A scam is a deception that manipulates a victim into willingly handing over money or information, and that consent is exactly what sets it apart from unauthorized fraud, where the victim never agrees. When the victim authorizes the action themselves, traditional unauthorized-transaction controls simply do not fire.
What is a scam, in plain English?
A scam is fraud that works by persuasion rather than intrusion. Instead of stealing credentials or forcing an unauthorized transaction, the scammer convinces the victim to act against their own interest: to send a payment, share a code, or hand over personal data. The victim is deceived, but they take the action themselves, believing it is legitimate or necessary.
That element of consent is the defining feature. In unauthorized fraud, the victim never agreed to the transaction; a criminal used a stolen card or hijacked account without them. In a scam, the victim authorizes it. The money leaves with a valid login, a real device, and the customer's own approval, which is precisely why it is so hard to catch with tools built to spot activity the customer never sanctioned.
In the fraud stack, scam is the umbrella category over a wide range of social-engineering losses: romance, investment, impersonation, purchase, refund, and many more. Whether a case is labeled scam or unauthorized shapes both the investigation and, often, who bears the loss, so the distinction is not academic.
Scam versus unauthorized fraud
What changes | Unauthorized fraud | Scam |
Who acts | A criminal, without the victim | The victim, deceived into acting |
Consent | None; the victim never agreed | Present; the victim authorized it |
What catches it | Device, credential, and anomaly controls | Behavioral, contextual, and payee-risk signals |
Best defense | Stronger authentication | Intervention and warnings at the point of payment |
The main families of scams
Family | How it deceives |
Romance and relationship | A fake relationship manipulates the victim into sending money or investing. |
Investment | A fake opportunity or platform promises high returns that never materialize. |
Impersonation | Posing as a bank, agency, or company to demand payment or account access. |
Purchase | Payment taken for goods or services that are never delivered. |
Advance-fee | An upfront fee to unlock a prize, loan, refund, or recovery that never comes. |
What it looks like in practice
In practice
A customer with a steady payment history suddenly makes a large transfer to a new payee after a phone call. Nothing about the login, device, or location is unusual, so automated fraud checks let it through: it is authenticated, from the right device, in the right place.
What the systems cannot see is that the customer was talked into it by someone posing as their bank. The transaction is genuine from a technical standpoint and fraudulent from a human one. Only behavioral cues, a first-time large transfer to an unknown account right after a call, and a direct question hinted that this authorized payment was a scam.
Why it matters for operators
Scams break the core assumption behind unauthorized-fraud controls, that a valid login and a trusted device mean a legitimate transaction. When the victim authorizes the payment, those controls stay silent, so detection has to shift to behavioral, contextual, and payee-risk signals: out-of-pattern amounts, first-time payees, transfers made during phone calls, and destinations linked to known scam or mule activity. Direct intervention with the customer at the point of payment is often the last and best line of defense.
Labeling also carries real consequences. Whether a case is recorded as a scam or as unauthorized fraud drives how it is investigated, how it is reported, and frequently who absorbs the loss under the relevant rules. Getting that classification right, and building controls suited to authorized scams rather than only to unauthorized fraud, is central to managing this fast-growing category.
What to watch for
- Authorized but out of character. A legitimate login and device paired with a payment that breaks the customer's normal behavior is the hallmark of a scam.
- Payments during calls. Transfers made while the customer is on the phone, especially to a new payee, are a strong contextual signal.
- Risky payees. Destinations tied to known scams, mule accounts, or high-risk crypto flows raise the odds a payment is a scam.
- Urgency and secrecy. Customers who are rushed, anxious, or unwilling to explain a payment may be under active manipulation.
- Correct classification. Recording scam versus unauthorized accurately shapes the investigation, reporting, and liability outcome.
Quick questions
What is the difference between a scam and fraud?
Fraud is a broad term for financial deception. In common industry use, a scam specifically involves the victim being manipulated into authorizing the action, while unauthorized fraud happens without the victim's consent. The presence of consent is the dividing line.
Why do standard controls miss scams?
Because the victim authorizes the transaction from their own device with a valid login, it looks legitimate to controls built to detect activity the customer never sanctioned. Catching scams requires behavioral, contextual, and payee-risk signals instead.
What is an authorized push payment scam?
It is a scam where the victim is tricked into pushing a payment themselves to an account the fraudster controls. Romance, investment, purchase, and safe account scams are common examples, and they fall under the broader scam umbrella.
Why does the scam-versus-unauthorized label matter?
The classification drives the investigation, the regulatory reporting, and often who bears the loss. Miscategorizing a case can send it down the wrong process and affect reimbursement outcomes for the customer and the institution.
How can institutions reduce scam losses?
By adding behavioral and payee-risk detection, applying friction and warnings at the point of payment, confirming payees, and training staff to ask direct, non-judgmental questions when a payment looks manipulated.
Are scams growing?
Authorized scams have grown sharply as authentication has improved, because tricking the victim into authorizing a payment sidesteps stronger login defenses. That shift has made scam detection a central priority for fraud teams.
Go deeper
- FTC Consumer Advice: Scams ↗ — US consumer guidance on current scams and fraud, and how to report them.
- FBI IC3 ↗ — The FBI Internet Crime Complaint Center. Fraud reporting and annual trend reports.

