Authorized Push Payment Fraud Prevention: What Actually Works

APP fraud prevention across UK, EU and US rules: what Confirmation of Payee fixes, what it cannot, and why receiving-side mule detection only got built when liability shifted.
Alexandre Berkovic

TL;DR: Authorized push payment fraud prevention is structurally different from unauthorized fraud prevention, because the customer initiates the payment with the right credentials on the right device. UK Finance reported £576.4 million in APP fraud losses across 248,070 cases in 2025, up 19 percent, while unauthorized fraud losses fell. The controls that have measurably worked are name verification on the sending side and mule detection on the receiving side — and one of them only got built because the UK made receiving institutions share the liability.

Why the Transaction Looks Perfect

Authorized push payment fraud is any scam in which the victim is manipulated into initiating a payment themselves. There is no compromised credential, no anomalous device, no session takeover, and no chargeback. Every dimension a fraud model measures comes back clean, because on those dimensions the payment genuinely is clean.

The UK data shows the consequence clearly. Unauthorized fraud losses fell 5 percent in 2025 while APP losses rose 19 percent. Banks got better at the problem their models were built for, and criminals moved to the one they were not.

UK Finance splits APP fraud into two structural families, and the distinction determines which controls can work at all. Malicious redirection covers cases where the victim intends to pay a legitimate payee but is diverted to a fraudster — invoice and mandate fraud, CEO fraud, and impersonation of police or bank staff. Malicious payee covers cases where the victim pays exactly the party they intended to pay, for what they believe is a legitimate purpose — purchase scams, investment scams, romance scams, and advance fee fraud.

Name matching defeats the first family entirely and does nothing for the second. That is not a theoretical point. Malicious redirection now accounts for just under a quarter of UK APP losses, down from more than half in 2020, and 11 percent of case volume, down from 30 percent. Confirmation of Payee is the direct cause. Meanwhile malicious payee scams grew, and investment fraud alone reached £221.5 million in 2025, up 40 percent.

What the UK Reimbursement Rules Actually Did

On 7 October 2024 the UK Payment Systems Regulator made reimbursement mandatory for in-scope APP scams over Faster Payments, with a parallel Bank of England rule for CHAPS. The parameters matter: reimbursement up to £85,000 per claim, payment within five business days with a 35-business-day maximum for information gathering, a 13-month reporting window, an optional excess of up to £100, and a Consumer Standard of Caution exception that places the burden of proving gross negligence on the firm and cannot be applied to vulnerable consumers.

The provision that changed institutional behavior most was none of those. It was the 50:50 liability split between the sending and receiving payment service provider — the first regime anywhere to put the receiving institution on the hook for scam losses.

An independent evaluation published by the PSR in July 2026 found that in-scope APP scam losses over Faster Payments fell roughly 21 percent, equivalent to about £73 million a year, with scam volumes down by nearly 35,000. Reimbursement rates rose from 54 percent to 65 percent overall, and to 97 percent for in-scope claims.

Two things complicate that headline. Fraud moved to the rails the rules do not cover: international APP scams grew £39 million between 2023 and 2025, and payments to crypto exchanges rose. Once displacement is counted, the evaluation's net benefit estimate narrows from £17–29 million to somewhere between negative £4 million and positive £8 million. And outcomes still depend heavily on which bank a victim uses — post-policy reimbursement rates ranged from 21 percent to 94 percent across individual firms, which is the stated reason the PSR opened a consultation on consistency at the end of 2026.

Three Jurisdictions, Three Different Answers

An institution operating across borders cannot run one policy here.

Jurisdiction Name verification Reimbursement Receiving-side liability
United Kingdom Confirmation of Payee, mandated, over 99% coverage Mandatory up to £85,000 since October 2024 Yes — 50:50 split with the sending firm
European Union Verification of Payee, mandatory for euro-area PSPs since 9 October 2025 No mandate No
United States No mandate No federal mandate; Regulation E covers unauthorized transfers only No

The U.S. position turns on one sentence in Regulation E. An unauthorized electronic fund transfer is one "initiated by a person other than the consumer without actual authority to initiate the transfer and from which the consumer receives no benefit." Credential compromise and phishing-induced credential sharing are covered. A payment the consumer initiates themselves, however thoroughly manipulated, is not.

The Consumer Financial Protection Bureau's action against Early Warning Services and three large banks was dismissed with prejudice in March 2025, which means it cannot be refiled. The live vehicle is now the New York Attorney General's August 2025 suit alleging that Zelle's design enabled more than $1 billion in losses between 2017 and 2023, which survived a motion to dismiss in July 2026 and is in discovery. That is a state consumer-protection theory, not a Regulation E theory. U.S. exposure today is reputational, state-level, and network-rule driven rather than statutory — which does not make it small.

Scale-wise, the FBI's Internet Crime Complaint Center logged $20.877 billion in losses across 1,008,597 complaints in 2025, a 26 percent increase. The FTC separately reported $3.5 billion lost to imposter scams in 2025, with nearly one in three fraud reports falling into that category, and noted that the costliest impersonation scams begin with a fake security alert purporting to come from the victim's bank.

Sending-Side Signals That Are Worth the Friction

The most useful finding in the PSR's evaluation is what UK firms stopped doing. They moved away from simple value-based thresholds toward analytics-led interventions segmented by scam type, transaction value, and customer risk. The value threshold is dead as a primary control, because purchase scams — 71 percent of UK cases — sit far below any threshold worth setting.

