Table of Contents
Push and pull payments may seem similar, but each presents a unique set of fraud risks that financial institutions must understand and manage.
The US Federal Reserve reported that noncash payments have more than tripled since 2000, reaching 236.6 billion transactions in 2024. As payment activity continues to grow, financial institutions need to understand where each payment model is most vulnerable and adapt their fraud controls accordingly.
In this article, we'll explore push vs. pull payments and strategies to better detect and prevent payment fraud.
Push vs. Pull Payments: The Main Differences
Before exploring each payment model in detail, here's a quick overview of the key differences:
|
Area |
Push payments |
Pull payments |
|
Initiating party |
Payer or sender |
Merchant, creditor, or recipient |
|
Typical examples |
Bank transfers, wire transfers, instant payments, person-to-person transfers |
Direct debits and recurring collections |
|
Authorization |
Usually provided for each payment |
Often provided in advance through a mandate |
|
Main fraud concern |
Manipulated or compromised payer authorization |
Invalid, stolen, exceeded, or fabricated permission |
|
Common fraud types |
|
|
|
Customer involvement |
Customer typically initiates or authorizes the payment |
Customer may not interact with each individual payment |
|
Recovery |
Often difficult after funds are credited and moved |
Dispute and return rights may be available, depending on the system |
|
Important risk focus |
Session activity, beneficiary risk, and receiving accounts |
Mandate validity, merchant behavior, collection patterns, and disputes |
What Are Push Payments?
Push payments are transactions where the person or organization sending the money initiates the transfer. The bank customer instructs their bank or payment service provider to send funds directly from their account to a specific recipient. Common examples include:
- Credit transfers initiated through online or mobile banking
- Domestic and international wire transfers
- Instant bank payments
- Person-to-person payments
- Payroll and supplier payments
Once the payment is authorized and submitted, the funds are pushed from the sender's account to the recipient's account.
How Push Payments Work
While the exact process depends on the payment method and network being used, it generally follows these steps:
- The payer creates a payment instruction: The customer enters or selects the recipient’s details, chooses an amount, and provides any required payment reference.
- The payer authorizes the transaction: Authorization may involve a password, PIN, biometric check, one-time passcode, security token, or another form of authentication.
- The sending institution performs its checks: The financial institution confirms that the account has sufficient funds and evaluates the payment against fraud, sanctions, and compliance controls.
- The payment instruction enters the relevant network: Depending on the payment type, it may be sent through a domestic transfer system, wire network, instant payment rail, or another clearing mechanism.
- The recipient’s institution receives the instruction: The receiving institution validates the payment information and credits the recipient’s account when appropriate.
- The payer receives confirmation: The customer is usually notified that the payment has been submitted, completed, delayed, or rejected.
Fraud Risks of Push Payments
Push payments come with unique fraud risks because the sender authorizes the transfer. Criminals often trick or manipulate the payer before the payment is made.
1. Authorized Push Payment Fraud
Authorized push payment (APP) fraud occurs when a customer is manipulated into sending money to an account controlled by a criminal. Since the payment is approved by the legitimate user, conventional authentication controls may not identify it as fraudulent.
Common forms of APP fraud include:
- Impersonation scams
- Investment scams
- Romance scams
- Purchase scams
- Invoice-redirection fraud
- CEO and executive impersonation
- Business email compromise
- “Safe account” scams
APP fraud remains a major threat despite continued investment in detection and customer education. UK Finance reported £576.4 million in APP fraud losses during 2025, a 19% increase from 2024. Personal losses accounted for £500.8 million, while non-personal losses accounted for £75.6 million.
These losses can directly impact banks' finances. Under the UK’s PS23/4 reimbursement rules, payment service providers must reimburse eligible APP scam victims up to £85,000 per claim, with the cost generally split equally between the sending and receiving providers.
2. Account Takeover
In an account takeover, a fraudster obtains access to a victim’s online or mobile banking account. Access may be gained through phishing, malware, credential stuffing, SIM swapping, social engineering, or compromised devices.
