KANSAS CITY — Batch systems and card networks built delay into the product. A wire could be stopped. A card charge could be disputed. An ACH debit could reverse. Those frictions were not marketed as fraud controls. They functioned as ones. Realtime account-to-account rails optimize for the opposite: 24x7 availability, immediate funds, and settlement that is hard or impossible to unwind.
Fraudsters optimize for the same properties. The design problem is not only stolen credentials. It is social engineering that convinces a customer to authorize a payment to a mule account. Once the push is authorized and final, the money is often gone before the first support ticket opens.
Realtime rails remove delay that used to function as a silent fraud brake. Authorized push payment scams are the residual risk.
APP scams on fast rails
In a November 2024 Payments System Research Briefing, Federal Reserve Bank of Kansas City economist Ying Lei Toh defines authorized push payment (APP) scams as cases where fraudsters manipulate individuals into authorizing their institution to push funds to accounts the fraudsters control. Fast payments offer around-the-clock service and instant or near-instant availability. For most systems, interbank settlement is irrevocable once funds land. That package is attractive to legitimate users. It is also attractive to organized scam operations that set up mule accounts, execute deception, and launder proceeds in minutes.
US consumer protection law, the briefing notes, generally protects consumers when a payment is unauthorized. APP scams are often treated as authorized. The customer said yes. Recovery is then a commercial goodwill or investigation problem, not a statutory chargeback right. Card networks’ dispute rails are not a universal template for account-to-account push payments.
The scale is already visible on US person-to-person rails. The Kansas City Fed briefing cites a July 2024 U.S. Senate Permanent Subcommittee on Investigations staff report: in 2023, customers at the three largest banks participating in Zelle disputed more than $206 million worth of Zelle transactions as scams, and scam victims bore more than 80 percent of the losses. That is one network and one year. It is enough to show who pays when authorization is the fraud vector.
The UK forced the liability redesign
The United Kingdom treated APP loss allocation as market structure, not only consumer education. The Payment Systems Regulator required reimbursement for Faster Payments APP scams. In policy statement PS24/7, the PSR confirmed that from 7 October 2024, payment service providers must reimburse victims of Faster Payments APP scams up to £85,000 per claim. At that cap, the PSR estimated 99.8 percent of Faster Payments APP scams by volume and 90 percent by value would be fully reimbursed when in scope. Sending and receiving PSPs broadly share the cost. Gross negligence and first-party fraud carve-outs remain, but the default flipped: the system absorbs most retail APP losses so firms invest in prevention.
That is a different equilibrium from customer education alone. Confirmation of Payee, velocity limits, mule detection, and warning screens become cost-of-doing-business when reimbursement is mandatory. Firms that only measured payment success rates discover a new P&L line for fraud reimbursement and a new launch gate for controls.
FedNow and the US control problem
The Federal Reserve’s FedNow Service is a 24x7x365 instant payments service with real-time gross settlement among participants. Speed and finality are design goals. Fraud management remains primarily a participant responsibility, with the network adding tools over time. Federal Reserve Financial Services has described work on network intelligence and exploration of payee name verification to help combat APP fraud. Those tools matter. They do not convert US law into a UK-style mandatory reimbursement regime overnight.
Banks and payment firms launching realtime send face a product choice set that batch ACH never forced into the same second:
| Control | When it fires | What it buys |
|---|---|---|
| Payee name verification / CoP | Before send | Catches many impersonation mismatches |
| First-time payee cooling-off | Before send | Trades speed for a short fraud window |
| Velocity and amount limits | Before send | Caps loss given scam success |
| Mule-account detection (receive side) | Onboarding and receive | Shrinks cash-out inventory for scammers |
| Post-send recall | After finality | Often fails; secondary at best |
The Kansas City Fed briefing maps the scam life cycle into set-up, execution, and laundering. Banks can harden identity checks and mule education at set-up. Sending institutions can warn and verify at execution. Receiving institutions and schemes can freeze and share intelligence at laundering. FPS schemes see network-wide flows that single banks do not. Cost-benefit still applies: every control adds latency or operational cost. The alternative is a silent subsidy from scam victims, as the Zelle loss split showed.
Realtime payments will keep expanding because cash-flow speed is real value. The fraud budget is part of that product. Success rate without time-to-freeze, recovery rate, and APP loss share is a partial scoreboard. Delay used to hide that fact. Instant rails publish it.
Product teams that launch “send money in seconds” without a published control list are shipping an incomplete design. Confirmation of payee, first-time payee delays, amount caps, and mule-account monitoring all trade a little speed for a smaller loss tail. The UK reimbursement rule prices that trade into PSP economics. US institutions that still leave most authorized-push losses with customers face a different political and franchise risk: adoption can stall if households decide instant rails are where savings vanish. Either path forces the same engineering conclusion. Finality without pre-send friction is a fraud product as much as a payments product.
Source notes
- Combating Authorized Push Payment Scams in Fast Payment Systems, Federal Reserve Bank of Kansas City, 15 Nov 2024: Supports the claim that APP scams occur when fraudsters manipulate victims into authorizing a push to an account the fraudster controls, and that US consumer protection law generally does not treat authorized scams like unauthorized fraud.
- Majority Staff Report on Zelle, U.S. Senate Permanent Subcommittee on Investigations, 23 Jul 2024: Supports the claim that in 2023, customers at the three largest Zelle banks disputed more than $206 million in transactions as scams, with victims bearing more than 80 percent of the losses.
- PS24/7 Faster Payments APP Scams Reimbursement Requirement, UK Payment Systems Regulator, Oct 2024: Supports the claim that from 7 October 2024, PSPs must reimburse Faster Payments APP scam victims up to £85,000 per claim, covering an estimated 99.8 percent of scams by volume and 90 percent by value.
- FedNow Service, Federal Reserve Financial Services: Supports the claim that FedNow is a 24x7x365 instant payments service built on real-time gross settlement among participants.
- FedNow Network Intelligence API press release, Federal Reserve Financial Services, 23 Apr 2026: Supports the claim that the Fed has worked on network intelligence tools and explored payee name verification to help combat APP fraud.
- Ground brief: Research log and retrieval gaps.