What Is Payment Fraud?
Payment fraud is the use of deception, stolen credentials, or unauthorized access to move money through a payment instrument or rail (card, ACH, wire, check, or instant transfer) for the attacker's gain. It covers two situations: a third party initiates a payment the accountholder never approved, or the accountholder approves the payment themselves because an impersonator deceived them into it.
Payments fraud has no consensus definition (opens in new tab), and a June 2025 US banking regulatory request for information includes scams as a subset of payment fraud.
How payment fraud works
Payment-fraud classification begins with one opening question: who initiated the payment (opens in new tab). If an attacker did, they first obtained account data or credentials, typically through phishing pages, data breaches, or malware, then used it to take over an account or push a card-not-present transaction.
If the authorized party did, the attacker built enough trust or urgency that the victim moved the money on their own device with their own credentials.
Both paths share the same front end. The attacker impersonates a party the victim already trusts: a bank's fraud department, a vendor, a CEO, a government agency, or a retail brand. Impersonation ranks among the main tools (opens in new tab) used in online fraud. Contact arrives through paid search ads, fake social profiles, SMS, messaging apps, or a spoofed caller ID, and the conversion happens on a phishing page, a fake payment portal, or a fraudulent invoice.
In a documented deepfake case (opens in new tab), attackers deceived a finance employee into transferring funds by impersonating the company's CFO in a video call. The employee noticed the CFO looked slightly off but sought confirmation from the other participants, who were also deepfakes, and proceeded with the transfer.
Why payment fraud is hard to stop
Authorized fraud can pass an identity check by design. The genuine customer logs in from their own device at a valid location and can supply the one-time passcode the bank requests, so controls that banks built to catch an unauthorized actor see a normal transaction. The attacker completed the manipulation in the conversation before the customer opened the banking app.
Even when authentication controls see a normal transaction, payment speed can remove the recovery window. After the receiving institution accepts them, senders generally cannot cancel RTP payments (opens in new tab), and wire transfers leave little more room to recover funds once they clear.
In documented cases (opens in new tab), callers posing as banks coached victims to distrust real bank staff.
Limited recovery time compounds another challenge: liability is shifting toward institutions for fraud induced before the transaction. UK rules have required payment firms to reimburse APP scam victims (opens in new tab) since 7 October 2024, subject to the applicable reimbursement limit (opens in new tab) per claim; sending and receiving firms split the cost.
Since 20 March 2026, financial institutions have applied fraud monitoring to ACH entries that customers authorized under false pretenses (opens in new tab), including BEC and vendor impersonation. Under the EU's provisional PSD3 agreement (opens in new tab) of November 2025, a payment provider becomes liable when someone impersonating its own employees manipulates a customer.
Types of payment fraud
Payment fraud classification follows one primary axis: whether the authorized party initiated the payment, recognizing the following principal types.
- Card-not-present fraud. Attackers use stolen card data in remote payment channels (opens in new tab) such as e-commerce and phone orders without presenting the physical card.
- Card-present fraud. Attackers write skimmed magnetic-stripe data to a counterfeit card and use it at a physical point of sale; lost and stolen cards (opens in new tab) fall here too.
- Account takeover. An attacker gains access to a legitimate account, usually after harvesting credentials through phishing, breaches, or malware, then initiates transfers, changes credentials, or locks the owner out.
- Business email compromise. An attacker compromises a business email account or spoofs one to divert a wire or ACH payment (opens in new tab). Variants include CEO fraud, vendor invoice impersonation, and payroll diversion.
- Authorized push payment fraud. A fraudster tricks the victim into sending a payment to an account the fraudster controls. APP scams fall into two groups under a widely used classification (opens in new tab): malicious payee (purchase, investment, romance, advance fee) and malicious redirection (invoice and mandate, CEO fraud, impersonation of police or bank staff).
- Check fraud. Stolen mail supplies checks that fraudsters alter, use as templates (opens in new tab), or fraudulently endorse and deposit.
- First-party fraud. The accountholder disputes a genuine purchase to force a chargeback, or abuses a merchant's refund policy directly. No stolen credentials are involved.
How to defend against payment fraud
Because impersonation sits at the front of most payment fraud, an effective program pairs transaction-level controls with controls that act on the deception itself.