Once inside the account, the fraudster may:
- Review the victim’s balance and transaction history
- Change contact information or authentication settings
- Register a new device
- Add one or more beneficiaries
- Increase payment limits
- Transfer funds to a mule account
- Make small test payments before sending a larger amount
Unlike APP fraud, this type of fraud doesn't involve the victim authorizing the payment. However, the transaction may still pass authentication if the criminal has gained access to relevant credentials or persuaded the user to share a one-time passcode used to approve the payment.
3. Business Email Compromise and Invoice Fraud
Businesses regularly use push payments to pay suppliers, contractors, and other business partners. Fraudsters exploit these trusted relationships by gaining access to business email accounts or by creating convincing fake emails that appear to come from a legitimate contact.
A common tactic is to impersonate a trusted supplier by sending a convincing email claiming that the supplier has updated its bank details. The message often appears genuine because it uses familiar branding, references recent invoices or projects, or is sent from a compromised email account, leading the business to redirect future payments to a fraudulent account.
In the US, Nacha’s Phase 2 fraud-monitoring rules now specifically address these scenarios. The rules require risk-based processes and procedures designed to identify ACH entries suspected of being unauthorized or authorized under “False Pretenses,” including business email compromise and vendor impersonation.
4. Money Mule Accounts
Many push payment scams rely on money mule accounts to receive and move stolen funds. These accounts may belong to:
- People who knowingly help criminals
- Individuals who have been tricked into acting as mules
- Victims whose accounts have been taken over
- Businesses set up to hide illegal activity
Once the money is deposited, it is often moved as quickly as possible to make it harder to trace. Criminals may split the funds across multiple accounts, convert them into cryptocurrency, withdraw them as cash, or transfer them overseas.
With instant payment systems, this can happen within minutes, leaving financial institutions with very little time to detect fraud and recover funds.
Worth knowing:
Acoru helps financial institutions identify money mule accounts before they become part of a larger fraud network. It continuously analyzes account activity, transaction patterns, counterparty relationships, and pre-fraud signals to detect suspicious activity as it develops.
Accounts are automatically classified as Regular, Victim, Mule, Launderer, or Honeypot, with mule accounts further categorized as complicit, witting, or unwitting. Each account receives a 0-1,000 risk score, allowing fraud teams to monitor how risk changes over time and intervene before stolen funds are moved further.
What Are Pull Payments?
Pull payments are initiated by the recipient, merchant, or creditor under authorization granted by the payer. Instead of the payer sending a new instruction for each transaction, the payee submits a request to collect funds from the payer’s account.
Direct debits, subscription payments, and many recurring billing arrangements are common examples of the pull payment model.
How Pull Payments Work
A typical pull payment follows these steps:
- The payer provides authorization: The customer agrees that the merchant or creditor may collect one or more payments. The authorization may apply to a fixed amount, a variable amount, a recurring schedule, or a single transaction.
- The merchant stores the payment agreement: The merchant records the customer’s authorization and the details needed to submit future requests.
- The merchant initiates collection: On the agreed-upon date, the merchant sends a payment request through its financial institution or payment provider.
- The request enters the payment network: The network routes the collection instruction toward the payer’s financial institution.
- The payer’s institution processes the request: The institution checks the account status, available funds, instruction details, and any applicable restrictions or fraud controls.
- Funds are debited from the payer’s account: If the request is accepted, the amount is removed from the customer’s account and transferred through the relevant settlement process.
- The merchant receives the funds: The recipient’s account is credited, although finality may depend on the payment method and applicable return period.
Fraud Risks of Pull Payments
Pull-payment fraud generally involves stealing payment credentials, fabricating authorization, misusing a valid mandate, or collecting an amount the payer did not knowingly authorize.
1. Mandate and Authorization Fraud
Pull payments require customer authorization before funds can be collected. Fraud occurs when criminals create fake authorizations, alter legitimate ones, or misuse a customer's permission to collect money.
Potential warning signs include:
- A high number of newly created mandates linked to the same creditor
- Multiple customers disputing collections from one originator
- Collections that begin immediately after account details change
- Unusually large increases in the amount collected
- A new merchant generating abnormal dispute levels
- Mandates associated with inconsistent customer information
- Repeated collections after cancellations or refund requests
2. Unauthorized Direct Debits
In this type of fraud, criminals use stolen bank account details to withdraw money from a customer's account without their permission. They may obtain these details through phishing attacks, data breaches, fake websites, stolen documents, or other forms of data theft.
