Push and pull payments may seem similar, but each presents a unique set of fraud risks that financial institutions must understand and manage.
The US Federal Reserve reported that noncash payments have more than tripled since 2000, reaching 236.6 billion transactions in 2024. As payment activity continues to grow, financial institutions need to understand where each payment model is most vulnerable and adapt their fraud controls accordingly.
In this article, we'll explore push vs. pull payments and strategies to better detect and prevent payment fraud.
Before exploring each payment model in detail, here's a quick overview of the key differences:
|
Area |
Push payments |
Pull payments |
|
Initiating party |
Payer or sender |
Merchant, creditor, or recipient |
|
Typical examples |
Bank transfers, wire transfers, instant payments, person-to-person transfers |
Direct debits and recurring collections |
|
Authorization |
Usually provided for each payment |
Often provided in advance through a mandate |
|
Main fraud concern |
Manipulated or compromised payer authorization |
Invalid, stolen, exceeded, or fabricated permission |
|
Common fraud types |
|
|
|
Customer involvement |
Customer typically initiates or authorizes the payment |
Customer may not interact with each individual payment |
|
Recovery |
Often difficult after funds are credited and moved |
Dispute and return rights may be available, depending on the system |
|
Important risk focus |
Session activity, beneficiary risk, and receiving accounts |
Mandate validity, merchant behavior, collection patterns, and disputes |
Push payments are transactions where the person or organization sending the money initiates the transfer. The bank customer instructs their bank or payment service provider to send funds directly from their account to a specific recipient. Common examples include:
Once the payment is authorized and submitted, the funds are pushed from the sender's account to the recipient's account.
While the exact process depends on the payment method and network being used, it generally follows these steps:
Push payments come with unique fraud risks because the sender authorizes the transfer. Criminals often trick or manipulate the payer before the payment is made.
Authorized push payment (APP) fraud occurs when a customer is manipulated into sending money to an account controlled by a criminal. Since the payment is approved by the legitimate user, conventional authentication controls may not identify it as fraudulent.
Common forms of APP fraud include:
APP fraud remains a major threat despite continued investment in detection and customer education. UK Finance reported £576.4 million in APP fraud losses during 2025, a 19% increase from 2024. Personal losses accounted for £500.8 million, while non-personal losses accounted for £75.6 million.
These losses can directly impact banks' finances. Under the UK’s PS23/4 reimbursement rules, payment service providers must reimburse eligible APP scam victims up to £85,000 per claim, with the cost generally split equally between the sending and receiving providers.
In an account takeover, a fraudster obtains access to a victim’s online or mobile banking account. Access may be gained through phishing, malware, credential stuffing, SIM swapping, social engineering, or compromised devices.
Once inside the account, the fraudster may:
Unlike APP fraud, this type of fraud doesn't involve the victim authorizing the payment. However, the transaction may still pass authentication if the criminal has gained access to relevant credentials or persuaded the user to share a one-time passcode used to approve the payment.
Businesses regularly use push payments to pay suppliers, contractors, and other business partners. Fraudsters exploit these trusted relationships by gaining access to business email accounts or by creating convincing fake emails that appear to come from a legitimate contact.
A common tactic is to impersonate a trusted supplier by sending a convincing email claiming that the supplier has updated its bank details. The message often appears genuine because it uses familiar branding, references recent invoices or projects, or is sent from a compromised email account, leading the business to redirect future payments to a fraudulent account.
In the US, Nacha’s Phase 2 fraud-monitoring rules now specifically address these scenarios. The rules require risk-based processes and procedures designed to identify ACH entries suspected of being unauthorized or authorized under “False Pretenses,” including business email compromise and vendor impersonation.
Many push payment scams rely on money mule accounts to receive and move stolen funds. These accounts may belong to:
Once the money is deposited, it is often moved as quickly as possible to make it harder to trace. Criminals may split the funds across multiple accounts, convert them into cryptocurrency, withdraw them as cash, or transfer them overseas.
With instant payment systems, this can happen within minutes, leaving financial institutions with very little time to detect fraud and recover funds.
Worth knowing:
Acoru helps financial institutions identify money mule accounts before they become part of a larger fraud network. It continuously analyzes account activity, transaction patterns, counterparty relationships, and pre-fraud signals to detect suspicious activity as it develops.
Accounts are automatically classified as Regular, Victim, Mule, Launderer, or Honeypot, with mule accounts further categorized as complicit, witting, or unwitting. Each account receives a 0-1,000 risk score, allowing fraud teams to monitor how risk changes over time and intervene before stolen funds are moved further.
Pull payments are initiated by the recipient, merchant, or creditor under authorization granted by the payer. Instead of the payer sending a new instruction for each transaction, the payee submits a request to collect funds from the payer’s account.
Direct debits, subscription payments, and many recurring billing arrangements are common examples of the pull payment model.
A typical pull payment follows these steps:
Pull-payment fraud generally involves stealing payment credentials, fabricating authorization, misusing a valid mandate, or collecting an amount the payer did not knowingly authorize.
Pull payments require customer authorization before funds can be collected. Fraud occurs when criminals create fake authorizations, alter legitimate ones, or misuse a customer's permission to collect money.
Potential warning signs include:
In this type of fraud, criminals use stolen bank account details to withdraw money from a customer's account without their permission. They may obtain these details through phishing attacks, data breaches, fake websites, stolen documents, or other forms of data theft.
