10 min read

3 Best Practices for Detecting APP Fraud in Banking

3 Best Practices for Detecting APP Fraud in Banking
3 Best Practices for Detecting APP Fraud in Banking
20:43

Authorized push payment (APP) fraud is a type of scam in which criminals manipulate victims over days or even weeks before convincing them to willingly transfer money to fraudulent accounts. These carefully planned social engineering campaigns build trust over time, making the final payment appear legitimate to both the customer and the financial institution.

According to UK Finance's 2026 Annual Fraud Report, APP fraud losses rose to £576.4 million in 2025, a 19% year-over-year increase, while the number of recorded cases increased by 7% to 248,070.

Because the payment is authorized by a legitimate customer after an extended manipulation campaign, traditional transaction-level fraud detection often struggles to distinguish APP fraud from genuine payments.

In this guide, you'll learn three best practices for detecting APP fraud so you can reduce losses, protect customers, and strengthen your fraud prevention strategy.

Key Takeaways

  • Omnichannel orchestration is essential for catching scams

Fraud signals are often spread across different banking products and systems. By unifying this data with signals like device activity, transaction patterns, geolocation, historical trust, and counterparty risk, banks can build more accurate account risk scores that detect APP fraud more effectively than isolated, channel-specific monitoring.

  • Behavioral biometrics are most effective when combined with broader customer context

Behavioral biometrics can detect suspicious signals such as unusual pauses, switching between banking and messaging apps, or changes in typing and navigation patterns. On their own, these behaviors may be legitimate, but when combined with cross-channel signals such as a recent instant loan application, credit card cash advance, or early savings withdrawal, they can reveal a customer being pressured into sending money.

  • Network intelligence helps uncover mule accounts and organized fraud rings

APP fraud rarely involves a single account. Cross-bank collaboration, graph analytics, payee verification, and privacy-preserving intelligence sharing help institutions identify suspicious relationships, expose mule networks, and prevent the laundering of funds.

  • Continuous Account Intelligence provides earlier detection and stronger protection

Acoru helps financial institutions identify APP fraud earlier by monitoring pre-fraud signals, unifying omnichannel data, detecting mule networks, and leveraging consortium intelligence.

What Is Authorized Push Payment Fraud?

Authorized push payment (APP) fraud occurs when a victim is persuaded to send money directly to a criminal via a bank transfer or other real-time payment method. In most cases, the payment is the result of an ongoing scam in which fraudsters spend time gaining the victim's trust before asking them to transfer the money. As a result, the bank sees what appears to be a legitimate transaction made using the customer's normal credentials and trusted device.

Because the payment is authorized, there is no automatic way to recover the funds. Once the money leaves the account, it can be quickly moved through networks of mule accounts, making it difficult to trace and recover.

Types of APP Fraud

Criminals use a wide range of tactics to persuade victims to authorize payments. Here are the most common types of APP fraud:

APP scam type

Description and characteristics

Purchase scams

Victims pay for goods or services advertised on online marketplaces or social media but never receive them. UK Finance estimates that purchase scams caused £87.1 million in losses in 2024.

Investment scams (“pig-butchering”)

Scammers spend weeks or months building trust before persuading victims to invest in fake cryptocurrency or high-return schemes, often moving funds overseas. Deloitte estimates that investment scams generated $4.6 billion in US losses in 2024.

Romance scams

Fraudsters build emotional relationships through dating apps or social media before asking for money for travel, medical expenses, or other emergencies. In 2024, romance scams accounted for roughly $672 million in US APP fraud losses.

Business and government impersonation scams

Criminals impersonate company executives, bank employees, or government officials and instruct victims to transfer money to a “safe account.” These scams disproportionately affect older adults, and studies show that individuals aged 60–79 accounted for 66% of losses from tech-support scams.

Invoice and mandate scams

Fraudsters intercept or spoof invoices and trick victims into paying legitimate bills into accounts controlled by those fraudsters. These scams often involve emails that appear to come from trusted suppliers or business partners but contain fraudulent payment instructions.

Advance fee and job scams

Victims are promised loans, prizes, or employment opportunities in exchange for upfront payments. After paying fees or signing contracts, they discover that the promised opportunity does not exist.

