Skip to content
Clear information. Thoughtful guidance. A way forward. You are in the right place to begin.
WorldwidePayments & complaints3 min read

Authorised vs unauthorised scam payments: why the difference matters

How to explain payment approval, deception and account takeover accurately when reporting fraud to a bank or payment service.

Two paper payment paths split around a ceramic security key
AI-generated illustration, not a photograph of real events.
The short answer

An authorised scam payment generally involves you approving a payment under deception; an unauthorised payment involves someone acting without your permission. The legal assessment depends on local rules and the facts. Give an accurate account rather than choosing a label to obtain a refund.

You may have followed instructions willingly while misunderstanding who you were paying. Alternatively, a criminal may have gained account access and transferred money without your approval. Both can involve fraud, but providers may assess them through different processes.

This guide explains practical distinctions worldwide. It does not replace the legal definition of authorisation in your jurisdiction. A bank’s initial classification can be questioned if its factual assumptions are wrong.

Describe the actions, not only the label

Record who entered the payment, who selected the recipient and who approved any app prompt or code. Explain what you believed the payment would accomplish and which false statement induced it. If a scammer operated your computer, say what you could see and what you actually approved.

Being tricked is not the same as inventing a transaction. Equally, authentication logs do not tell the whole story by themselves. A correct login or successful security code may require context, especially if remote access, phishing or coercion occurred.

Treat different transactions separately

One incident can include several payment types: a card purchase, a transfer you made, a later transfer you did not make and a crypto withdrawal. Do not assume they must all receive the same classification. Build a list with the amount, date, mechanism and approval facts for each.

For instance, approving a deposit to a fake investment does not mean you approved every later payment from your account. If the bank’s decision groups them together, ask it to explain its assessment for each disputed transaction.

Do not import another country’s reimbursement rule

The UK PSR distinguishes APP fraud from unauthorised fraud and gives eligible domestic APP transfers particular protections. That framework has scope conditions, dates, exclusions and limits. It does not mean an approved transfer is reimbursed identically in Canada, Sweden, Belgium or Australia.

Likewise, practical FTC advice to contact a provider is not a declaration of worldwide legal liability. Ask your own provider what local rules and contractual terms it applies. If it uses a jurisdiction-specific term, request a plain-language explanation.

Challenge a decision with evidence

If the bank says you approved a payment you did not approve, identify the disputed factual point and request its reasoning. If you did approve it under deception, describe the scam, warnings, timing and other circumstances rather than denying approval. Keep your original account consistent and correct mistakes transparently.

Where available, escalate through the provider’s complaint process and an eligible external dispute body. Secure affected accounts immediately even if liability remains disputed. The security response and the reimbursement decision are separate tasks.

A short checklist

  • Document who entered and approved each payment.
  • Explain the deception and any remote access.
  • Assess each transaction separately.
  • Ask which local rules apply.
  • Correct errors without rewriting the underlying facts.

Common questions

Does a security code prove I authorised the payment?

It can be evidence, but the surrounding facts matter. Explain whether you disclosed a code, what the message said and whether someone controlled your device. The legal result is jurisdiction-specific.

Is my bank allowed to reject every approved scam payment?

There is no worldwide answer. Some local frameworks protect specified authorised scam payments. Ask for the applicable rule and use the complaint route if you disagree with its application.

References

  1. APP fraud reimbursement protectionsPayment Systems Regulator · United Kingdom
  2. What to do if you were scammedFederal Trade Commission · United States; practical prevention guidance
  3. What to do if you've been scammedASIC Moneysmart · Australia
  4. How to file a complaint with your bankFinancial Consumer Agency of Canada · Canada; federally regulated banks