ArticleBanking industry trends

Who pays for a scam? Reimbursement, verification and the end of the bank-only defence

The UK's mandatory reimbursement regime is two years old, the EU has made payee verification universal for euro payments and Australia is legislating shared duties for banks, telcos and platforms. The evidence so far: shifting liability changes behaviour, but banks cannot stop scams alone.

8 min read By · Point of view
£576.4m
lost to authorised push payment fraud in the UK in 2025, up 19% on 20241

Key takeaways

  • UK APP fraud losses rose 19% to £576.4 million in 2025, even as unauthorised fraud fell; two-thirds of APP cases started online and telecoms channels drove 28% of losses.
  • Mandatory reimbursement works for victims: 88% of money lost to in-scope APP scams was returned in the first year, and the regulator's evaluation links the regime to a 21% fall in APP losses over Faster Payments.
  • The EU is following with a different mix: universal verification of payee from October 2025, and, under the agreed PSR, refunds for bank-impersonation scams and platform liability.
  • Australia's Scams Prevention Framework goes furthest on shared responsibility, placing enforceable duties on banks, telcos and digital platforms, with sector codes due by early 2027.

Authorised push payment (APP) scams, in which victims are manipulated into sending money themselves, have become the defining fraud problem of instant payments. Because the customer authorises the payment, traditional authentication does not stop it, and until recently the loss usually stayed with the victim. That settlement is breaking down. Regulators are reallocating liability to payment providers and, increasingly, to the telecoms and technology platforms where scams begin.

The UK: two years of mandatory reimbursement

Since 7 October 2024, UK payment firms sending or receiving Faster Payments and CHAPS have been required to reimburse victims of qualifying APP scams, with costs split between sending and receiving firms. The first year's data are encouraging for consumers. Between October 2024 and September 2025, 88% (£173 million) of money lost to reimbursable APP scams was returned; about 269,000 claims were made, of which 188,000 were in scope, around 15% fewer than the year before3. Firms resolved 84% of claims within five business days2.

The deeper question is whether liability changes prevention. The regulator's evaluation, published in mid-2026, estimated that APP losses over Faster Payments fell by about 21% after the requirement was introduced, equivalent to around £73 million a year, and that reimbursement rates rose from 54% to 65% on the broader measure it used; it also found inconsistent outcomes for some victims and plans a formal consultation in December 20264.

Yet the headline numbers are moving the wrong way. UK Finance reports that APP fraud losses rose 19% to £576.4 million in 2025, across 248,070 cases, while unauthorised fraud fell 5%; banks reimbursed £354.3 million, or 61% of APP losses. Investment scams accounted for £221.5 million, up 40%1. The pattern is consistent: as bank controls harden, criminals move further upstream, to the platforms and phone lines where persuasion happens.

Exhibit 1

Scams start outside the bank

UK APP fraud by channel of origin, share of cases and of losses, 2025, % (%)

Note: Remaining cases and losses originated through other channels.

Source: UK Finance, “Fraud remains a national security threat as criminals steal almost £1.3 billion (Annual Fraud Report 2026)” (2026)

Online channels account for two-thirds of APP cases but under a third of losses; telecoms account for fewer cases but, at 28% of losses, a disproportionate share of value, consistent with high-value impersonation and investment scams run by phone1. A reimbursement regime that binds only payment firms asks banks to pay for failures they cannot fully see.

Our view: reimbursement shifts who pays for scams. Only shared data between banks, telcos and platforms shifts how many scams happen.

The EU: verify first, refund impersonation

The EU has started with prevention at the point of payment. Under the Instant Payments Regulation, payment providers in the euro area have had to offer verification of payee, checking that the name and IBAN match, before every credit transfer since 9 October 2025; providers outside the euro area follow by 9 July 20275. The PSD3/PSR package agreed in November 2025 goes further: providers must refund customers in full when a fraudster impersonates the provider's own staff, provided the victim reports it to the police; online platforms become liable to providers that have reimbursed victims if they were told about fraudulent content and failed to remove it; and the rules reach electronic communications providers in some cases6. Formal adoption of the package was still pending as of August 20267.

The EU and UK approaches are converging from opposite ends. The UK started with liability and is now pushing prevention upstream; the EU started with prevention at the point of payment and is adding targeted liability. Both leave banks carrying most of the direct cost while the channels where scams originate remain lightly obligated. That imbalance is the next policy battleground.

