United Kingdom · APP fraud · Bank transfers · 25 min read
Can You Get an APP Scam Payment Refunded in the UK?
Most eligible UK consumers who were deceived into sending an in-scope Faster Payment or CHAPS payment on or after 7 October 2024 should start by making an APP fraud reimbursement claim to the payment provider that sent the money. The mandatory rules are powerful, but they do not cover every loss called a scam: card purchases, cash, cryptocurrency transfers, international payments, civil disputes and payments to an account the customer controls can follow different routes. This guide separates those routes, explains the £85,000 mandatory cap, the usual five-business-day decision timetable, the 35-business-day longstop where a firm legitimately stops the clock, the optional excess of up to £100, and the narrow consumer-standard-of-caution exception. It is an editorial guide based on published regulator material, not legal advice or a promise that a particular claim will be paid.
Sources for the introduction, figures and summary
- Payment Systems Regulator: APP fraud reimbursement protectionsRules effective 7 October 2024; Accessed 28 July 2026
- Financial Conduct Authority: fraudulent paymentsUpdated 15 May 2026
- City of London Police: Report FraudAccessed 28 July 2026
- Payment Systems Regulator: consolidated APP reimbursement policy statement PS25/5Published May 2025
- Financial Ombudsman Service: fraud and scam complaintsAccessed 28 July 2026
- Financial Ombudsman Service: time limit after a final responseAccessed 29 July 2026
- Financial Ombudsman Service: what to expectUpdated 24 July 2026; accessed 29 July 2026
- Financial Ombudsman Service: section 75 complaintsAccessed 28 July 2026
The direct answer: when the UK APP rules can require reimbursement
Direct answer: The mandatory regime can require reimbursement where a qualifying customer was tricked into authorising an in-scope UK Faster Payment or CHAPS payment to a fraudster on or after 7 October 2024, subject to the rules, cap and limited exceptions.
An authorised push payment scam is not the same thing as an account takeover. In an APP case, the genuine customer instructs the payment because a criminal has lied about the recipient, the purpose or the expected benefit. Common examples include an impersonation call, a false invoice, a purchase that was never genuine, a romance narrative or an investment proposition built on a fake platform. The customer really pressed send, yet the consent was obtained through deception. Parliament and the Payment Systems Regulator created a reimbursement framework precisely because older arguments often stopped at the fact that the customer had authorised the transfer.
Start with four facts, not the label attached by the scammer or the bank: the date of each payment, the payment system used, the account from which it left, and the account to which it went. A payment made before 7 October 2024 is not assessed under the new mandatory regime. A card transaction is not converted into a Faster Payment merely because the merchant was fraudulent. A transfer to an account in the customer’s own name may be outside the APP definition even if a later crypto transfer completed the fraud. International transfers and cash also need separate analysis. Getting this classification right prevents a valid complaint from being rejected because it was presented under the wrong rule.
The PSR’s consumer page says the protection applies to UK bank transfers where money moves from one UK account to another through Faster Payments or CHAPS. It does not say that every financial loss must be reimbursed. The safest editorial formulation is therefore conditional: an eligible claim should be assessed under the mandatory rules; a non-qualifying payment may still have a card, unauthorised-payment, contractual, negligence, tracing or complaints route. No private adviser can approve the claim or guarantee the provider’s decision.
| What happened | Likely first route | Do not assume |
|---|---|---|
| You instructed a UK bank transfer to the scammer | APP reimbursement assessment | Authorisation automatically defeats the claim |
| A criminal made a payment without your consent | Unauthorised-payment claim | It is an APP claim simply because a scam was involved |
| You paid a merchant by card | Card dispute, chargeback or section 75 assessment | The APP cap and five-day timetable apply |
| You sent cash, crypto or an overseas transfer | Provider, police and asset-specific route | The UK APP rules cover that payment |
Source: Payment Systems Regulator: APP fraud reimbursement protectionsRules effective 7 October 2024; Accessed 28 July 2026
Source: Financial Conduct Authority: fraudulent paymentsUpdated 15 May 2026
What to do in the first hour after discovering the transfer
Direct answer: Contact the sending provider immediately through a trusted channel, say that you are reporting an APP scam, ask it to contact the receiving provider, secure your accounts and preserve the evidence before messages or websites disappear.