3 Best Practices for Detecting APP Fraud

To successfully detect APP fraud, you need to adopt a combination of advanced technologies and data-driven approaches. Below are three best practices that can help you identify APP fraud earlier.

1. Adopt AI-Driven Risk Scoring

AI-driven risk scoring helps identify suspicious payments by learning what normal behavior looks like for each customer, device, and payment corridor. It continuously adapts to changing patterns, helping detect the gradual changes that show long before a fraudulent payment is initiated.

Here is how to use AI for risk scoring:

  • Combine multiple signals: Use AI models that analyze factors such as device activity, session activity, payee type, transaction size, time of day, and geographic context to build a more complete picture of risk.
  • Use risk tiers instead of binary decisions: AI-driven risk scores can place transactions into risk bands, allowing low-risk payments to proceed while applying additional checks only when needed.
  • Optimize for speed: Ensure AI models can score transactions within milliseconds so suspicious activity is detected without delaying legitimate payments.
  • Monitor both senders and recipients: Use AI to profile both sending and receiving accounts, helping identify mule accounts and unusual fund flows that may indicate fraud.

The table below summarizes the main signals used to calculate a fraud score and the role each signal plays in the overall risk assessment:

Risk Signal

What it indicates

Transaction patterns

Identifies unusual transaction amounts, frequency, or locations that may suggest suspicious activity

Device profile

Checks device consistency and looks for anomalies such as virtualization or unstable configurations

Behaviour analysis

Detects actions that deviate from normal user behavior and may indicate misuse

Historical trust

Considers past interactions and successful transactions to assess long-term reliability

IP and location signals

Assesses network-related risks, including suspicious IP ranges and geographic inconsistencies

Model predictions

Combines multiple signals to determine how closely the activity matches known fraud patterns

 

Worth knowing:

Many AI risk scoring systems evaluate payments one transaction at a time. While this is effective for identifying suspicious transactions, it can miss the gradual changes that often precede APP fraud.

Acoru continuously scores accounts using signals from customer behavior, account activity, counterparties, and existing fraud systems, helping financial institutions identify early warning signs before a fraudulent payment is authorized.

2. Leverage Account Intelligence with Omnichannel Orchestration

Social engineering scams rarely leave a single warning sign. Instead, they create small risk signals across different customer interactions, products, and channels that, when viewed together, reveal a much clearer picture of potential APP fraud.

Behavioral biometrics and device intelligence can contribute to this picture by detecting unusual session behavior, but on their own they provide only limited context. The real value comes from combining these signals with account activity, payment history, lending behavior, customer profile changes, and other data already available across the bank to build a unified view of customer risk.

More modern account intelligence solutions have added AI models that can analyze subtle behavioral and device signals alongside account activity, payment history, and customer context to identify patterns that rule-based systems often miss. These models can recognize:

  • Unusual session activity: AI models can compare a customer's current session with their typical banking activity to identify unusual navigation patterns, extended session times, or other deviations from their usual patterns. They can also combine multiple signals, such as switching from a messaging or phone app directly to a payment, to identify patterns that may indicate the customer is being coached as part of an APP scam.
  • Signs of stress or external influence: AI models can identify behavioral patterns associated with stress or coercion, such as erratic device movement, unnatural pauses between interactions, changes in typing or touch behavior, or movements suggesting a device is being passed between multiple people. These signals may indicate that a customer is acting under pressure or receiving real-time instructions.

Worth knowing:

Acoru complements behavioral biometrics, device intelligence, and transaction monitoring by bringing their pre-fraud signals together with data from online and mobile banking, payment systems, contact centers, customer interactions, and account activity.

This unified, account-level view helps you uncover social engineering attacks and identify customers who may be manipulated into authorizing fraudulent payments that siloed fraud tools might otherwise miss.

3. Build Network Intelligence and Collaborate Across Industries

APP fraud is rarely carried out by a single individual, as it often involves networks of money mules, facilitators, and cross-border actors. Network analytics can connect transaction data across customers and institutions to uncover suspicious links and identify counterparties associated with previous APP scams.

