Skip to content

Independent industry intelligence in your inbox. Unsubscribe any time - every newsletter carries a one-click link.

Compliance

APP Fraud (Authorised Push Payment Fraud)

Authorised Push Payment Fraud

Definition

Fraud in which a player is manipulated into authorizing a payment to a criminal, increasingly relevant under open banking deposit flows.

Why it matters

APP fraud is one of the fastest-growing fraud categories in the wider payments industry and is starting to affect gambling operators directly as open banking and instant payment rails become standard deposit methods. The pattern typically involves social engineering: a player is convinced to make a deposit that ultimately benefits a fraudster, whether through fake account-takeover assistance, impersonated customer support, or romance scams that pressure the victim to gamble or transfer funds.

For operators, the issue is that APP-fraud transactions are technically authorized by the legitimate account holder, so traditional fraud signals (unfamiliar device, unfamiliar IP) don't fire. The detection signal moves to behavioral patterns: unusual deposit timing, mismatch between deposit and play, social engineering keywords in customer support conversations. UK regulation now mandates reimbursement of APP fraud victims by their banks under defined conditions, which puts pressure on operators to reduce the gambling sector's contribution to APP loss statistics.

Frequently asked questions

  • Are operators liable for APP fraud losses?

    Generally not directly. The liability framework in markets like the UK assigns reimbursement to the receiving and sending banks under the new mandatory reimbursement rules. Operators are not part of that scheme. However, operators that consistently appear as the destination for APP fraud transactions can come under regulatory and reputational pressure.

  • How does open banking change the APP fraud picture?

    Open banking enables instant deposits without card friction. The same convenience benefits fraudsters, because authorized push payments are irreversible once made. Operators implementing open banking deposits typically add session-level checks and slowed-flow options for first-time large deposits to mitigate exposure.

Cookie Preferences

Choose which cookies you want to accept. Essential cookies are required for the website to function properly.

Required

Necessary for the website to function. Cannot be disabled.

Help us understand how visitors interact with our website.

Used to deliver relevant advertisements and track ad performance.

Remember your preferences and settings for a better experience.