By NHI Mgmt Group Editorial TeamDomain: Identity Beyond IAMSource: FingerprintPublished March 30, 2026

TL;DR: APP fraud is driving rising losses because customers can authenticate correctly while still being manipulated into authorizing payments, and Fingerprint argues that device continuity, cross-session signals, and earlier intervention matter more than stronger login controls alone. The core failure is that banks are verifying access, not intent, so fraud teams need identity context before the transfer screen, not after.


At a glance

What this is: This is an analysis of authorized push payment fraud showing that scammers exploit trust, not account takeover, and that the decisive weakness is fragmented identity continuity across sessions and devices.

Why it matters: It matters to IAM and fraud practitioners because payment authorization, customer identity, and session trust now overlap, and traditional authentication controls do not address coercion or cross-channel manipulation.

By the numbers:

  • In the European Economic Area, fraud involving credit transfers reached €2.5 billion in 2024 and accounted for roughly 60% of total payment fraud losses by value.
  • In the United States, APP scams generated more than $2 billion in reported losses in 2023.
  • Across six major real-time payment markets, losses are projected to reach $7.6 billion by 2028.
  • Up to 1 in 3 UK consumers report being victimized by APP fraud, and more than half say it is becoming harder to detect scam activity.

👉 Read Fingerprint's analysis of authorized push payment fraud and identity continuity


Context

Authorized push payment fraud is a trust and identity problem that sits outside the protection boundary of standard login security. The customer is authenticated, but the payment is still fraudulent because the attacker has manipulated the person, the session, or the surrounding channel context before the transfer occurs.

For identity and fraud programmes, that means the security question is no longer only whether an account was accessed correctly. It is whether the institution can see continuity across devices, sessions, and channels well enough to distinguish legitimate intent from guided authorisation, especially when real-time payment rails compress response windows.


Key questions

Q: How should banks reduce APP fraud without making every payment slower?

A: Banks should use adaptive friction, not universal friction. That means reserving extra checks for sessions that show device change, remote-access tooling, suspicious payee behaviour, or cross-account reuse. Legitimate customers move quickly, while elevated-risk sessions get step-up review, cooling-off periods, or manual intervention before funds settle.

Q: Why do MFA and strong login controls fail against APP fraud?

A: Because APP fraud attacks the customer’s decision, not the login challenge. MFA can prove that the account holder authenticated, but it cannot prove the payment was made free of coercion, impersonation, or guided manipulation. The control gap is intent, not access.

Q: How can security teams tell whether adaptive fraud detection is working?

A: Look for improvement in both detection speed and decision quality under changing attack conditions. A working system should absorb new fraud patterns without long manual retraining cycles, and it should reduce successful abuse in onboarding, recovery, or payment flows. If the model remains accurate only after lengthy tuning, it is not adaptive enough for current threat tempo.

Q: Who is accountable when APP fraud occurs under reimbursement rules?

A: Accountability is shared across fraud operations, payment governance, and compliance because the event spans customer protection, transaction monitoring, and AML obligations. Reimbursement may transfer the cost, but it does not remove the need to prove how the institution detected, triaged, and reported the scam.


Technical breakdown

Why authentication does not stop authorized push payment fraud

APP fraud exploits a gap between authentication and authorisation intent. MFA, biometrics, and login scoring confirm that a real customer reached the account, but they do not prove the customer is acting independently. In scam journeys, the attacker may use impersonation, remote-access software, or social pressure to shape the customer’s behaviour while the session remains technically valid. That is why the fraud looks legitimate at the credential layer. The control boundary is too narrow: banks are verifying identity at login, then assuming the subsequent payment decision remains trustworthy.

Practical implication: fraud controls need behavioural and session context before payment confirmation, not only stronger authentication at login.

How cross-channel identity signals get lost before the payment is made

APP scams develop across email, messaging apps, call centres, desktop sessions, and mobile banking. Each channel emits useful signals, but they are usually stored in different tools and teams, which prevents a coherent view of the customer journey. When device reuse, new payee creation, remote-access artefacts, and unusual timing are not correlated, the institution sees fragments instead of an attack path. The technical failure is not absence of data. It is the lack of persistent linkage that turns separate events into one risk narrative.

Practical implication: correlate channel, device, and account activity into a single risk timeline before the transfer is accepted.

Why real-time payments compress the fraud response window

Real-time rails such as Faster Payments, SEPA Instant, RTP, and FedNow move money in seconds, which means the detection model has very little time to interpret context. Once funds are released, mule accounts can disperse them across institutions and jurisdictions almost immediately. That makes post-transaction review useful for investigation but weak for prevention. In practical terms, the control problem shifts left: if risk scoring waits until the confirmation screen, the institution is already late.

Practical implication: move risk scoring earlier in the session so step-up checks or payment holds happen before settlement, not after.


Threat narrative

Attacker objective: The attacker’s objective is to convert a legitimate customer into the instrument of the fraud and move funds beyond effective recovery.

  1. Entry occurs when the attacker gains the victim’s trust through impersonation, scam support calls, investment fraud, or remote-access tooling.
  2. Escalation happens as the attacker guides the victim through authentication and payment steps while keeping the session technically legitimate.
  3. Impact occurs when the authorised transfer reaches a mule account and funds are dispersed before recovery or intervention can succeed.

