Skip to content
EBA · EU-wide

Manipulation of the payer — the EU name for APP fraud

Fintech Passport
August 20, 2026 · 4-min read
Manipulation of the payer — the EU name for APP fraud

What the market calls authorised push payment fraud, EU supervisory reporting calls manipulation of the payer — and the official definition is narrower than the market’s. Under the EBA Guidelines on fraud reporting under Article 96(6) of PSD2, it covers payment transactions made as a result of the payer being manipulated by the fraudster to issue a payment order, or to instruct the provider to do so, in good faith, to a payment account it believes belongs to a legitimate payee. Three elements, all of which have to hold.

1. The three elements

ElementWhat it requiresWhy it matters
Manipulation by the fraudsterThe payer acted because they were deceivedExcludes buyer’s remorse and disputes about goods or services actually supplied
The payer issues the order (or instructs the provider to)The transaction is authorised by the payerThis is what puts it outside the unauthorised category entirely
In good faith, to an account believed to belong to a legitimate payeeA genuine belief about the identity of the payeeExcludes a complicit payer, which is a mule question rather than a fraud-reporting one

2. Why it is reported separately

Because the two categories fail differently. Unauthorised fraud is a failure of authentication and data protection: someone transacted who should not have been able to. Manipulation of the payer is a failure of context: the authentication worked perfectly and produced the wrong outcome.

Reporting them together would let improvement in one mask deterioration in the other — which is precisely what tends to happen operationally as strong customer authentication pushes attackers away from credential theft and towards deception. Separating them at source is what makes that shift visible.

3. Where the controls actually sit

Because the payer authenticates correctly, the effective controls are not authentication controls. Three families do the work:

  • Payee verification. Checking that the name the payer supplied matches the account they are paying attacks the element the fraud depends on. In the EU this is now a regulated function in its own right for credit transfers in euro, through the verification of payee service under the Instant Payments Regulation.
  • Behavioural and contextual monitoring. First payment to a new payee, unusual amount for the profile, a payment made during a long inbound call, a beneficiary account opened days earlier — none of these are authentication signals, and all of them are available.
  • Friction that interrupts a script. The defining feature of manipulation is that the payer is being coached in real time. A warning the payer can dismiss without reading does not interrupt a script; a step that requires a specific, unscripted response does.

4. How it is counted

The same counting rules apply as for the rest of the framework, and two of them shape the picture materially. Only transactions that were initiated and executed are reported, so interventions that stopped a payment never appear. And the transaction is reported regardless of whether the amount has been recovered, so recovery success is invisible in the transaction counts and appears only in the separate loss figures.

For card payments the taxonomy carries a dedicated line — manipulation of the payer to make a card payment — reported under both the strong-customer-authentication and the non-strong-customer-authentication branches. That the line exists at all under SCA-authenticated card payments is the clearest statement in the framework that authentication is not the control for this category.

FAQ

Is manipulation of the payer the same as APP fraud?

It is the EU supervisory reporting term for the same phenomenon, with a defined test: manipulation, an order issued by the payer, and a good-faith belief about the payee’s identity.

Does strong customer authentication prevent it?

No. The payer authenticates genuinely. The framework reports this fraud type under SCA-authenticated transactions as well as non-authenticated ones for exactly that reason.

What if the payer was complicit?

Then the good-faith element fails and it is not manipulation of the payer. That scenario belongs to money-mule and account-misuse analysis instead.

Do prevented cases show in the statistics?

No — only initiated and executed transactions are reported, so successful intervention is absent from the published figures.


Related: The supervisory fraud taxonomy · Verification of Payee · PSD2 fraud reporting

Related reads.