What replaced it is a combination of payment-level and session-level signals:

That last one deserves emphasis. Fraudsters coach victims to defeat interventions — they script the payment reason, warn that the bank will try to stop the transfer, and stay on the line while it happens. Warning dismissal should be treated as a model feature, not as an end state where the institution's duty is discharged. The UK evaluation found that specialist teams frequently had to engage customers directly to interrupt the scam and, in their phrasing, break the spell.

The Receiving Side Only Got Built When Someone Paid For It

The clearest lesson from the UK regime is about incentives rather than technology. The PSR's evaluation found that the most commonly reported firm actions following the rules were new in-house data monitoring and profiling systems and new third-party transactional and user profiling — and that these were aimed primarily at identifying mule activity and preventing accounts from receiving fraudulent funds. Firms also tightened controls earlier in the customer lifecycle.

None of that was new capability. It was capability nobody had a commercial reason to build until receiving institutions started paying half the claim.

The signals themselves are structural and comparatively tractable: account age against inbound value, fan-in patterns where round-dollar credits arrive from many unconnected individuals with no corresponding business activity, rapid pass-through with near-zero end-of-day balance, onward transfer to crypto or cross-border, account names plausibly mimicking a business or agency, and shared devices, IP addresses, or contact details across nominally unrelated accounts. Second-generation mules — accounts receiving from another mule rather than from the victim — are a distinct layer that most programs do not model at all. This work overlaps almost entirely with mule account detection and investigation.

Why Post-Hoc Detection Does Not Save the Money

Traditional AML transaction monitoring looks for laundering patterns in aggregate over days or weeks and produces a SAR after the fact. APP fraud needs a decision in the seconds before an irrevocable payment settles. A SAR filed on Tuesday does not recover Monday's money.

The recovery data quantifies how little room there is. Sending firms in the UK recovered only 16 percent of reimbursable claim value, and recovered some or all funds in just 28 percent of claims. On rails that settle in seconds, detection after settlement is close to worthless — which is why APP fraud is one of the strongest practical arguments for bringing fraud and AML operations together rather than running them as separate queues with separate data.

Two further structural problems are worth naming honestly. Reporting lag corrupts the feedback loop: romance and investment victims often do not realize for months, so models trained on date-of-report data learn from a distorted picture. And 66 percent of UK APP cases originate online with a further 17 percent via telecoms, meaning the manipulation happens on platforms the bank cannot see, over weeks, while the bank observes only the final ten seconds.

Where Sphinx Fits

The parts of APP fraud work that scale badly are not the real-time scoring decisions. They are the investigations behind them — reviewing the flagged inbound account, tracing the onward hops, checking the entity formation date and registered address, assembling the evidence the frontline needs before it calls a customer who is going to argue.

Sphinx's agents run inside the same systems analysts use and produce a documented case file rather than a score, which matters when a reimbursement decision has to be defended and when the alternative is an analyst spending an hour per account on work that is mostly retrieval. The intervention conversation, the vulnerability assessment, and the decision to override a customer's explicit instruction stay with people. Those are the points where judgment is the product.

Frequently Asked Questions

What is authorized push payment fraud?

APP fraud is any scam in which the victim is manipulated into initiating a payment themselves, using their own credentials and device. Because the payment is genuinely authorized, it falls outside the controls built for unauthorized fraud and, in the United States, outside Regulation E's definition of an unauthorized electronic fund transfer.

Are U.S. banks required to reimburse scam victims?

No. Regulation E covers only transfers initiated by someone other than the consumer, which excludes payments the consumer makes themselves under manipulation. The CFPB's suit against Early Warning Services and three large banks was dismissed with prejudice in March 2025. Liability is currently contested through state consumer-protection law — most prominently the New York Attorney General's case against Early Warning Services — and through private network rules.

Does Confirmation of Payee stop APP fraud?

It stops one of the two families. Confirmation of Payee is highly effective against malicious redirection, where the victim intends to pay a legitimate party and is diverted — UK losses in that category fell from over half of APP losses in 2020 to under a quarter. It has no effect on malicious payee scams like purchase, investment, and romance fraud, because the payee is genuinely who the victim believes it is. Those categories now make up the majority of losses.

Did mandatory reimbursement reduce fraud overall?

Partly, and the honest answer requires two numbers. The PSR's independent evaluation found in-scope Faster Payments scam losses fell about 21 percent, roughly £73 million a year. UK Finance separately reported total APP losses rising 19 percent to £576.4 million. Both are correct — they measure different populations on different dates, and the gap is largely fraud displaced to international payments and crypto rails that the rules do not cover.

What changed receiving-bank behavior in the UK?

The 50:50 liability split between sending and receiving payment service providers. Before it, no institution had a commercial reason to invest in detecting inbound mule activity. After it, the PSR's evaluation found that the most commonly reported new controls were monitoring and profiling systems aimed specifically at identifying mule accounts and stopping them from receiving fraudulent funds.

Get Your Free AI Compliance Handbook

What compliance leaders need to know about AI-driven fraud, autonomous laundering, and how your team can
fight back.
Submit
Thank you! Your submission has been received!
Something went wrong while submitting the form. Please try again.