< Back to all clusters
[BUSINESS] · 2 sources

started · updated

Financial fraud evolves as APP scams bypass traditional authentication

Financial institutions are facing evolving challenges in fraud detection, specifically regarding the distinction between identity authentication and user intent. While traditional controls focus on verifying that a user is the legitimate account holder through transaction data, KYC (Know Your Customer) datasets, and behavioral analytics, these methods are increasingly bypassed by Authorized Push Payment (APP) scams.

In APP fraud, criminals use social engineering to manipulate customers into authorizing payments themselves. Because the customer uses their own device and passes all multifactor authentication checks, the transaction appears legitimate to standard security systems. This creates a paradox where authentication confirms identity but fails to verify the legitimacy of the customer's intent, especially as generative AI enhances the sophistication of social engineering tactics.