TL;DR Your scam losses are recorded at the payment. The scam behind that payment sits below the line: a mule account, an assembled identity, a reused device, a cash-out chain and the network running all of it. Almost none of that survives in the reported case, so APP fraud detection built on reported cases sees the payment and very little else.
What does a reported scam case actually contain?
In the bank's records, a scam appears as one row of data: a credible request the customer believed, a payment recorded with correct credentials from the customer's own device, and one beneficiary account identified days or months after the funds moved.
While that row is accurate, it is also a thin record of what happened. By the time a scam reaches the payment stage it has already cleared identity checks, device checks and authorization, because the person who approved the transfer was the real customer on the real phone.
Take an illustrative case: A finance manager at a mid-size business gets a call that appears to come from her bank. She confirms a change of supplier details she was already expecting and approves a £42,000 payment from her own laptop. Every control passes, and every control was built to check whether she meant to do it. However, the call was a scam. It was a fraudster impersonating the bank, the new supplier details belonged to the fraudster, and the £42,000 went to an account they controlled.
Once the scam is reported, the bank opens a case file for the £42,000 payment. The file holds only what the bank saw when the payment was made: correct credentials, her own laptop and one beneficiary account. It does not hold how that account was opened, whose identity was used to open it, which device was behind it, where the money went next, or which other institutions the same criminals were targeting. The loss number a board reads describes the payment without any of that.
Why don't rules-based fraud controls catch authorized payments?
A rules-based control built to spot an unauthorized transaction has nothing anomalous to score in a payment that looks like ordinary customer activity.
A rule also fires only on the depth of the scam it was written for, such as the payment itself or the accounts that receive the funds, so fraudsters move to a depth the rule does not cover. Tightening thresholds does not close the gap, as thresholds tight enough to catch mule intake also stop good payments, and false positives become the visible cost. You pay twice, once in scam losses and once in declined revenue.
Every control also teaches the fraudster where its boundaries lie. When a payment is declined or an account is frozen, they learn which pattern triggered the rule and change it, tweaking the amount, the script or the accounts involved, so the next attack clears what the rule covers. A rule can only describe patterns the bank has already seen, so detection built only on known patterns will inevitably overlook newer methodologies.
How is APP fraud detected beneath the reported payment?
Authorized push payment (APP) fraud scams occur when a customer is deceived into approving a payment, such as a wire transfer or remittance. It can occur on any payment method where the customer sends the funds. Because the payment itself clears every identity, device and authorization check, APP fraud detection has to look at the five layers of the scam behind it, and each layer leaves a different signal and needs a different detection method. The signal that would have blocked the transaction sits in the deeper layers: the account that received the money, the identity assembled to open it, the device that ran it, and the network that will try again next week.
Each layer hides a different part of the scam and has its own way of surfacing it:
- Mule account intake: accounts opened or bought to receive scam funds, surfaced by inbound payment monitoring and velocity rules.
- Identity assembly: synthetic identities built from real fragments, surfaced by element-level normalization and identity models.
- Device and session reuse: one operator running many accounts at once, surfaced by device graphs and behavioral signals.
- Layering and cash-out: funds moved through hops, ramps and borders, surfaced by fund-flow tracing across accounts and rails.
- Network coordination: the group operating across many institutions, surfaced by entity resolution and consortium intelligence.
Each layer needs a different method, and the signals only help when they are read together. Separate tools return separate answers, and the criminals move faster than you can reconcile the information.
Let's go back to the finance manager's £42,000 payment, but from the other end, starting with the account that received it. That account was opened four months earlier, using an identity assembled from fragments of three real people. The device that opened it had opened nineteen others. The funds left within the hour, split across two accounts and a cash-out ramp. None of these details appear in the case file the bank opened for her payment, which holds only what the bank saw at the moment of transaction. Account-opening, device and transfer data are held by the bank, but are spread across siloed systems.
So how can banks detect mule accounts?
If the payment itself looks clean, detection has to happen at the receiving end. This is where the account behaves differently from the payment that fills it. A scam payment looks legitimate because the customer authorized it. The mule account behind it does not: it shows unexpected credit velocity, rapid dispersal of the full balance, a mismatch between the declared purpose of the account and the money actually flowing through it, and device reuse across unrelated accounts.
Mule account detection therefore starts with inbound payment monitoring and velocity rules, which work on the beneficiary side rather than the payer side. Rules alone have a cost, because thresholds tight enough to catch mule intake also stop good payments. Reading the account against the identity and device behind it gives a rule something to corroborate before it declines a customer.
What share of scam victims show up in reporting?
Roughly 7% of US consumer fraud victims are counted in FTC data, according to Consumer Federation of America analysis, so for most victims there is no reported case at all. The same analysis sets $20.8 billion in reported losses against an implied $148.2 billion in actual losses, which means a team working only from reported losses sees a small corner of the real total.
