Blog
Guides

Authorised push payment fraud: the signals banks can see before the money moves

Orca Team
October 8, 2026
•
5
min read
IconIcon

One of the harder forms of fraud to fight is when a person or business is manipulated into making a payment into an account controlled by a fraudster. This is known as authorised push payment fraud (APP fraud), and it happens in the form of purchase and investment scams, romance scams, impersonation scams, and invoice redirection. 

According to SABRIC’s 2025 Annual Crime Statistics, reported client losses to digital banking crime more than doubled between 2023 and 2025, rising 29.2% in 2025 alone. SABRIC also found the crime was driven mainly by social engineering and customer manipulation rather than direct attacks on banking systems; the banking app was the channel for about 89% of reported cases and 70.5% of the value claimed. Fraudsters don’t need to hack into systems if they can convince someone to make the payment themselves. 

In the early 2000s, card skimming was a major threat, until EMV chip-and-PIN and contactless payments largely neutralised it. APP fraud is harder to design out. A bank’s system sees a legitimate customer executing a transaction, on a recognised device, entering the correct credentials. The fraud only becomes visible when the transaction, the customer’s behaviour in the app, and the account receiving the money are read together, and those signals are often split between two institutions. 

Why authorised push payment fraud works 

APP fraud can be initiated through nearly any form of contact: a phone call, an email, a text or even a fake ad. But importantly, the fraudster on the other side calls with a very plausible story. 

  • Bank impersonation
    Someone claiming to be from the bank’s fraud team calls about an unusual transaction (the cruel irony), they may run through the bank’s own identity verification screening, and say the money must move to a safe account. This is vishing-led APP fraud, which SABRIC identifies as a dominant typology.
  • Purchase scams
    A seller advertises a car, a rental property or goods online, often below market price, takes payment or deposit upfront and disappears.
  •  Investment scams
    A contact on social media or in a messaging group promotes returns that look credible, sometimes with a dashboard showing money growing. Small early withdrawals may even succeed, which encourages larger deposits, until the customer tries to take the money out.
  • Romance scams
    A relationship built on a dating app or social media over weeks or months, until an emergency arrives, such as a medical bill or fee to release a parcel. The payments often recur as the story extends. 
  • Invoice redirection
    A supplier’s banking details are changed on an email or invoice that looks like every other one, often sent from a compromised or spoofed email account. The business pays a real bill into the wrong account. SABRIC lists supplier mandate fraud and business email compromise among the material risks for businesses. 

In each case, the fraudster needs to establish trust, and sometimes urgency, to provoke action, and each form borrows the shape of a real transaction to do it. The most effective versions keep the fraudster in contact at the moment of payment. SABRIC describes impersonation fraudsters staying on the line throughout, giving step-by-step instructions and leaving little room to check with anyone else. AI makes these voices and messages more convincing as models grow in sophistication. 

For a fraud team, the variety is the problem. A romance scam and a bank impersonation call produce payments that look nothing alike, and neither looks different from an ordinary payment of the same kind. A rule written for one form will miss the others, so the signal has to come from how this payment compares with the customer’s own normal behaviour. 

What happens inside the app 

Whatever the story, the sequence inside the banking app is short. The customer adds one or more new beneficiaries, sometimes raises a payment limit first, and approves the transfers. In impersonation scams, SABRIC reports that payments are often made in rapid succession to several newly created beneficiaries, which spreads the money before anyone has a reason to look at it. Romance and investment scams tend to run slowly, with repeated payments to the same account over weeks. 

From there, the money moves through mule accounts. Some are opened for this purpose. Others belong to people recruited to receive funds, or to people who don’t know their account is being used. SABRIC’s Banking Industry Anti-Scam Centre describes funds being disbursed through multiple accounts, cash withdrawals, gaming platforms, and crypto. 

The bank usually hears about it from the customer, sometimes days later, because people who have been scammed often feel embarrassed or unsure what happened. By then, the first receiving account has typically been emptied. 

What gives APP fraud away

None of these steps fails an authentication check but they can look out of place when measured against the customer’s own history and against known fraud patterns. The signals fall into three groups: 

  1. Transaction (what is the customer doing?) 
  2. Behaviour (how is the customer using the app?)
  3. Beneficiary (what does the receiving account look like?) 

Transaction signals

  • New beneficiary, then a large transfer Was a beneficiary added minutes before one of the largest payments this customer has made?
  • Limit changes Was a payment limit raised shortly before the transfer?
  • Rapid succession Are several payments going to newly created beneficiaries within a short window?
  • Timing Is this happening at a time of day this customer doesn't usually bank?

