Last year, UK customers sent more than £576 million (~$780 million) to criminals in payments they made themselves. That is up 19% in a single year, even as other types of fraud went down.
These payments did not come from stolen logins. Not malware. Not a password reset.
The account holder was fed a story, believed it, and willingly pressed send.
That is what we call authorized push payment (APP) fraud. The customer authorizes the payment. The credentials are valid. The transaction clears. The money is gone.
Sometimes the scenarios are quite ordinary. You buy concert tickets online, or a puppy, or a used couch. You pay by bank transfer, and nothing ever arrives.
Sometimes it is a lot of money, and it moves fast. Deepfakes are everywhere now, and the people using them are good at manufacturing urgency. You get a phone call from someone who sounds completely legitimate, telling you your money is not safe where it is and you need to move it right now. So you do. Or they tell you a bill is past due and you will be arrested if you do not pay immediately, and in a panic you scramble to make the payment. Or maybe you list an item for sale on a marketplace, and the buyer says they accidentally sent you too much and asks you to refund the difference. This is the fastest-growing method in fraud today. Deloitte expects AI-enabled fraud losses in the US to reach $40 billion by 2027, up from about $12 billion in 2023.
In these scenarios, and many more, the customer voluntarily pressed the button to send money. These are not one-off cases of careless people. Even smart people who know the tricks can be fooled. This could happen to anyone.
And by the time anyone reacts, it is already too late.
Here is what leaders in the financial industry find so frustrating.
By the time the fraud is spotted, the money is already on the move. It lands in one account, splits into three, and keeps going. In India, the central bank identified 2.65 million accounts set up to do exactly this kind of relay work.
Once the money has moved through that chain, getting it back is close to impossible. Chargebacks are not an option. On instant payment rails, including stablecoins, the payment is final in seconds.
So it all comes down to timing. And right now, the timing is not on our side.
Fraudsters are nimble. If one version of a scam stops working, they are on to another one that same afternoon. New wording. A new account. A slightly different story. They learn fast, because nothing is slowing them down.
Now look at how most financial institutions respond.
Financial institutions run on governance. Every new rule goes through review, approval, and testing before it can go live. It can take days, weeks, or even months to adjust a threshold after a loss report comes in. A suspicious payment often sits in a queue until someone has the bandwidth to review it. For an overnight attack, that means the morning.
That is how the systems are built. Sign-offs. Evidence before action. For most of banking history, that caution worked well, because money moved slowly enough for institutions to catch up with it.
That has changed. AI makes the criminal’s job easier. And money moves faster. Our review systems have not been updated to reflect this new reality.
I need to say this, because it does not get talked about enough.
A lot of the fraud detection running at financial institutions today does not happen in real time. It happens after the transaction has already moved. On a batch. Overnight. The next business day.
That worked fine when a transfer took days to settle. There was time to pull it back.
That does not work in today’s environment. When your fraud detection runs after a transaction has been initiated, and the money has already moved through three other accounts, you no longer have a fraud control. You have a report of what you lost.
There is no one tool that can stop this cleanly. The customer authorized the payment, so the login looks exactly like the real account owner. With only a single fraud tool in play, no alert gets tripped. It is easy to miss.
What improves the odds is layering the signals, and reading them while the payment is still in your control.
Is this the customer’s usual device, or one that showed up an hour ago under a different user? Does the way they are moving through the app match how this person normally behaves? Has the destination account been rapidly funneling money into other accounts, the way a mule account does?
Device profiling. Behavioral biometrics. Account and beneficiary risk. On its own, each tool gives you only part of the picture. Together, in the moment, they give you enough to pause a payment for a second look before it is final, instead of analyzing it after it is too late.
This is what I mean when I talk about a Real-Time Control Layer™. It is the one place where all of those signals meet and become a single decision your institution designed and can actually explain. You are not rebuilding your whole stack. You are making one point in the flow dependable.
So here is what I would say to senior leaders.
After check fraud, authorized push payment fraud is the largest category of fraud loss at many institutions, making up 32% of all fraud losses. It is also the fastest-growing category of payment fraud. Investment scams alone jumped 40% last year, to a record £221.5 million (~$300 million). It is also one of the most under-funded, relative to the losses it produces. Part of the reason is that these defenses are hard to see and touch. Their value is not obvious, so the budget quietly flows to more visible things.
Do not let it. This is the biggest vulnerability most of you face right now.
Share this with a colleague. This is the biggest threat most financial institutions are dealing with, and they still aren’t allocating enough resources to it.
And do not scope your security solutions too narrowly. This is not an instant payments problem. Authorized push payment fraud runs across every channel and every payment type you operate. The exposure is not limited to your instant rails. Instant is just where the speed of the money turns an existing weakness into a loss you cannot reverse.
The payoff is worth it, and it will lower your fraud loss ratio.
The same tool that stops an ACH scam is what lets you say yes to instant payments Send with confidence, instead of holding back out of fear. Defense in depth stops being a cost you resent. It becomes the reason you can grow your business and better serve your customers and your institution.
We know what is coming. Today, you are dealing with a human attacker using deepfakes to convince a human, your customer or your agent, to press send. But tomorrow? The thing pressing send is an AI agent, with no hesitation to exploit and no second thoughts to catch. And the receiver may no longer be human either. Right now, the human in the loop is a signal you still have. It is worth using while you have it.
The ecosystem is evolving fast. Pandora’s box is open. You cannot slow the bad actors down. You cannot slow the money down. You cannot always trust the story behind a transaction. The one thing you can still control is how, and when, you decide. That is not a smaller job for governance. It is a bigger one. It is what an architecture of calm is actually made of.
Here is the question worth taking into your next risk conversation. If your fraud defense only sees the payment after it clears, what is it actually defending?
If your leadership team would benefit from this perspective in the room, I’d welcome the conversation.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.