Once a niche FinTech experiment, Open Banking (OB) is now embedded in the daily lives of more than 15 million people and businesses across the UK. It delivers faster, more personalised financial experiences and continues to show far lower fraud rates than the wider payments industry – 0.013% versus 0.045%
But beneath these low figures, fraud is quietly reinventing itself. One of the biggest threats facing the industry is Authorised Push Payment (APP) fraud, where victims are manipulated into transferring money themselves. And with AI-powered impersonation and social engineering attacks rising, the industry is entering a pivotal moment. A moment PSD3 and the upcoming Payment Services Regulation (PSR) aim to address by tightening liability, authentication and data sharing standards.
The threat landscape: Why APP Fraud is surging
In the modern FinTech era, consumers expect payments to be immediate and effortless, expectations that OB fulfils by design. However, the same frictionless pathways that empower users also create opportunities for manipulation. APP fraud isn’t rising by accident; it mirrors the very behaviours and payment patterns customers have come to embrace.
APP fraud is now the UK’s most common financial scam, costing an estimated £450.7 million in 2024, and it accounts for a striking 74% of fraud cases in OB. The drivers behind this surge are becoming increasingly clear. As security measures strengthen and unauthorised access becomes harder for criminals, their focus has shifted to the one area technology can’t fully protect: human behaviour.
The rise of AI-powered impersonation, deepfake voices and highly convincing phishing messages means fraudsters no longer need to break into accounts. They just need to persuade users to act.
AI now enables criminals to scale identity fraud and account takeover at scale, demonstrating how fraud is increasingly becoming industrialised. Deep Learning (DL) technology allows fraudsters to mimic legitimate behaviour, bypass traditional controls and manipulate victims far more effectively. This is fuelling the rise in APP‑style scams and identity‑driven attacks.
Fraudsters have also evolved and are now targeting higher‑value payments far more frequently. As OB is often leveraged for larger account‑to‑account transfers, the financial impact of successful fraud cases is far greater. Recent data shows the average OB fraud case now costs around £707 – almost three times the wider industry average of £259.
The combination of instant payments, sophisticated social engineering and higher transaction values has created a perfect storm. It is one that fraudsters are exploiting faster than traditional controls can keep pace.
The hidden safeguards PSD3 builds into every payment
As APP fraud rises and AI‑enabled deception becomes harder to spot, PSD3 and the Payment Services Regulation (PSR) mark the biggest tightening of Europe’s fraud‑prevention framework since PSD2. Together, they introduce behind‑the‑scenes reforms designed to close the gaps fraudsters frequently exploit.
PSD3 targets APP fraud head‑on by recognising that victims are deceived, not careless. PSPs will be required to educate customers on emerging scams, but the regulation also accepts that awareness alone isn’t enough. This paves the way for more automated safeguards that work quietly in the background, reducing reliance on users to spot the red flags themselves.
A key part of that protection is the expansion of Verification of Payee (VoP). Now mandatory for all credit transfers, VoP checks whether the payee’s name and International Bank Account Number (IBAN) match, helping prevent impersonation scams, invoice‑redirection attacks and payments to mule accounts. When a mismatch is flagged, the customer receives an instant warning. And if they’re being pressured to ignore it, PSD3 introduces a cooling‑off period for raising spending limits, giving users crucial time to rethink.
PSD3 also mandates a major upgrade in how PSPs monitor transactions. Instead of fixed checks, providers must use richer, real‑time signals to spot fraud before money moves. This includes device intelligence (detecting malware, remote‑access tools or unusual device changes), behavioural analytics (typing rhythm, touch patterns, interaction speed) and environmental cues such as whether a customer is on a call during a suspicious transaction, an increasingly common sign of coercion. If monitoring systems flag a high‑risk transfer, PSPs must block it unless they can verify it as genuine.
Clearer liability rules reinforce these expectations. PSPs can now be held responsible if they fail to use VoP properly, neglect monitoring obligations or allow suspicious payments through. This shift pushes banks and payment firms to invest in stronger, earlier and more accurate fraud controls.
Together, these changes mean that under PSD3, much of Europe’s fraud defence will happen quietly and automatically in real time, mostly unseen, and long before customers realise something might be wrong.
How businesses must future-proof payment methods
While PSD3 introduces essential safeguards, it won’t stop APP fraud on its own. To stay ahead in an Open Banking environment, businesses need to build on these foundations with a more connected, intelligence‑led approach to detecting and preventing fraud.
As payment journeys now span web, mobile, call centres and telecom channels, organisations need a joined‑up view of how fraud actually unfolds. Single‑channel tools only ever see isolated events, whereas cross‑channel visibility links signals – device changes, login behaviour, call‑centre interactions, so suspicious patterns surface earlier.
With Open Banking accelerating real‑time account‑to‑account payments, these channels are becoming even more interconnected. And because many scams now begin outside the banking ecosystem – through fake text messages (smishing), SIM-swap attacks hijacking phone numbers or fraudsters using spoofed numbers to impersonate a bank – banks need the same level of insight that telecom networks use to spot suspicious activity.
Revolut’s most recent Financial Crime and Consumer Security report found that around 75% of authorised fraud now originates on social platforms such as Facebook, Instagram, WhatsApp and Telegram, highlighting just how far beyond traditional payment journeys these risks now sit.
But visibility is only the starting point. Once businesses can see risk clearly, they need controls that adapt in real time. This is where smarter friction comes in – security that steps in only when something genuinely looks unusual based on contextual risk scoring.
Rather than applying the same authentication to every transaction, machine‑learning models analyse behavioural signals, device activity and network patterns in the moment, quietly approving low‑risk payments while escalating only those that appear suspicious. Visa’s approach highlights the impact: issuers using its risk‑based authentication saw 48% fewer challenges alongside reductions in fraud and abandonment.
Together, cross‑channel visibility, telecom‑bank collaboration and adaptive, context‑driven controls give businesses the best chance of staying ahead of APP fraud and meeting PSD3’s higher bar for protection while keeping payments fast, seamless and trusted in the age of Open Banking.
The future of payments is smarter and more secure
APP fraud is reshaping the risks behind real‑time payments and changing what ‘secure’ looks like in the age of Open Banking.
The businesses that thrive under PSD3 will be those that recognise fraud has become multi‑channel, faster and increasingly AI‑driven – and adapt their controls just as quickly. Those who don’t risk being outpaced by more agile, intelligence‑led competitors.
To stay resilient, payment providers must unify their signals, embrace adaptive controls and build security designed for how fraud actually works today.
Learn more at exactly.com
- Digital Payments
- Neobanking




























































































































































