Solidgate logo in black and white.

Authorised push payment (APP) fraud

What is Authorised push payment (APP) fraud?

Authorised push payment (APP) fraud is a scam in which a fraudster tricks an account holder into knowingly sending money, over a such as a bank transfer, to an account the fraudster controls. Because the account holder authorises the transfer themselves, the payment looks legitimate to the sending bank right up until the deception comes to light.
APP fraud sits within the broader category of , but it works differently from unauthorised card fraud, where a stolen card or stolen credentials are used without the account holder's knowledge. APP fraud targets real-time transfer rails - Faster Payments in the UK, Pix in Brazil, and similar instant payment networks - because same-day settlement leaves little time to intercept the funds before the fraudster withdraws them.

Key facts

  • Payment method: real-time bank transfers and other irrevocable push payments, not card transactions
  • Consent: the account holder initiates and authorises the transfer, so no unauthorised-transaction claim applies the way it would for a stolen card
  • Common vectors: impersonation scams (bank, police, tax authority), romance scams, investment scams, invoice and mandate fraud, purchase scams
  • UK reimbursement rule: the Payment Systems Regulator's mandatory reimbursement requirement covers eligible Faster Payments transactions made on or after 7 October 2024, with the loss split 50/50 between the sending and receiving payment service provider

How it works

  1. Contact and pretext: the scammer reaches the victim by phone, text, email, or social media, posing as a bank, government agency, romantic interest, or trusted supplier.
  2. Building urgency or trust: the scammer gives a reason to act fast, such as a compromised account, a fake invoice, or a time-limited investment, so the victim doesn't verify independently.
  3. Victim-initiated transfer: the victim logs into their own banking app and pushes the payment to an account the scammer controls, believing it's going to a legitimate destination.
  4. Fund extraction: the scammer moves or withdraws the money quickly, often routing it through several accounts, before the bank or the victim can flag it.
  5. Detection and reporting: the victim or their bank identifies the payment as fraudulent, usually after the money has already left the fraudster's first receiving account.

Why it matters

Because the transfer is authorised by the genuine account holder, standard unauthorised-transaction protections don't cover APP fraud automatically - there's no card network chargeback right to fall back on, since the payment never touched a card scheme. That gap is what drove the UK's mandatory reimbursement regime: it shifts the loss back onto the sending and receiving payment service providers rather than leaving the victim to absorb it. For providers operating real-time transfer rails, APP fraud losses now attach directly to the bank account relationship instead of running through a card-scheme dispute process.
Unlike , where a cardholder disputes a legitimate card charge after the fact, an APP fraud victim sent the money themselves under deception, and there's no equivalent right to reverse it once it clears.

Common issues

  • Reversal is difficult because push payments settle almost instantly, and the scammer withdraws the funds before the sending bank can intervene.
  • Receiving banks don't always catch mule accounts fast enough, since account-opening checks aren't built to flag an account opened specifically to receive fraud proceeds.
  • models tuned to catch stolen-card patterns often miss APP scams, since the transaction carries no compromised card data or device mismatch signal to flag.
  • Telling APP fraud apart from a customer who knowingly took part in a scheme complicates reimbursement decisions, since some rules carve out cases of gross negligence by the account holder.

Related terms