Australia: shared duties by statute

Australia has taken the most explicit shared-responsibility approach. The Scams Prevention Framework Act 2025 places obligations on banks, telecommunications providers and digital platforms to prevent, detect, disrupt and respond to scams, with consumers able to seek redress from businesses that fail to meet them. Treasury's May 2026 exposure drafts proposed that the SPF rules commence on 1 September 2026 and the sector codes by 31 March 2027; the draft banking code requires payee confirmation before electronic funds transfers, controls on high-risk transactions and recall requests for suspected scam payments8. The backdrop: Australians reported A$2.18 billion of scam losses in 2025, up 7.8% on 2024 but about 30% below the 2022 peak, with investment scams alone costing A$837.7 million9.

Exhibit 2

Investment scams dominate losses

Top five scam types by reported loss, Australia, 2025, A$ million (A$m)

Note: Combined reports to Scamwatch, ReportCyber, IDCARE, AFCA, banks and payment providers.

Source: Australian Competition and Consumer Commission, “Continued action critical to combat fraud as annual scam losses exceed $2 billion” (2026)

Globally the problem is vast, if hard to measure. The Global Anti-Scam Alliance's 2025 survey of 46,000 adults in 42 countries estimated $442 billion lost to scams in the previous year, and found that 64% of scams concluded within a day of first contact10. Speed is the attacker's advantage; data sharing is the defender's.

What banks should do now

  • Score the payee, not just the payer. Receiving-side analytics, mule detection and verification-of-payee outcomes are as important as sender authentication under 50:50 cost-sharing.
  • Engineer friction by risk. Targeted delays, confirmations and conversations for high-risk first-time payments, rather than blanket warnings customers ignore.
  • Build the data bridges. Structured intelligence exchange with telcos and platforms on numbers, domains, accounts and adverts, as Australia's framework will require.
  • Industrialise claims. Fast, consistent decisions, with evidence captured for cost-recovery from receiving firms and, in future, platforms.

The UK experience offers a clear lesson for other markets. Liability shifted behaviour quickly: faster claims decisions, more intervention on risky payments and more attention to the receiving side of the transaction. But it did not reverse the growth in losses, because the scam economy adapts faster than any single sector's controls. Reimbursement is a floor for consumer protection, not a strategy for reducing fraud.

For banks, the practical agenda is to be excellent at the parts they control, to evidence that excellence in every claim, and to push hard, commercially and through policy engagement, for the telecoms and platform obligations that Australia has legislated and the EU has begun to adopt. The banks that do this well will turn scam prevention from a rising cost into a source of customer trust.

For executives

What this means for your bank

  1. Treat scam losses and reimbursement costs as a board-level P&L line, reported by channel of origin and by sending versus receiving role.
  2. Invest in receiving-side mule detection and payee-risk scoring, not only sender authentication.
  3. Integrate verification-of-payee and confirmation-of-payee outcomes into real-time payment risk decisions.
  4. Establish data-sharing agreements with telcos and platforms now, ahead of PSR platform liability and Australia's SPF codes.
  5. Automate claims handling with full evidence capture to support consistent outcomes, regulator reporting and cost recovery.
Put it to work

How DaasLabs can help

Score payments and payees in real time with our Real-Time Fraud & Authorization Intelligence accelerator.

Explore the accelerator

Detect mule networks and strengthen AML controls with our Regulatory Compliance & AML accelerator.

Explore the accelerator

Deploy supervised financial-crime agent squads for triage and claims handling.

Watch an agent run

Join fraud, device and external intelligence data on the DaasLabs Data Fabric Framework.

Explore the framework

Sources

  1. 1
  2. 2
  3. 3
  4. 4
    Payment fraud falls by £73m following PSR reimbursement scheme (opens in a new tab) Regulation Tomorrow (Norton Rose Fulbright), 1 July 2026
  5. 5
    Instant Payments Regulation (opens in a new tab) European Central Bank, 9 October 2025
  6. 6
  7. 7
  8. 8
  9. 9
  10. 10
    5 key takeaways from the GASA Global State of Scams 2025 report (opens in a new tab) Feedzai (summarising the Global Anti-Scam Alliance), 9 October 2025

Figures are drawn from the cited public sources. Opinions labelled “DaasLabs point of view” are our own.

Stay informed

Get new banking insights in your inbox

New perspectives on AI, data and transformation in banking — a few times a month. Browse all insights.

AI
AI Analystagentic

I'm the DaasLabs AI Analyst, working with tools rather than from memory. I can:

  • Query the live platform APIs (disputes, fraud, AML, recon, revenue…)
  • Report what the digital workforce is doing: runs, approvals, overrides
  • Start an agent run on a real case and hand you the link to watch it

Every answer shows the tools it used.