Speed matters because the first operational goal is not an argument about final legal liability; it is an attempt to stop or contain movement of the money. Call the number in the banking app, on the back of the card or on the provider’s independently located website. Do not use a telephone number supplied by the person who induced the payment. Ask for a fraud case reference, the time the report was logged, the name or identifier of the team handling it, and written confirmation of the next step. If another payment is pending, state that clearly. If remote-access software was installed, disconnect the affected device from banking activity and tell the provider how the criminal interacted with it.
Preserve the original material in a form that retains dates and context. Export chats rather than relying only on selected screenshots. Download bank statements and payment confirmations. Save the advert, profile, email headers, telephone numbers, web addresses, invoices and the wording of warnings shown by the provider. Record what the criminal said immediately before each payment and what you believed at the time. The reimbursement test concerns the actual transaction and the customer’s conduct; a clean chronology is more useful than a long conclusion that simply says the bank should have known.
The PSR consumer standard also includes prompt reporting and cooperation with reasonable, proportionate information requests. Reporting quickly is therefore useful both practically and procedurally. It is still worth reporting a claim that was not discovered immediately: the regime uses a 13-month outer claim period measured from the last relevant payment, but a long unexplained delay can make preservation and recovery harder. Do not pay anyone who calls after the loss and claims that a release fee, bond or tax will unlock money already recovered.
- 01Call the sending provider
Use a contact you verified independently and state that the transfer was induced by an APP scam.
- 02Ask for containment
Request contact with the receiving provider, recall or freezing action where available, and a case reference.
- 03Secure access
Change credentials from a clean device, end remote sessions and disclose any remote-access software.
- 04Preserve the record
Export chats, statements, warnings, adverts and payment confirmations with dates intact.
- 05Make the official report
Report through the genuine police fraud channel or consent to the provider reporting as the rules require.
Source: Payment Systems Regulator: APP fraud reimbursement protectionsRules effective 7 October 2024; Accessed 28 July 2026
Source: City of London Police: Report FraudAccessed 28 July 2026
Related steps:Recovering money after a scam in Canada · Getting money back after a scam in Australia
APP fraud, unauthorised payment and civil dispute are different claims
Direct answer: An APP claim concerns a payment you authorised because of fraud; an unauthorised-payment claim concerns a payment you did not consent to; a civil dispute concerns a genuine counterparty that may have breached a contract.
Those categories sometimes overlap at the edges, but they should not be collapsed. If a criminal logged in and transferred money without the account holder’s consent, the FCA’s unauthorised-payment guidance is the starting point. It says a customer should notify the provider promptly and generally within 13 months. Subject to the legal exceptions, an unauthorised payment should normally be refunded by the end of the next business day. The firm may investigate whether the customer authorised the payment, acted fraudulently or failed to protect security credentials in the legally relevant way. Use of a password or PIN is not, by itself, conclusive proof of authorisation.
An APP scam has the opposite factual feature: the customer did instruct the payment, but the surrounding story was fraudulent. The new reimbursement regime supplies a dedicated route for qualifying transfers. Calling every transaction ‘unauthorised’ can undermine credibility when the audit trail shows the customer approved it. Describe what happened accurately: who initiated the instruction, who controlled the device, what the customer believed, and whether the recipient was the person or business the customer intended to pay.
A civil dispute is different again. Suppose a real trader delivered late, work was poor, or the parties disagree about cancellation. The PSR page expressly distinguishes civil disputes and points to consumer protections such as the Consumer Rights Act. A fake seller that never intended to supply anything may be an APP scam; a genuine seller who later breaches a contract may not be. The provider should assess the facts rather than rely on a label, but the claimant should give it the material needed to draw the distinction.
Source: Payment Systems Regulator: APP fraud reimbursement protectionsRules effective 7 October 2024; Accessed 28 July 2026
Source: Financial Conduct Authority: fraudulent paymentsUpdated 15 May 2026
Who and what are inside the mandatory regime
Direct answer: The regime protects qualifying consumers, microenterprises and eligible charities using relevant accounts, and it applies to in-scope Faster Payments and CHAPS transfers between UK payment accounts.
