Authorized Push Payment (APP) Fraud
Authorized Push Payment (APP) fraud happens when a criminal tricks a victim into sending money themselves, often by posing as a genuine person or organization the victim believes they should pay. Because the victim personally authorizes and initiates the transfer, this type of fraud relies on manipulation and social engineering rather than on stealing account credentials or card data. It is commonly associated with real-time or fast payment systems where funds move quickly.
APP fraud is a form of authorized fraud in which a legitimate account holder is deceived or manipulated—typically through social engineering—into initiating a push payment to an account controlled by a fraudster, often while believing they are paying a genuine payee. Unlike account takeover or unauthorized transactions, the payment is initiated and authorized by the genuine payer, which complicates detection and attribution because the transaction may appear valid on standard authentication and authorization checks. APP fraud is particularly prominent in fast or real-time payment systems, where the speed and finality of settlement can reduce opportunities to recall or reverse funds. It is distinct from card-not-present fraud and credential theft; the fraud vector is coercion of the payer rather than compromise of authentication factors. Note that liability, reimbursement, and consumer-protection obligations for APP fraud are governed by regional regulatory regimes and scheme rules, which vary by jurisdiction and change over time; readers should confirm applicable rules against current published requirements.
Why it matters
APP fraud is significant because it exploits the genuine account holder rather than any weakness in authentication or credential security. When a victim is manipulated into initiating and authorizing a payment themselves, the transaction typically passes standard authentication and authorization checks because, from the payment system's perspective, the legitimate payer has approved it. This makes APP fraud harder to detect and attribute than account takeover or credential theft, where an unauthorized party is acting on the account.
The risk is heightened in fast or real-time payment systems, where the speed and finality of settlement can reduce the opportunities to recall, hold, or reverse funds once a payment is sent. Because the fraud vector is social engineering—coercion or deception of the payer—rather than a technical compromise, controls that focus solely on authentication factors may offer limited protection against it.
Liability, reimbursement, and consumer-protection obligations for APP fraud are governed by regional regulatory regimes and scheme rules, which vary by jurisdiction and change over time. Institutions should confirm the applicable rules against current published requirements rather than assuming a uniform standard applies across markets.
Who it's relevant to
Inside APP Fraud
Common questions
Answers to the questions practitioners most commonly ask about APP Fraud.