SardineCon SF/2026

Learn More
Card & payment fraud4 min de leitura

O que é Unauthorized payment fraud?

SUBSCRIBE

Unauthorized payment fraud is a payment made without the account holder's real consent, usually through stolen credentials, account takeover, or intercepted authentication. Unlike a scam, where the victim is tricked into paying, here the customer never approved the transaction at all.

What is unauthorized payment fraud, in plain English?

Unauthorized payment fraud is the classic case most people picture when they hear the word fraud: someone else moved money out of an account and the real owner never agreed to it. There was no consent, informed or otherwise. The attacker got in through stolen card details, phished login credentials, a full account takeover, or by intercepting a one-time code, and pushed the payment through.

The defining line is consent. In unauthorized fraud the customer did not initiate or approve the transaction. This is what separates it from authorized push payment fraud, where the customer is deceived into sending the money themselves. Both leave the victim out of pocket, but the mechanism, and the rights that follow, are different.

That distinction drives everything downstream. Because the customer never authorized it, standard unauthorized-transaction protections usually apply and the customer generally has stronger refund rights, with the loss falling on the bank, issuer, or merchant depending on the rails and rules involved.

Unauthorized versus authorized fraud

The two look similar on a statement but differ on the one thing that matters most:

What changes

Authorized (scam) fraud

Unauthorized fraud

Who moved the money

The customer, tricked into it

The attacker, without consent

Consent given

Yes, but under deception

None at all

Typical entry point

Social engineering, impersonation

Stolen credentials, ATO, intercepted codes

Refund rights

Weaker, varies by scheme

Stronger under unauthorized rules

Detection focus

Victim behavior, payee risk

Device, credential, and pattern anomalies

Who is involved?

Who

Their role

The account holder

The victim who never consented; usually files the dispute and expects a refund.

The attacker

Uses stolen credentials or a hijacked session to push payments out to accounts they control.

The bank or issuer

Investigates consent, applies unauthorized-transaction rules, and often absorbs the loss.

The receiving institution

Holds the destination account; a target for freeze and recovery requests.

What it looks like in practice

In practice

A customer's login credentials are phished. From a new device in a different country, the attacker signs in, adds a fresh payee, and moves the balance in two transfers. The customer is asleep and approves nothing; a one-time code is intercepted through a redirect page on the phishing site.

The next morning the customer sees the transfers and reports them. Because there was no consent, the bank treats this as unauthorized fraud, opens a dispute under unauthorized-transaction rules, and issues a provisional refund while chasing a recall against the receiving account. The investigation focuses on the device change and the impossible travel, not on tricking the customer.

Why it matters to operators

Sorting unauthorized from authorized is one of the highest-stakes calls an investigator makes, because it decides both the investigation path and who pays. Misclassify a scam as unauthorized and you refund a loss the rules may not require; misclassify an unauthorized takeover as a scam and you wrongly deny a customer their protections. Getting it right depends on evidence of consent, not on how the customer feels about the loss.

Operationally, unauthorized fraud is a detection problem you can attack with signals: device changes, impossible travel, reused or breached credentials, and behavior that breaks the customer's normal pattern. These are the levers that catch it before the money leaves, which authorized fraud rarely gives you.

What to watch in the data

  • New device, new session. Login from an unrecognized device or IP shortly before a high-value payment is a core takeover signal.
  • Impossible travel. Access from two locations too far apart for the time between them points to a hijacked session.
  • Payee and limit changes. A new payee added, then paid immediately, or contact details changed just before the transfer.
  • Credential reuse. Logins matching known breached or credential-stuffing patterns suggest the account holder never touched it.
  • Behavioral break. Payment amount, timing, or navigation that does not match how this customer normally uses the account.

Quick questions

How do I tell unauthorized from authorized fraud?

Ask whether the customer took part in initiating the payment. If they were deceived into sending it themselves, it is authorized (scam) fraud. If the attacker moved the money with no consent from the customer, it is unauthorized. The presence or absence of consent is the whole test.

Why does the classification affect who pays?

Unauthorized transactions generally carry stronger consumer protections, so the loss tends to fall on the bank, issuer, or merchant. Authorized fraud has historically left more liability with the customer, though rules in some regions are shifting reimbursement toward the sending and receiving banks.

Is account takeover always unauthorized fraud?

Payments made by an attacker after a takeover are unauthorized, because the real owner did not consent. The takeover itself is the entry method; the resulting transactions are the unauthorized fraud.

What if the customer shared their own password?

It gets murky. If the customer was tricked into handing over credentials or codes, banks weigh whether that shifts it toward a scam. Investigators look closely at how the credentials were obtained and how much the customer knowingly did.

What signals catch it earliest?

Device and session anomalies, impossible travel, new-payee-then-pay sequences, and behavior that breaks pattern. These fire during the takeover, giving a chance to step up authentication or hold the payment before funds leave.

Can unauthorized funds be recovered?

Sometimes, if the receiving account is frozen quickly. Speed matters, because attackers move money onward fast. A rapid recall or freeze request against the destination bank is the best shot at recovery.

Go deeper

O que saber junto com Unauthorized payment fraud