For an individual, the ordinary pattern is a personal account used for purposes outside a trade or profession. The rules also extend beyond individuals to categories of microenterprise and charity defined in the scheme. A business should not assume that any company qualifies merely because it is small; it should give the provider its status and ask for a written scope decision. The same care is required with account type. The payment must leave and reach relevant UK accounts through an in-scope system. The fact that a fraudster communicated from abroad does not by itself remove a UK account-to-account transfer from scope, while an actual international wire is not brought into scope merely because the payer lives in Britain.
Multi-step scams require a payment-by-payment map. A victim may send money from Bank A to an account in their own name at Bank B and then send it to a fraudster or buy crypto. The first leg may be legitimate movement between controlled accounts; the later leg may be the loss-causing payment. The PSR rules contain a treatment for multi-step fraud, but an article should not tell a reader that every preliminary transfer is reimbursable. List every leg, its account holder, payment rail, date and recipient. Let the provider identify which transaction is the qualifying APP payment.
Excluded payment types still deserve urgent action. A debit-card payment may support a chargeback. A credit-card purchase may require both chargeback and section 75 analysis. Cash and gift cards should be reported to the issuer or retailer promptly. A crypto transfer cannot be reversed by the APP rules, although an in-scope bank transfer directly to a fraudulent recipient and a later blockchain transfer are factually different legs. The central discipline is to follow the money rather than apply one attractive rule to the entire story.
- Identify the customer category and account type.
- Record whether the payment used Faster Payments, CHAPS, a card, an international rail or another method.
- Name the holder of every receiving account in a multi-step chain.
- Separate the loss-causing transfer from preparatory movements between your own accounts.
Source: Payment Systems Regulator: APP fraud reimbursement protectionsRules effective 7 October 2024; Accessed 28 July 2026
Source: Payment Systems Regulator: consolidated APP reimbursement policy statement PS25/5Published May 2025
Why 7 October 2024 changes the route
Direct answer: Payments made on or after 7 October 2024 can fall under the mandatory regime; earlier authorised payments must be assessed under the rules and standards that applied at the time, including the former voluntary CRM Code where relevant.
The FCA divides authorised scam payments into time periods. For qualifying transfers from 7 October 2024, it directs consumers to the mandatory APP framework. For payments made from 28 May 2019 to before 7 October 2024, the voluntary Contingent Reimbursement Model Code may matter if the provider was a signatory. That older code is not retroactively converted into the mandatory rules. The provider’s warnings, intervention, recovery work and treatment of vulnerability may also be considered under the standards in force when the payment occurred.
A scam can cross the boundary. Imagine a supposed investment receiving payments in September and October 2024. Do not merge them into one total and quote the newer cap. Put each transfer in a dated table and identify the payment system. A provider may have to assess different payments under different frameworks. The last-payment date also matters for the 13-month claim window under the mandatory rules, but it does not revive a different historical regime for earlier transactions.
Use current law without rewriting history. The PSR later consolidated and clarified its policy, and the current consumer page should guide claims made now. Yet the operative payment date remains essential. A good complaint says both: ‘I am submitting this claim today’ and ‘the relevant payments were made on these dates’. It then asks the firm to identify the rule applied to each payment. This is stronger than attaching a 2026 article and assuming every rule in it governed a payment made years earlier.
| Payment date | Framework to examine | Practical note |
|---|---|---|
| On or after 7 October 2024 | Mandatory APP reimbursement rules for qualifying payments | Check system, customer, account and exclusions |
| 28 May 2019 to 6 October 2024 | CRM Code if the provider was a signatory, plus wider duties | Do not apply the new £85,000 cap mechanically |
| Before 28 May 2019 | Law, complaint standards and provider conduct at the time | Obtain specialist advice for an old, high-value dispute |
Source: Financial Conduct Authority: fraudulent paymentsUpdated 15 May 2026
Source: Payment Systems Regulator: consolidated APP reimbursement policy statement PS25/5Published May 2025
The £85,000 cap and optional excess
Direct answer: The mandatory maximum is £85,000 per qualifying claim, while a sending provider may apply an excess of up to £100; it cannot apply that excess to a consumer assessed as vulnerable in relation to the scam.
The cap is not a valuation of how serious the crime was and not a promise that every claim below it will be paid. It sets the maximum amount required by the reimbursement regime for a qualifying claim. A provider may choose to reimburse more. The PSR consumer page also says a person with an unreimbursed loss above the cap can complain to the Financial Ombudsman Service, whose current compensation limit is described there as £430,000. An ombudsman complaint still requires an assessment of jurisdiction, facts, causation and fairness; the higher figure is not an automatic second layer of insurance.
