Authorised Push Payment Fraud: A Complete Guide for 2026
Few threats cost UK banking customers more than authorised push payment fraud. What sets it apart is who moves the money. The victim does. After a criminal persuades them to send it, the funds go to an account that the criminal owns, and because the customer issues the instruction willingly and a bank reads it as a normal payment, the transfer is difficult to block while it happens and close to impossible to claw back afterwards.
Speed is the weakness here. Instant bank transfers and peer-to-peer apps now carry a large share of everyday spending, and on those rails a fraudulent payment can clear before anyone has a chance to question it, since the review window has shrunk to a matter of seconds. Below, you will find the mechanics of APP fraud, the shapes it takes, and the controls that genuinely lower a firm's exposure.
Mandatory Reimbursement Changed APP Fraud in the UK
Regulation has moved most. Since this guide first appeared, the UK's Payment Systems Regulator made victim reimbursement compulsory on 7 October 2024, so firms now have to repay authorised push payment scam claims up to GBP 85,000, and the bill is shared fifty-fifty between the bank that sent the payment and the bank that received it. Payments running over Faster Payments and CHAPS between UK accounts fall inside the rules.
Early numbers tell a consistent story. Fifteen months in, by the end of December 2025, the PSR's reimbursement dashboard showed that roughly 89% of in-scope losses, about GBP 243 million, had gone back to victims; 82% of claims closed inside five business days, and more than 99% of them came in under the cap. For the bank on the receiving end, an account that accepts scam money is now a direct source of financial loss. That exposure has prompted far heavier scrutiny of inbound payments, and the economics of fraud control have shifted for every firm that moves money over UK rails.
Authorised Push Payment Fraud
Several points anchor everything that follows.
- APP fraud is social engineering. The criminal talks the victim into transferring money by hand to an account under the criminal's control.
- Belief is what does the damage. A victim sends the money convinced it is going somewhere legitimate, and the deception (rather than any hacked system or stolen credential) is the mechanism of the loss. Individuals and organisations alike lose heavily for exactly that reason.
- UK Finance recorded GBP 450.7 million lost to APP fraud across 2024, a 2% drop on the year before. Of that total, GBP 365.7 million hit individuals and GBP 84.9 million hit businesses.
- Reported cases fell by roughly 20% to under 186,000, the lowest count since 2021. Sharper detection technology helped, and so did wider consumer awareness.
- Investment scams inflicted the most financial harm. They accounted for GBP 144.4 million of APP losses in 2024 and climbed 34% year on year, even though case numbers were falling.
- Purchase scams remained the type people reported most, responsible for GBP 87.1 million in losses across 2024.
- This is a worldwide problem. ACI Worldwide's Scamscope research projects APP scam losses reaching USD 7.6 billion by 2028 across six of the leading real-time payment markets, which it identifies as the US, the UK, India, Brazil, Australia, and the UAE.
- Fast payment systems are what APP fraud rides on. Subject to the bank and the account, the UK's Faster Payments now clears single, irreversible transactions of up to GBP 1 million.
- Criminals impersonate a bank, a supplier, an employer, or a romantic partner, among others. Phishing, spoofed email, and fake phone calls all feed the deception.
- Blame is genuinely hard to assign. Since the victim authorises every transfer, the warning signs that flag unauthorised access simply are not there.
- Prevention rests on four things working together: customer education, transaction monitoring, payee verification, and analytics built on machine learning.
What are Authorized Push Payments (APP)?
A push payment is a transaction the account holder sets in motion, instructing their bank or payment provider to send money straight from their account to someone else's. People start these payments through online banking, over phone banking, or via peer-to-peer payment platforms.
Setting the push payment beside its mirror image makes the idea clearer. A pull payment runs the other way, with the payee drawing money out of the payer's account under a pre-agreed arrangement, which is how a direct debit operates.
What separates the two is control. In a push payment, the payer holds it. In a pull payment, the payee does, choosing the moment funds leave the other party's account. The side that triggers the movement determines how exposed each method is to fraud, and that asymmetry is why the social engineering tactics described below cluster around push payments specifically.
What is Authorized Push Payment Fraud (APPF)?
When a criminal cons a person or a business into sending a push payment to an account they secretly control, that is authorised push payment fraud. The attacker generally pretends to be an entity the victim trusts, a bank or a supplier being the common choices, and from behind that disguise steers the victim into approving a payment they would otherwise refuse.
One characteristic of the push payment process outweighs the rest. Reversal is hard. Reading the instruction as legitimate, a bank settles it almost at once, and once the money reaches the recipient's account, getting it back is generally hopeless; that goes double when the criminal pulls or relays the funds within minutes of arrival.
