What is a peer-to-peer payment?¶
A peer-to-peer payment is a transfer of money or value between users of a payment service, often using an email address, phone number, username or payment handle.
Avoid the dangerous assumption¶
The dangerous assumption is that the sender and recipient names prove the identities of the people who controlled the transaction.
The payment may remain within the provider’s internal system or be funded by a linked card, bank account or stored balance.
Relevant records may include sender and recipient account IDs, payment handle, amount, currency, timestamp, transaction reference, funding source, status and any message attached to the payment.
The provider may also hold device, session, IP address, authentication and account-security records.
A payment can be sent to the wrong handle, redirected, refunded, reversed or withdrawn to another account.
The recipient account may belong to a mule, associate, business, shared user or compromised victim.
A payment note or emoji may be useful context, but it does not prove the true purpose of the transfer.
Preserve both parties’ identifiers exactly and determine whether the transfer was internal or moved through another provider.
Ask the service for account, access, funding and withdrawal records for both sides where lawful and proportionate.
Compare the payment with communications, device evidence and subsequent movement of funds.
Do not assume that the person whose bank account funded the payment controlled the peer-to-peer account.
When reporting, distinguish the platform account, funding source, recipient account and actual user.
Operational takeaway¶
Trace peer-to-peer payments through the service accounts, funding source and withdrawal destination, and establish the users through provider, device and contextual evidence.