The Scam Economy: Instant Payments and the Liability War
The Scam Economy: Instant Payments and the Liability War
The payments industry spent fifty years perfecting defenses against stolen credentials — and then built rails so fast and so final that criminals stopped stealing credentials and started stealing people. Convince the victim to press send themselves, and every technical defense is bypassed by design: the transaction is authorized, instant, and irreversible. This is authorized push payment fraud, the fastest-growing crime in payments, and the war over who eats the loss — victim, bank, or platform — is being fought right now in Congress, the states, and a billion-dollar lawsuit. This report maps the battlefield.
In this report
- The core thesis
- The great fraud migration
- The Regulation E gap
- The reimbursement reality
- The liability war: federal collapse, state revival
- The UK experiment: liability as fraud prevention
- The defense stack — and the playbook for individuals
- Scenarios and what we're watching
- Frequently asked questions
The core thesis
Authorized push payment fraud is what happens when payment security wins: as tokenization, chips, and machine-learning fraud models made credential theft harder, criminals rationally migrated to the one attack surface no cryptography protects — human trust. The instant rails we analyzed in the pay-by-bank report completed the opportunity: transfers that settle in seconds and cannot be recalled convert a moment of successful deception into a permanent loss. The scam economy is thus not a bug of instant payments; it is their shadow — speed and finality are the product and the vulnerability.
Our thesis: the fight over scam losses is really a fight over where liability creates the most prevention. The current American regime — losses mostly stay with the deceived victim — places the burden on the party least equipped to detect organized fraud at scale. The UK's counter-experiment places it on institutions, betting that banks forced to eat scam losses will finally spend what it takes to stop them (the incentive logic that made card chargebacks the engine of card security, as we showed in the chargeback playbook). The American trajectory — network policy expanding, a state AG suing for $1 billion, federal legislation drafted — points toward a negotiated middle. Where liability lands will determine how safe instant money becomes, because in payments, liability is where security budgets come from.
Fifty years of payment security taught criminals to stop attacking the system and start attacking the customer. The liability question is whether the system or the customer pays for that lesson.
The great fraud migration
The numbers trace the migration cleanly. Consumers reported hundreds of millions in P2P-app scam losses in a single nine-month stretch — up roughly 35% year over year — while survey research finds nearly one in three Americans scammed in a year, averaging about $1,600 per victim. The playbook is industrialized: bank impersonation (a spoofed call from "the fraud department" walks the victim through "protecting" their money — the notorious "me-to-me" scam); marketplace fraud (fake sellers, instant payment, vanished goods); romance and investment scams (trust built over months, harvested in transfers); and the accidental-payment reversal con (a stranger's "mistaken" payment, made with stolen credentials, "refunded" by the victim with real money). Note what unites them: none attacks the payment system's security. The system performs flawlessly — authenticated user, authorized instruction, instant settlement. The attack is upstream, on the person; the rails merely deliver the outcome at machine speed. This is the same structural insight we traced in synthetic identity fraud: modern financial crime exploits the gap between what systems verify and what is actually true.
The Regulation E gap
American law draws one line, and everything follows from it. Under the Electronic Fund Transfer Act and Regulation E, unauthorized transfers — someone else moved your money without you — must generally be reimbursed. But a transfer the victim was deceived into making themselves is, in the law's eyes, authorized: your finger pressed send, so the statute's protection doesn't attach, however fraudulent the inducement. Consumer advocates argue consent obtained by fraud isn't meaningful consent; banks answer that they cannot underwrite every customer's judgment. The result is a liability regime perfectly misaligned with the modern threat: full protection against the attack that's declining (credential theft), near-zero protection against the attack that's exploding (deception). Every major reform proposal — including the drafted federal legislation that would amend the EFTA to cover "fraudulently induced" transfers — aims at exactly this line.
The reimbursement reality
What does the gap mean in practice? A Senate investigation put hard numbers on it: only about 12% of consumers who disputed Zelle payments as scams were reimbursed, reimbursement rates at three major owner banks fell from 62% to 38% over four years, and roughly $560 million in scam disputes were rejected across three years. Against that, the industry's defense has real content too: the network reports that 99.95% of transactions generate no fraud report — the rails are overwhelmingly used safely — and network policy has genuinely moved: since 2023, participating banks must reimburse qualifying imposter scams, notably the bank-impersonation "me-to-me" pattern, and that framework has continued expanding. The honest synthesis: protection has improved from "essentially none" to "partial, inconsistent, and category-dependent" — a patchwork where your recovery depends on which scam got you, which bank you use, and how you were classified when you called. Patchworks are what regimes look like mid-transition.
The liability war: federal collapse, state revival
The institutional fight compressed into eighteen remarkable months. December 2024: the CFPB sues the network's operator and its three largest owner banks over $870 million in fraud losses. March 2025: the new administration's CFPB drops the case entirely — part of the broader deprioritization of digital-payments oversight (the same retrenchment that repealed the payment-apps supervision rule). August 2025: New York's attorney general revives the abandoned theory as a $1 billion state lawsuit, alleging the platform was designed without basic safeguards while marketed as safe — and inviting other states to follow. Meanwhile the drafted federal fix (extending Reg E to fraudulently induced transfers) waits on a Congress that has shown more appetite for repealing payment rules than adding them. The pattern should look familiar from EWA and open banking: federal referee steps back, states step in, and the market inherits fifty potential rulebooks. For the institutions, the strategic risk isn't any single case — it's that scam liability gets set by the most aggressive state's verdict rather than a negotiated national standard.
