What is authorised push-payment fraud?¶
Authorised push-payment fraud occurs when a victim is deceived into instructing their bank or payment provider to send money to an account controlled by, or accessible to, an offender.
Avoid this assumption: That because the victim entered the payment details and completed authentication, the transaction was genuinely voluntary and informed. The payment instruction may be technically authorised by the victim.
The fraud lies in the false explanation, impersonation or pressure that caused the instruction.
Common scenarios include impersonation of banks, police, suppliers, employers, investment services, relatives or conveyancers.
The victim may be told that funds must be moved to a safe account, an invoice must be paid, an investment opportunity will expire or a family member needs urgent help.
Provider records may show the victim’s normal device, IP address, beneficiary creation, authentication and payment confirmation.
Those records establish the technical transaction process.
They do not establish that the victim understood the true identity of the recipient or the real purpose of the payment.
Preserve the complete payment record, beneficiary details, warning messages, authentication events and transaction references.
Preserve calls, emails, messages, invoices, payment instructions and any remote-access activity.
Establish what the victim was told, what they believed and whether recipient details changed during the interaction.
Do not describe the payment as merely “authorised” without explaining the deception.
When reporting, distinguish technical authorisation, informed consent, deception and the onward movement of the funds.
Operational takeaway¶
Treat authorised push-payment fraud as a technically approved payment induced by deception, and prove the fraud through communications, warnings, timing, recipient details and transaction evidence.