TL;DR: APP fraud is driving rising losses because customers can authenticate correctly while still being manipulated into authorizing payments, and Fingerprint argues that device continuity, cross-session signals, and earlier intervention matter more than stronger login controls alone. The core failure is that banks are verifying access, not intent, so fraud teams need identity context before the transfer screen, not after.
NHIMG editorial — based on content published by Fingerprint: LLMjacking and how attackers hijack AI using compromised NHIs
By the numbers:
- In the European Economic Area, fraud involving credit transfers reached €2.5 billion in 2024 and accounted for roughly 60% of total payment fraud losses by value.
- In the United States, APP scams generated more than $2 billion in reported losses in 2023.
- Across six major real-time payment markets, losses are projected to reach $7.6 billion by 2028.
Questions worth separating out
Q: How should banks reduce APP fraud without making every payment slower?
A: Banks should use adaptive friction, not universal friction.
Q: Why do MFA and strong login controls fail against APP fraud?
A: Because APP fraud attacks the customer’s decision, not the login challenge.
Q: How can security teams tell whether adaptive fraud detection is working?
A: Look for improvement in both detection speed and decision quality under changing attack conditions.
Practitioner guidance
- Correlate identity signals across the full payment journey Link login, device, payee creation, call-centre contact, and transaction events into one timeline so analysts can see manipulation before the payment is authorised.
- Detect remote-access and coercion artefacts before settlement Flag virtualised devices, remote-control software, rapid channel switching, and abnormal assistance patterns as pre-payment risk indicators rather than post-fraud evidence.
- Apply adaptive friction only to elevated-risk sessions Use step-up checks, cooling-off periods, or manual review when device continuity breaks, a new payee appears, or the session shows cross-account reuse.
What's in the full article
Fingerprint's full analysis covers the operational detail this post intentionally leaves for the source:
- Case-by-case loss patterns across UK, U.S., and other real-time payment markets that show where the highest exposure is concentrated
- Detailed discussion of purchase, investment, and romance scam patterns, including how volume and value differ in practice
- Operational examples of device intelligence and persistent session signals that support earlier fraud intervention
- The reimbursement and regulatory context behind scam handling outcomes, including how liability and recovery are being managed
👉 Read Fingerprint's analysis of authorized push payment fraud and identity continuity →
APP fraud and identity continuity: are your controls keeping up?
Explore further
APP fraud reveals a verification trust gap: banks are still optimising authentication while the real attack is happening in the customer’s decision path. Identity assurance at login is not enough when the attacker is steering the payment outcome through deception, coercion, or remote access. This is why fraud programmes need a concept broader than account security. Practitioners should treat the trust gap between authentication and authorisation as a distinct governance problem.
A question worth separating out:
Q: Who is accountable when APP fraud occurs under reimbursement rules?
A: Accountability is shared across fraud operations, payment governance, and compliance because the event spans customer protection, transaction monitoring, and AML obligations. Reimbursement may transfer the cost, but it does not remove the need to prove how the institution detected, triaged, and reported the scam.
👉 Read our full editorial: APP fraud is exploiting trust chains that MFA cannot see