To strengthen network intelligence and improve collaboration, you should:

  • Participate in cross-bank intelligence sharing: Exchange fraud intelligence with other financial institutions to gain visibility beyond your own customer base.
  • Adopt privacy-preserving collaboration: Use technologies such as federated learning or zero-knowledge proofs to share account risk intelligence without exposing customer data.
  • Leverage graph analytics: Analyze relationships between customers, counterparties, devices, and transactions to reveal coordinated fraud networks and identify suspicious payment destinations.

Worth knowing:

Acoru's Consortium Manager enables financial institutions to collaborate through a real-time, privacy-preserving intelligence network. Rather than relying on static blacklists, it helps institutions share actionable fraud intelligence to improve APP scam detection and identify high-risk counterparties without exposing customer data.

Acoru analyzes accounts across three coverage levels:

  • Level 1: Every account at your institution, including customer and internal accounts
  • Level 2: External accounts your customers interact with, assessed using your own observed counterparty patterns
  • Level 3: External accounts with no relationship to your customer, identified through optional consortium sharing

Together, these three levels provide the context needed to uncover emerging scam patterns and suspicious payment destinations that may not be visible within a single institution.

How to Detect Social Engineering Signals

Most social engineering shows up in the data somewhere, but rarely as one clean giveaway.

A first-time payment to a new account might be a scam, or it might be someone paying a deposit on a used car. A payment well above what a customer normally sends could be suspicious, or it could be a planned purchase they've been saving for.

Any of these signals, looked at alone, is easy to misread. Act on one in isolation, and you either wave through the sophisticated scams or pile friction onto genuine customers.

What changes the picture is context. Instead of focusing only on what's happening right now, banks need to consider what has happened to the account over the previous weeks, because a single pause means very little on its own. It becomes much more meaningful when you can see that the customer has:

  • Experienced a recent account takeover attempt
  • Had their personal details exposed in a recent data breach or another banking channel
  • Moved money out of a long-term savings or investment account to fund the payment

A lot of that information already exists inside the bank. The problem is that it sits in separate systems that don't talk to each other, and most tools only ever look at the live session.

It helps to think about the signals in three groups:

1. In-session behavior is what behavioral biometrics and device tools pick up while the customer is in the app:

Signal

Potential APP indicator

A switch between banking and messaging apps made mid-session

Real-time coaching by a fraudster

A payment made shortly after a long phone call

Impersonation or "tech support" scam

Unusual pauses, erratic device movement, or a device being passed between people

Customer acting under pressure or instruction

 

This is useful, but it only covers the session itself. It tells you nothing about the days or weeks of grooming that often came first.

2. The payment itself is where transaction monitoring already flags anomalies:

Signal

Potential APP indicator

First payment to a new beneficiary, combined with urgency

Invoice, impersonation, or emergency scam

A large jump over the customer's usual amounts

Investment or high-pressure scam

Balances draining fast, or a sudden spike in transfers

Romance, investment, or crypto scam

Payments at times that don't fit the customer's normal pattern

Fraudster-directed activity

 

The catch is that, on their own, they generate as many false alarms as real hits because they overlap heavily with ordinary behavior.

3. Cross-channel and account history is the layer most tools never reach, and it's often where the ambiguity clears up. It covers two things:

  • How the customer is funding the payment
  • What has already happened to their account elsewhere

When someone is being persuaded to send money they don't have, the way they try to obtain that money can reveal important warning signs:

Signal

Potential APP indicator

A recent instant loan or credit application, particularly one drawn down or declined just before a big payment

Customer being pushed to raise funds they don't have

A credit card cash advance

Customer reaching for expensive, last-resort money

Money pulled early from a long-term savings or investment account and taking the penalty

Urgent fund-gathering that doesn't fit a planned purchase

 

On history, the account may already carry signs of an earlier stage in the same campaign:

Signal

Potential APP indicator

An account takeover attempt on the same customer weeks earlier

An earlier stage of a campaign now reaching the payment

The customer's credentials or personal details compromised on another product or channel

Groundwork already laid by the fraudster

Recent changes to contact details or communication preferences

A common step used to control the channel

A call to the contact center asking how to make or raise the limit on a large payment

Preparation activity under someone else's direction

 

Someone buying a car tends to fund it calmly, usually from money they've set aside, on an account with nothing unusual behind it. Someone being coached does the opposite; they break a savings account early, take a cash advance, or go looking for another loan the moment the first is refused.

This often happens on an account that was already probed or compromised earlier in the scam. Pieced together from data the bank already holds, that history is usually a far clearer sign that a hesitation is due to manipulation.

Identify Early Signs of APP Fraud with Acoru

Acoru is an AI-native fraud platform that provides continuous account intelligence to help financial institutions detect APP fraud before transactions are initiated.

By monitoring account activity over time, classifying mule accounts, evaluating counterparty risk, and connecting signals across channels, Acoru helps institutions detect scam activity in the preparation phase.

It complements and strengthens existing fraud prevention capabilities without requiring replacement of current systems.

Here are Acoru's key capabilities that can help you detect and prevent APP fraud:

1. Pre-fraud signal detection – APP scams leave a trail of risk signals long before a fraudulent payment is initiated. Acoru analyzes these early indicators to classify accounts, generate real-time risk scores, and help you assess customer risk before money leaves the account. This includes:

  • Detecting hidden traces left by fraudsters during the preparation phase, before any fraud is committed
  • Generating a Pre-Transaction Score before a payment is submitted to assess the risk of fraud before money leaves the account
  • Recommending the most appropriate MFA challenge based on the customer's activity and transaction context
  • Continuously updating account classification and risk scores as new risk signals are detected throughout the customer journey.

2. Omnichannel orchestration – Acoru unifies data from online banking, mobile banking, payment systems, and contact centers to create a single risk view. This helps you detect social engineering attacks that traditional siloed systems may miss.

3. Mule account and network detection – Acoru continuously evaluates relationships between accounts and counterparties to identify mule activity, suspicious fund flows, and laundering patterns. This network-level approach helps expose organized fraud that transaction-based systems struggle to detect.

4. Consortium intelligence – Through its Consortium Manager, Acoru enables institutions to collaborate using privacy-preserving intelligence. Banks can benefit from ecosystem-wide fraud insights and identify previously unseen mule accounts and scam destinations without sharing sensitive customer data.

5. Integration with existing fraud systems – Acoru complements existing fraud prevention investments rather than replacing them. The platform can integrate data from transaction monitoring, behavioral analytics, device intelligence, and other fraud tools to provide a continuous, account-centric view of risk.

Request a demo today and see how Acoru strengthens your existing fraud stack with AI-driven account intelligence and early scam detection.

See Acoru in Action

Fraud in Latin America is moving fast, and the institutions keeping pace are the ones rethinking how they detect, share, and act on intelligence. If the challenges discussed in this episode sound familiar, we would be glad to show you how Acoru works in practice.

 

FAQ:

1. Who is liable for losses caused by authorized push payment (APP) fraud?

Liability for APP fraud depends on the country and payment system. Because the customer authorizes the payment, banks have not always been required to reimburse victims.

However, some countries have introduced reimbursement rules that require banks to compensate eligible APP fraud victims.

2. What is the difference between APP fraud and account takeover fraud?

In account takeover (ATO) fraud, criminals gain unauthorized access to a customer's account and initiate transactions without the victim's knowledge.

In APP fraud, the customer authorizes the payment themselves after being manipulated, making the transaction appear legitimate.

3. Can banks recover money lost through APP scams?

Recovering funds lost via APP scams is difficult because criminals often move the money quickly through mule accounts and across jurisdictions. However, banks may be able to freeze and recover some funds if the fraud is reported soon enough.

How to Detect Mule Accounts in 2026 [5 Best Strategies]

1 min read

How to Detect Mule Accounts in 2026 [5 Best Strategies]

Money mule activity has reached a global scale. In a single coordinated operation, Europol’s European Money Mule Action (EMMA 9) identified 10,759...

Read More
Most Common Money Mule Red Flags to Be Aware of in 2026

1 min read

Most Common Money Mule Red Flags to Be Aware of in 2026

Money mule red flags are indicators that a customer may be using their account to move money linked to financial scams or other fraudulent activity.

Read More
Fraud Prevention in the Banking Industry: A Complete Guide

1 min read

Fraud Prevention in the Banking Industry: A Complete Guide

In the banking industry, fraud often starts long before any payment is made, sometimes even weeks before any losses can be detected. For that reason,...

Read More