A phone call from your bank's fraud department might just be the exact moment your life savings disappear.
A criminal does not need to hack your bank account if they can simply convince you to log in and hand over the money yourself.
Authorized push payment fraud is a massive global problem. According to the Federal Trade Commission's Consumer Sentinel Network Data Book, US consumers reported losing about $2.09 billion to scams paid through bank transfers in 2024, the largest single payment category in the dataset and a 13 percent increase from 2023. The FTC also found that losses from business and government impersonation scams where older adults lost $100,000 or more grew eight-fold in four years, from $55 million in 2020 to $445 million in 2024.
The problem is just as severe overseas. UK Finance reported that authorized push payment fraud cost UK consumers £450.7 million in 2024, made up of £365.7 million in personal losses and £84.9 million in business losses. That figure actually fell 2 percent from 2023, which UK Finance credits to new detection technology and a reimbursement rule that came into force in October 2024, though nearly 186,000 cases were still recorded that year.
Traditional bank fraud involves a criminal stealing your password and breaking into your account. Authorized push payment fraud happens when you are manipulated into willingly sending money to an account controlled by a criminal. The attacker does not break any security barrier. They use fear and urgency to make you break the barrier for them.
What this means for ordinary users: Because you authorized the transaction, the bank's security systems treat the transfer as legitimate, which makes it extremely difficult to get your money back once you realize you were tricked.
The scam begins with a phone call or a text message. The criminal uses spoofing technology to make your bank's real name and phone number appear on your caller ID. When you answer, a professional and urgent voice tells you that unauthorized charges are happening on your account right now.
The caller will often recite a few real details about you, such as your address or the last four digits of your debit card. This information is usually bought from data breached on the dark web, and it is used to build fast trust.
Once you believe they are a real bank employee, they tell you that you must act to secure your funds. They will send a one-time passcode to your phone and ask you to read it back to them. In reality, they just triggered a password reset or a money transfer on your actual banking app, and reading back that code hands them what they need to complete it.
In the most damaging version of this attack, the caller claims your account is entirely compromised. They instruct you to wire your money to a secure government holding vault or a new "safe account" created in your name.
Key distinction: A real bank freezes a compromised account to protect your money. A scammer tells you to move your money to a holding vault.
In June 2024, the U.S. Attorney's Office and the FBI in San Diego announced they had recovered more than $3.3 million for victims of scams that primarily targeted the elderly, many of which combined tech-support pop-ups with bank and government impersonation calls. Since launching the effort in January 2024, investigators had obtained over 40 seizure warrants covering more than $5.6 million in frozen funds. The lesson from the case is straightforward: victims who report a suspicious transfer within about 12 hours give investigators a real chance to freeze the money before it disappears overseas.
The FTC's 2024 Consumer Sentinel data shows that government impersonation losses alone rose by $171 million from the prior year, reaching $789 million, while imposter scams as a whole reached $2.95 billion, the second-highest fraud category after investment scams. Impersonation scams remained the most commonly reported category of complaint that year, ahead of online shopping issues and job scams.
In a March 2026 release, the Australian Federal Police detailed a case in which a victim transferred $156,000 into fraudulent accounts after a scammer, posing as a bank's fraud team, convinced her that her account had been compromised and talked her through cancelling and reissuing her card and deleting the bank's app. In a separate case flagged by the AFP, a victim lost $350,000 in cryptocurrency in eighteen hours after a scammer claimed to represent a crypto ledger company and told them their wallet had been compromised. The AFP reported that Australians lost $97.6 million to phishing scams, which includes bank impersonation, in 2025, up from $84.5 million in 2024.
Santander UK reported in June 2026 that its customers had lost £160,000 so far that year to "Hi Dad" style scams, in which fraudsters use text messages or AI-generated phone calls that mimic a family member's voice to request urgent payments. Santander's quarterly scam tracker also found that men handed over the equivalent of £100,000 to scammers every single day during the first half of 2026, with investment and purchase scams accounting for the largest share of losses. Chris Ainsley, the bank's head of fraud risk management, has warned that criminals routinely impersonate trusted organizations, friends, or family members to create a false sense of urgency.
When a fake bank representative sends you a text asking you to log in and secure your funds, use the ScamAdviser website safety checker to investigate the link. Paste the exact URL into the search bar, and the tool returns a Trust Score based on domain age, server location, and community reviews. That output tells you instantly whether the site was registered yesterday in a foreign country or whether it belongs to your actual bank. Understanding how to tell if a site is legit takes only a few seconds, but it gives you the proof you need to hang up the phone with confidence.
Scammers rely on panic to make you act without thinking. When a text message claims your account is locked, asking is this a legit website before tapping the link is your best defense against handing over your password. Make it a habit to run a website safety check on any unprompted alert claiming to be from your financial institution.
Log into your banking app and set up alerts for any transaction over a specific dollar amount. You can also lower your daily wire transfer limits. This creates an automatic roadblock if a scammer tries to drain your account, or if you are manipulated into trying to send a large sum all at once.
Authorized push payment fraud is devastating because the harm is almost impossible to reverse. Once you authorize a transfer to a safe account, the bank treats the transaction as valid, leaving victims like those in the FBI's San Diego cases and the AFP's Australian cases with empty accounts and no clear path to reimbursement. Before you trust a panicked text message, check a URL for scams to break the illusion of authority.
A legitimate bank secures your money by locking the account in place. Only a criminal needs you to transfer the funds to a new destination.
Adam Collins is a cybersecurity researcher at ScamAdviser who operates under a pseudonym for privacy and security. With over four years on the digital frontlines, he specialises in translating complex threats into actionable advice. His mission: exposing red flags so you can navigate the web with confidence.