A conveyancer's inbox gets hijacked three days before completion. The buyer receives an email from what looks like the same solicitor's address, telling her the firm's bank details have changed. She wires £340,000. It's gone within four minutes, split across nine mule accounts before anyone at the receiving bank even looks at it twice.

That single case sits inside a much bigger number. UK Finance recorded £1.28 billion in payment fraud losses across the UK in 2025, a four percent rise on the year before, spread across 3.81 million individual cases.

Numbers like that get quoted constantly and mean almost nothing on their own. What matters is the shift underneath them. Card fraud and account takeovers, the kind a bank can often spot and reverse, are edging down. Authorised push payment fraud, money victims send themselves after being manipulated, keeps climbing. That's the harder problem to solve, because the payment worked exactly as it was designed to. The victim authorised it, willingly, at the time.

£1.28bnTotal UK payment fraud losses in 2025, up 4% on 2024
£576.4mAuthorised push payment fraud losses, up 19% year-on-year
88%Of eligible APP losses reimbursed under the PSR scheme

A £1.28 Billion Year: What the UK Finance Numbers Actually Show

Unauthorised fraud (stolen cards, hacked accounts, cloned payment details) fell to £703.4 million in 2025, down five percent on 2024. UK Finance credits the drop partly to the £1.68 billion in attempted unauthorised fraud that banks say they blocked before it ever reached a victim's account. Authorised push payment fraud moved the opposite way: £576.4 million lost, up nineteen percent, across 248,070 reported cases, up seven percent on the year.

Where the fraud starts matters as much as where the money ends up. Sixty-six percent of APP cases began online, through fake shops, social media ads, or messaging apps, yet those cases accounted for only thirty-two percent of the total value lost. Seventeen percent of cases started through a phone call or text message, and those tend to carry a far bigger price tag per victim: impersonation scams, courier fraud, and fake "bank security team" calls that walk someone through moving their savings in real time.

Purchase Scams Are the Volume Problem, Investment Fraud Is the Value Problem

Purchase scams, fake goods, holiday rentals that don't exist, concert tickets sold twice, made up seventy-one percent of every APP case reported in 2025. In cash terms they only cost victims £118.1 million, up twenty percent. That's a lot of small, painful losses spread across hundreds of thousands of people, each one usually a few hundred pounds. It is not where the serious money went, and it's rarely the case that keeps a fraud team up at night.

Track the last few UK Finance releases side by side and one shift stands out among current financial fraud trends: money is migrating away from one-off purchase scams and toward slower, relationship-based cons that take weeks or months to pay off. Investment fraud lost UK consumers £221.5 million in 2025, up forty percent, across 14,893 cases, up twenty-six percent. That's the fastest-growing major fraud category in the entire report, by a wide margin.

Romance and Investment Scams: Why the Slow Cons Pay Off

The investment scams driving that growth rarely look crude. Victims get shown a cloned website carrying the branding of a real, FCA-authorised firm, a dashboard tracking "returns" that climb steadily, and a relationship manager who answers messages within minutes. The first deposit might be a few hundred pounds. By the time a victim tries to withdraw anything, they've often put in tens of thousands, and the platform either stalls the withdrawal with a fake "tax" or "release fee," or simply stops responding.

Romance fraud shows the same pattern of patience over speed. UK Finance's bank-reported figure puts 2025 romance fraud losses at £39.2 million, up twenty-three percent, but that number only counts payments banks can trace and flag as romance-related. Broader reporting through Action Fraud, which captures cash transfers, gift cards, and crypto payments that never touch a traditional bank flag, puts UK romance fraud losses for 2025 closer to £102 million. The gap between those two figures is a reminder that bank data, however detailed, only sees part of the picture. A scammer who spends eight weeks building trust before ever mentioning money is optimising for exactly that blind spot.

The £85,000 Question: How the New APP Reimbursement Rules Actually Work

Since October 2024, most Faster Payments APP fraud in the UK has fallen under a mandatory reimbursement scheme run by the Payment Systems Regulator. The mechanics are specific enough to matter. Claims are capped at £85,000 per case. The cost splits fifty-fifty between the sending bank and the receiving bank, which gives receiving institutions a real financial reason to question suspicious inbound payments instead of just processing them. Consumers can be charged an excess of up to £100 on a standard claim, though vulnerable customers are exempt from that excess entirely.

The receiving-bank side of that split is doing more work than it gets credit for. Before October 2024, a bank that received stolen funds into one of its accounts had little direct financial reason to interrogate why a brand-new account was suddenly taking in tens of thousands of pounds from a stranger. Under the fifty-fifty rule, that same bank now carries half the cost if the payment turns out to be fraud, which is a much sharper incentive to flag accounts that look like they exist purely to receive and forward money.

UK Finance's headline number, that banks reimbursed 61 percent of 2025 APP losses, blends every claim reported that year, including cases outside the mandatory scheme's scope. Narrow the lens to claims that actually qualify under the PSR's reimbursement dashboard and the picture looks different: 88 percent of eligible losses, worth around £316 million, reimbursed across the scheme's first eighteen months, with 82 percent of claims resolved within five business days and 98 percent within thirty-five.

