top of page
Search

The Two Ways Scammers Empty Accounts (And How to Stop Them)

Writer: we3volution
we3volution
13 hours ago
5 min read



UK scam statistics are often presented as a wall of numbers. But look a little closer and they tell us something much more useful: how criminals get our money - and where a few simple habits can make a difference.


In 2025, UK Finance members recorded £1.28 billion lost to payment fraud.

But that figure covers two very different things.


How much was taken without the victim's permission, and how much was sent because the victim was tricked into sending it?


Let's break it down:



Info graphic showing the 2 ways money leaves your account: unauthorised fraud and authorised push payment fraud


1. Unauthorised Fraud: They Make the Payment


The numbers: £703.4 million lost across 3.81 million cases.


This is the larger of the two types of payment fraud recorded by UK Finance. It happens without your knowledge or permission.



How it actually happens


Criminals need a way to get hold of your account or payment details. There are several ways they can do this.


For example:


  1. A company suffers a data breach: A company you shop with or have an account with is hacked and customer information, such as usernames or passwords, is stolen.


  2. Passwords are reused: If your email address and password are exposed, criminals don't have to manually try them on different websites. Automated software can test stolen details against hundreds of accounts very quickly. If the same password works elsewhere, another account may be at risk too. Even if only your email address is known, automated tools can rapidly test common or previously leaked passwords against it.


  3. Phishing messages: Criminals send convincing texts or emails pretending to be from a bank, delivery company or another organisation. A link may take you to a fake website where you are asked to enter your card details, password or security code.



The methods can vary, but the result is the same:


Someone else makes the payment. You didn't approve it.



In 2025,UK banks and payment providers also prevented £1.68bn of attempted unauthorised fraud


How to reduce the risk


  • Use different passwords: You don't need to remember dozens of passwords yourself. A password manager can create and store long, unique passwords for each account. If one company is hacked, that password shouldn't also work somewhere else.


  • Turn on two-step verification: Use two-factor authentication (2FA) on important accounts such as your email and banking apps where available. It adds another check when someone tries to log in, so a stolen password alone may not be enough. Authenticator apps or biometrics preferred over sms.


  • Don't use links in unexpected messages: If a bank, delivery company or government department texts or emails you about a problem with your account, don't use the link in the message. Go directly to the organisation's official website or app instead.





2. Authorised Fraud (APP): You Make the Payment


The numbers: £576.4 million lost across 248,070 cases.


This is Authorised Push Payment (APP) fraud. The name sounds complicated, but the idea is straightforward:


You make the payment yourself - but only because you've been tricked.



If you look at the figures, the two biggest categories are:


  • The Most Common (Purchase Scams): 175,809 cases totaling £118.1 million (accounting for 71% of all APP cases). You pay for goods or services -like concert tickets, cars, or holiday rentals - advertised via social media posts or online marketplaces, but the items never arrive.


  • The Most Expensive (Investment Scams): 14,893 cases totaling £221.5 million (a 40% spike in losses from the previous year). Criminals spend weeks convincing victims to invest in fake cryptocurrency, gold, or property schemes using professional-looking platforms.


Together, those two categories account for £339.6 million of APP losses.


So what about the rest?


The other £236.8 million comes from several other types of scam recorded by UK Finance:


  • Advance Fee Scams (£58.4 million): You are asked to pay money upfront for something that doesn't exist, such as a loan, prize or other offer.

  • Impersonation Scams (£55.5 million): Someone pretends to be a person or organisation you trust, such as the police, tax office or a utility company.

  • Invoice and Mandate Scams (£41.3 million): Criminals interfere with genuine payment requests and change the bank details, so the money goes to them instead.

  • Romance Scams (£39.2 million): Someone builds a relationship with you online and eventually asks you for money.



The figures show an important difference:


Purchase scams are by far the most common APP scam, but investment scams cause the biggest losses.

How to reduce the risk


According to the UK Finance data, 66% of these cases were enabled by online sources, while 17% were enabled through telecommunications like phone calls and texts.


The deception often starts somewhere else, but once the story feels believable, the victim makes the payment themselves. When something unexpected asks you to move money, simply stop and ask two questions:


  1. What am I actually being asked to do? (Am I being asked to click a link? Give up information? Send money? Connect a wallet? Sign something?)


  2. How do I know the person or organisation asking me is really who they say they are?


Taking a moment to slow the process down can give you the opportunity to check what is really happening before the decision becomes irreversible.



Stay Safe. Pause before you click, connect, sign or send




The Hidden Scale: While unauthorised fraud happens far more often, the relative financial damage per case is completely different. The average unauthorised fraud case costs around £185, but the average APP scam costs a massive £2,324 - making this 12 times more expensive per hit. If scammers managed to pull off as many APP scams as they did unauthorised data hacks, the losses would explode from millions into a staggering £8.8 billion.






What to Do If Something Doesn't Feel Right



  • If you receive a suspicious text or call: Stop the conversation and check the organisation through a trusted route. For example, use the number on the back of your bank card rather than a number provided in the message.


  • Report it: You can forward suspicious texts and report calls to 7726, free of charge in the UK.


  • If you have lost money: Contact your bank or payment provider immediately and report the fraud.







Why We3volution Has a Stay Safe Hub



Statistics can show us how much fraud is happening.


But numbers alone don't necessarily help when a scam lands in your inbox, appears on your phone or shows up while you're browsing online.


That's why we've built the Stay Safe section on We3volution.


It takes some of the common scams behind these numbers and explains them in plain language. You can use it to learn about traditional phishing and impersonation tactics, or newer Web3 traps like malicious wallet approvals, address poisoning, and wallet drainers.


The aim isn't to turn everyone into a security expert. It's to make the warning signs easier to understand, so you have a better chance of recognising what's happening before you act.



Pause before you click, connect, sign or send.



Explore the Stay Safe resources to learn more.

 
 
 

Comments


W3digiHead.jpg
W3 logo

Stay Connected with Us

Facebook icon
Instagram icon
X icon

 

© 2025 by We3volution. Powered and secured by Wix 

 

“We3volution is a purely educational literacy initiative. This platform does not issue financial tokens, does not handle real currency, and does not provide financial or investment advice. All practical exercises take place in zero-value test environments.”

Informed. Empowered. Engaged

bottom of page