The customer approved it.
That doesn't make it legitimate.

In Authorized Push Payment (APP) fraud, the bank’s controls often work as designed. The customer initiates the transfer, so identity and device checks pass clean. What gives the scam away is the footprint left by the exploit technique: a small probe payment, then others that rotate through fresh beneficiaries, alongside unusual amounts and an out-of-character sequence. Vyntra reads the footprint and detects the manipulation before the money leaves.

lost to financial fraud globally in 2025

$ 0 B
Source: INTERPOL, 2026

more profitable when fraud is AI-enhanced

0 x
Source: INTERPOL, 2026

ost to APP fraud in the UK in 2024

£ 0 M
Source: UK Finance, 2025

The core challenge

When the human is the attack surface.

APP fraud exploits customer consent rather than system vulnerabilities. The victim is often groomed over time, with psychological and technical manipulation combined until the payment is made, leaving emotional and financial havoc. Vyntra combines the transactional footprint the scam leaves behind with behavioral biometrics, session and device intelligence signals, including device fingerprints, as well as community intelligence (CS&I) for real-time detection that reaches further than any one of these approaches could on its own.

Social engineering & psychological manipulation

The payment clears customer confirmation, and advanced fraud techniques can carry it past traditional systems, including manipulating the customer into sharing a one-time password (OTP). Only the behavioral context around it gives the scam away: a probe payment sent earlier to a new beneficiary, an unusual amount, an active phone call, a signal shared by another institution.

How Vyntra detects it

Authorized push payment at industrial scale

Modern scam operations don’t target one victim at a time. AI and automation let criminal networks groom victims around the clock, running the same playbook against hundreds of customers at once, using generative AI to personalize every message, recycling beneficiary IBANs and refining their modus operandi with every iteration. Speed and cross-customer pattern detection are the defense.

How Vyntra detects it

Scam proceeds on the mule side

When an APP victim transfers funds, those funds land in a mule account at another bank. Without inbound monitoring on the receiving side, the rinsing of scam proceeds, a common form of money laundering, is invisible. The receiving institution absorbs the reputational and regulatory exposure without ever knowing it happened.

How Vyntra detects it

Business Email Compromise & invoice fraud

BEC attacks target the payment instructions themselves. Attackers compromise corporate email accounts, intercept supplier invoice threads, or impersonate a CFO to redirect legitimate payments to fraudulent IBANs. The victim believes it is paying a known counterparty.

How Vyntra detects it

GET IN TOUCH

The consent was manipulated.
The fraud can still be caught.

See how Vyntra detects social engineering patterns, industrial-scale scam campaigns, Business Email Compromise, and mule-side rinsing — all in one platform, in real time.

FAQs​

How can APP fraud be detected when the customer authorized the payment?
APP fraud detection looks beyond whether the customer successfully authenticated and approved the transfer. It analyses the payment’s wider context, including the beneficiary, amount, timing, device intelligence and the customer’s usual behaviour. Vyntra combines these signals into a real-time risk score, helping identify signs of manipulation before funds leave the account.
Banks can reduce false positives by assessing each payment against the customer’s normal behavior rather than relying solely on fixed rules or transaction limits. Combining behavioral profiling, anomaly detection and community intelligence helps distinguish genuinely suspicious payments from legitimate changes in customer activity. Payments that require investigation can then be routed into case management with the relevant context attached.
Machine learning models can identify combinations of signals that may be difficult to capture through individual rules. These can include a first-time beneficiary, an unusual amount, a new IP address, unexpected device fingerprints or several payments made in quick succession. Use machine learning within fraud detection software to analyze these patterns in real time and adapt as scam behavior changes.
No. Identity verification, multi-factor authentication and one-time password controls help establish that the person accessing an account has passed the required security checks. In an APP scam, however, the genuine customer may complete every check after being manipulated by a fraudster. Vyntra adds another layer of fraud prevention by assessing the payment and surrounding behavior even when authentication has succeeded.
Transaction monitoring can help identify mule activity by analyzing incoming and outgoing payment patterns. Warning signs may include funds arriving from several unrelated accounts and being transferred onward shortly afterwards. Apply behavioral analysis to these patterns, to help receiving institutions identify suspected mule accounts, support money laundering controls and share confirmed risk signals with other financial institutions.