Behaviour signals

  • Active call Is the customer on a phone call while the banking app is in session?
  • Hesitation Is there an unusually long pause on the confirmation screen?
  • Pasted details Was the account number pasted in rather than typed or chosen from saved beneficiaries?
  • Repeated edits Is the same field being corrected several times, as if the customer is following dictation?
  • Remote access Is remote access or screen-sharing software running while the customer is in the banking app?

Beneficiary signals

  • No prior relationship Is a large payment arriving from a sender who has never paid this account before?
  • Account age Was the receiving account opened recently?
  • Pass-through Is the account emptying within minutes of being paid?
  • Fan-in Is the account receiving money from several unrelated senders in a short window?

No single one of these proves fraud. A customer can be on the phone with a partner while paying a new plumber. Read together and scored against that customer’s normal behaviour, they can show a fraud team the likelihood that a payment is being made under someone’s direction, early enough to intervene. 

Why the sending and receiving bank each see half the picture 

Look at who holds these signals. 

The sending bank sees the transaction and behaviour. It knows the beneficiary is new, the limit went up, and the customer hesitated on the confirmation screen. It has no view of what the receiving account did in the hour before the payment arrived, or what it does in the minutes after. 

The receiving institution sees the beneficiary side. It can watch the money arrive from strangers and leave again almost immediately. It has no way of knowing that the sender was on a call or that they pasted in an account number given to them. 

Both institutions are doing what their systems ask of them. The sending bank confirms that an authenticated customer has authorised a payment, and the receiving bank accepts a credit into an open account. The pattern that would identify the fraud only exists when both halves are in view, and at the moment the payment is made, neither institution holds both. 

Putting the signals to work 

In many banks, the parts of an APP fraud transaction are watched by different systems. Beneficiary creation and limit changes often sit with digital channel controls, session behaviour with authentication, and the payment itself with transaction monitoring. A fraudster guiding a customer through all of it is running one attack against several separate views.  

The first step is to assess those parts together and in real time, so the pattern is visible while it forms.

Next, match the intervention to what the signals show. A hold on settlement buys time to look closer. A step-up check or a call-back puts a pause between the customer and whoever is directing them. Warnings need the same precision. A customer who trusts the person they’re paying will click past a generic one, but a warning that names what is actually happening, such as a request to move a large sum of money to a new account, gives them reason to stop. 

Every bank is also somebody’s receiving bank, so it can check incoming payments against the beneficiary signals above using its own data. When the sender and recipient bank with the same institution, or a payment provider sees both ends of the payment, the two halves can be joined directly. 

Fraudsters change their story and their victims from one scam to the next. The accounts that receive the money, and the devices and identities behind them, are much harder to replace. That makes them the one thing worth sharing between banks: a mule account flagged in one bank’s case should be visible to the next bank before another payment arrives. SABRIC’s Banking Industry Anti-Scam Centre is an early version of this. It has already helped banks respond faster and improved their ability to trace and preserve funds, though SABRIC notes that it is not yet operating at the scale needed to reduce industry losses. 

Order matters the most. Start with the sending side, where most of the signal sits and the money can still be stopped. Add the receiving-side monitoring next. Shared intelligence then strengthens both, but it can’t replace either. 

Banking apps made payments fast and simple, and APP fraud relies on that speed. The task now is to introduce the same pace to fraud monitoring. Read each payment closely enough, in the seconds before it leaves, and we can tell when authenticated and authorised don’t add up to safety. 

‍

Share this post
IconIconIconIcon

Check out our latest posts

In this article, we unpack how fraudsters persuade people to make a payment under false pretences, and the transaction, behaviour, and beneficiary signals that can make APP fraud visible before the money moves.
Orca Team
October 8, 2026
•
5
min read
Orca Fraud has raised $2.35 million in seed funding to advance its real-time transaction monitoring and fraud intelligence capabilities across Africa and other emerging markets.
Orca Team
March 8, 2026
•
4
min read
Orca Fraud has been selected for the sixth cohort of the Visa Accelerator Program, a 12-week pan-African initiative supporting fintechs building next-generation payment infrastructure. The program offers a chance to learn from Visa's decades of experience in card risk management while contributing insights from wallet-first, emerging markets—where fraud moves fast, crosses borders, and threatens the trust that underpins financial inclusion.
Orca Team
January 27, 2026
•
5
min read
Discover how Ozow, one of South Africa’s leading payment providers, is partnering with Orca Fraud to embed real-time fraud orchestration across its platform, protecting millions of transactions, empowering merchants to scale safely, and strengthening the trust foundation of South Africa’s digital economy.
Orca Team
October 29, 2025
•
7
min read

Book a demo

Discover AI-powered, contextual intelligence to detect fraud in real-time.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.