https://whitelabel-manager-production.ams3.digitaloceanspaces.com/thumbs/unnamed-50-59d74.png_800x.png
September 3, 2026
Author: Adam Collins

Authorized Push Payment Fraud | The "Safe Account" Scam

A phone call from your bank's fraud department might just be the exact moment your life savings disappear.

Key Takeaways

  • Fraudsters use spoofed caller IDs and high-pressure scripts to convince you your bank account is compromised and you must move your funds.
  • Billions of dollars are lost globally each year because victims willingly authorize these transfers and bypass traditional banking security.
  • The strongest defense against this attack is hanging up the phone and dialing the number on the back of your official bank card.
  • You can use the ScamAdviser URL checker to verify whether any link texted to you by a supposed bank representative actually belongs to a known financial institution.

A criminal does not need to hack your bank account if they can simply convince you to log in and hand over the money yourself.

How Much Money is Lost to APP Fraud? 

Authorized push payment fraud is a massive global problem. According to the Federal Trade Commission's Consumer Sentinel Network Data Book, US consumers reported losing about $2.09 billion to scams paid through bank transfers in 2024, the largest single payment category in the dataset and a 13 percent increase from 2023. The FTC also found that losses from business and government impersonation scams where older adults lost $100,000 or more grew eight-fold in four years, from $55 million in 2020 to $445 million in 2024.

The problem is just as severe overseas. UK Finance reported that authorized push payment fraud cost UK consumers £450.7 million in 2024, made up of £365.7 million in personal losses and £84.9 million in business losses. That figure actually fell 2 percent from 2023, which UK Finance credits to new detection technology and a reimbursement rule that came into force in October 2024, though nearly 186,000 cases were still recorded that year.

What is Authorized Push Payment Fraud? 

Traditional bank fraud involves a criminal stealing your password and breaking into your account. Authorized push payment fraud happens when you are manipulated into willingly sending money to an account controlled by a criminal. The attacker does not break any security barrier. They use fear and urgency to make you break the barrier for them.

What this means for ordinary users: Because you authorized the transaction, the bank's security systems treat the transfer as legitimate, which makes it extremely difficult to get your money back once you realize you were tricked.

How Bank Impersonation Scams Trick Victims 

The scam begins with a phone call or a text message. The criminal uses spoofing technology to make your bank's real name and phone number appear on your caller ID. When you answer, a professional and urgent voice tells you that unauthorized charges are happening on your account right now.

The caller will often recite a few real details about you, such as your address or the last four digits of your debit card. This information is usually bought from data breached on the dark web, and it is used to build fast trust.

Once you believe they are a real bank employee, they tell you that you must act to secure your funds. They will send a one-time passcode to your phone and ask you to read it back to them. In reality, they just triggered a password reset or a money transfer on your actual banking app, and reading back that code hands them what they need to complete it.

The "Safe Account" Variant

In the most damaging version of this attack, the caller claims your account is entirely compromised. They instruct you to wire your money to a secure government holding vault or a new "safe account" created in your name.

Key distinction: A real bank freezes a compromised account to protect your money. A scammer tells you to move your money to a holding vault.

Real Bank Impersonation Scam Cases 

The San Diego Elder Fraud Recovery Effort

In June 2024, the U.S. Attorney's Office and the FBI in San Diego announced they had recovered more than $3.3 million for victims of scams that primarily targeted the elderly, many of which combined tech-support pop-ups with bank and government impersonation calls. Since launching the effort in January 2024, investigators had obtained over 40 seizure warrants covering more than $5.6 million in frozen funds. The lesson from the case is straightforward: victims who report a suspicious transfer within about 12 hours give investigators a real chance to freeze the money before it disappears overseas.

The FTC's Government Impersonation Surge

The FTC's 2024 Consumer Sentinel data shows that government impersonation losses alone rose by $171 million from the prior year, reaching $789 million, while imposter scams as a whole reached $2.95 billion, the second-highest fraud category after investment scams. Impersonation scams remained the most commonly reported category of complaint that year, ahead of online shopping issues and job scams.

