Dictionary

Authorized Push Payment (APP) Fraud

What Is Authorized Push Payment Fraud?

Authorized Push Payment (APP) fraud, commonly referred to as APP fraud, is a type of financial scam where victims are manipulated into authorizing payments to fraudsters. This form of fraud typically involves social engineering techniques, where scammers impersonate trusted entities or individuals to deceive the victim into making a payment under false pretenses.

As digital scams grow more sophisticated, APP fraud has surged, leading to significant financial losses for both businesses and consumers. In 2023, the UK saw a 12% year-on-year increase in APP fraud cases, with losses projected to reach $934.7 million by 2027.

How Advanced Technology is Driving APP Fraud Prevention

Discover how a dynamic and holistic approach to fraud prevention powered by advanced technologies like AI and digital footprint analysis affords the speed and scale needed to counteract fraudsters’ tactics and can help you prevent APP fraud.

Learn More

How Does Authorized Push Payment Fraud Work?

This form of fraud exploits the instantaneous and irreversible nature of real-time payment systems, making it particularly challenging to detect and prevent. Criminals manipulate victims into willingly transferring money to the fraudster’s account, often through social engineering techniques. They thoroughly research their targets, establish trust and convince them to send money voluntarily. Common tactics include phishing, email spoofing and fraudulent phone calls pretending to be from legitimate entities such as banks or businesses, often creating a sense of urgency to convince victims to move funds as soon as possible. 

Essentially, APP fraud relies on tricking the victim into believing they are acting in their best interest. Ironically, the fraudster may claim to be protecting the victim from a fraud attempt, adding a layer of credibility. The fraudster provides new account details, supposedly for security, but in reality, these belong to the criminal. Once the victim transfers the money and the funds are in a “bank drop” account, the fraudster quickly moves it using techniques like smurfing, where funds are broken into smaller amounts to avoid detection by transaction monitoring systems.

Authorized Push Payment Fraud Examples

APP fraud always involves tricking the victim into transferring money to the fraudster’s account. Here are a few ways it commonly unfolds:

Home Renovation Scam

Fraudsters identify a homeowner undergoing renovations and the contractor managing the work. They send a fake invoice, appearing to be from the building firm but with the fraudster’s bank details. By the time the homeowner realizes the scam, the fraudsters—and the money—are long gone.

New Bank Details Scam

Targeting a business, fraudsters pose as a regular supplier and send an email or letter claiming their bank details have changed. The company updates their records, rerouting payments to the fraudster’s account, often without realizing it for some time.

Property Purchase Fraud

Fraudsters intercept emails between a homebuyer and their solicitor, estate agent, or bank. At a crucial point in the transaction, they switch the bank details on a key document. When the buyer makes a payment, such as for a deposit, it goes to the fraudsters instead of the intended recipient.

How to Prevent and Combat Authorized Push Payment Fraud

Preventing authorized push payment (APP) fraud relies heavily on communication, education and enhanced financial safeguards.

For businesses, clear communication with customers is key. Many now include warnings in emails or during customer interactions, advising against transferring money to new accounts based on unverified messages. This proactive approach reduces the risk of fraudsters exploiting unsuspecting customers.

Financial institutions also play a crucial role. Some banks implement cooling-off periods before payments are processed, while others apply stricter due diligence, such as monitoring accounts that frequently receive high-value payments. Additionally, tools like the UK’s Confirmation of Payee (CoP) service help verify that bank account details match the name of the recipient.

Education is equally important. Banks and fintech companies must continually raise awareness about APP fraud, educating both consumers and employees on recognizing social engineering schemes. Combined with robust fraud prevention software using machine learning and transaction monitoring, these measures significantly reduce the risk of this widespread fraud.

Through a multi-layered approach of communication, education, and technology, both businesses and financial institutions can help mitigate the impact of APP fraud.

Sources: