// APP FRAUD

–82% APP fraud in 90 days
Fortiva, a digital challenger bank with 380,000 customers, was losing $1.4M per month to authorized push-payment fraud. Customers were being called by scammers posing as Fortiva's own fraud team and persuaded to move their savings to "safe accounts."
Authorized push-payment fraud is the hardest fraud category to stop because the customer is the one initiating the transfer — willingly, from their own authenticated session, to an account they've just been coached to trust. Every existing fraud control assumes the attacker is the one initiating. APP fraud inverts that assumption entirely.
Fortiva's customers were receiving calls from spoofed Fortiva numbers. The script was polished: "We've detected suspicious activity on your account. To protect your funds, we're asking you to move them to a temporary secure account while we investigate. I'll stay on the line while you do this." The customer would open the app, create a new payee, and move everything. By the time they called to check on the "investigation," the money was gone.
Fortiva's existing controls flagged nothing — the customer was authenticated, the session was legitimate, and the payment was authorized. Their dispute team was handling 200+ APP cases per month with no upstream solution in sight.
| Month 0 | CyberPhoenix engagement begins. Baseline: $1.4M/month APP fraud losses, 200+ cases/month. |
| Week 2 | Real-time risk scoring deployed on all new payee additions. Friction prompts introduced for high-risk payee characteristics. |
| Week 3 | In-app scam education deployed — contextual warnings at the exact moment a payment matches high-risk patterns. |
| Week 4 | Agent Confirmation of Payee scripts deployed. All inbound fraud calls now include scripted payee verification questions. |
| Week 5 | First ML model retrained on 3 weeks of labeled scam reports. False positive rate drops from 8% to 3%. |
| Month 2 | 24-hour model retraining cycle operational. Scammer tactic shifts detected and reflected in scoring within one day. |
| Month 3 | Month 3 results: –82% APP fraud, –34% customer complaints, false positives below 2%. |
The initial friction prompts were too aggressive — blocking 8% of legitimate new payee additions and generating a spike in angry support calls in week one. We almost pulled the friction prompts entirely under pressure. Instead, we tuned the risk threshold over 72 hours and got false positives below 3% without removing the friction layer. That decision to tune rather than remove is what made the 90-day result possible.