Zarv

Authorized push payment fraud (APP)

Also known as: APP fraud · Authorized push payment fraud · Push payment scam · Social engineering scam · Scam

A scam in which the victim themselves is tricked into authorizing a payment to the fraudster — believing in a fake bill, person or opportunity — rather than having their account hacked.

Legal basis

Wikipedia — Authorised push payment fraud

In authorized push payment (*APP*) fraud there is no break-in: the victim makes the transfer themselves, convinced by social engineering. It is the fake bank employee, the fake relative over text, the doctored invoice, the bogus investment opportunity. Because the transaction is authorized by the account owner, from the system's point of view it is legitimate — which is exactly why classic access controls do not stop it.

In the US, instant rails like Zelle, FedNow and RTP made this the central risk: settlement is immediate and effectively irreversible, so the money is gone before the scam is noticed. The defense shifts from "was it really the owner?" to "does this payment make sense?": a payee never seen before, an out-of-pattern amount, unusual haste and hours, signs of coercion in the session. The CFPB has pressed banks on reimbursement for these scams precisely because the money moves faster than the victim can react.

Frequently asked questions

What is authorized push payment (APP) fraud?

It is a scam in which the victim is tricked into authorizing the payment to the fraudster — believing in a fake bill, person or opportunity. Unlike a hacked account, the owner makes the transfer, which makes the transaction look legitimate to the system and hard to block.

Sources

Related terms

See it in practice

See risk before it costs you.

GDPR & CCPA Compliant · No commitment · Live in minutes