Types of Authorized Push Payment Fraud (APPF)
There are several distinct varieties of APP fraud, and each brings its own difficulties for detection and prevention. A single thread ties them together. In every case, whatever the cover story or the channel, the victim is steered into approving a payment that reaches an account the scammer controls and can empty within minutes.
Common types of APP fraud include the following:
1: Purchase Scams
Goods or services that were never going to materialise get paid for in advance, and once the payment clears, the supposed seller drops out of contact entirely, leaving the buyer with nothing and no obvious way to trace the money. The buyer waits in vain. Of all the variants, this one shows up most often.
2: Advance Fee Scams
Victims are told to pay a fee that will release a service, a loan, or a prize. What was promised never materialises.
3: CEO Fraud
Known too as business email compromise (BEC), this one involves a criminal posing as a senior executive who then leans on an employee to make a payment dressed up as ordinary company business.
4: Investment Scams
Criminals draw the victim into an investment that exists only on paper, after which the money flows to the scammer's account and the fund itself turns out to be a complete fiction. Returns never come. Of all the categories, this one was behind the biggest slice of UK APP losses in 2024.
5: Romance Scams
Staging a romantic relationship, a criminal trades on the feelings it generates to pull money out of the victim. The supposed partner vanishes as soon as the funds go through.
6: Invoice Fraud
Posing as a supplier, the scammer sends out fake invoices. A more dangerous version has the criminal intercepting a real invoice and quietly changing the bank details, which routes the payment to a fraudster while the business believes it is paying its genuine supplier.
7: Property Purchase Scams
What makes property scams work is the interception of messages passing between a buyer and their conveyancer, estate agent, or solicitor. Slipping into the conversation as one of those parties, the fraudster reroutes the deposit or the completion funds to an account they control.
How Does Authorized Push Payment (APP) Fraud Work?
Sometimes called bank transfer fraud, an authorised push payment scam turns on a transfer the payer starts. Direct debits and standing orders work differently, because there the payee runs the collection.
In an APP, the payer tells their bank to shift a specific amount from one account to another. Everyday uses cover the ground here, from online shopping to settling bills to sending money to family.
It starts when the payer hands the bank the beneficiary's details, usually an account number and a sort code. Acting on what it has been given, the payer's bank carries out the request and sends the funds to the named recipient.
Convenience is the entire reason the method exists, and people run their own payments with nobody else standing in the way. There lies the weakness. Fraudsters find the openings in the flow and, time and again, fool ordinary people into approving transfers that go straight to criminal accounts they have no reason to suspect.
As the technology moves, so do the criminal methods built around it, which leaves staying alert, sticking to security procedures, and grasping the dangers that come with authorised push payments squarely on the user. The burden is real. Now that the mechanics are clear, the next section turns to the particular methods scammers depend on.
Methods used in Authorized Push Payment Scams
Push payment fraud runs on a handful of recurring tactics.
- Social engineering: Psychological pressure is the lever here, applied through impersonation more often than not, to get an account holder to give up personal details, approve a payment, or surrender login credentials. Of every approach, impersonation produces some of the largest losses.
- Phishing scams: Posing as a trusted organisation over email or text, a fraudster nudges the victim into clicking a link or installing malware, which opens a path into their personal information and accounts. What often comes next is account takeover. Having grabbed control of a person's or a company's account, the criminal then poses as the victim, sometimes messaging that person's friends from a hijacked social media profile to ask for money.
- Confidence scams: These run on earning someone's trust in order to reach their account or talk money out of them. A fabricated relationship is one hook; a bogus business opportunity is another.
- Property purchase scams: Here the criminal listens in on a buyer's exchanges with conveyancers, estate agents, and solicitors. During a house purchase the buyer is dealing with a crowd of unfamiliar contacts anyway, so slipping in as one more party gets considerably easier.
Authorized Push Payment Fraud Examples
Misrepresentation, and frequently outright impersonation, is how fraudsters run these schemes past the victim. The examples below show what that looks like once it reaches real situations.
1: Invoice Scam
Invoice fraud cons the victim into settling a bill that is not real. To make a fraudulent invoice convincing, criminals draw on social engineering, impersonation, and forged paperwork.
For individuals, the targets are usually recurring bills, with energy, broadband, or television services being the typical examples a fraudster picks because the payment looks routine. A company might instead be hit with a single one-off invoice. Another route changes the payee held in a finance system, so that a whole stream of legitimate-looking payments flows to the fraudster month after month before anyone reconciles the account. Volumes add up fast.
