Thisismoney Surge in APP Fraud Losses Driven by AI Exploitation
Article Content
- •UK fraud losses reached £1.3 billion in 2025, with APP fraud losses at £576.4 million.
- •Fraudsters increasingly use AI to enhance the sophistication of scams, including impersonation.
- •Banks refunded only 61% of APP losses, highlighting gaps in fraud prevention measures.
In 2025, UK Finance reported that fraudsters stole nearly £1.3 billion from victims, with 4.1 million cases of fraud, marking an 11% increase from the previous year. Losses from authorised push payment (APP) fraud rose 19% to £576.4 million, the highest since 2021. The rise in fraud is attributed to increasingly sophisticated social engineering tactics, including the use of AI for impersonation and automated scams. Despite a mandatory reimbursement framework, banks only refunded 61% of APP losses. The Payment Systems Regulator noted that while reimbursement rates are improving, the actual losses continue to rise, indicating a need for better prevention measures. Calls for stronger responsibilities on tech platforms like Meta are growing, as many scams originate from these sites. The industry is also seeing a significant rise in investment scams, with losses reaching record levels. The ongoing challenge is balancing customer protection with the need for effective fraud prevention.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…