← All terms

Authorized Push Payment (APP) Fraud

APP fraud manipulates a victim into sending a payment themselves — the transfer is authorized, so standard fraud controls and recalls often fail.

Authorized push payment (APP) fraud is a scam in which the victim is manipulated into initiating a payment to an account the attacker controls. The word authorized is what makes it dangerous: no account was hacked and no card was cloned — the legitimate account holder pressed send. That authorization strips away many of the technical defenses and recall mechanisms built for unauthorized fraud, which is why APP losses keep climbing even as banks get better at blocking account takeovers. In the UK, which measures it most rigorously, APP fraud reached £576.4 million in 2025, up 19% year on year, with two-thirds of cases originating online.

How it works

Every APP scam pairs a pretext with urgency. Consumer variants include purchase scams (goods that never arrive), impersonation of a bank's own fraud team ("your account is compromised — move your money to this safe account"), investment and romance-baiting schemes, and invoice redirection on house purchases. The enterprise twin is business email compromise: a finance employee is persuaded that a supplier's bank details have changed or that an executive urgently needs a wire sent, and the employee — fully authorized — executes the transfer. Funds land in a money mule account and are dispersed within hours, often before anyone questions the instruction.

How to defend against it

Because the payment itself is legitimate, defense has to happen before the send button. Enforce out-of-band verification for any new payee, any bank-detail change, and any urgent or unusual payment request — a callback to a number already on file, never one supplied in the message. Regulation is moving the same way: since October 2024, UK payment firms have been required to reimburse most APP fraud victims, converting employee and customer gullibility into a direct balance-sheet cost. For organizations, the durable control is behavioral: train and test payment-handling roles against the exact pretexts attackers use, and measure whether verification actually happens under pressure. Our guide to human risk in financial services covers how to build that program.

Related terms

Business Email Compromise (BEC)Business email compromise is a targeted attack where criminals impersonate executives or trusted partners via email to trick employees into transferring money or sensitive data.Invoice FraudInvoice fraud tricks a company into paying a fake or altered invoice, typically by impersonating a real supplier and changing the bank account details.Money MuleA money mule moves stolen funds through their own accounts for criminals — knowingly or not. How mule recruitment works and how to keep employees out of it.Pig Butchering ScamPig butchering is a long-con investment scam where fraudsters build trust over weeks, then lure victims into fake crypto platforms and drain their funds.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo