they are specific to the risk scenario. A first payment to a new recipient, a sudden change in amount, or unusual payment timing can justify a targeted interruption that asks the customer to pause and verify the circumstances.
This is where design matters. The goal is not to create blanket delay. The goal is to introduce informed, proportionate intervention when behavior and context indicate scam risk.
How real-time payments increase APP fraud risk
Real-time payments increase APP fraud risk because they combine speed, irrevocability, and customer-initiated approval. Those three conditions leave little room for recovery once a payment has been sent.
That does not mean instant payments are the problem. It means fraud controls need to act at decision speed. Real-time schemes require real-time risk evaluation, real-time intelligence, and real-time intervention.
This is a major theme in social engineering attacks in real-time payments. Faster settlement raises the cost of delayed decisions.
What regulators and payment authorities expect
Regulatory expectations for APP fraud are rising, especially where account-to-account and instant payments are widely used.
In the UK, the Payment Systems Regulator defines APP scams as cases where someone is tricked into sending money to a fraudster posing as a genuine payee. The regulator also introduced mandatory reimbursement protections for many APP fraud cases on Faster Payments and CHAPS, with implementation beginning on October 7, 2024.
The PSR states that reimbursement protections apply to individuals, microenterprises, and charities using in-scope UK bank transfers, and that most victims should be reimbursed within five business days under the new rules. The consumer-facing explanation is available in the PSR’s guidance on APP fraud reimbursement protections.
The broader signal is clear. Payment firms are increasingly expected to stop scam payments earlier, share intelligence more effectively, and design controls around customer harm, not just access control.
How APP fraud relates to authentication
APP fraud is closely tied to authentication because authentication answers only part of the problem. It can confirm who is present. It cannot, by itself, confirm why the payment is being made.
That is why authentication for APP fraud has to become more contextual. Entersekt connects authentication to transaction risk, device trust, and behavioral context so that payment decisions are better aligned to real customer intent.
Put simply, identity proof is necessary, but payment intent is decisive.
Questions banks should ask about their APP fraud controls
Banks reviewing their APP fraud posture should test whether their controls can detect manipulation as well as misuse.
- Can you distinguish a normal payment from a socially engineered one?
- Can you detect unusual beneficiary, channel, or behavior patterns before funds leave the account?
- Can you apply stronger verification only when payment context justifies it?
- Can your digital, call center, and payment controls share risk signals quickly enough to matter?
- Can you intervene early enough to stop loss before settlement makes recovery unlikely?
If the answer to several of these questions is no, the gap is usually not visibility alone. It is decisioning at the moment of payment.
Frequently asked questions about APP fraud
➡️ What does APP fraud mean?
APP fraud means authorized push payment fraud. It refers to a scam in which a victim is deceived into sending money from their own account to a fraudster.
➡️ Is APP fraud the same as unauthorized payment fraud?
No. Unauthorized payment fraud happens when a transaction is made without the victim’s approval. APP fraud happens when the victim approves the payment, but the approval was obtained through deception.
➡️ Can multi-factor authentication stop APP fraud?
Not on its own. Multi-factor authentication can confirm identity at login or approval, but APP fraud often succeeds because the real customer is manipulated into making the payment.
➡️ Why is APP fraud associated with social engineering?
APP fraud is associated with social engineering because the fraudster usually needs to influence the victim’s judgment. The payment is induced through trust, fear, urgency, or impersonation rather than silent back-end compromise alone.
➡️ Why do instant payments make APP fraud harder to contain?
Instant payments make APP fraud harder to contain because funds can move and disappear quickly after approval. That shortens the time available for intervention, investigation, and recovery.
➡️ How can banks reduce APP fraud losses?
Banks can reduce APP fraud losses by combining adaptive authentication, real-time payment risk analysis, behavioral monitoring, payee checks, and targeted interventions. Entersekt supports this approach by connecting identity, context, and payment decisioning across channels.