APP Fraud Evidence: What to Secure When a Hacked Account Asks You for Money
Published September 4, 2026
APP fraud evidence is the material showing how you were persuaded to send the money yourself: the conversation, the payment request that came with it, and the sender’s profile as it looked at the time, fixed in a form somebody else can verify. You need it because a transfer approved with your own credentials counts as authorized, so the refund route written for unauthorized transactions never opens.
This is the second half of a crime that began elsewhere, when someone took over a real account and started spending the trust attached to it. In the UK, authorized push payment fraud reached 576.4 million pounds in 2025 across 248,070 cases, up 19 percent, while unauthorized fraud fell 5 percent (UK Finance Annual Fraud Report 2026).
This insight is part of our guide: Digital Identity Theft and Cloned Accounts: How to Certify Evidence for a Complaint
Why the request comes from a genuine account, and what is left after the payment
Nothing in the message looks wrong because nothing in it is forged. The account is real and so is the history above the request. A call to the number you already have would settle it, which is why the request always arrives with a reason not to call: a deadline, or something that has to stay between the two of you. Afterwards, only the record of the exchange separates the contact from the impostor.
The account takeover pattern
Takeover comes before contact. Criminals get in through a stolen verification code, a hijacked web session or, in the waves reported during 2026, an exploit needing no action from the victim. The account then goes quiet while it is read, because the names and plans in the archive are what make the request sound like someone you know. That archive is also where the takeover left its traces, which is why evidence of cloned accounts and stolen digital identities matters to the real holder as much as it matters to you.
Europol calls fraud schemes the fastest growing area of organized crime, with generative AI letting criminal networks personalize a story at scale (IOCTA 2026). Supervisors see the same movement: manipulation of the payer rose from 65 to 74 percent of the value of EEA credit transfer fraud between 2023 and 2024, and account holders bore roughly 85 percent of those losses (ECB and EBA, 2025 Report on Payment Fraud). In Italy, the postal police issued a public warning about urgent money requests sent from stolen messaging accounts.
Why a screenshot taken afterwards does not hold up
A screenshot is an image of a screen at a moment nobody can verify. It carries the content without proof that the content existed, unaltered, when you say it did, and the gap only costs you when somebody pushes on it.
A provider assessing a claim, or a court weighing the same file, will ask what the image is anchored to, and the answer decides its probative value. Under Article 41 of Regulation (EU) 910/2014 a qualified electronic time stamp is presumed to carry an accurate date, and the data bound to it is presumed intact. An image saved to a camera roll carries no presumption at all, and nothing inside it supplies one. Meanwhile the source is disappearing, because the holder’s first instinct on regaining control is to delete the thread.
What to capture, and when: the conversation before it is wiped
Three things carry the story and they decay at different speeds: the conversation frames the request, the request itself carries the amount and the time, and the profile shows what the account looked like in someone else’s hands.
The elements to secure
| Element to secure | Why it disappears | What it establishes |
|---|---|---|
| The full thread, not the request alone | The real holder deletes it after recovery, or disappearing messages expire | The urgency, the relationship invoked, the request for discretion |
| The payment request or transfer notification | Requests expire or are cancelled, notifications roll out of the tray | The amount, the exact time, the handle that asked for money |
| The sender’s profile as it appeared | Name, picture and status revert once the owner is back in control | That the account presented itself as the person you were paying |
Capture the thread whole, not the passage that stings. A handler reading only the request sees a request; the same handler reading the forty messages above it sees why a reasonable person paid. That is the reason to certify the conversation rather than retell it.
What forensic capture produces
TrueScreen is the Data Authenticity Platform that acquires the conversation, the payment request and the sender’s profile with a forensic method, then certifies them with a qualified timestamp and a digital seal applied through a third-party QTSP. The output is a package: the content, its cryptographic fingerprint, a record of how and when the acquisition ran, and an unbroken chain of custody, so somebody who was never there can check that nothing changed.
Where a screenshot asks to be believed, a certified acquisition can be tested. Picture a partner who pays an invoice requested from her co-founder’s account and watches him wipe the thread two hours later: captured beforehand, the claim has an attachment rather than a story.
Where the evidence is needed: the report, the claim, and the real account holder
The same package is used in three places, and the order matters because two of them run against a clock. The capture comes before all three.
- Capture before you notify anyone, since every message you send starts somebody else’s deletion.
- Ask your payment service provider for a recall the same day, while the money may still sit in the receiving account.
- Report the APP fraud to law enforcement and keep the reference number.
- Warn the real account holder, who has their own record of the unauthorized account access to preserve.
Why the automatic refund does not apply, and what replaces it
The refund most people expect belongs to a different category of transaction. Under Directive (EU) 2015/2366 a provider must refund an unauthorized transaction by the end of the following business day (Article 73), with the payer’s exposure capped at 50 euro absent fraud, intent or gross negligence (Article 74). A transfer you instructed yourself is authorized, so neither article reaches your case.
The EU institutions say as much. In the recitals of the proposed Payment Services Regulation the Commission wrote that these new types of spoofing fraud “are blurring the difference that existed in Directive (EU) 2015/2366 between authorised and unauthorised transactions”, making it “no longer possible … to limit refunds to unauthorised transactions only” (recital 79, COM(2023) 367 final). That regulation is still unpublished as of 4 September 2026 (procedure 2023/0210(COD)).
Your claim therefore turns on facts rather than an entitlement: what the message said, when it arrived, and what the provider could have seen at the moment of transfer. It holds when the attachment can be checked by somebody outside the exchange, which is what a forensic acquisition with TrueScreen produces. UK Finance reports 61 percent of APP losses reimbursed in 2025, which leaves almost two pounds in five with the person who paid. The same discipline settles claims about IBAN swap fraud.
Verification of Payee, and the narrow duty it creates
Since 9 October 2025, providers in the euro area have had to check the payee’s name against the account identifier before the payer can authorize a euro credit transfer, instant or not. The obligation sits in Article 5c of Regulation (EU) 260/2012, inserted by Regulation (EU) 2024/886. On a mismatch the provider warns that authorizing anyway may send the money to an account not held by the payee named. The check informs, it does not block.
So the warning that appeared on your screen, or its absence, is a fact about the transaction and belongs in the same package as the conversation. The duty is narrow. If a provider skips the check and the transfer goes wrong as a result, it has to refund the payer right away; anything past that is settled between the providers involved, or under the law that governs your contract.
FAQ: APP fraud evidence after a payment request scam
What is authorized push payment fraud?
Can I get my money back if I approved the payment myself?
What should I capture if I have already paid?
Is a screenshot of the chat enough for a claim?
Does Verification of Payee stop this kind of scam?
Capture the conversation before it is deleted
TrueScreen acquires chats, payment requests and profiles with a forensic method and certifies them with a qualified timestamp and a digital seal issued through an integrated QTSP.
