Join our Newsletter — 33% off our NHI Course
Home FAQ Threats, Abuse & Incident Response What are the signs that a customer may…
Threats, Abuse & Incident Response

What are the signs that a customer may be in the middle of an authorized push payment scam?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Threats, Abuse & Incident Response

Common warning signs include a long phone call overlapping the transaction, unusual network or call patterns, and device behaviour that does not match the customer’s normal interaction style. These signals matter because they often indicate social engineering in progress. The goal is not to infer fraud from one clue alone, but to combine multiple indicators into a stronger risk decision.

What the observed signals usually mean in practice

In an authorized push payment scam, the strongest warning signs are not the payment itself but the conditions around it. A customer may be under live social engineering if the transaction is happening during a prolonged call, if their network or device activity looks unusual for that person, or if the interaction pattern suddenly becomes scripted, hurried, or highly controlled.

Those signals are useful because APP scams often depend on keeping the customer engaged while the scammer suppresses normal hesitation. When a person stops behaving like they usually do, especially around timing, navigation, and responsiveness, you should treat that as an active intervention problem rather than a simple payment-risk anomaly.

What matters most is correlation. One strange call or one odd device event is rarely enough on its own. A stronger signal appears when the call, the device behaviour, and the transaction timing all line up in the same direction, especially when the customer is moving money in a way that breaks their normal pattern.

What should make you pause before the payment completes

Practitioners should pay close attention to tempo changes, not just content. A customer who is speaking to someone throughout the transfer, repeatedly pausing to receive instructions, or showing signs of being coached in real time is more concerning than a customer who simply asks questions about a payment.

Device and network behaviour also matter when they suggest a changed operating context. If the customer suddenly switches devices, changes location, uses an unusual access path, or shows interaction patterns that do not match their historical behaviour, the payment may be occurring under external influence.

Useful escalation triggers are usually combinations, not single events: prolonged communication during the transaction, unusual navigation speed, repeated correction of the customer’s actions by another party, or a mismatch between the payment urgency and the customer’s normal transaction habits. That is the point where extra confirmation becomes materially justified.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1 — Identity and Access ManagementCustomer behaviour under coercion affects trusted access decisions at payment time.
DE.CM-1 — Monitoring for Anomalies and EventsUnusual call, network, and device patterns are anomaly signals that support APP scam detection.
RS.AN-1 — AnalysisSuspected APP scam cases require rapid analysis of behavioural and contextual indicators.
Recommendation — Use PR.AC-1 to validate that the customer is acting with the expected authorised intent before release. Monitor transaction-adjacent anomalies and correlate them with payment events for escalation. Analyze combined behavioural indicators quickly to decide whether to pause or step up verification.
CIS Controls v88 — Audit Log ManagementCall, device, and transaction telemetry are needed to detect unusual interaction patterns.
6 — Access Control ManagementPAYMENT approval depends on confirming the requester still has legitimate decision authority.
Recommendation — Centralize and review transaction-linked logs to spot live coaching or abnormal activity. Apply stricter verification when payment timing or behaviour indicates possible coercion.

Practitioner Guidance

What to prioritise: Treat concurrent call activity and unusual interaction patterns as the first triage layer, then look for confirmation that the customer is being coached or pressured in real time. The most reliable judgement comes from linking behavioural change with transaction context, not from one isolated alert.

What to verify: Confirm whether the customer can describe the payment purpose, recipient relationship, and urgency consistently without relying on prompts. If answers are fragmented, delayed, or visibly repeated back from another source, the situation deserves escalation before funds leave the account.

Common mistake: Do not wait for a definitive fraud indicator. APP scams often present as a believable customer-initiated transfer right up to the point of completion, so the operational question is whether the surrounding behaviour shows loss of independent decision-making.

Practitioner takeaway: The decisive signal is not “fraud confirmed”, it is whether the customer is still acting independently enough for the payment to be trusted.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 18, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org