← Industry Insights
Financial Crimes

Authorised Push Payment Fraud: A Complete Guide for 2026

Updated Jun 2026 · 12 min read
SHAREinXf
Authorized Push Payment Fraud: A Complete Guide for 2025

Few threats cost UK banking customers more than authorised push payment fraud. What sets it apart is who moves the money. The victim does. After a criminal persuades them to send it, the funds go to an account that the criminal owns, and because the customer issues the instruction willingly and a bank reads it as a normal payment, the transfer is difficult to block while it happens and close to impossible to claw back afterwards.

Speed is the weakness here. Instant bank transfers and peer-to-peer apps now carry a large share of everyday spending, and on those rails a fraudulent payment can clear before anyone has a chance to question it, since the review window has shrunk to a matter of seconds. Below, you will find the mechanics of APP fraud, the shapes it takes, and the controls that genuinely lower a firm's exposure.

Mandatory Reimbursement Changed APP Fraud in the UK

Regulation has moved most. Since this guide first appeared, the UK's Payment Systems Regulator made victim reimbursement compulsory on 7 October 2024, so firms now have to repay authorised push payment scam claims up to GBP 85,000, and the bill is shared fifty-fifty between the bank that sent the payment and the bank that received it. Payments running over Faster Payments and CHAPS between UK accounts fall inside the rules.

Early numbers tell a consistent story. Fifteen months in, by the end of December 2025, the PSR's reimbursement dashboard showed that roughly 89% of in-scope losses, about GBP 243 million, had gone back to victims; 82% of claims closed inside five business days, and more than 99% of them came in under the cap. For the bank on the receiving end, an account that accepts scam money is now a direct source of financial loss. That exposure has prompted far heavier scrutiny of inbound payments, and the economics of fraud control have shifted for every firm that moves money over UK rails.

Authorised Push Payment Fraud

Several points anchor everything that follows.

  • APP fraud is social engineering. The criminal talks the victim into transferring money by hand to an account under the criminal's control.
  • Belief is what does the damage. A victim sends the money convinced it is going somewhere legitimate, and the deception (rather than any hacked system or stolen credential) is the mechanism of the loss. Individuals and organisations alike lose heavily for exactly that reason.
  • UK Finance recorded GBP 450.7 million lost to APP fraud across 2024, a 2% drop on the year before. Of that total, GBP 365.7 million hit individuals and GBP 84.9 million hit businesses.
  • Reported cases fell by roughly 20% to under 186,000, the lowest count since 2021. Sharper detection technology helped, and so did wider consumer awareness.
  • Investment scams inflicted the most financial harm. They accounted for GBP 144.4 million of APP losses in 2024 and climbed 34% year on year, even though case numbers were falling.
  • Purchase scams remained the type people reported most, responsible for GBP 87.1 million in losses across 2024.
  • This is a worldwide problem. ACI Worldwide's Scamscope research projects APP scam losses reaching USD 7.6 billion by 2028 across six of the leading real-time payment markets, which it identifies as the US, the UK, India, Brazil, Australia, and the UAE.
  • Fast payment systems are what APP fraud rides on. Subject to the bank and the account, the UK's Faster Payments now clears single, irreversible transactions of up to GBP 1 million.
  • Criminals impersonate a bank, a supplier, an employer, or a romantic partner, among others. Phishing, spoofed email, and fake phone calls all feed the deception.
  • Blame is genuinely hard to assign. Since the victim authorises every transfer, the warning signs that flag unauthorised access simply are not there.
  • Prevention rests on four things working together: customer education, transaction monitoring, payee verification, and analytics built on machine learning.

What are Authorized Push Payments (APP)?

A push payment is a transaction the account holder sets in motion, instructing their bank or payment provider to send money straight from their account to someone else's. People start these payments through online banking, over phone banking, or via peer-to-peer payment platforms.

Setting the push payment beside its mirror image makes the idea clearer. A pull payment runs the other way, with the payee drawing money out of the payer's account under a pre-agreed arrangement, which is how a direct debit operates.

What separates the two is control. In a push payment, the payer holds it. In a pull payment, the payee does, choosing the moment funds leave the other party's account. The side that triggers the movement determines how exposed each method is to fraud, and that asymmetry is why the social engineering tactics described below cluster around push payments specifically.

What is Authorized Push Payment Fraud (APPF)?

