Skip to main content

The art of assessing customer intent: Authorized party fraud trends

Over recent years, authorized party fraud committed deliberately by legitimate customers (often referred to as first-party fraud) has emerged as a fast-growing, complex category of loss for financial institutions. One industry source estimated that in 2025, this type of fraudulent behavior made up 37% of fraud events (PDF, Off-site) across financial services globally. Fraudulent behavior, such as false claims, misuse of payment channels or money mule activity, may resemble normal behavior. This often makes it difficult for financial institutions to distinguish fraudulent intent from routine activity.

Understanding the current trends and drivers of this type of fraud is essential to reducing losses while preserving a positive customer experience.

Test your knowledge: Do you know how to classify first-party fraud? Learn how you can take insight to action with the FraudClassifier model (Off-site).

FraudClassifier model

When customers exploit the financial institution relationship

When a customer intentionally misuses access to products, services or customer protections, they exploit the relationship with their financial institution for their own personal or financial gain. Common examples include:

  • Authorized party check fraud. This occurs when the account holder knowingly issues or deposits checks for the purpose of committing fraud. Common instances include issuing checks with the knowledge that funds are insufficient; depositing the same check multiple times through different channels; or check kiting (PDF, Off-site), where a customer deliberately writes a check for more than is available in their account and then deposits the check into another account to falsely inflate the balance.
  • False claims. Although false claims often are directed at merchants or service providers, financial institutions may be targeted, as well. For example, customers may dispute a legitimate ACH debit that they knowingly authorized in hopes of receiving credit for it. Furthermore, as scams have become relatively common, individuals can more plausibly make false claims of victimization. For example, customers may send a wire or ACH transfer to themselves or to another complicit party and later claim they were “scammed,” hoping to trigger reimbursement.
  • Intentional money mules. Intentional money mules knowingly allow their financial accounts to be used to move or conceal illicit funds, often in exchange for payment or other benefits. Unlike unwitting participants, these individuals are aware that the money they receive and transfer is tied to fraud, scams or other criminal activity. Mule activity plays a critical role in scaling fraud operations and complicates efforts to trace and recover stolen funds.

Recent drivers of authorized party fraud

Several factors have contributed to recent growth in authorized party fraud, where account holders act fraudulently using their real identities.

First is the shift from in-person banking to mobile and online banking. Historically, branch employees played a meaningful role in identifying red flags. While digital interactions improve customer convenience, they also reduce opportunities for frontline staff to observe and question unusual behavior.

Digital account opening also has created new pathways for exploitation. Criminals may open accounts digitally at any time of day, season the account over time to appear legitimate, and later engage in fraudulent activities — such as intentional account overdrafts or money mule activity. Losses tied to new account fraud continue to grow, reaching $7 billion in 2025 (Off-site), a 13% increase year over year.

Second, individuals now have access to “how-to” resources, both on the dark web and mainstream platforms. Social media influencers can post content that spreads misinformation about false claims or describes how to manipulate customer protections. Examples include:

  • Video tutorials suggesting ways to “get money back fast” by disputing legitimate transactions or credit records
  • Social media videos advising that financial institutions “always side with the consumer”
  • Online forum threads portraying certain dispute processes as “loopholes”
  • Misinformation about technical glitches that enable “free money”

The ease of committing scams has fueled intentional money mule activity, as criminals need financial accounts to move or launder scam proceeds. Criminals leverage social media and private forums to recruit willing mules, promoting “money flipping” or mule opportunities as low-risk ways to earn fast cash.

Want to learn more about how to detect and prevent this fraud? Read the full article on FedPaymentsImprovement.org to see how financial institutions are modernizing controls for customer intent.

Read the full article (Off-site)

The FraudClassifier model was developed by a cross-industry work group to provide a consistent way to classify and understand how fraud occurs across the payments industry. The FraudClassifier model is not intended to result in mandates or regulations, and does not give any legal status, rights or responsibilities, nor is it intended to define or imply liabilities for fraud loss or create legal definitions, regulatory or reporting requirements. While sharing and use of the FraudClassifier model throughout the industry is encouraged, any adoption of the FraudClassifier model is voluntary at the direction of each individual entity. Absent written consent, the FraudClassifier model may not be used in a manner that suggests the Federal Reserve endorses a third-party product or service.

In This Issue