The excess is optional. A firm may use no excess, a lower amount or up to £100. It should not be described as a universal £100 deduction. The provider cannot apply it where the consumer is vulnerable under the scheme in relation to the particular scam. Vulnerability is assessed on the actual circumstances, and a characteristic does not produce the same result in every case. Explain how health, bereavement, financial pressure, cognitive difficulty, communication needs or another circumstance affected the person’s ability to detect or resist the social engineering, and supply proportionate evidence if requested.
For a series of payments, ask the provider to state what it treats as one claim and how it calculated the cap and any excess. Do not split or combine transactions strategically in the narrative. Give the complete sequence. The scheme rules, not the claimant’s preferred arithmetic, determine the claim unit. Also distinguish money recovered from the receiving account from reimbursement paid by the provider: both reduce loss, but they are different mechanisms and should be shown separately in any settlement calculation.
Source: Payment Systems Regulator: APP fraud reimbursement protectionsRules effective 7 October 2024; Accessed 28 July 2026
Source: Payment Systems Regulator: consolidated APP reimbursement policy statement PS25/5Published May 2025
Related steps:Investment scam recovery routes · Crypto scam recovery: realistic options
Five business days, stop-the-clock and the 35-day longstop
Direct answer: A qualifying claim is generally expected to be reimbursed within five business days, but the provider may stop the clock for permitted enquiries and must reach an outcome within 35 business days.
The five-day figure begins with the claim, not the original transfer. It is a decision-and-reimbursement timetable, not a promise that recipient funds can still be recalled within five days. The provider may need information about the fraud, the customer’s vulnerability or the payment chain. The PSR allows a stop-the-clock process for legitimate information gathering, but it also sets the 35-business-day outer timetable to prevent open-ended delay. Ask in writing whether the clock has been stopped, why, what information is outstanding and when it resumed.
Respond to reasonable and proportionate requests. If a request is unclear or asks for material you cannot obtain, explain that promptly and offer an alternative. A bank statement, exported chat, police report reference and timeline are usually more useful than hundreds of unsorted images. Keep a contact log showing the date, channel, case number, request and response. If the firm exceeds the published timetable, add the delay to the formal complaint; do not assume silence means approval.
The consumer must notify the provider promptly after suspecting an APP scam and, under the rules, no later than 13 months after the last relevant payment. Thirteen months is an outer limit, not a recommended waiting period. The chance of operational recovery usually declines as money moves. A late discovery may be entirely genuine, especially in long investment or relationship scams, so state when and how the deception became apparent. That date may explain why the report followed the transfer by weeks or months.
- 01Day zero
Submit the APP claim and obtain a timestamped reference.
- 02During assessment
Answer proportionate questions and preserve every request and response.
- 03If the clock stops
Ask for the reason, missing information and revised calculation of business days.
- 04By the longstop
Expect an outcome within 35 business days and complain formally if the process has drifted.
Source: Payment Systems Regulator: APP fraud reimbursement protectionsRules effective 7 October 2024; Accessed 28 July 2026
Source: Payment Systems Regulator: consolidated APP reimbursement policy statement PS25/5Published May 2025
The consumer standard of caution is not an ordinary-negligence test
Direct answer: A provider relying on the consumer-standard exception must prove gross negligence in relation to specified duties; the PSR describes that as a very high bar expected to apply only in a small minority of cases.
The duties include having regard to a specific, directed warning, reporting promptly, responding to reasonable and proportionate information requests, and reporting to police or consenting to the provider doing so. Missing one item does not automatically defeat a claim. The provider must connect the conduct to the gross-negligence standard and the circumstances. A generic warning that appears during routine payments is not necessarily equivalent to a tailored warning saying the intended recipient is likely to be a fraudster. Preserve the exact screen where possible.
Social engineering is central. A criminal may keep the victim on the phone, impersonate a trusted institution, tell them to hide the transaction, coach answers to bank questions or create a false emergency. A complaint should describe that pressure without removing personal agency or embellishing the facts. The issue is not whether a calm observer can now identify a red flag. It is what information and warnings the customer had, what the fraudster said, and how the specific payment decision occurred.
