What is authorized push payment (APP) fraud? | Transmit Security

Glossary

What is authorized push payment (APP) fraud?

Authorized push payment (APP) fraud tricks victims into willingly sending money to a fraudster.
by Transmit Security

Authorized push payment (APP) fraud is a scam in which a fraudster manipulates a victim into willingly authorizing a payment to an account the fraudster controls. Because the genuine customer initiates and approves the transfer themselves, it sidesteps traditional fraud controls that look for unauthorized access, the payment is technically legitimate; the authorization was obtained by deception.

APP fraud has exploded alongside real-time payments. When money moves instantly and irreversibly, a victim tricked into sending it has little chance of clawing it back, and the fraudster cashes out before anyone notices. In several markets it now rivals card fraud for losses, and it keeps climbing.

How APP fraud works

The fraud is social engineering at its core. Common variants include:

  • Impersonation scams: the fraudster poses as the bank, a government agency, or a trusted company, creating urgency to move money "to safety."
  • Purchase scams: the victim pays for goods or services that never arrive.
  • Investment scams: fake opportunities that lure victims into transferring funds.
  • Romance scams: exploiting a relationship to extract payments.
  • Invoice/CEO fraud: tricking a business into paying a fraudulent invoice or a spoofed executive’s request.

In each case, the victim is manipulated into authorizing the payment, which is what makes APP fraud so insidious.

Why it’s so hard to stop

Traditional fraud detection asks "is this the real account owner?", and in APP fraud, it is. The controls that catch account takeover don’t trigger, because there’s no unauthorized access. Detection has to shift to subtler questions: is this payment consistent with the customer’s normal behavior? Are there signs the customer is under manipulation, hesitation, unusual urgency, a first-time payee, a session that looks coached or remotely controlled? These behavioral and contextual signals, rather than authentication, are the front line against APP fraud.

The regulatory and industry response

APP fraud has drawn regulatory action because victims can suffer devastating losses. New rules and industry frameworks increasingly push liability toward banks and mandate reimbursement in some markets, and payment-network rules (such as updated NACHA rules in the US and reimbursement regimes elsewhere) are reshaping who bears the cost. Industry accords (like scam-prevention frameworks that coordinate banks against these attacks) are emerging in response. This shift makes stopping APP fraud not just a loss-prevention issue but a compliance and cost imperative.

How to fight APP fraud

Because the payment is authorized, defense centers on detecting the manipulation and the anomaly around it: behavioral analytics to spot coached or out-of-pattern activity, device and session signals to detect remote-access tools controlling the victim’s device, payee and transaction-risk analysis to flag first-time or suspicious destinations, and real-time intervention (warnings or step-up friction) at the moment money is about to move. Transaction monitoring "at the moment money moves," combined with the full identity picture, is what gives banks a chance to interrupt an APP scam before the transfer completes.

Why real-time payments changed everything

APP fraud existed before instant payments, but real-time rails supercharged it. When a transfer clears in seconds and can’t be reversed, the victim’s window to realize they’ve been scammed and stop the payment collapses to nothing, and the fraudster moves the money onward through mule accounts before anyone reacts. The convenience customers love (instant, irreversible payments) is exactly the property scammers exploit. This is why interventions have to happen before the payment completes, not after: once the money lands in the fraudster’s account and is swept away, recovery is close to hopeless.

Why detection has to be behavioral

The uncomfortable truth of APP fraud is that every traditional control says the transaction is fine, the right person, on their own device, entering their real credentials, authorizing a payment they intend to make. The only tells are behavioral and contextual: a payment to a brand-new payee, an amount out of pattern, a session showing signs of remote control or coaching, hesitation or unusual navigation suggesting the customer is being talked through it live. Detecting these requires behavioral analytics and device intelligence layered on top of the payment itself. It’s a fundamentally harder problem than stopping account takeover, which is why APP fraud has outpaced defenses built for an earlier era.

Frequently asked questions

Why has APP fraud grown so fast?

Real-time, irreversible payments give victims no window to reverse a scammed transfer, and fraudsters cash out before detection.

Can technology stop APP fraud if the customer authorizes it?

Yes, in part, behavioral and device signals can detect manipulation and trigger real-time warnings or friction before the payment completes.

What is APP fraud?

Authorized push payment fraud, tricking a victim into willingly authorizing a payment to a fraudster’s account.

Why is APP fraud hard to detect?

The genuine customer authorizes the payment, so controls that look for unauthorized access don’t trigger.

How can APP fraud be stopped?

Through behavioral analytics, remote-access detection, payee/transaction-risk analysis, and real-time intervention as money moves.

Who is liable for APP fraud?

Increasingly, regulation and payment-network rules are shifting liability and reimbursement toward banks in several markets.

Related: Scams / Social Engineering Scams · Transaction Monitoring · Money Mule · Behavioral Analytics · NACHA Rules · Scam-Safe Accord

Request a Demo

By clicking the button, you agree to the Terms and Conditions