When a criminal cons a person or a business into sending a push payment to an account they secretly control, that is authorised push payment fraud. The attacker generally pretends to be an entity the victim trusts, a bank or a supplier being the common choices, and from behind that disguise steers the victim into approving a payment they would otherwise refuse.

One characteristic of the push payment process outweighs the rest. Reversal is hard. Reading the instruction as legitimate, a bank settles it almost at once, and once the money reaches the recipient's account, getting it back is generally hopeless; that goes double when the criminal pulls or relays the funds within minutes of arrival.

Types of Authorized Push Payment Fraud (APPF)

There are several distinct varieties of APP fraud, and each brings its own difficulties for detection and prevention. A single thread ties them together. In every case, whatever the cover story or the channel, the victim is steered into approving a payment that reaches an account the scammer controls and can empty within minutes.

Common types of APP fraud include the following:

1: Purchase Scams

Goods or services that were never going to materialise get paid for in advance, and once the payment clears, the supposed seller drops out of contact entirely, leaving the buyer with nothing and no obvious way to trace the money. The buyer waits in vain. Of all the variants, this one shows up most often.

2: Advance Fee Scams

Victims are told to pay a fee that will release a service, a loan, or a prize. What was promised never materialises.

3: CEO Fraud

Known too as business email compromise (BEC), this one involves a criminal posing as a senior executive who then leans on an employee to make a payment dressed up as ordinary company business.

4: Investment Scams

Criminals draw the victim into an investment that exists only on paper, after which the money flows to the scammer's account and the fund itself turns out to be a complete fiction. Returns never come. Of all the categories, this one was behind the biggest slice of UK APP losses in 2024.

5: Romance Scams

Staging a romantic relationship, a criminal trades on the feelings it generates to pull money out of the victim. The supposed partner vanishes as soon as the funds go through.

6: Invoice Fraud

Posing as a supplier, the scammer sends out fake invoices. A more dangerous version has the criminal intercepting a real invoice and quietly changing the bank details, which routes the payment to a fraudster while the business believes it is paying its genuine supplier.

7: Property Purchase Scams

What makes property scams work is the interception of messages passing between a buyer and their conveyancer, estate agent, or solicitor. Slipping into the conversation as one of those parties, the fraudster reroutes the deposit or the completion funds to an account they control.

How Does Authorized Push Payment (APP) Fraud Work?

Sometimes called bank transfer fraud, an authorised push payment scam turns on a transfer the payer starts. Direct debits and standing orders work differently, because there the payee runs the collection.

In an APP, the payer tells their bank to shift a specific amount from one account to another. Everyday uses cover the ground here, from online shopping to settling bills to sending money to family.

It starts when the payer hands the bank the beneficiary's details, usually an account number and a sort code. Acting on what it has been given, the payer's bank carries out the request and sends the funds to the named recipient.

Convenience is the entire reason the method exists, and people run their own payments with nobody else standing in the way. There lies the weakness. Fraudsters find the openings in the flow and, time and again, fool ordinary people into approving transfers that go straight to criminal accounts they have no reason to suspect.

As the technology moves, so do the criminal methods built around it, which leaves staying alert, sticking to security procedures, and grasping the dangers that come with authorised push payments squarely on the user. The burden is real. Now that the mechanics are clear, the next section turns to the particular methods scammers depend on.

Methods used in Authorized Push Payment Scams

Push payment fraud runs on a handful of recurring tactics.

  • Social engineering: Psychological pressure is the lever here, applied through impersonation more often than not, to get an account holder to give up personal details, approve a payment, or surrender login credentials. Of every approach, impersonation produces some of the largest losses.
  • Phishing scams: Posing as a trusted organisation over email or text, a fraudster nudges the victim into clicking a link or installing malware, which opens a path into their personal information and accounts. What often comes next is account takeover. Having grabbed control of a person's or a company's account, the criminal then poses as the victim, sometimes messaging that person's friends from a hijacked social media profile to ask for money.
  • Confidence scams: These run on earning someone's trust in order to reach their account or talk money out of them. A fabricated relationship is one hook; a bogus business opportunity is another.
  • Property purchase scams: Here the criminal listens in on a buyer's exchanges with conveyancers, estate agents, and solicitors. During a house purchase the buyer is dealing with a crowd of unfamiliar contacts anyway, so slipping in as one more party gets considerably easier.

Authorized Push Payment Fraud Examples

Misrepresentation, and frequently outright impersonation, is how fraudsters run these schemes past the victim. The examples below show what that looks like once it reaches real situations.

1: Invoice Scam

Invoice fraud cons the victim into settling a bill that is not real. To make a fraudulent invoice convincing, criminals draw on social engineering, impersonation, and forged paperwork.

For individuals, the targets are usually recurring bills, with energy, broadband, or television services being the typical examples a fraudster picks because the payment looks routine. A company might instead be hit with a single one-off invoice. Another route changes the payee held in a finance system, so that a whole stream of legitimate-looking payments flows to the fraudster month after month before anyone reconciles the account. Volumes add up fast.

2: Romance Scam

Romance fraud has criminals constructing relationships that never existed and cashing in on the closeness to draw out money and other assets.

Authorised push payment is how most romance scams end. A criminal may be after more than cash, yet the money itself nearly always moves by push payment, and almost every case runs on impersonation plus the unhurried social engineering it takes to earn a victim's trust and sympathy over weeks. Patience is the method. When the connection feels solid, the scammer asks for a real-time transfer.

3: Personal Relationship Scam

A close cousin of the romance scam, this version has the fraudster posing as a relative or a friend who then asks for money by push payment.

Bringing it off generally takes personal detail about the victim, picked up through phishing, hacking, or data purchased on illicit markets. Just as in romance fraud, the criminal manufactures urgency, pressing the line that the money is critical and has to be sent right away.

4: Property Funds Scam

Here a victim is tricked into paying fraudsters for the costs of a property purchase. Because the sums attached to real estate are so large, the fallout when one of these works is severe.

Getting inside the deal means learning the details of the sale, which fraudsters obtain by intercepting messages among the buyer, the seller, the agent, and the lender. Forged documents, impersonation, and social engineering then do the persuading, the goal being to get the victim to change the payee for a property payment.

5: Account Takeover Fraud

Account takeover (ATO) fraud is what happens once criminals get direct access to a victim's account and put it to work committing fraud.

In an APP scenario, that control lets them make authorised push payments while the account holder knows nothing about it. Doing so cuts out one of the more awkward stages of APP fraud, the patient grooming needed to get a victim to send the money on their own.

6: Contractor Scam

Think of a home renovation or contracting scam as a more elaborate invoice scam. The victim winds up paying renovation fees to the fraudster in place of the real tradesperson.

Phishing and other reconnaissance is how criminals learn that home improvements are under way. Once they understand a project well enough, they wedge themselves into the transaction, sending the homeowner an invoice while pretending to be the genuine contractor and timing it to look like the real thing. The trap is set. With the homeowner having paid and the fraudster gone, the scam comes to light only when the genuine invoice finally arrives.

Mitigating APP Fraud Risks

Bringing APP fraud risk down calls for technology, education, and disciplined operational controls in combination. Set out below are the strategies that carry most of the weight.

1: Customer Education

Show customers what APP fraud looks like, which warning signs to watch for, and the steps to take before they approve a payment to anyone new.

2: Transaction Monitoring

Monitor transaction patterns to bring unusual activity into view where it may point to fraud, and send the highest-risk payments for review before they settle.

3: Transaction Delays

Put short holds on payments that are high in value or out of pattern. The pause creates room for extra checks, and it gives the customer a chance to think again.

4: Confirmation of Payee (CoP)

Run Confirmation of Payee checks, which match the recipient's name against the account details so the money reaches the person actually intended and not a lookalike account.

5: Account Takeover Fraud Prevention

Account takeover is frequently what comes right before APP fraud. A strong ATO defence spots suspicious account access and shuts it down quickly, ahead of any chance for a criminal to push through a fraudulent transfer.

How to Detect and Prevent APP Fraud with KYC Hub?

KYC Hub puts anti-money laundering and fraud detection together on one platform. A firm moving money across UK rails can combine its payments fraud and AML controls with the measures set out here.