To collect the funds, the fraudster uses the stolen bank details to set up a fraudulent authorization or falsely claim permission to collect money from the account. They then submit debit requests through a merchant or payment service provider that participates in the direct debit scheme.
Because the payment appears to be supported by a valid direct debit authorization, the funds may be withdrawn before the customer realizes anything is wrong. The account holder may not notice the unauthorized transaction until they review their account statement or receive a balance notification.
3. Refund and Chargeback Abuse
The ability to dispute pull payments protects customers, but it can also be exploited. First-party misuse, sometimes called “friendly fraud” in the card industry, occurs when a customer disputes a transaction they authorized. They may falsely claim that:
- The card was used without permission
- Goods were never delivered
- A subscription had been canceled
- The merchant was not recognized
- The transaction amount was incorrect
How Financial Institutions Can Manage Both Types of Fraud
Push and pull payments require different controls, but neither should be monitored in isolation. Financial institutions can strengthen their protection by following these best practices:
1. Monitor Events as Part of a Sequence
A single event, such as a large payment to a new beneficiary, can be a warning sign. But looking at what happened before the payment often tells a much clearer story. For example, a customer might:
- Register a new device
- Change their phone number
- Increase their transfer limit
- Add a new beneficiary
- Move money from savings before sending a high-value payment
The same idea applies to pull payments. A merchant might change its settlement account, start collecting larger volumes of payments, begin charging many new customers, and then suddenly see a spike in disputes.
Analyzing these events as part of a sequence, rather than as isolated activities, makes it easier to identify suspicious activity early and intervene before additional losses occur.
Worth knowing:
Acoru continuously monitors pre-fraud signals that often appear before a suspicious transaction takes place. These include:
- Profile and account changes
- New payees and payment preparation activity
- Unusual login behavior and channel switching
- Interactions across online banking, mobile apps, branches, and contact centers
- Counterparty behavior and account relationships
By correlating these events over time rather than evaluating each one in isolation, Acoru helps you identify high-risk activity earlier and with greater confidence.
2. Assess Both Sides of the Payment
A push payment may appear completely legitimate when you monitor only the sender's account and activity. However, the recipient account may already be linked to a money mule network or other fraudulent activity that would not be detected without examining both sides of the transaction.
Likewise, a pull payment may seem legitimate to the customer, while the merchant requesting the funds is generating an unusually high number of complaints or disputes.
Worth knowing:
Acoru helps you assess recipient accounts before a payment is initiated. When a recipient account is added, Acoru analyzes previous interactions captured in the institution's own customer and transaction data to provide additional risk context. This helps determine whether the account has been associated with suspicious activity in the past.
3. Use Risk-Based Responses
Not every unusual payment is fraudulent, so blocking every suspicious transaction can create unnecessary frustration for your customers and increase operational costs. Instead, you should match your response to the level of risk. Depending on the situation, you may:
- Display a warning before the payment is completed
- Request additional authentication
- Ask the customer to confirm the purpose of the payment
- Verify a new beneficiary through a separate communication channel
- Temporarily delay a high-risk transaction for further checks
- Contact the customer to confirm the payment
- Review the recipient or merchant for suspicious activity
- Restrict an account suspected of being used as a money mule
- Escalate the case for further investigation
Worth knowing:
Acoru continuously classifies and scores account risk throughout the customer journey. Before a transaction is confirmed or 2FA/SCA is completed, Acoru will have already generated a risk score using all available historical account data. This could be data from the financial institution’s internal channels or data collected by behavioral analytics, device intelligence, or other fraud tools.
This allows you to apply the appropriate level of verification based on the account's current risk, instead of evaluating every payment or session in isolation at a specific point in time.
4. Improve Cross-Institution Collaboration
Fraudsters often move money through multiple financial institutions, making it difficult for any single bank to see the full picture. One institution may notice unusual behavior from the sender, while another sees the same recipient receiving payments from many unrelated people. On their own, these signals may not be enough to identify fraud.