Where vulnerability contributed to the person being defrauded, the sending provider must not apply the consumer-standard-of-caution exception or the claim excess. The PSR’s May 2025 consolidated statement emphasises case-by-case assessment. Do not reduce vulnerability to age alone or assume that a medical diagnosis automatically determines the claim. Explain the functional effect at the relevant time. If the provider rejects vulnerability, ask it to identify the evidence considered and its reasons.
- Save the exact warning, not a recollection of a generic warning.
- Explain any coaching, urgency, impersonation or remote access.
- Give the discovery and reporting dates.
- Answer reasonable questions and record anything you cannot supply.
- Describe how a vulnerability affected this scam, where applicable.
Source: Payment Systems Regulator: consolidated APP reimbursement policy statement PS25/5Published May 2025
Source: Payment Systems Regulator: APP fraud reimbursement protectionsRules effective 7 October 2024; Accessed 28 July 2026
Build a claim file the bank can actually assess
Direct answer: A useful APP claim file joins each payment to the deception that caused it, the warning shown, the recipient details, the discovery event and the action taken immediately afterwards.
Begin with a one-page chronology. Give every payment its own row: date and time, amount, sending account, receiving name and details, reference, payment system, stated purpose, and the message or call that prompted it. Add a column for any intervention by the provider. If a call handler questioned the payment, write down the questions and the answers actually given. If the fraudster coached a false answer, say so. A complete record is more credible than deleting awkward details that the provider’s logs will reveal.
Attach evidence in labelled groups rather than one large archive. Group A can contain statements and confirmations; Group B communications; Group C website, advert and company records; Group D provider warnings and contacts; Group E police and platform reports; Group F evidence of vulnerability where relevant. Preserve originals and use copies for annotation. Avoid editing screenshots in a way that removes the status bar, date or surrounding thread. Where a platform no longer exists, record when it disappeared and use lawful archive material if available.
State the remedy precisely: assessment under the mandatory APP rules for listed payments, reimbursement calculated under those rules, return of any separately recovered funds, and a reasoned written decision. If some transactions are card payments or transfers between your own accounts, identify them but do not demand that the provider pretend they are Faster Payments to a fraudster. Accurate separation gives the strongest part of the claim room to stand on its own.
| Field | Why it matters | Evidence |
|---|---|---|
| Payment route and recipient | Tests scope and identifies the receiving provider | Statement, confirmation, payee record |
| Representation made | Connects deception to authorisation | Chat, email, advert, call note |
| Provider intervention | Shows warnings and questions | Screenshot, call record, complaint disclosure |
| Discovery and report | Tests prompt-reporting facts | Case reference, email, police report |
| Vulnerability effect | May affect excess and caution exception | Short explanation and proportionate supporting record |
Source: Payment Systems Regulator: APP fraud reimbursement protectionsRules effective 7 October 2024; Accessed 28 July 2026
Source: Financial Conduct Authority: fraudulent paymentsUpdated 15 May 2026
How to challenge a refusal or underpayment
Direct answer: Ask for the complete written reasons, identify the disputed factual or rule-based finding, make a formal complaint to the provider, and take an eligible unresolved complaint to the Financial Ombudsman Service.
A useful refusal should say whether the firm found the payment outside scope, considered it a civil dispute, relied on first-party fraud, applied the consumer-standard exception, disputed vulnerability, calculated the cap or excess, or treated money as already recovered. Do not answer a detailed refusal with a generic statement that all scam victims must be reimbursed. Match evidence to each reason. If the firm says the payment was international, provide the payment confirmation. If it says you ignored a tailored warning, request the wording and timestamp. If it says the transaction was to your own account, map the later loss-causing leg.
Use the provider’s formal complaints process even if the fraud team has already answered. Mark the communication as a complaint, state the outcome sought and ask for a final response. Because this route concerns payment services, the firm should respond within 15 business days; if it cannot give a final response then, it must explain why and provide one within 35 business days. The eight-week timetable applies to many other complaint categories, not this payment-services route. The reimbursement assessment timetable and the complaint timetable are related but not identical: a firm cannot turn the five/35-day claim process into an indefinite investigation merely by calling it a complaint.