The UK experiment: liability as fraud prevention
The world's most important data point is running across the Atlantic. In late 2024, the UK made reimbursement of APP fraud mandatory on its instant rails: victims refunded within days, costs split between sending and receiving institutions, a per-claim cap, and narrow exceptions for gross negligence. Two design choices matter enormously. Splitting liability with the receiving bank attacks the scam economy's soft underbelly — mule accounts — by making the institutions that host scammer accounts pay for hosting them. And mandatory reimbursement converts fraud prevention from a customer-service cost into a P&L imperative: the bank that must refund scams has, for the first time, the full financial incentive to detect them before the money leaves. The American objections are serious — moral hazard (does guaranteed reimbursement dull victim caution?), first-party fraud risk (staged "scams" for refunds — the same abuse pattern plaguing chargebacks), and cost pass-through. The UK's emerging experience will answer empirically what American lobbying answers rhetorically, and both sides of the Atlantic know it — which is why every US hearing now cites British numbers.
The defense stack — and the playbook for individuals
Whatever liability regime emerges, the detection frontier is the same one running through every fraud domain we cover: behavior. Scam-time interventions (warnings triggered by anomalous first-time payees and amounts), behavioral biometrics that detect coercion signatures (hesitation, scripted navigation, an open phone call during the transfer), receiving-side mule-account detection through network analysis, and — increasingly urgent as agentic payments arrive — verified-recipient infrastructure that confirms who is actually behind an account before money moves. For individuals, the playbook is brief and worth stating plainly: treat instant transfers as cash for people you personally know; assume every inbound "your account is at risk" contact is a scam and verify by calling the number on your card; never "refund" an unexpected payment through the same app (return it through your bank); and if struck, report within minutes, not days — the brief window before funds hop onward is the only realistic recovery chance, and documentation determines how your claim is classified.
Scenarios and what we're watching
| Scenario | Shape of the world | Signposts |
|---|---|---|
| Base case — the negotiated patchwork | Network reimbursement categories keep expanding under litigation pressure; no federal statute; state suits settle with reforms attached; protection improves unevenly | The NY case's outcome; new state AG filings; network policy expansions |
| Bull case (for consumers) — the UK import | British results show fraud falling without moral-hazard blowup; the EFTA amendment passes; shared sender/receiver liability forces the mule-account crackdown | UK reimbursement and fraud-rate data; the federal bill gaining cosponsors; receiving-bank liability language appearing |
| Bear case — the trust tax | Liability stays with victims; scam losses keep compounding; consumers rationally retreat from instant rails, taxing adoption of the entire A2A stack just as it challenges cards | P2P volume growth decelerating; scam-loss trajectory; consumer-trust surveys on instant payments |
What we're watching: the New York verdict or settlement (the de facto national standard-setter for now); UK reimbursement data (the empirical answer to the moral-hazard debate); the federal EFTA amendment's cosponsor count; receiving-institution liability language anywhere (the mule-account key); and scam-time intervention adoption across major banks. The deepest point is the one this research series keeps arriving at: every payments era is defined by who bears its losses, because loss-bearers build the defenses. Cards became safe when merchants and issuers ate the fraud. Instant payments will become safe when someone other than the victim eats the scams — and the war being fought right now is over who.
Frequently asked questions
Fraud where the victim is deceived into sending money themselves — impersonated banks, fake sellers, romance scams — over instant rails. Because the victim initiated it, the transfer is legally "authorized," historically placing it outside mandatory reimbursement protections.
Unauthorized transactions (account takeover) generally must be reimbursed under Regulation E. Authorized-but-deceived transfers are the gap: no federal mandate, though network policy now requires refunding certain imposter scams and coverage varies by bank. A Senate probe found only ~12% of scam disputes reimbursed.
Mandatory APP-fraud reimbursement on instant rails since late 2024 — refunds within days, costs split between sending and receiving banks, with a claim cap and narrow exceptions. It's the world's largest test of liability-driven fraud prevention, and it's shaping the US debate.
Treat instant transfers like cash for people you know; assume every "protect your account" contact is a scam and verify via the number on your card; never refund unexpected payments through the same app; report within minutes if struck — speed and documentation decide recovery.
Key takeaways
- Payment security's success migrated fraud from stealing credentials to deceiving people — and instant rails made deception final.
- Reg E protects against the declining attack (unauthorized) and not the exploding one (authorized-but-deceived).
- Reality check: ~12% scam reimbursement, falling bank refund rates, partial network-policy fixes.
- The federal case collapsed; a $1B state suit revived it — the patchwork era of scam liability has begun.
- Liability is where security budgets come from; the UK experiment is testing whether shifting it stops the scams.
Keep reading
This report is for general information only and does not constitute financial or legal advice. Litigation, network policies, and regulatory positions in this area change rapidly; figures are drawn from publicly reported sources.