Only two to three percent of claims get turned down on the grounds of insufficient consumer caution, which was meant to be the exception rather than the rule and, so far, has stayed that way.

Money Mules and Identity Fraud: The Account-Opening Problem Behind the Headline Numbers

Every one of those APP scams needs somewhere to send the money, and that's where a separate but connected fraud economy shows up. Cifas, the UK's fraud prevention data-sharing body, recorded 444,993 fraud filings across its National Fraud Database in 2025, a record and a six percent rise on 2024. Identity fraud and account takeover between them made up seventy-two percent of that total.

Identity fraud alone accounted for 242,003 filings, fifty-four percent of everything logged, even though the raw figure dipped three percent on the year before. Account takeover moved the other way, up six percent to 78,387 cases, with SIM swap attacks, where a fraudster ports a victim's phone number to intercept one-time passcodes, surging thirty-eight percent year on year. Sixty-two percent of account takeover filings involved a telecoms element somewhere in the chain, which lines up with how many APP scams start with a phone call rather than a fake webpage.

Cifas introduced a new filing category for money mule activity in 2025 and logged more than 22,000 incidents in the first year of tracking it that way. Forty percent involved someone aged twenty-one to thirty, the single largest age band, and separate Cifas survey work found over a third of Gen Z respondents said they'd consider moving money for strangers in exchange for a fee. None of that happens without an account to move the money through. Every mule account that clears onboarding checks is a fraud case waiting to be reported six months later, once the money's long gone and the "customer" has vanished.

Failure to Prevent Fraud: A New Corporate Offence With Real Teeth

Reimbursement rules change what happens after a scam succeeds. A separate piece of law aims at what happens before one gets the chance. Section 199 of the Economic Crime and Corporate Transparency Act 2023 created a new corporate offence, failure to prevent fraud, which came into force on 1 September 2025.

The offence applies to "large organisations," defined as meeting at least two of three thresholds: more than 250 employees, turnover above £36 million, or a balance sheet above £18 million. If an employee, agent, or subsidiary commits fraud intending to benefit the organisation or its clients, the organisation itself can now be prosecuted under Section 199 of the Act, unless it can show it had reasonable fraud prevention procedures in place at the time. That last clause is the one worth sitting with. It removes the old requirement to prove a "directing mind," a senior individual who knew and approved, which for decades made corporate fraud prosecutions in the UK notoriously hard to bring. A company can be liable now even if nobody on the board knew a thing.

The offence carries an unlimited fine, and the Serious Fraud Office has already made clear it intends to use it. Home Office guidance on what counts as "reasonable procedures" borrows heavily from the framework used under the Bribery Act: a documented risk assessment, proportionate controls, visible commitment from senior leadership, due diligence on the people and third parties an organisation deals with, staff training, and regular review of whether any of it is actually working. Firms that treat this as a one-off policy update rather than an ongoing programme are likely to find that out the hard way, in front of a prosecutor rather than an auditor.

For anyone running identity verification or onboarding, the "due diligence" limb of that guidance is the one worth reading twice. A large firm that lets a supplier, agent, or customer onto its books without checking who they actually are has a much harder time arguing its fraud prevention procedures were reasonable, if that same relationship later turns out to be the vehicle for a fraud. Identity checks stop being a compliance formality at that point. They become part of a legal defence.

What Banks and Fintechs Should Actually Change, Not Just Document

None of this is abstract for anyone running onboarding, transaction monitoring, or a fraud operations desk. A few adjustments matter more than the rest:

  • Tune monitoring rules around APP typologies, not just card fraud. A model built to catch stolen-card transactions won't flag a customer calmly authorising a large transfer to a "new" supplier account, because nothing about the transaction looks technically wrong.
  • Treat receiving-account risk as seriously as sending-account risk. With costs split fifty-fifty under the PSR scheme, a bank that lets mule accounts open easily is now paying for that laxity directly, not just absorbing reputational damage.
  • Build a genuine, documented vulnerable-customer process. It affects reimbursement excess eligibility and shows up directly in ECCTA's "reasonable procedures" test.
  • Give staff training a paper trail, not just a slide deck. Under the new corporate offence, an organisation's defence rests on being able to show what it actually did, not what its policy says it should have done.
  • Revisit third-party and agent due diligence. The offence extends liability to fraud committed by "associated persons," a category wide enough to include agents, contractors, and introducers acting on the organisation's behalf, not just direct employees.
  • Screen new accounts for mule indicators at opening, not just at the point a victim reports a scam. By the time a bank matches an inbound APP payment to a fraud report, the receiving account has often already moved the money on, sometimes within minutes, and the eventual recovery rate on funds tracked that late is poor.

Banks reimbursed more money in 2025 than they ever have before, and a new law now makes it riskier for large firms to look away from fraud committed in their name. Losses still climbed anyway, faster than reimbursement did. That gap is the real story here. Rules and reimbursement schemes change who pays when a scam succeeds. They don't, on their own, stop the scam from working in the first place. The organisations that actually bend the 2026 numbers downward will be the ones treating fraud prevention as a live operational problem, not a compliance box checked once a year.