The Financial Ombudsman Service can consider eligible complaints about fraud and scams. Its consumer process is free and does not require a lawyer. A referral normally must reach FOS within six months from the date on the financial business’s final response; exceptional circumstances, an invalid final response or the business’s agreement can affect a late case. Preserve that date and do not confuse this referral window with the firm’s complaint-response timetable.
FOS looks at the law, relevant rules and what is fair and reasonable in the circumstances. Supply the provider’s final response, claim schedule, evidence bundle and a focused explanation of the alleged error. Do not present an ombudsman referral as a guaranteed appeal. Published decisions turn on their facts, and court deadlines or high-value losses can require separate legal advice rather than waiting passively for every complaints stage.
- 01Get the reasons
Request the scope finding, exception, calculation and evidence relied on.
- 02Correct the record
Answer each disputed point with a dated document or concise factual explanation.
- 03Make a formal complaint
State the remedy and ask for a final response.
- 04Refer an eligible case
Send the final response and organised file to the Financial Ombudsman Service.
- 05Protect other deadlines
Do not let complaint handling obscure limitation or court advice in a substantial case.
Source: Financial Conduct Authority: fraudulent paymentsUpdated 15 May 2026
Source: Financial Ombudsman Service: fraud and scam complaintsAccessed 28 July 2026
Source: Financial Ombudsman Service: time limit after a final responseAccessed 29 July 2026
Source: Financial Ombudsman Service: what to expectUpdated 24 July 2026; accessed 29 July 2026
Card payments need chargeback or section 75 analysis, not APP wording
Direct answer: A debit- or credit-card payment to a fraudulent merchant is generally assessed through card-dispute rules and, for qualifying credit purchases, section 75—not through the APP bank-transfer regime.
Chargeback is a card-scheme process in which the issuing provider may seek funds from the merchant’s side under a reason code and deadline. The useful facts are what was purchased, what was promised, when performance was due, what was delivered, and whether the merchant was contacted. A criminal investment platform may have used a payment processor whose statement descriptor differs from the brand shown online. Preserve both. Do not assume ‘fraud’ is always the correct card reason where the customer knowingly made a purchase but the service was not supplied or was misrepresented.
Section 75 of the Consumer Credit Act can make a credit provider jointly liable for a supplier’s breach of contract or misrepresentation in qualifying debtor-creditor-supplier arrangements. It has its own financial and transactional conditions. It is not simply a stronger word for chargeback, and the use of an intermediary can complicate the required relationship. Ask the card provider to consider every properly applicable route and give separate reasons if it rejects one.
Card and APP claims can coexist in one scam if different deposits used different methods. Present a master chronology, then separate schedules by route. This avoids importing the £85,000 APP cap into a card claim or presenting a scheme deadline as the time limit for a bank-transfer reimbursement claim. It also makes later review easier because the ombudsman can see which provider decision relates to which payment.
Source: Financial Ombudsman Service: section 75 complaintsAccessed 28 July 2026
Source: Financial Ombudsman Service: fraud and scam complaintsAccessed 28 July 2026
Crypto, international payments and payments to your own account
Direct answer: The APP rules do not automatically reimburse a blockchain transfer, an overseas payment or a transfer to an account you control, so each leg must be routed to the provider and legal process that actually governs it.
In a crypto-investment scam, a bank transfer may fund a genuine exchange account held in the victim’s name. The victim then buys an asset and sends it to a wallet controlled by the criminal. The bank-to-exchange transfer can look like a legitimate transfer between the victim’s own accounts; the irreversible blockchain transfer is the loss event. Another case may involve a direct Faster Payment to an account named by the scammer. Those patterns should not be described as equivalent. Record exchange account ownership, order receipts, wallet addresses, transaction hashes and every payment leg.
For an international wire, ask the sending institution immediately for a recall and fraud escalation, but do not quote the domestic APP rule as if it governs. Report through the official police fraud service and retain the beneficiary bank, SWIFT or transfer references. Cross-border recovery may require cooperation from foreign institutions or authorities. A private party cannot compel disclosure merely by sending a legal-looking letter.
If the firm rejects an APP claim because the first transfer went to your own account, ask it to identify the precise payment it assessed and whether it considered the full multi-step fraud under applicable rules and wider duties. Avoid the opposite overstatement: the existence of a multi-step policy does not make every movement reimbursable. A careful file shows control of each account and the point at which control or beneficial ownership passed to the criminal.