- Phishing-resistant MFA. Authenticator Assurance Level 3 (opens in new tab) requires hardware-bound cryptographic authenticators under NIST SP 800-63-4, finalized in July 2025; these do not release credentials to a fraudulent site.
- Beneficiary name verification. Confirmation of Payee (opens in new tab) in the UK and Verification of Payee in the eurozone, mandatory on euro transfers since 9 October 2025 (opens in new tab), check the payee name against the destination account before funds move.
- Dual authorization and segregation of duties. Require a second, independent approver (opens in new tab) for outbound payments, and prevent the person who creates or edits (opens in new tab) a vendor record from releasing payments to it.
- Out-of-band callback for bank-detail changes. Verify any change to vendor payment details by calling a previously known number (opens in new tab) rather than one supplied in the request, and prohibit teams from authorizing payment changes by email alone.
- Behavioral transaction monitoring. Baseline each account's counterparties, velocity, timing, and device, and route deviations for review. Behavioral signals (opens in new tab) can flag coercion even when the genuine user initiates it.
- Multi-channel social engineering training. Run simulations that reproduce vishing and smishing. Include deepfake video calls, since the attacker's first contact rarely arrives by email alone.
- External impersonation monitoring and takedown. Continuously scan for lookalike domains, fake social profiles, scam ads, and counterfeit apps carrying your brand, then dismantle them before they reach a customer or employee.
Organizations can run this monitoring in-house or contracted (opens in new tab), per OCC guidance dating to 2005.
How Doppel helps
Doppel is the Frontier AI-native Social Engineering Defense (SED) platform that unifies Digital Risk Protection (DRP) and Human Risk Management (HRM). Its Brand Protection and Executive Protection capabilities detect the spoofed domains, fake social profiles, scam ads, and cloned executive personas that open an impersonation-driven payment fraud campaign, then dismantle that infrastructure before a customer or finance employee acts on it.
Its agentic AI correlates those signals in the Doppel Threat Graph into a single campaign view across domains, social, ads, telco, and messaging apps, then executes takedowns at scale, while human analysts handle the complex escalations that require judgment.
Simulation reproduces the same tactics internally. A finance team can receive a deepfake-voice call, a WhatsApp lure derived from a campaign detected in the wild, or a Microsoft Teams meeting invite, so the person who eventually gets a real "CFO" request has already refused a rehearsed one. Completed takedowns feed back into the Threat Graph, and a detected campaign converts to a simulation in one click.
Request a demo to see live impersonation infrastructure targeting your brand and how the platform makes it too costly to attack.
Frequently asked questions about payment fraud
What is payment fraud?
Payment fraud covers any payment a third party initiates without the accountholder's authority, and any payment the accountholder authorizes after an impersonator deceives them into it. It is a subset of financial crime, the broader category that also covers money laundering and other illicit finance.
What is payment fraud in cybersecurity?
In cybersecurity, payment fraud is the financial outcome of an attack chain that usually begins with impersonation: a lookalike domain, a spoofed bank text, a fake executive profile, or a deepfake call. The attacker either harvests credentials to take over an account or persuades an employee to send funds to an account the attacker controls. Security teams treat the impersonation infrastructure as part of the attack surface, because dismantling it disrupts the campaign before the attacker can initiate or induce a payment. In the United States, wire fraud is a federal crime (opens in new tab) under 18 U.S.C. § 1343.
What is the difference between authorized and unauthorized payment fraud?
Unauthorized payment fraud occurs when someone other than the accountholder initiates a payment without actual authority, for example by using stolen card data or a hijacked account. Authorized push payment (APP) fraud occurs when the accountholder sends the payment themselves because a fraudster deceived them. Under US Regulation E, when a third party uses credentials after tricking the consumer (opens in new tab) into sharing them, the transfer still counts as unauthorized, while a transfer the consumer personally initiates under deception generally falls outside those protections.
What is an example of payment fraud?
Vendor invoice impersonation is a common enterprise example. An attacker compromises or spoofs a supplier's email account and sends a genuine-looking invoice with updated bank details, and the accounts payable team pays the next invoice to an account the attacker controls. Fraudulent vendor invoices often involve larger sums (opens in new tab) than CEO impersonation because they mimic recurring, high-value payments. The standard defense is confirming any bank-detail change by phone at a number already on file before releasing funds.