  • Advanced fraud detection: Algorithmic models surface the patterns that signal fraud, picking up behaviour that static rules let through.
  • Real-time transaction monitoring: Software checks transactions as they happen and pulls out the suspicious, high-risk ones for action.
  • Account takeover prevention: Access controls keep customer accounts away from the wrong hands.
  • Unified fraud management: A single integrated suite manages detection, prevention, and response as one connected workflow, with no siloed handoffs between them.
  • Thorough customer onboarding: Careful checks at sign-up keep fake documents and synthetic identities off the platform.
  • Event and activity monitoring: Continuous review of what users do flags behaviour that is drifting toward fraud.
  • Periodic identity checks: Re-verifying account holders over time defends against accounts being quietly taken over.
  • KYC checks on transactions: Identity and payee validation built into the payment flow confirm who is genuinely being paid.
  • Behavioural analytics: Pattern analysis surfaces the anomalies that frequently mark where a scam begins.

Conclusion

Even with losses easing across 2024, authorised push payment fraud is still a serious danger to UK payments. Customer education, sharp fraud detection, real-time transaction monitoring, and a strong account takeover defence each pull the risk down, and they work best in concert.

KYC Hub's AML solutions help a business hold fraud in check and tackle money laundering in the same motion. Compliance and risk teams get what they need to detect, prevent, and respond to fraudulent activity, which protects the firm's own money as well as the trust its customers place in it.

[ FREQUENTLY ASKED QUESTIONS ]

Any questions? We got you.

What is authorised push payment fraud?

Authorised push payment fraud is a scam where a criminal manoeuvres a person or a business into sending a bank transfer to an account the criminal controls. Believing the money is bound for a legitimate person or company, the victim approves the payment themselves, and that willing authorisation is the very thing that makes the loss so hard to recover.

Can I get my money back after an authorised push payment scam?

In many cases, yes. UK firms have had to reimburse victims of APP scams sent over Faster Payments or CHAPS since 7 October 2024, up to GBP 85,000 a claim, with the sending and receiving banks splitting the cost. Tell your bank about the fraud at once, and in any event within 13 months of the last payment. Where a customer has acted with gross negligence, reimbursement can be cut back or turned down.

What are the most common types of APP fraud?

Topping the list for frequency are purchase scams, which made up GBP 87.1 million in losses across 2024. Beyond those come several other major forms. Investment scams caused the largest losses of any type that year, and the picture also takes in romance scams, impersonation fraud, invoice fraud, and CEO or business email compromise fraud.

How can businesses protect themselves from APP fraud?

Strong defence stacks several controls on top of one another. Transaction monitoring brings unusual payments to attention. Confirmation of Payee flags a mismatched account name before the transfer completes, short holds on risky payments open up time for checks, and account takeover prevention closes off compromised access. Running alongside all of it is customer education, because a payer who knows the signs is the final barrier before the money goes.

What is a push payment?

Any transfer the sender sets going, rather than the recipient, is a push payment. The payer instructs their bank or app to move a set sum into another account, which is what people do when they settle a bill, pay a supplier, or send money to family. Control rests with the sender. That is the dividing line between a push payment and a pull payment such as a direct debit.

How does KYC Hub help mitigate APP fraud?

KYC Hub runs an integrated AML and fraud platform that detects, prevents, and responds to fraudulent activity. Real-time transaction monitoring, behavioural analytics, account takeover prevention, and payee validation operate together to bring a firm's exposure down across UK payment rails.

[ KYC HUB ]

Stop fraud before it reaches your customers

Detect and prevent fraud across onboarding and transactions with device, behaviour and identity signals.

Explore the fraud preventionBook a demo
[ RELATED READING ]
Combating Financial Crimes in 2026: Global Efforts to Fight Back
[ Financial Crimes ]

Combating Financial Crime in 2026: A Compliance Playbook

A B2B compliance view of combating financial crime in 2026: the global bodies, regulators, FIUs, and AI-driven controls that detect, report, and disrupt illicit finance.

Dec 2025 · 6 min read
Biggest Banking Frauds in India: All You Need to Know in 2025
[ Financial Crimes ]

Bank Fraud Examples in India: Top 15 Cases, Types and Prevention (2026)

Explore the top 15 banking frauds in India that shook the financial industry. Learn about key bank fraud cases, their impact, and ways to prevent financial scams.

Mar 2025 · 15 min read
Deepfake Laws and Regulations: All You Need to Know in 2025
[ Financial Crimes ]

What Are Deepfakes? Detection, Fraud Risks, and Global Laws in 2026

A practical guide to deepfakes for compliance and fraud teams: what they are, how detection works, the fraud risks to financial services, and how laws are evolving worldwide.

Feb 2025 · 12 min read