2: Romance Scam
Romance fraud has criminals constructing relationships that never existed and cashing in on the closeness to draw out money and other assets.
Authorised push payment is how most romance scams end. A criminal may be after more than cash, yet the money itself nearly always moves by push payment, and almost every case runs on impersonation plus the unhurried social engineering it takes to earn a victim's trust and sympathy over weeks. Patience is the method. When the connection feels solid, the scammer asks for a real-time transfer.
3: Personal Relationship Scam
A close cousin of the romance scam, this version has the fraudster posing as a relative or a friend who then asks for money by push payment.
Bringing it off generally takes personal detail about the victim, picked up through phishing, hacking, or data purchased on illicit markets. Just as in romance fraud, the criminal manufactures urgency, pressing the line that the money is critical and has to be sent right away.
4: Property Funds Scam
Here a victim is tricked into paying fraudsters for the costs of a property purchase. Because the sums attached to real estate are so large, the fallout when one of these works is severe.
Getting inside the deal means learning the details of the sale, which fraudsters obtain by intercepting messages among the buyer, the seller, the agent, and the lender. Forged documents, impersonation, and social engineering then do the persuading, the goal being to get the victim to change the payee for a property payment.
5: Account Takeover Fraud
Account takeover (ATO) fraud is what happens once criminals get direct access to a victim's account and put it to work committing fraud.
In an APP scenario, that control lets them make authorised push payments while the account holder knows nothing about it. Doing so cuts out one of the more awkward stages of APP fraud, the patient grooming needed to get a victim to send the money on their own.
6: Contractor Scam
Think of a home renovation or contracting scam as a more elaborate invoice scam. The victim winds up paying renovation fees to the fraudster in place of the real tradesperson.
Phishing and other reconnaissance is how criminals learn that home improvements are under way. Once they understand a project well enough, they wedge themselves into the transaction, sending the homeowner an invoice while pretending to be the genuine contractor and timing it to look like the real thing. The trap is set. With the homeowner having paid and the fraudster gone, the scam comes to light only when the genuine invoice finally arrives.
Mitigating APP Fraud Risks
Bringing APP fraud risk down calls for technology, education, and disciplined operational controls in combination. Set out below are the strategies that carry most of the weight.
1: Customer Education
Show customers what APP fraud looks like, which warning signs to watch for, and the steps to take before they approve a payment to anyone new.
2: Transaction Monitoring
Monitor transaction patterns to bring unusual activity into view where it may point to fraud, and send the highest-risk payments for review before they settle.
3: Transaction Delays
Put short holds on payments that are high in value or out of pattern. The pause creates room for extra checks, and it gives the customer a chance to think again.
4: Confirmation of Payee (CoP)
Run Confirmation of Payee checks, which match the recipient's name against the account details so the money reaches the person actually intended and not a lookalike account.
5: Account Takeover Fraud Prevention
Account takeover is frequently what comes right before APP fraud. A strong ATO defence spots suspicious account access and shuts it down quickly, ahead of any chance for a criminal to push through a fraudulent transfer.
How to Detect and Prevent APP Fraud with KYC Hub?
KYC Hub puts anti-money laundering and fraud detection together on one platform. A firm moving money across UK rails can combine its payments fraud and AML controls with the measures set out here.
- Advanced fraud detection: Algorithmic models surface the patterns that signal fraud, picking up behaviour that static rules let through.
- Real-time transaction monitoring: Software checks transactions as they happen and pulls out the suspicious, high-risk ones for action.
- Account takeover prevention: Access controls keep customer accounts away from the wrong hands.
- Unified fraud management: A single integrated suite manages detection, prevention, and response as one connected workflow, with no siloed handoffs between them.
- Thorough customer onboarding: Careful checks at sign-up keep fake documents and synthetic identities off the platform.
- Event and activity monitoring: Continuous review of what users do flags behaviour that is drifting toward fraud.
- Periodic identity checks: Re-verifying account holders over time defends against accounts being quietly taken over.
- KYC checks on transactions: Identity and payee validation built into the payment flow confirm who is genuinely being paid.
- Behavioural analytics: Pattern analysis surfaces the anomalies that frequently mark where a scam begins.
Conclusion
Even with losses easing across 2024, authorised push payment fraud is still a serious danger to UK payments. Customer education, sharp fraud detection, real-time transaction monitoring, and a strong account takeover defence each pull the risk down, and they work best in concert.
KYC Hub's AML solutions help a business hold fraud in check and tackle money laundering in the same motion. Compliance and risk teams get what they need to detect, prevent, and respond to fraudulent activity, which protects the firm's own money as well as the trust its customers place in it.



