APP Fraud Evidence: What to Secure When a Hacked Account Asks You for Money

APP fraud evidence is the material showing how you were persuaded to send the money yourself: the conversation, the payment request that came with it, and the sender’s profile as it looked at the time, fixed in a form somebody else can verify. You need it because a transfer approved with your own credentials counts as authorized, so the refund route written for unauthorized transactions never opens.

This is the second half of a crime that began elsewhere, when someone took over a real account and started spending the trust attached to it. In the UK, authorized push payment fraud reached 576.4 million pounds in 2025 across 248,070 cases, up 19 percent, while unauthorized fraud fell 5 percent (UK Finance Annual Fraud Report 2026).

This insight is part of our guide: Digital Identity Theft and Cloned Accounts: How to Certify Evidence for a Complaint

Why the request comes from a genuine account, and what is left after the payment

Nothing in the message looks wrong because nothing in it is forged. The account is real and so is the history above the request. A call to the number you already have would settle it, which is why the request always arrives with a reason not to call: a deadline, or something that has to stay between the two of you. Afterwards, only the record of the exchange separates the contact from the impostor.

The account takeover pattern

Takeover comes before contact. Criminals get in through a stolen verification code, a hijacked web session or, in the waves reported during 2026, an exploit needing no action from the victim. The account then goes quiet while it is read, because the names and plans in the archive are what make the request sound like someone you know. That archive is also where the takeover left its traces, which is why evidence of cloned accounts and stolen digital identities matters to the real holder as much as it matters to you.

Europol calls fraud schemes the fastest growing area of organized crime, with generative AI letting criminal networks personalize a story at scale (IOCTA 2026). Supervisors see the same movement: manipulation of the payer rose from 65 to 74 percent of the value of EEA credit transfer fraud between 2023 and 2024, and account holders bore roughly 85 percent of those losses (ECB and EBA, 2025 Report on Payment Fraud). In Italy, the postal police issued a public warning about urgent money requests sent from stolen messaging accounts.

Why a screenshot taken afterwards does not hold up

A screenshot is an image of a screen at a moment nobody can verify. It carries the content without proof that the content existed, unaltered, when you say it did, and the gap only costs you when somebody pushes on it.

A provider assessing a claim, or a court weighing the same file, will ask what the image is anchored to, and the answer decides its probative value. Under Article 41 of Regulation (EU) 910/2014 a qualified electronic time stamp is presumed to carry an accurate date, and the data bound to it is presumed intact. An image saved to a camera roll carries no presumption at all, and nothing inside it supplies one. Meanwhile the source is disappearing, because the holder’s first instinct on regaining control is to delete the thread.

What to capture, and when: the conversation before it is wiped

Three things carry the story and they decay at different speeds: the conversation frames the request, the request itself carries the amount and the time, and the profile shows what the account looked like in someone else’s hands.

The elements to secure

Element to secure Why it disappears What it establishes
The full thread, not the request alone The real holder deletes it after recovery, or disappearing messages expire The urgency, the relationship invoked, the request for discretion
The payment request or transfer notification Requests expire or are cancelled, notifications roll out of the tray The amount, the exact time, the handle that asked for money
The sender’s profile as it appeared Name, picture and status revert once the owner is back in control That the account presented itself as the person you were paying

Capture the thread whole, not the passage that stings. A handler reading only the request sees a request; the same handler reading the forty messages above it sees why a reasonable person paid. That is the reason to certify the conversation rather than retell it.

What forensic capture produces

TrueScreen is the Data Authenticity Platform that acquires the conversation, the payment request and the sender’s profile with a forensic method, then certifies them with a qualified timestamp and a digital seal applied through a third-party QTSP. The output is a package: the content, its cryptographic fingerprint, a record of how and when the acquisition ran, and an unbroken chain of custody, so somebody who was never there can check that nothing changed.

Where a screenshot asks to be believed, a certified acquisition can be tested. Picture a partner who pays an invoice requested from her co-founder’s account and watches him wipe the thread two hours later: captured beforehand, the claim has an attachment rather than a story.

TrueScreen certified acquisition of WhatsApp chats

Use case

Certified acquisition of WhatsApp chats with legal value

TrueScreen captures the thread with a forensic method, a qualified timestamp and a chain of custody.

