swel

GlossaryAPP fraud (authorised push payment fraud)

APP fraud (authorised push payment fraud)

Authorised push payment (APP) fraud occurs when a payer is manipulated into authorising a payment to a bank account controlled by a fraudster, typically by impersonating a legitimate counterparty or intercepting payment instructions. It is distinct from unauthorised fraud because the payer themselves executes the transfer; the authorisation is technically genuine, even though it is based on deception.

Private funds are a high-value target for APP fraud because capital calls and distributions involve large, infrequent transfers to counterparties whose bank account details change rarely but are communicated through channels that can be compromised.

How it works

In conventional APP fraud, a fraudster impersonates a trusted party, such as a solicitor, supplier, or bank, and convinces the victim to transfer funds to a "new" or "updated" account. Because the payer authorises the payment themselves, the payment is technically valid from the bank's perspective, making recovery difficult or impossible once funds have been moved.

In private fund administration, the most common vector for APP fraud is the interception or forgery of capital call notices or payment instruction updates. Fraudsters monitor or access fund administrator email systems, LP investor portals, or GP communications channels, and substitute legitimate bank account details with their own. Because capital calls are sent on irregular schedules and for large amounts, a single successful interception can yield tens of millions of pounds or euros.

The fund administrator is simultaneously the primary target and the primary line of defence. A fraudster who successfully impersonates a GP and instructs a fund administrator to redirect LP payments to a fraudulent account has bypassed the LP entirely. Conversely, a fraudster who impersonates a fund administrator and sends fake capital call notices directly to LPs targets the LP's treasury or accounts payable function, not the administrator.

Regulatory frameworks in the UK now require payment service providers to reimburse victims of APP fraud up to defined thresholds under the mandatory reimbursement regime introduced by the Payment Systems Regulator. This creates additional incentive for banks to implement pre-payment controls, including Confirmation of Payee and transaction monitoring. However, reimbursement frameworks are calibrated for retail and SME payments; the amounts involved in fund administration typically exceed the maximum reimbursable amounts, making prevention materially more important than recovery.

The key structural vulnerability in fund administration is that payment instructions have historically been communicated by email, a channel that is inherently insecure. "Payment instructions never travel by email" is the foundational principle of payment-secure fund infrastructure. When bank details are held in a verified, static registry and all payment instructions reference that registry rather than ad hoc email communications, the primary attack surface for APP fraud is removed.

Worked example

Redwood Partners, a mid-market private equity fund administrator, manages capital calls for twelve funds. In November, the fund administrator's general inbox receives an email appearing to come from the CFO of Harstone Capital Partners (one of the GPs whose funds Redwood administers), requesting that "LP payment instructions for Fund IV capital call three" be routed to updated bank account details, citing a banking migration.

The email domain is harstone-capital-partners.com. The legitimate GP's domain is harstonecapitalpartners.com. The difference is a single hyphen.

Without a control requiring all payment instruction changes to be verified through an authenticated portal or direct voice call to a pre-registered contact, the fund administrator's operations team may process the update. The result is that capital call proceeds from Fund IV are wired to an account controlled by the fraudster.

If instead the fund administrator operates on the principle that payment instructions can only be changed through a verified counterparty portal, with mandatory confirmation to the pre-registered mobile number of the authorised GP contact, the fraudulent email instruction fails at the first control and the fraud is prevented.

Frequently asked questions

How is APP fraud different from business email compromise (BEC)? Business email compromise is one specific method of executing APP fraud: a fraudster compromises or impersonates a legitimate email account to redirect payments. APP fraud is the broader category; BEC is a delivery mechanism. Other APP fraud mechanisms include vishing (phone-based impersonation), fake invoice substitution, and social engineering through legitimate-looking portals.

Who bears the loss when APP fraud hits a fund capital call? Liability depends on the specific facts and jurisdiction, but the general principle is that where the fund administrator or LP authorised the payment (even under false pretences), recovery from the bank is difficult unless the bank failed to apply required controls such as Confirmation of Payee. In practice, APP fraud losses in fund administration are often borne by the defrauded party, with potential recourse against the administrator if negligent procedures can be established.

What controls reduce APP fraud risk in fund administration? The most effective controls are: verified payment instruction registries where counterparty bank details are authenticated at onboarding and only updatable through a documented, multi-step verification process; segregation of payment instruction receipt from payment execution (no single individual should both receive updated instructions and release payments); mandatory Confirmation of Payee at point of execution; and independent verification of all payment instruction changes to a registered contact through a separate channel.

Are LPs or GPs more commonly targeted in fund APP fraud? Both are targeted through different vectors. LPs are targeted through fake capital call notices directing payment to fraudulent accounts. GPs are targeted through fake "fund administrator" communications requesting updated LP bank details. Fund administrators are targeted through impersonation of both GPs and LPs. The highest-value attack surface is typically the fund administrator, because a successful compromise of the administrator's payment workflow can redirect payments across multiple funds and counterparties simultaneously.

Does the mandatory APP reimbursement scheme apply to fund payments? The UK Payment Systems Regulator's mandatory reimbursement scheme applies to Faster Payments. Most institutional fund payments use CHAPS or SWIFT for large-value domestic and cross-border transfers. CHAPS falls within the PSR's scope; SWIFT does not. Even within scope, the per-claim reimbursement limit is set at a level that covers only a small fraction of the amounts typically involved in a fund capital call.

Related terms

Confirmation of Payee, Business email compromise (BEC) in capital calls, IBAN verification in private fund payments, Maker-checker in fund administration, Straight-through processing (STP) in fund payments

Related pages

How fund administrators should protect capital call payments from wire fraud, Swelv for fund administrators