The Australian Federal Police Bank Impersonation Cases

In a March 2026 release, the Australian Federal Police detailed a case in which a victim transferred $156,000 into fraudulent accounts after a scammer, posing as a bank's fraud team, convinced her that her account had been compromised and talked her through cancelling and reissuing her card and deleting the bank's app. In a separate case flagged by the AFP, a victim lost $350,000 in cryptocurrency in eighteen hours after a scammer claimed to represent a crypto ledger company and told them their wallet had been compromised. The AFP reported that Australians lost $97.6 million to phishing scams, which includes bank impersonation, in 2025, up from $84.5 million in 2024.

Santander UK's "Hi Dad" Voice-Clone Scam

Santander UK reported in June 2026 that its customers had lost £160,000 so far that year to "Hi Dad" style scams, in which fraudsters use text messages or AI-generated phone calls that mimic a family member's voice to request urgent payments. Santander's quarterly scam tracker also found that men handed over the equivalent of £100,000 to scammers every single day during the first half of 2026, with investment and purchase scams accounting for the largest share of losses. Chris Ainsley, the bank's head of fraud risk management, has warned that criminals routinely impersonate trusted organizations, friends, or family members to create a false sense of urgency.

How to Tell if a Bank Call is a Scam 

  • If a caller texts you a link to verify your identity, you need to ask yourself is this website legit before clicking anything.
  • The caller instructs you to transfer money to a "safe account," a "holding vault," or a cryptocurrency ATM to protect it.
  • The representative asks you to read back a one-time passcode or two-factor authentication code sent to your phone.
  • The person on the phone tells you to lie to bank tellers or ignore fraud warnings inside your banking app.
  • You are told that a local branch employee is in on the fraud and that you must not speak to them.
  • You receive a text with a link, and while figuring out how to check if a website is legit, you notice the URL is slightly misspelled compared to your bank's real domain.

Step-by-Step: What to Do if You Receive a Suspicious Bank Call

  1. Hang up the phone immediately, even if the caller ID matches your bank's exact name and number.
  2. Find your physical debit or credit card and locate the official customer service number printed on the back.
  3. Call that official number and ask to speak to the fraud department to check whether there is an actual issue with your account.
  4. If the caller sent you a text message with a link to "secure" your account, do not tap it.
  5. Type the link into the ScamAdviser URL checker to see who actually registered the domain.

How ScamAdviser Helps Check Suspicious Bank Links 

When a fake bank representative sends you a text asking you to log in and secure your funds, use the ScamAdviser website safety checker to investigate the link. Paste the exact URL into the search bar, and the tool returns a Trust Score based on domain age, server location, and community reviews. That output tells you instantly whether the site was registered yesterday in a foreign country or whether it belongs to your actual bank. Understanding how to tell if a site is legit takes only a few seconds, but it gives you the proof you need to hang up the phone with confidence.

unnamed-5-754c2.jpg

How to Protect Yourself From APP Fraud 

Pause Before Clicking Links

Scammers rely on panic to make you act without thinking. When a text message claims your account is locked, asking is this a legit website before tapping the link is your best defense against handing over your password. Make it a habit to run a website safety check on any unprompted alert claiming to be from your financial institution.

Set Up Transaction Limits and Alerts

Log into your banking app and set up alerts for any transaction over a specific dollar amount. You can also lower your daily wire transfer limits. This creates an automatic roadblock if a scammer tries to drain your account, or if you are manipulated into trying to send a large sum all at once.

The Bottom Line on Safe Account Scams 

Authorized push payment fraud is devastating because the harm is almost impossible to reverse. Once you authorize a transfer to a safe account, the bank treats the transaction as valid, leaving victims like those in the FBI's San Diego cases and the AFP's Australian cases with empty accounts and no clear path to reimbursement. Before you trust a panicked text message, check a URL for scams to break the illusion of authority.

  • Hang up on unexpected fraud alerts.
  • Call the number on the back of your card, never a number given to you on the call.
  • Never move money to a "safe account."
  • Report the attempt to your bank and to law enforcement, even if you did not lose money.

A legitimate bank secures your money by locking the account in place. Only a criminal needs you to transfer the funds to a new destination.

Adam Collins is a cybersecurity researcher at ScamAdviser who operates under a pseudonym for privacy and security. With over four years on the digital frontlines, he specialises in translating complex threats into actionable advice. His mission: exposing red flags so you can navigate the web with confidence.

See Full Bio

Report a Scam!
Have you fallen for a hoax, bought a fake product? Report the site and warn others!
About Us Check Yourself Contact Disclaimer
Developed By: scamadviser-logo