Cyberphoenix
HomeServicesCase StudiesResourcesBlogContact
Book a Demo
Cyberphoenix

We stop scams before they cost you. Specialist fraud & scam defense for enterprises and individuals - backed by senior investigators and recovery support.

Only trust contact details published on this official website (cyberphoenixscamdefense.com).

Company

  • Services
  • Case Studies
  • Remote Support
  • Contact

Resources

  • Threat Intel
  • Playbooks
  • Blog

Legal

  • Privacy Policy
  • Terms of Service
  • Remote Support Consent
  • No Cold-Call Policy
  • Refund & Cancellation
  • Recovery Disclaimer
  • Compliance
  • Data Processing (DPA)

Safety notice: Cyberphoenix does not cold-call, impersonate companies or agencies, use fake virus alerts, demand gift cards or crypto payments, or ask for seed phrases or recovery words. Remote access is provided only on client request, with full consent and using approved secure tools. Cyberphoenix will never send you a session code or remote-support link by chat, email, SMS or phone. Only trust contact details published on this official website.

© 2026 Cyberphoenix LLC. All rights reserved.

Compliance program in progress.

All case studies

// APP FRAUD

Cutting Authorized Push-Payment Fraud by 82% in 90 Days

C
CyberPhoenix Team
June 27, 20264 min read40 views
Cutting Authorized Push-Payment Fraud by 82% in 90 Days

–82% APP fraud in 90 days

Fortiva, a digital challenger bank with 380,000 customers, was losing $1.4M per month to authorized push-payment fraud. Customers were being called by scammers posing as Fortiva's own fraud team and persuaded to move their savings to "safe accounts."

Background

Authorized push-payment fraud is the hardest fraud category to stop because the customer is the one initiating the transfer — willingly, from their own authenticated session, to an account they've just been coached to trust. Every existing fraud control assumes the attacker is the one initiating. APP fraud inverts that assumption entirely.

What Happened

Fortiva's customers were receiving calls from spoofed Fortiva numbers. The script was polished: "We've detected suspicious activity on your account. To protect your funds, we're asking you to move them to a temporary secure account while we investigate. I'll stay on the line while you do this." The customer would open the app, create a new payee, and move everything. By the time they called to check on the "investigation," the money was gone.

Fortiva's existing controls flagged nothing — the customer was authenticated, the session was legitimate, and the payment was authorized. Their dispute team was handling 200+ APP cases per month with no upstream solution in sight.

Timeline

Month 0CyberPhoenix engagement begins. Baseline: $1.4M/month APP fraud losses, 200+ cases/month.
Week 2Real-time risk scoring deployed on all new payee additions. Friction prompts introduced for high-risk payee characteristics.
Week 3In-app scam education deployed — contextual warnings at the exact moment a payment matches high-risk patterns.
Week 4Agent Confirmation of Payee scripts deployed. All inbound fraud calls now include scripted payee verification questions.
Week 5First ML model retrained on 3 weeks of labeled scam reports. False positive rate drops from 8% to 3%.
Month 224-hour model retraining cycle operational. Scammer tactic shifts detected and reflected in scoring within one day.
Month 3Month 3 results: –82% APP fraud, –34% customer complaints, false positives below 2%.

How We Responded

  1. Payee risk scoring with graduated friction. We built a real-time risk model scoring every new payee addition on 40+ signals: account age, sort code patterns, prior fraud associations, time-of-day, session behavior. High-risk payees trigger a friction flow — a confirmation screen with scam awareness copy — not a block. The difference matters: blocks frustrate legitimate customers; friction interrupts the scammer's coached script.
  2. Contextual in-app scam education. Generic fraud warnings don't work — customers dismiss them. We deployed scenario-specific warnings that match the exact attack in progress: "Are you on the phone with someone who asked you to make this payment? Fortiva will never ask you to move funds to protect them." Tested in a 50/50 split: specific warnings reduced completion of high-risk payments by 61% vs. generic warnings.
  3. Agent Confirmation of Payee scripting. Scammers frequently keep victims on the phone while the transfer happens. We trained Fortiva's agents to identify this pattern and equipped them with interruption scripts — questions designed to break the social engineering trance without embarrassing the customer.
  4. 24-hour ML retraining cycle. APP fraud tactics evolve fast. When a new scam script circulates, reported cases cluster within days. By retraining the model on confirmed scam labels every 24 hours, we reduced the lag between a new tactic appearing and Phoenix detecting it from ~3 weeks (manual update cycle) to under 36 hours.

What Almost Went Wrong

The initial friction prompts were too aggressive — blocking 8% of legitimate new payee additions and generating a spike in angry support calls in week one. We almost pulled the friction prompts entirely under pressure. Instead, we tuned the risk threshold over 72 hours and got false positives below 3% without removing the friction layer. That decision to tune rather than remove is what made the 90-day result possible.

Outcome

  • APP fraud reduction: –82%
  • Monthly savings: ~$1.15M
  • Customer complaints: –34%
  • False positive rate: <2%

Key Takeaways

  • APP fraud cannot be stopped at the transaction level — it has to be stopped at the moment the customer is being coached. That means friction at payee creation, not payment authorization.
  • Contextual, scenario-specific warnings dramatically outperform generic fraud alerts. Customers have learned to dismiss banner warnings; they cannot dismiss a warning that describes exactly what is happening to them.
  • Model retraining frequency is a competitive advantage against fraud. Criminals iterate daily; your models need to keep pace.
  • Tuning is not failure. Pulling a control entirely because of early false positives is the worst outcome. Tune under pressure, don't retreat.

Key Result

–82% APP fraud in 90 days

Threat category

APP FRAUD
Discuss your situation

Under active attack right now?

Our team responds within 15 minutes. Call directly or open the chat widget below.

Get emergency help

More case studies

BEC

How We Stopped a $4.7M Business Email Compromise (BEC) Attack in Under 6 Minutes

$0 lost · 6 min response · 22 banks alerted

Deepfake

Deepfake Voice Scam Defense: Blocking a $1.2M AI-Cloned CEO Fraud Call

$1.2M loss prevented · 9-second detection

Investment

Pig Butchering Crypto Scam Recovery: Reclaiming $890K Across 31 Wallets

68% recovered · 12 days · 31 wallets traced