A second source sizes the problem from the victim side. Gallup and the Stop Scams Alliance put US scam losses at $68 billion in 2025 across roughly 15 million adults, with an average loss of $5,578. Of reported scams, 56% cost $500 or less, so most individual cases look minor even though together they add up to losses on that scale.
Your team's scam priorities follow your reported cases, so whatever goes unreported never reaches the queue. That makes reporting the limit on what you can see, because far fewer scams are reported than actually happen.
How much is lost to scams each year?
UK Finance recorded £576.4 million in APP scam losses for 2025, up 19%, across 248,070 cases, up 7%, so losses are growing faster than the number of cases and each case costs more. Of that, £354.3 million was reimbursed to victims, about 61% of total APP losses, which puts most of the loss on the institution's own books.
Federal Trade Commission figures show $2.09 billion in consumer losses paid by bank transfer and payment in 2024, up 13% on 2023 and the largest single payment method in the data, so the biggest single route for these losses runs through payments banks process. The European Central Bank and European Banking Authority put total EEA payment fraud at €4.2 billion for 2024, up 17%, with credit transfers alone at €2.5 billion, up 24%, so push payments are growing faster than payment fraud as a whole.
Each of the loss measures above is rising, across the UK, the US and the EEA, and the controls built for the visible layer of a scam, meaning the reported payment, have not bent the curve.
How fast do scams move from first contact to payment?
Nearly half of scams are over within 24 hours, from the first approach to the money leaving the victim's account, according to research from the Global Anti-Scam Alliance and Feedzai. That leaves little room for anything that starts after a case is opened.
The window is narrowing, because ACI Worldwide projects that 80% of APP scam value will move on real-time rails by 2028, or $6.1 billion of a projected $7.6 billion, and faster rails shorten the time between a victim's decision and an irrecoverable position.
Post-case investigation still matters for reporting and for recovery attempts, but with scams completing inside a day it cannot inform a decision already made. Link analysis run on a confirmed case documents a network whose money left days ago. In the finance manager's £42,000 case, the funds left within the hour, so the useful question is whether anything in your stack recognized the beneficiary account before it received its first payment.
What does the hidden part of a scam cost you?
Four costs follow from what the payment does not show, and only one of them appears in your scam loss number.
- Repeat exposure. A closed case leaves the criminals with their accounts, identities, devices and playbook, so the same network returns on infrastructure you never shut down.
- Investigation load. One analyst works one reported case with no link to the other cases in the queue, so the same network can be investigated several times as several unrelated incidents.
- False positives. Thresholds tightened to catch mule intake stop legitimate payments, and the cost lands on customers and revenue.
- Reimbursement. You refund the customer for the payment you can see while the criminals behind it keep operating, so the cost moves from the customer to your bank and the scam keeps going.
Each of these costs persists while a scam is judged only by its reported payment, and one bank looking at its own cases faces an even wider blind spot.
Why can't a single bank see the whole criminal network?
Because a criminal network runs against a dozen other institutions at the same time, each bank sees only its own slice, and every institution's picture is structurally incomplete.
Each of those banks holds a case file that looks like an isolated incident. Laid side by side, though, those files would show one criminal network at work. However, because no single institution holds all of them, the network never appears as one, and every bank closes its piece as a one-off while the same criminals move on to the next target.
Consortium data addresses that gap. In a consortium, participating organizations contribute anonymized fraud data to a shared pool, and every member's risk scoring can draw on patterns the whole network has seen, not only its own history. A pattern first seen at one participant can then inform risk scoring and alerts at another.
No single bank can build that view alone, because each institution sees only its own cases and relearns the same criminal network one loss at a time. A consortium lets one participant's loss warn the rest. FraudNet's Global Anti-Fraud Network is built on that idea: a secure, anonymized and aggregated intelligence network that spans financial enterprises, payment events and geographies. Seeing across institutions starts with seeing across your own cases.
Closing the gap below the payment
A reported scam shows a bank one clean payment, while the accounts, identities, devices and criminal network behind it stay out of view. Before you evaluate anything else, run one check on your own data: how many of your confirmed scams connect to other cases? Almost no institution can answer that from current reporting, and the answer shows how much of your scam volume sits below the line.
Seeing past your own cases is the part no single bank can do alone, and it is where FraudNet's Global Anti-Fraud Network comes in. It gives a bank's risk scoring the patterns seen across the network, alongside machine learning models, a no-code rules engine and real-time decisioning in one AI-Native platform. To learn more about FraudNet's approach to scams, book a demo today.

You might be interested in…
Get Started Today
Experience how FraudNet can help you reduce fraud, stay compliant, and protect your business and bottom line
%20(640%20x%201229%20px).png)
