APP fraud: the scam where the victim makes the payment

Authorized push payment fraud, short APP fraud, is the scam in which the victim authorizes the transfer themselves. Nobody steals a card number and nobody breaks into an account. The criminal persuades the account holder to send the money, which means every control built to stop unauthorized access sees a legitimate customer making a legitimate payment.

That is what makes it the hardest fraud in payments to police and the one the rules have been rewritten for. This page goes below fraud prevention in Germany, which names the pattern, and beside financial crime in payments. Here the subject is the reimbursement regime: who pays the victim back, under what conditions, and what the EU is building.

A person pauses over a suspicious alert on a mobile banking app.

What makes an APP scam different from unauthorized fraud

In unauthorized fraud the payer did not consent, and the law has been clear for years: the payment service provider refunds unless the customer acted fraudulently or with gross negligence. In an APP scam the payer did consent. The consent was obtained by deception, so the payment is valid as a payment instruction and void as a transaction the customer wanted.

Three consequences follow. The money arrives in an account the criminal controls and leaves it within minutes, which instant payments made faster. The receiving bank, not the sending bank, is the only party that could have seen the receiving account behaving oddly. And no card-style chargeback exists on a credit transfer, which is why account-to-account payments needed a new legal answer instead of an existing commercial one.

The scam patterns

Impersonation is the biggest category: a call or message that appears to come from the bank, the tax office or the police, telling the customer to move money to a safe account. Invoice redirection targets businesses: a supplier's real invoice arrives with a changed IBAN, often after the supplier's mailbox was compromised. Purchase scams take a payment for goods that never existed. Investment scams move larger sums over longer relationships, and romance scams move the largest sums of all over the longest ones.

The business-facing patterns deserve separate controls, because they do not look like consumer scams. An invoice redirection succeeds against a finance department, not against an individual, and it defeats any process where one person can change a payee IBAN and release the payment. A callback on a number from the supplier contract, not from the invoice, stops most of it.

The UK mandatory reimbursement rules and the cap

The UK moved first and bound the industry. From October 7, 2024 the Payment Systems Regulator requires payment service providers to reimburse victims of APP fraud, with the cost split 50:50 between the sending and the receiving provider. The rules cover payments between UK accounts over Faster Payments and CHAPS, and a firm has to decide most claims within five business days, or 35 days if it stops the clock to investigate.

The cap is the part that was fought over. The PSR originally set it at 415,000 pounds, matching the ombudsman limit, and reduced it to 85,000 pounds in September 2024 after industry pressure. Which? recorded the effect: the higher cap would have covered 98 percent of scam value, the lower one covers around 90 percent, and the difference falls on victims of investment and property fraud. A firm may also levy an excess of up to 100 pounds per claim.

When a firm may refuse: the consumer standard of caution

Reimbursement is not automatic. A provider may refuse where the customer failed to meet the consumer standard of caution: ignoring a specific warning the firm gave, failing to report the scam within 13 months of the last payment, not responding to reasonable requests for information, or refusing to report the matter to the police. The firm has to show gross negligence, defined as a very significant degree of carelessness, which is a high bar.

Customers who are vulnerable to the particular scam that caught them are outside that standard entirely and outside the 100-pound excess, which means full reimbursement. Three payment types are excluded from the regime: card payments, which have their own chargeback route, international payments, and transfers of cryptoassets. A civil dispute with a real trader is also not a scam, however badly the purchase went.

The refund right PSD3 and the PSR would create in the EU

The EU answer is narrower than the UK one and arrives later. Under the Payment Services Regulation a payer would gain a refund right for a specific scam pattern: impersonation of the payment service provider, where a criminal poses as the bank and the customer is deceived into paying. That is deliberately tighter than a general right covering every scam type.

It also connects to a duty the EU already imposed. Where a provider failed to run verification of payee and the payer lost money as a result, the exposure sits with the provider, which is the lever the instant payments regulation already created. The provisional political agreement on PSD3 and the PSR came in November 2025, with application expected around 2028, so a German bank today is operating under the name-check duty and not yet under a statutory scam refund right. Payments regulation in Germany covers the supervisory side.

How verification of payee reduces the exposure, and where it does not

The name check works beautifully against one pattern and not at all against another. Invoice redirection is its best case: the criminal supplies a real IBAN belonging to an account in a different name, the check flags the mismatch, and the finance department sees a warning before the file goes out. Mistyped IBANs and outdated supplier records get caught the same way.

Against impersonation it mostly fails. A criminal running a safe-account scam has often already arranged a mule account in a name that matches what the victim is told to enter, so the check returns a clean match and reassures the victim. The limit is structural: the check verifies that the name fits the account, not that the payee deserves the money. That gap is why the receiving-side controls on money mules carry as much weight as the sending-side warning.

What a payment institution has to run to meet the duty

Four capabilities, and none of them is a product you can buy whole. Detection has to score an outgoing payment against the customer's own history and against known scam patterns, in the seconds an instant transfer allows. Intervention has to deliver a warning the customer actually reads, which means specific to the scam suspected and not a generic banner, because a generic warning fails the standard-of-caution test for the firm as much as for the customer.

Then the back end. Claims handling has to decide most cases in five business days under the UK rules, which is an operational commitment, not a policy document. And the receiving side has to monitor inbound credits for mule behavior and respond to the sending firm's notification, since under a 50:50 split the receiving institution now pays for what lands in its accounts. KYC in Germany and AML in Germany cover the onboarding controls underneath that.

What is APP fraud?

APP fraud, authorized push payment fraud, is a scam in which the victim is deceived into authorizing a payment from their own account to an account the criminal controls. Because the customer gave a valid instruction, the payment is not unauthorized fraud, and the remedies come from dedicated reimbursement rules instead of from the law on unauthorized transactions.

Will the bank refund APP fraud?

In the UK, usually yes, up to 85,000 pounds, with the cost split between the sending and receiving providers, unless the firm shows the customer was grossly negligent against the consumer standard of caution. In the EU there is no general statutory refund right yet; the Payment Services Regulation would create one for impersonation of the bank, and application is expected around 2028. A German customer today relies on the bank's own policy and on the duty to run the payee name check.

How can a company prevent invoice redirection fraud?

Treat a change of a supplier's bank details as an event that requires verification, never as a data update. Call the supplier on a number from the contract and not from the invoice, require two people to approve a payee change, and keep the payee master data clean so verification of payee produces a meaningful warning instead of daily noise.

APP fraud and Finance Loop

Finance Loop puts the fraud teams, the payment product owners and the regulatory lawyers in the same room, which is where an APP case actually gets solved, since the detection sits with one of them and the liability with another. Finance Loop is the meeting place for payments in Germany, with meetups and conferences on fraud, instant transfers and payment regulation. Finance Loop keeps those dates in its event calendar.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.