Skip to main content

Independent UK reporting on scams, fraud and financial harm

Explainer

What authorised push payment fraud is, and how it differs from card fraud

An authorised push payment happens when you are tricked into sending money yourself. Because you pressed send, the protections are different from those on a card payment.

By Daniel Okoye, Senior reporter, fraud and payments · Updated

A hand holding a phone showing a bank transfer screen at a kitchen table
Illustrative picture. It does not depict any firm or individual named in this report.

Explainer

Scam types

Published
6 Aug 2026
Last revised
9 Aug 2026
Sources cited
5
Names named
None
Share thisWhatsAppXLinkedInFacebook Email

Authorised push payment fraud, usually shortened to APP fraud, happens when you are tricked into authorising a payment yourself. The money leaves your account with your own approval, which is exactly why these cases are argued over: the bank's systems worked, and the deception happened before the payment was made.

How the money actually moves

Almost every case follows the same three stages. First, contact: a text, an email, a call, a marketplace listing or a message from an account you already trust. Second, a reason to move fast: a "compromised" account, an invoice that has changed bank details, a deposit that must be paid tonight or the flat goes to someone else. Third, the transfer, made by you, from your own banking app, often while you are still on the phone.

  • Bank or police impersonation: you are told your account is compromised and asked to move money to a "safe account". No bank operates safe accounts.
  • Invoice redirection: a genuine builder, solicitor or supplier's email thread is hijacked and the account number is changed at the last minute.
  • Purchase scams: a car, a puppy, a festival ticket or a holiday let that does not exist, always paid by transfer rather than card.
  • Investment scams: a broker who reports gains for weeks and then asks for a fee before you can withdraw.
  • Romance and long-game fraud: months of contact before the first request for money.

Why the payment usually clears

Faster Payments settle in seconds. Once the money lands, the receiving account — often a "mule" account opened with stolen or borrowed identity documents — is emptied within minutes and moved on through several more accounts, frequently into crypto. Recovery of the actual cash is rare. What you are claiming is not usually the money back from the fraudster; it is reimbursement from the bank that sent it.

What decides a reimbursement claim

Under the reimbursement rules that now apply to Faster Payments, a bank should refund most consumers, small businesses and charities and should tell you its decision quickly, normally within five business days. The arguments that come up are narrow: whether you ignored a specific, targeted warning; whether the claim is a genuine scam rather than a private dispute; and whether the payment falls inside the rules at all.

What to do, in order

  1. Call your bank. Use the number on your card, not a number from a message. Ask them to attempt recall and to log the case as a scam.
  2. Report to Action Fraud (actionfraud.police.uk), or Police Scotland on 101, and keep the reference.
  3. Preserve everything — messages, adverts, screenshots, the account details you paid, the times of each call.
  4. If the bank refuses or goes silent, complain in writing, then take it to the Financial Ombudsman Service (financial-ombudsman.org.uk). It is free.
  5. For questions about whether a firm is authorised, the FCA consumer helpline is 0800 111 6768, also free.

What this article is not

This is a description of how a category of fraud works and which free routes exist. It is not advice on your own case, and we never assess whether anyone has a claim.

Firm warnings published each month

98 in this window · down 17 on the month before

  • 2Apr
  • 1May
  • 2Jun
  • 4Jul
  • 53Aug
  • 36Sept

Counted from the warning notices in our own archive. One notice can name several trading styles.

The wider record

Counts from our own archive, for context around this report. Not an estimate of fraud across the UK.

Clone firms as a share of our Warning List archive

Clone firms copy the name or details of a genuine authorised business.

106
  • Clone of an authorised firm17(16%)
  • Not recorded as a clone89(84%)

Contact details recorded against warned firms

One firm can appear in more than one row.

  • Website recorded76(35%)

    Website recorded: 76 entries
  • Phone recorded39(18%)

    Phone recorded: 39 entries
  • Email recorded85(39%)

    Email recorded: 85 entries
  • No contact details held16(7%)

    No contact details held: 16 entries

Open the data page to see how each figure is counted.

See all of our fraud data

How this report was made

Updated
3 times
Primary sources
5 sources
Following this subject
0 readers
Reader comments
0 comments

Checked against the published record

Sourcing. Every claim is tied to a published record — a regulator's notice, a court or ombudsman decision, or a document we hold. We quote a headline and a short summary and link the original.

Right of reply. Firms and people we criticise are put on notice before publication and their response is carried in the piece.

Independence. No affiliate links, no sponsored placements and no referrals to solicitors or claims firms. The only routes we point to are free. Read the full method · first published 06/08/2026

Trust and sourcing

  • Reported by

    Daniel Okoye

    Senior reporter, fraud and payments

    Bylined
  • Approved for publication by

    Helen Marsden

    Editor

    Editor approved
  • Legal review

    Not required

    No individual or firm is criticised, so no right of reply was required.

    Not flagged for review

Source URLs behind this report

What changed in each update

First published 6 August 2026 at 08:00 · last updated 9 August 2026 at 10:00

  1. Added the current free reporting routes and clarified what the reimbursement rules do and do not cover.

    Payment Systems Regulator
  2. Checked against the source record and refreshed the figures and dates in the panels. No findings changed.

    FCA Financial Services Register
  3. First published.

    FCA Warning List
How we source and correct our reporting

Updates and change log

First published
Last updated
  1. Added the current free reporting routes and clarified what the reimbursement rules do and do not cover.

    Payment Systems Regulator
  2. Checked against the source record and refreshed the figures and dates in the panels. No findings changed.

    FCA Financial Services Register
  3. First published.

    FCA Warning List

Sources for this report

Sources for this report

  • FCA logo

    Financial Conduct Authority Warning List

    FCA

    Primary record of firms the FCA says may be operating without authorisation.

    Read the original source
  • FCA logo

    FCA Financial Services Register

    FCA

    Authoritative check on whether a firm is authorised and for what.

    Read the original source
  • PSR logo

    Payment Systems Regulator — APP fraud reimbursement

    PSR

    The reimbursement requirement for authorised push payment fraud.

    Read the original source
  • FOS logo

    Financial Ombudsman Service

    FOS

    Free, independent adjudication and published decision data.

    Read the original source
  • Action Fraud logo

    Action Fraud reporting service

    Action Fraud

    The UK national reporting centre for fraud and cybercrime.

    Read the original source

We link directly to the original source wherever possible. A source may update its own page after we publish; we show the date we last recorded or updated the citation.

Readers can upvote helpful reporting.
Share thisWhatsAppXLinkedInFacebook Email

Share a quote card

Generate a branded image of the key line from this report, with the link on it, to post or send on.

  • Scam types
  • Authorised push payment fraud

Reader comments

0 published comments · moderated by the newsroom

House rules: comments are for readers' own experience and questions about the reporting. We remove spam, abuse and anything that names a private individual without cause. Comments containing links are held for an editor before they appear. We cannot tell you whether you have a claim, and we do not pass details to any solicitor, claims firm or representative.

  1. Loading comments…

About the author

Byline portrait of Daniel Okoye

Daniel Okoye Daniel covers authorised push payment fraud, payment systems and the reimbursement rules. He previously worked on a regional investigations desk.