NHI Mgmt Group analysis

APP fraud reveals a verification trust gap: banks are still optimising authentication while the real attack is happening in the customer’s decision path. Identity assurance at login is not enough when the attacker is steering the payment outcome through deception, coercion, or remote access. This is why fraud programmes need a concept broader than account security. Practitioners should treat the trust gap between authentication and authorisation as a distinct governance problem.

Cross-channel identity continuity is the named failure mode: the institution loses sight of the same user across mobile, desktop, call centre, messaging, and payment workflows. That fragmentation breaks detection because no single system sees the full manipulation sequence. In governance terms, the issue is not missing alerts but missing continuity. Practitioners should design for session linkage across channels instead of relying on isolated risk scores.

Real-time payment rails turn fraud into a timing problem: once funds move instantly, recovery depends on earlier detection and faster intervention. This shifts the centre of gravity from post-event case handling to pre-payment risk orchestration. The practical conclusion is that reimbursement frameworks can soften customer harm, but they do not reduce the underlying attack surface. Teams should measure how much risk is caught before settlement, not how many cases are resolved later.

The control model must move from credential verification to behavioural governance: APP fraud is a reminder that identity systems can be technically correct and still operationally blind. Security architecture needs to understand coercion, remote access, and abnormal payment journeys as first-class risk signals. That aligns more closely with NIST CSF, NIST SP 800-53, and fraud governance patterns than with classic MFA thinking. Practitioners should reframe fraud prevention as identity continuity governance.

What this signals

Verification trust gap: APP fraud shows how institutions can authenticate correctly and still fail to establish whether the customer’s decision is trustworthy. That has implications for fraud stacks, case management, and identity assurance design, especially where a single session no longer represents a single intent.

Persistent device and session intelligence will become more important as real-time payment volume grows and scam journeys become more industrialised. Banks that can connect behaviour across channels will catch more manipulation before settlement and reduce dependence on customer complaints as the first signal.

The practical programme shift is toward earlier, context-rich decisioning that sits between IAM, fraud, and AML. Teams should align with fraud detection patterns in NIST SP 800-53 and identity assurance principles in NIST SP 800-63, while recognising that the signal problem is broader than classical access control.


For practitioners

  • Correlate identity signals across the full payment journey Link login, device, payee creation, call-centre contact, and transaction events into one timeline so analysts can see manipulation before the payment is authorised.
  • Detect remote-access and coercion artefacts before settlement Flag virtualised devices, remote-control software, rapid channel switching, and abnormal assistance patterns as pre-payment risk indicators rather than post-fraud evidence.
  • Apply adaptive friction only to elevated-risk sessions Use step-up checks, cooling-off periods, or manual review when device continuity breaks, a new payee appears, or the session shows cross-account reuse.
  • Align fraud and AML workflows around mule-account dispersal Coordinate fraud investigation, suspicious activity reporting, and reimbursement handling so the institution can respond while funds are still traceable across receiving accounts.

Key takeaways

  • APP fraud succeeds because the institution verifies access, not intent, and that leaves a trust gap between login and payment authorisation.
  • The scale is material, with billions in losses and real-time payment rails shrinking the time available to intervene.
  • Fraud teams need cross-channel identity continuity, earlier scoring, and adaptive friction before settlement if they want to reduce loss without harming legitimate customers.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63BLogin assurance is central, but the article shows it is insufficient alone.
NIST CSF 2.0PR.AC-1The article concerns identity proofing and access decisions in payment journeys.
NIST SP 800-53 Rev 5IA-2Identity verification and authentication controls underpin the login stage discussed here.
GDPRArt.32Fraud analytics may process personal data and behavioural signals in regulated banking contexts.

Document lawful processing, minimisation, and security measures for customer behaviour data used in fraud detection.


Key terms

  • Authorised Push Payment Fraud: A payment scam in which the victim is persuaded to authorise the transfer themselves. The transfer is technically authorised, but the decision is corrupted by deception, which makes liability, evidence, and prevention harder to separate from standard transaction controls.
  • Identity Continuity: Identity continuity is the ability to preserve a workload’s verified identity across proxies, services, and other infrastructure boundaries. It matters because zero trust breaks down when a request loses its original proof of identity and falls back to network trust or header-based assumptions.
  • Real-Time Payment Rail: A payment network that settles funds almost immediately after initiation. These rails reduce the window for intervention, which makes pre-payment risk scoring, adaptive friction, and coordinated fraud monitoring much more important than delayed post-transaction review.
  • Access Friction: Access friction is the delay, inconsistency, or effort a person experiences when trying to reach a system or task. It becomes a governance issue when it is high enough to encourage shortcuts, exceptions, or support-heavy workarounds that weaken the intended control model.

What's in the full article

Fingerprint's full analysis covers the operational detail this post intentionally leaves for the source:

  • Case-by-case loss patterns across UK, U.S., and other real-time payment markets that show where the highest exposure is concentrated
  • Detailed discussion of purchase, investment, and romance scam patterns, including how volume and value differ in practice
  • Operational examples of device intelligence and persistent session signals that support earlier fraud intervention
  • The reimbursement and regulatory context behind scam handling outcomes, including how liability and recovery are being managed

👉 Fingerprint's full article covers the scam journey, regulatory pressure, and device intelligence approach in more detail

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, secrets management, workload identity, and identity lifecycle fundamentals. It is suitable for practitioners who need a stronger basis for controlling identities and access across modern security programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 15, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org