Source: Payment Systems Regulator: consolidated APP reimbursement policy statement PS25/5Published May 2025
Source: Financial Conduct Authority: fraudulent paymentsUpdated 15 May 2026
Source: City of London Police: Report FraudAccessed 28 July 2026
A second approach offering guaranteed recovery is a danger signal
Direct answer: Do not pay a stranger who says your money has already been located and needs a tax, bond, wallet activation or legal release fee; verify every organisation through an independently found official register and contact.
Previous victims are valuable targets because the criminal already knows the loss, payment method and emotional pressure points. The follow-up contact may pose as a bank investigator, police officer, solicitor, regulator, blockchain analyst or another victim. Documents can copy real logos and names. A caller may quote a real report number obtained from earlier communications. None of that proves authority. End the conversation and contact the named institution through its official website or an existing secure account.
A real complaint does not require a seed phrase, one-time code, screen-sharing session or transfer to a ‘safe wallet’. Government bodies do not release recovered money because a victim buys cryptocurrency to pay tax. A provider may require identity verification and a regulated adviser may charge transparent fees under a written agreement, but no adviser can guarantee an APP decision or privately order a bank to seize money. Check the legal entity, regulator, practising status, physical contact details, engagement terms and complaints route before disclosing more personal information.
If a recovery approach follows the first scam, add it to the existing police and provider reports. Preserve the message, domain, telephone number, wallet and payment demand. Do not test the caller by sending a small amount. The safest CTA on a recovery information site is an assessment of the payment and complaint route, with an explicit no-guarantee statement—not a claim that specialists have already found the assets.
Source: City of London Police: Report FraudAccessed 28 July 2026
Source: Financial Conduct Authority: fraudulent paymentsUpdated 15 May 2026
Concise answers
Frequently asked questions
Does a UK bank have to refund every authorised scam payment?
No. The mandatory rules cover qualifying customers and in-scope UK Faster Payments and CHAPS payments made on or after 7 October 2024, subject to the cap and limited exceptions. Cards, overseas transfers, cash, crypto, civil disputes and some multi-step payments require different analysis.
How quickly should an APP scam claim be decided?
The usual reimbursement timetable is five business days. A provider may stop the clock for permitted information gathering, but the PSR says it must reach an outcome within 35 business days. Ask for a written explanation whenever the clock is stopped.
Is the APP reimbursement limit £85,000?
The mandatory maximum is £85,000 per qualifying claim. A provider may choose to reimburse more, and an eligible complaint about an unreimbursed amount can be taken to the Financial Ombudsman Service. Neither route guarantees the full loss.
Can the bank refuse because I ignored a warning?
A refusal is not automatic. To rely on the consumer-standard exception, the provider must prove gross negligence, a very high threshold, in relation to specified duties and the actual circumstances. The exception and excess do not apply where relevant vulnerability contributed to the scam.
Is the Financial Ombudsman Service free, and when is the deadline?
FOS says its consumer service is free. A complaint normally has to be referred within six months from the date on the financial business’s final response. Limited exceptions can apply, so read the current time-limit page and preserve the final-response date.
Should I call a fund-recovery company before my bank?
No. Contact the sending provider immediately, secure access, preserve evidence and use the official reporting route. Be highly cautious about unsolicited recovery offers, advance fees, guarantees and requests for remote access or wallet credentials.
Evidence register
Sources and relevant dates
We link to primary sources whenever available. Sources are grouped under the section they support; the displayed date may be a publication, effective or editorial-review date. A public outcome does not promise the same result in another case.
- Payment Systems Regulator: APP fraud reimbursement protectionsRules effective 7 October 2024; Accessed 28 July 2026
- Financial Conduct Authority: fraudulent paymentsUpdated 15 May 2026
- City of London Police: Report FraudAccessed 28 July 2026
- Payment Systems Regulator: consolidated APP reimbursement policy statement PS25/5Published May 2025
- Financial Ombudsman Service: fraud and scam complaintsAccessed 28 July 2026
- Financial Ombudsman Service: time limit after a final responseAccessed 29 July 2026
- Financial Ombudsman Service: what to expectUpdated 24 July 2026; accessed 29 July 2026
- Financial Ombudsman Service: section 75 complaintsAccessed 28 July 2026