Discover more →

Where the evidence is needed: the report, the claim, and the real account holder

The same package is used in three places, and the order matters because two of them run against a clock. The capture comes before all three.

  1. Capture before you notify anyone, since every message you send starts somebody else’s deletion.
  2. Ask your payment service provider for a recall the same day, while the money may still sit in the receiving account.
  3. Report the APP fraud to law enforcement and keep the reference number.
  4. Warn the real account holder, who has their own record of the unauthorized account access to preserve.

Why the automatic refund does not apply, and what replaces it

The refund most people expect belongs to a different category of transaction. Under Directive (EU) 2015/2366 a provider must refund an unauthorized transaction by the end of the following business day (Article 73), with the payer’s exposure capped at 50 euro absent fraud, intent or gross negligence (Article 74). A transfer you instructed yourself is authorized, so neither article reaches your case.

The EU institutions say as much. In the recitals of the proposed Payment Services Regulation the Commission wrote that these new types of spoofing fraud “are blurring the difference that existed in Directive (EU) 2015/2366 between authorised and unauthorised transactions”, making it “no longer possible … to limit refunds to unauthorised transactions only” (recital 79, COM(2023) 367 final). That regulation is still unpublished as of 4 September 2026 (procedure 2023/0210(COD)).

Your claim therefore turns on facts rather than an entitlement: what the message said, when it arrived, and what the provider could have seen at the moment of transfer. It holds when the attachment can be checked by somebody outside the exchange, which is what a forensic acquisition with TrueScreen produces. UK Finance reports 61 percent of APP losses reimbursed in 2025, which leaves almost two pounds in five with the person who paid. The same discipline settles claims about IBAN swap fraud.

Verification of Payee, and the narrow duty it creates

Since 9 October 2025, providers in the euro area have had to check the payee’s name against the account identifier before the payer can authorize a euro credit transfer, instant or not. The obligation sits in Article 5c of Regulation (EU) 260/2012, inserted by Regulation (EU) 2024/886. On a mismatch the provider warns that authorizing anyway may send the money to an account not held by the payee named. The check informs, it does not block.

So the warning that appeared on your screen, or its absence, is a fact about the transaction and belongs in the same package as the conversation. The duty is narrow. If a provider skips the check and the transfer goes wrong as a result, it has to refund the payer right away; anything past that is settled between the providers involved, or under the law that governs your contract.

FAQ: APP fraud evidence after a payment request scam

What is authorized push payment fraud?
Authorized push payment fraud, or APP fraud, is the case where a criminal deceives somebody into sending a transfer themselves rather than taking control of the payment. Because the victim enters the credentials and approves it, the payment counts as authorized. UK Finance recorded 576.4 million pounds lost this way in 2025.
Can I get my money back if I approved the payment myself?
Not automatically. Directive (EU) 2015/2366 gives a right to a refund for unauthorized transactions (Article 73), and a payment approved by the payer sits outside it. Recovery depends on recalling the funds before they move on, and on showing how the deception worked. UK Finance reports 61 percent of APP losses reimbursed in 2025.
What should I capture if I have already paid?
Three things, before anyone deletes anything: the whole conversation rather than the request alone, the payment request or notification with its amount and time, and the sender’s profile while the account is compromised. A forensic capture fixes each with a cryptographic fingerprint and a certified time.
Is a screenshot of the chat enough for a claim?
A screenshot carries content but no independent proof of when it was taken or whether it was altered, so its weight depends on nobody challenging it. When a provider or a court does, nothing inside the image answers back. A certified capture adds a fingerprint, a qualified timestamp and a chain of custody.
Does Verification of Payee stop this kind of scam?
No. Since 9 October 2025 providers of euro credit transfers have had to check the payee’s name against the account identifier and warn the payer before authorization, under Article 5c of Regulation (EU) 260/2012 as amended by Regulation (EU) 2024/886. The warning informs, it does not block, and the payer stays free to authorize.

Capture the conversation before it is deleted

TrueScreen acquires chats, payment requests and profiles with a forensic method and certifies them with a qualified timestamp and a digital seal issued through an integrated QTSP.

Start now
Request a demo

TrueScreen