Authorised push payment (APP) fraud is the largest category of bank fraud affecting UK businesses. Unlike traditional card fraud or account takeovers — where criminals act without your knowledge — APP fraud works by deceiving you or your staff into authorising the payment yourselves. The bank, from its perspective, sees an authorised transfer. Getting that money back has historically been very difficult.
That changed when the Payment Systems Regulator (PSR) introduced mandatory reimbursement rules for APP fraud on Faster Payments. But the rules have important limits, and prevention is still the right strategy.
How APP Fraud Hits Small Businesses
The mechanism is almost always social engineering — convincing someone in the business to authorise a payment to a fraudulent account. The most common patterns:
Invoice payment redirection. A criminal either hacks into your email or your supplier’s email, monitors communications, and intercepts at the right moment to send a fake invoice or payment instruction with changed bank details. Or they impersonate a supplier convincingly enough to get you to update payment records. A payment you believe is going to your legitimate supplier goes to a mule account instead.
CEO or director impersonation. A staff member responsible for payments receives an urgent request from what appears to be a director or business owner to make a transfer — often to a new account or for an unusual reason. The urgency is designed to bypass normal approval processes. In smaller businesses where the owner often calls in with quick requests, this works.
Fake supplier setup. During a new supplier onboarding process, a fraudster poses as the legitimate company and provides fraudulent bank details before proper verification has been completed.
Pension or investment fraud. Business owners are targeted with offers of unusually high-return investment products, leading them to authorise transfers from business accounts to fraudulent platforms.
The Mandatory Reimbursement Rules: What They Actually Cover
The PSR’s mandatory reimbursement scheme requires banks to reimburse APP fraud victims in most cases, split 50/50 between the sending and receiving bank.
But there are exclusions that matter:
- Claims are rejected if the bank determines you had “gross negligence” — ignoring specific fraud warnings, disregarding reasonable bank warnings during the transaction, or failing to verify recipient details in ways a reasonable business would.
- Business accounts have historically received different treatment from personal accounts under the PSR framework. Check your specific bank’s policy for business customers.
- International transfers via SWIFT or CHAPS have separate rules — the Faster Payments reimbursement scheme doesn’t automatically apply.
The practical takeaway: the reimbursement rules are useful protection but not a guarantee. Banks are rejecting claims where businesses ignored their own verification steps or proceeded despite fraud warnings. Prevention remains the right posture.
Verification Practices That Actually Stop APP Fraud
Call back on a known number for any payment instruction change. If a supplier, customer, or internal contact requests a change to payment details, verify by calling a phone number you already have in your records — not a number provided in the same communication asking for the change. This is not a marginal improvement; it stops the vast majority of invoice redirection fraud.
Confirm new supplier bank details before the first payment. When onboarding a new supplier, call their publicly listed number to confirm the account details you’ve been given. The check takes two minutes; the loss if you skip it can be tens of thousands.
Require dual authorisation for payments above a threshold. Set an internal rule that transfers above a set amount (£2,000–£5,000 depending on your business) require approval from two named individuals, not just the person initiating the payment. This creates a second check without requiring anyone to catch the fraud themselves.
Don’t override bank fraud warnings. When your bank’s fraud detection flags a payment and prompts you to confirm you’ve verified the recipient, that is not a formality. Stop, verify by an out-of-band method, and then proceed — or don’t proceed. Overriding the warning and then discovering the payment was fraudulent weakens your reimbursement claim significantly.
Use Confirmation of Payee checks. Most UK business banking platforms now have Confirmation of Payee (CoP) — a system that checks whether the account name matches the sort code and account number you’re paying. If CoP returns a mismatch or partial match, stop and verify before proceeding. A mismatch isn’t always fraud (the account holder name might be a trading name), but it’s always worth a verification call.
Protecting Your Online Banking Access
Beyond payment authorisation, the business banking account itself is a target:
Enable transaction notifications for all outgoing payments. Real-time notifications mean fraudulent activity is detected as it happens, not when you review the statement weekly. Most business banking apps support this at no extra cost.
Know your bank’s fraud reporting number and have it saved. If you suspect a fraudulent payment has been authorised, calling immediately — within minutes where possible — increases the chance of the payment being recalled. CHAPS payments in particular have a brief window for recall before funds are released.
Review authorised app connections to your banking. Open banking connections and third-party apps with access to your business bank account accumulate over time. Review them periodically under your banking settings and revoke any that are no longer in active use.
Use a dedicated device for high-value banking activity where practical. A device used only for banking and accounting is significantly harder to compromise than a general-purpose work laptop used for email, browsing, and software. Not practical for all businesses, but for sole traders or small teams with high-value payment flows, it reduces exposure.
What to Do If It Happens
If a fraudulent payment has been made:
- Call your bank’s fraud line immediately — not general customer service. Every minute reduces recovery chances as the receiving bank may not yet have processed the transfer.
- Report to Action Fraud at actionfraud.police.uk — you’ll need this reference number for your reimbursement claim.
- Document everything — the fraudulent communication, payment details, timeline of events, and any warnings you may have seen and how you responded to them.
- Make a formal reimbursement claim with your bank under the APP fraud reimbursement scheme. Be specific about the circumstances and do not downplay what happened.
The PSR mandatory reimbursement rules have materially improved the position of UK businesses that fall victim to APP fraud. But the claims process takes time, the exclusions are real, and cash flow disruption during the process can be significant. The better outcome is not needing to make the claim.