Authorized push payment fraud is when a scammer tricks a victim into sending money themselves to an account the fraudster controls. Because the real customer approves the transfer, the payment looks legitimate and is very hard to claw back once it lands, which is what makes it so damaging.
What is APP fraud, in plain English?
Authorized push payment fraud turns the victim into the person who moves the money. Instead of stealing credentials and pushing a payment themselves, the fraudster manipulates the customer into sending the transfer, using a real-time or bank transfer that the customer approves with their own credentials. The result is a payment that is technically genuine: the right person, on the right device, authorized it.
The deception can take many shapes. A fake invoice or supplier redirection convinces a business to pay a criminal's account. A safe-account scam has someone posing as the bank or police telling a victim to move funds to a protected account for safety. Romance and investment scams build trust over weeks, then request transfer after transfer. In every case the customer believes the payment is legitimate and necessary.
What sets APP fraud apart from most card and account fraud is consent. The transaction is authorized, so it does not trip the controls built to catch unauthorized access. And because many of these payments run on fast or instant rails, the money is often gone within minutes, forwarded through mule accounts before anyone realizes it was a scam.
How an APP scam unfolds
- Contact — Build a believable story. The fraudster poses as a bank, supplier, official, romantic partner, or investment advisor.
- Pressure — Create urgency or trust. A threat, a deadline, or a relationship pushes the victim to act without independent checks.
- Transfer — Victim sends the money. The customer authorizes the payment themselves, so it looks entirely legitimate to the bank.
- Vanish — Funds are layered away. The money lands in a mule account and is forwarded or cashed out fast, often within minutes.
Who is involved?
Who | Their role |
The fraudster | Runs the social-engineering script and controls the destination account. |
The victim | Sends the payment themselves, believing it is genuine and often urgent. |
The sending bank | Processes an authorized transfer, so its usual unauthorized-access controls do not fire. |
The receiving bank | Holds the mule account. Its onboarding and monitoring often decide whether funds can be frozen. |
The mule | Owns the receiving account and forwards or withdraws the funds to break the trail. |
What it looks like in practice
In practice
A customer gets a call from someone claiming to be the bank's fraud team. They say her account has been compromised and, to keep her savings safe, she needs to move everything to a new secure account they will set up for her right now. The caller knows her name and the last four digits of her card, which makes it feel real.
Under pressure and afraid of losing her money, she logs in and transfers her balance to the account they read out. It is a mule account. Minutes later the funds are split and forwarded to two more accounts. Because she authorized every step herself, nothing looked unauthorized to her bank until she called back, panicked, an hour later, and by then the money had moved twice.
Why standard controls miss it
Most fraud controls are tuned to catch unauthorized activity: a stranger logging in, a new device, a credential that does not match. APP fraud sidesteps all of that because the genuine customer, on their own trusted device, authorizes the payment. The transaction looks perfect from the account-security angle. That is why detection has to shift toward behavior and destination risk rather than access anomalies.
The useful signals live on both sides of the payment. On the sending side: a first-time or unusually large transfer, a new payee, hesitation, or a payment reason that does not fit the customer's pattern. On the receiving side: newly opened accounts, rapid pass-through of funds, and links to known mule networks. Regulators in some markets now require sending and receiving banks to reimburse victims of APP fraud, which sharpens the incentive to detect it before the money leaves.
What to watch in the data
- New payee, high value. A first-time beneficiary receiving a large or unusual transfer, especially the customer's full balance.
- Mule-like destinations. Recently opened receiving accounts that immediately forward or withdraw incoming funds.
- Out-of-pattern reason. A payment purpose that does not match the customer's history, such as investment, safe account, or a stranger.
- Session pressure signals. Long help-line calls during the payment, hesitation, or on-screen coaching indicating the customer is being directed.
- Warning overridden. The customer pushing past a scam warning or confirming they know the payee when behavior suggests otherwise.
Quick questions
How is APP fraud different from unauthorized fraud?
In unauthorized fraud, someone accesses the account without the customer's consent. In APP fraud, the genuine customer authorizes the payment themselves after being deceived. That consent is why it evades access-based controls and is harder to reverse.
What are the most common APP scam types?
Fake invoice and supplier redirection, safe-account or bank-impersonation scams, romance scams, investment scams, and purchase scams for goods that never arrive. They differ in the story but share the same mechanic: the victim sends the money.
Can the money be recovered?
Rarely once it moves. Fast rails let mules forward or cash out within minutes. Recovery depends on catching it quickly and the receiving bank freezing funds, which is why prevention and real-time destination checks matter so much.
Do victims get refunded?
It depends on the market. Some jurisdictions now require sending and receiving banks to reimburse APP fraud victims under set rules, shifting more of the loss and the detection burden onto the institutions.
What helps detect it?
Behavioral monitoring on the sending side, payee and destination risk scoring, in-session scam warnings, and receiving-side controls on new accounts and rapid pass-through. Confirmation-of-payee style name checks also reduce misdirected transfers.
Go deeper
- EMVCo ↗ — Maintains the EMV chip and 3-D Secure specifications for card payments.
- PCI Security Standards Council ↗ — Security standards for handling cardholder data, including PCI DSS.