By securely sharing account risk insights, financial institutions can detect mule networks, identify suspicious payment patterns earlier, and stop fraudulent funds before they are moved again.
Modern privacy-enhancing technologies, such as encrypted processing and zero-knowledge proofs, enable the exchange of meaningful risk information securely without exposing any PII. This gives you better visibility into cross-bank fraud while maintaining privacy and regulatory compliance.
Worth knowing:
Acoru's Consortium Manager enables financial institutions to collaborate through a real-time, privacy-preserving intelligence network. Instead of relying only on static blacklists, it shares dynamic account risk insights to improve fraud and mule account detection without exposing customer data.
Here is what it does:
- Continuously classifies account risk to help detect threats across institutions
- Enables secure information sharing using privacy-enhancing technologies, including encrypted processing and zero-knowledge proofs, without exposing customer data
- Integrates with existing fraud detection systems, allowing institutions to collaborate without replacing their current tools
- Supports collaborative fraud prevention while helping institutions comply with privacy regulations such as GDPR and GLBA
Strengthen Push and Pull Payment Fraud Detection with Acoru
Push and pull payments each introduce different fraud risks, but they have one thing in common: The payment itself is often the final step in a much longer chain of suspicious activity.
By the time funds move, fraudsters may have already compromised an account, manipulated a victim, created a fake mandate, or routed money through mule accounts.
Effective fraud prevention requires more than transaction monitoring. Financial institutions need continuous visibility into customer activity, account relationships, counterparties, merchants, and pre-fraud signals across the entire customer lifecycle.
Acoru delivers Continuous Account Intelligence, helping financial institutions detect both push- and pull-payment fraud earlier by analyzing how risk develops over time. Instead of evaluating transactions in isolation, it continuously monitors account activity to identify scams, mule accounts, unauthorized collections, and other emerging threats before losses occur.
With Acoru, you can:
- Detect fraud before payments are initiated: Continuously monitor pre-fraud signals, customer behavior, device activity, and account changes to identify elevated risk before transactions are confirmed.
- Assess both sides of the payment: Evaluate recipient accounts, merchants, creditors, and counterparties alongside customer activity to uncover hidden fraud risks that transaction monitoring alone may miss.
- Let AI do the heavy lifting, with your team in control: AI Workforce works in the background under your policy, clustering related risk into investigation packages and applying cooling-off periods or temporary limits, but never moves money without your sign-off. AI Assistant helps your team investigate faster, explaining flagged accounts and drafting detection rules in natural language.
- Apply risk-based responses: Use continuously updated account risk scores to trigger the right level of authentication, warnings, or investigation instead of applying the same controls to every customer.
- Collaborate securely across institutions: Share privacy-preserving account risk intelligence to identify mule networks and emerging fraud patterns without exposing customer data.
- Work alongside your existing fraud systems: Integrate with your current fraud detection and case management tools to enhance existing controls rather than replace them.
Request a demo today and discover how Acoru helps you stay ahead of evolving payment fraud.
FAQ:
1. Can scam detection tools catch fraudulent APP transactions?
Not always. Because APP fraud is authorized by the customer, these payments often pass standard authentication checks, making continuous monitoring of customer activity essential to identifying scams before the payment is initiated.
2. Which payment model is generally more difficult to recover after fraud?
Push-payment fraud is generally harder to recover because funds are often moved or withdrawn within minutes after the customer authorizes the transfer. Pull payments may offer dispute or return mechanisms, depending on the payment scheme, making recovery more likely in some cases.
In the UK, PS23/4 requires reimbursement for eligible APP scam victims, with the cost generally split 50/50 between sending and receiving payment providers, while Nacha’s 2026 rules require US financial institutions to strengthen fraud monitoring for ACH credit-push payments.
3. Why are money mule accounts difficult to detect?
Money mule accounts often behave like legitimate customer accounts in the early stages. Detecting them usually requires monitoring account activity, transaction patterns, and links to other accounts over time rather than relying on a single transaction.
4. Why is transaction monitoring alone not enough to detect payment fraud?
Many fraud schemes begin long before a payment is initiated. Changes such as new beneficiaries, updated contact details, new devices, or unusual login activity can provide earlier warning signs that are often missed when institutions monitor only transactions.