Instant Payments, Instant Losses: A Data Science Approach for the Era of APP Scams
For years, banks fought fraud by answering a main question: Is the person initiating this payment really who they claim to be? The industry’s largest investments in fraud prevention, from device fingerprinting and behavioral biometrics to multi-factor authentication and machine learning, were all designed to improve the confidence of that prediction. Authorized Push Payment (APP) scams are different.
Fraudsters have changed strategy.
Instead of stealing identities, they began manipulating them.
APP scams have rapidly become one of the most damaging forms of financial fraud, not because criminals have found a way to defeat authentication, but because they have learned how to bypass it altogether. In APP scams, nothing is stolen. The customer opens their own banking application, authenticates using their own credentials, verifies the transaction with Face ID or a one-time password, and willingly authorizes the payment. Whether persuaded by a fake investment opportunity, convinced they are helping a loved one in distress, or deceived into paying a supplier whose identity has been expertly impersonated, the victim performs every action the bank expects. The payment is genuine. The customer is genuine. Only the story behind the payment is fraudulent.
When the Customer Is Genuine, What Exactly Should the Model Predict?
As APP scams have become increasingly common, fraud models have had to solve a fundamentally different problem. Verifying the sender’s identity is no longer enough because, in most APP scams, the sender is exactly who they claim to be. The model may correctly conclude that the customer is genuine while still approving a payment that is destined for a fraudster.
Instead of estimating whether the sender is legitimate, modern models increasingly estimate whether the relationship between the sender and the receiver is legitimate. Has the customer ever paid this beneficiary before? Is the payment amount consistent with their history? Does this transaction resemble a genuine financial relationship, or the sudden creation of a new one?
At the same time, the receiver becomes just as important as the sender. A beneficiary account that was opened recently, has rapidly accumulated payments from unrelated individuals, or exhibits the behavior of a money mule carries valuable predictive signal. Even if the receiving account has never been confirmed as fraudulent, its connections may reveal otherwise. Is it linked to known mule accounts? Does it belong to a suspicious cluster of accounts sharing devices, phone numbers, or other infrastructure?
The prediction target has fundamentally changed. Instead of asking whether the sender can be trusted, modern APP models estimate both the legitimacy of the sender–receiver relationship and the likelihood that the recipient is connected to a broader network of fraudulent activity.
Can Human Manipulation Like APP Scams Leave a Statistical Signature?
Perhaps the most fascinating aspect of APP scams is that the fraud itself occurs almost entirely outside the banking application. The manipulation happens during phone calls, text messages, social media conversations, fake investment platforms, or carefully orchestrated impersonation campaigns. By the time the customer opens their banking app, the psychological attack has already succeeded.
Yet even human persuasion often leaves subtle traces in digital behavior.
Customers under manipulation frequently behave differently from customers making routine financial decisions. They hesitate before confirming unusually large payments, repeatedly edit beneficiary details, copy and paste account information between applications, remain on lengthy phone calls throughout the payment session, or initiate transfers while remote-access software is active on their device. None of these behaviors independently indicates fraud, and many occur during perfectly legitimate transactions. Their value emerges only when hundreds of weak behavioral signals are combined into a statistical model capable of estimating whether the customer’s decision-making process appears unusually influenced.
In many respects, fraud models are no longer attempting to recognize stolen identities. They are attempting to recognize the digital footprints of human manipulation.
How Do You Train a Model When the Answers Arrive Months Later?
Unlike card fraud, APP fraud rarely provides immediate feedback. A fraudulent card transaction often generates a chargeback within days or weeks, giving data scientists a relatively reliable label for future model training. APP fraud is far less cooperative. Victims may even spend months believing the payment was legitimate before realizing they have been deceived. Some never report the fraud at all, either because of embarrassment or because they continue trusting the fraudster.
For a data scientist, this creates a difficult learning problem. Machine learning depends on historical examples, yet many of the examples are incomplete, delayed, or simply incorrect. Before improving model performance, teams must first determine which historical transactions genuinely represent social engineering and which do not. The challenge is no longer limited to building better algorithms; it begins with constructing trustworthy training data.
Why Can No Bank Solve APP Scams Alone?
Even the most sophisticated fraud model is constrained by the information available to it. A bank can observe every interaction its own customers have with its own accounts, but APP scams rarely remain confined within a single institution. The receiving account collecting fraudulent payments today may already have attracted suspicious transfers from dozens of other banks before the next payment request ever arrives.
Viewed from one institution, the account may appear entirely ordinary. Viewed across the financial ecosystem, it may already be part of a rapidly expanding mule network.
This fragmented visibility has accelerated investment in consortium intelligence, real-time signal sharing, and cross-institutional risk scoring. Rather than relying exclusively on internal history, modern fraud platforms increasingly enrich their models with external intelligence describing the behavior of receiving accounts across the broader banking network. As instant payment schemes continue to expand, predictive accuracy will depend not only on better machine learning models, but also on better collective visibility.
The Future Is Relationship Intelligence
As real-time payments expand and AI-powered scams become increasingly convincing, fraud models will continue shifting away from verifying identities toward understanding relationships. The competitive advantage will no longer come from knowing who initiated the payment, but from understanding who they are paying, how they are connected, and whether that relationship makes sense.
No institution, however sophisticated its models, can solve this problem alone. The future of APP scam prevention will depend not only on better data science, but on greater collaboration where financial institutions share intelligence, enrich each other’s models, and collectively identify criminal networks before the next payment is sent.



