To collect the funds, the fraudster uses the stolen bank details to set up a fraudulent authorization or falsely claim permission to collect money from the account. They then submit debit requests through a merchant or payment service provider that participates in the direct debit scheme.
Because the payment appears to be supported by a valid direct debit authorization, the funds may be withdrawn before the customer realizes anything is wrong. The account holder may not notice the unauthorized transaction until they review their account statement or receive a balance notification.
The ability to dispute pull payments protects customers, but it can also be exploited. First-party misuse, sometimes called “friendly fraud” in the card industry, occurs when a customer disputes a transaction they authorized. They may falsely claim that:
Push and pull payments require different controls, but neither should be monitored in isolation. Financial institutions can strengthen their protection by following these best practices:
A single event, such as a large payment to a new beneficiary, can be a warning sign. But looking at what happened before the payment often tells a much clearer story. For example, a customer might:
The same idea applies to pull payments. A merchant might change its settlement account, start collecting larger volumes of payments, begin charging many new customers, and then suddenly see a spike in disputes.
Analyzing these events as part of a sequence, rather than as isolated activities, makes it easier to identify suspicious activity early and intervene before additional losses occur.
Worth knowing:
Acoru continuously monitors pre-fraud signals that often appear before a suspicious transaction takes place. These include:
By correlating these events over time rather than evaluating each one in isolation, Acoru helps you identify high-risk activity earlier and with greater confidence.
A push payment may appear completely legitimate when you monitor only the sender's account and activity. However, the recipient account may already be linked to a money mule network or other fraudulent activity that would not be detected without examining both sides of the transaction.
Likewise, a pull payment may seem legitimate to the customer, while the merchant requesting the funds is generating an unusually high number of complaints or disputes.
Worth knowing:
Acoru helps you assess recipient accounts before a payment is initiated. When a recipient account is added, Acoru analyzes previous interactions captured in the institution's own customer and transaction data to provide additional risk context. This helps determine whether the account has been associated with suspicious activity in the past.
Not every unusual payment is fraudulent, so blocking every suspicious transaction can create unnecessary frustration for your customers and increase operational costs. Instead, you should match your response to the level of risk. Depending on the situation, you may:
Worth knowing:
Acoru continuously classifies and scores account risk throughout the customer journey. Before a transaction is confirmed or 2FA/SCA is completed, Acoru will have already generated a risk score using all available historical account data. This could be data from the financial institution’s internal channels or data collected by behavioral analytics, device intelligence, or other fraud tools.
This allows you to apply the appropriate level of verification based on the account's current risk, instead of evaluating every payment or session in isolation at a specific point in time.
Fraudsters often move money through multiple financial institutions, making it difficult for any single bank to see the full picture. One institution may notice unusual behavior from the sender, while another sees the same recipient receiving payments from many unrelated people. On their own, these signals may not be enough to identify fraud.
By securely sharing account risk insights, financial institutions can detect mule networks, identify suspicious payment patterns earlier, and stop fraudulent funds before they are moved again.
Modern privacy-enhancing technologies, such as encrypted processing and zero-knowledge proofs, enable the exchange of meaningful risk information securely without exposing any PII. This gives you better visibility into cross-bank fraud while maintaining privacy and regulatory compliance.
Worth knowing:
Acoru's Consortium Manager enables financial institutions to collaborate through a real-time, privacy-preserving intelligence network. Instead of relying only on static blacklists, it shares dynamic account risk insights to improve fraud and mule account detection without exposing customer data.
Here is what it does:
Push and pull payments each introduce different fraud risks, but they have one thing in common: The payment itself is often the final step in a much longer chain of suspicious activity.
By the time funds move, fraudsters may have already compromised an account, manipulated a victim, created a fake mandate, or routed money through mule accounts.
Effective fraud prevention requires more than transaction monitoring. Financial institutions need continuous visibility into customer activity, account relationships, counterparties, merchants, and pre-fraud signals across the entire customer lifecycle.
Acoru delivers Continuous Account Intelligence, helping financial institutions detect both push- and pull-payment fraud earlier by analyzing how risk develops over time. Instead of evaluating transactions in isolation, it continuously monitors account activity to identify scams, mule accounts, unauthorized collections, and other emerging threats before losses occur.
With Acoru, you can:
Request a demo today and discover how Acoru helps you stay ahead of evolving payment fraud.
Not always. Because APP fraud is authorized by the customer, these payments often pass standard authentication checks, making continuous monitoring of customer activity essential to identifying scams before the payment is initiated.
Push-payment fraud is generally harder to recover because funds are often moved or withdrawn within minutes after the customer authorizes the transfer. Pull payments may offer dispute or return mechanisms, depending on the payment scheme, making recovery more likely in some cases.
In the UK, PS23/4 requires reimbursement for eligible APP scam victims, with the cost generally split 50/50 between sending and receiving payment providers, while Nacha’s 2026 rules require US financial institutions to strengthen fraud monitoring for ACH credit-push payments.
Money mule accounts often behave like legitimate customer accounts in the early stages. Detecting them usually requires monitoring account activity, transaction patterns, and links to other accounts over time rather than relying on a single transaction.
Many fraud schemes begin long before a payment is initiated. Changes such as new beneficiaries, updated contact details, new devices, or unusual login activity can provide earlier warning signs that are often missed when institutions monitor only transactions.