The customer approved it.
That doesn't make it legitimate.
In Authorized Push Payment (APP) fraud, the bank’s controls often work as designed. The customer initiates the transfer, so identity and device checks pass clean. What gives the scam away is the footprint left by the exploit technique: a small probe payment, then others that rotate through fresh beneficiaries, alongside unusual amounts and an out-of-character sequence. Vyntra reads the footprint and detects the manipulation before the money leaves.
lost to financial fraud globally in 2025
more profitable when fraud is AI-enhanced
ost to APP fraud in the UK in 2024
The core challenge
When the human is the attack surface.
APP fraud exploits customer consent rather than system vulnerabilities. The victim is often groomed over time, with psychological and technical manipulation combined until the payment is made, leaving emotional and financial havoc. Vyntra combines the transactional footprint the scam leaves behind with behavioral biometrics, session and device intelligence signals, including device fingerprints, as well as community intelligence (CS&I) for real-time detection that reaches further than any one of these approaches could on its own.
Social engineering & psychological manipulation
The payment clears customer confirmation, and advanced fraud techniques can carry it past traditional systems, including manipulating the customer into sharing a one-time password (OTP). Only the behavioral context around it gives the scam away: a probe payment sent earlier to a new beneficiary, an unusual amount, an active phone call, a signal shared by another institution.
How Vyntra detects it
- AI profiling detects payments to beneficiaries outside the customer's established transfer history and risk profile
- The transactional footprint, built on continuous transaction monitoring, reveals cumulative exposure building across a scam campaign, since the first transfer is almost always followed by more
- AI profiling detects payments to beneficiaries outside the customer's established transfer history and risk profile
Authorized push payment at industrial scale
How Vyntra detects it
- Pattern-Based Intelligence detects coordinated surge patterns across the customer base, flagging campaigns before they spread
- Community signals flag beneficiary IBANs already confirmed as fraudulent elsewhere and score them as weighted features rather than a static blacklist
- Successive transfers from the same account are flagged from the transactional footprint once the first suspicious payment fires
Scam proceeds on the mule side
How Vyntra detects it
- Inbound detection profiles incoming flows in near-real time, detecting the receive-then-forward pattern characteristic of mule rinsing
- Frequency of receipts from diverse sending institutions, variability in amounts, and time-of-day patterns trigger mule scoring
- Confirmed mule accounts feed back into the community intelligence network, so peer institutions benefit from the signal immediately
Business Email Compromise & invoice fraud
BEC attacks target the payment instructions themselves. Attackers compromise corporate email accounts, intercept supplier invoice threads, or impersonate a CFO to redirect legitimate payments to fraudulent IBANs. The victim believes it is paying a known counterparty.
How Vyntra detects it
- AI profiling flags a new IBAN behind a known supplier name, the primary BEC indicator, scored at payment initiation
- Unusual amount, first-time beneficiary and out-of-hours instruction are scored in combination, catching payments that pass each rule alone
- Pattern-Based Intelligence spots coordinated campaigns, where multiple corporates are directed to the same fraudulent IBAN, and alerts before they spread
GET IN TOUCH
The consent was manipulated.
The fraud can still be caught.
See how Vyntra detects social engineering patterns, industrial-scale scam campaigns, Business Email Compromise, and mule-side rinsing — all in one platform, in real time.