My Perspective on APP Fraud
Why Behavioral Biometrics Is the Missing Layer in Scam Defense
Authorized Push Payment (APP) fraud is one of the most misunderstood challenges in modern financial crime. Despite growing regulatory and media attention, most of the industry's focus still lands on the wrong defensive layer: stronger authentication, more user education, more friction in the payment flow.
APP fraud doesn't succeed because authentication fails. It succeeds because human decision-making is hijacked.
If that is the real failure mode, then the solution can't stop at credentials. It requires designing defenses around human behavior itself.
APP Fraud Is Not a Technical Breach - It's a Behavioral One
In a typical APP scam, nothing in the system is broken. The user logs in correctly. A trusted device processes the transaction. Multi-factor authentication passes without complaint. The user authorizes the payment - intentionally. And yet the criminal still walks away with the funds.
The attacker never compromised the system. They rewired the victim's perception of reality - through social engineering, deepfakes, impersonation, and relentless time pressure. Every technical control did its job, and the fraud happened anyway.
Why Existing Controls Struggle with APP Fraud
Banks already deploy an impressive arsenal: device fingerprinting, transaction rules, velocity checks, risk scoring, step-up authentication. Against account takeovers and automated fraud, these controls work well. Against manipulation-driven scams, they struggle.
The limitation is structural. They measure what the user does - not how the user behaves while doing it. A coerced payment and a routine payment can look identical on paper, because the data points those systems inspect were never designed to capture a person acting under someone else's instruction.
Behavioral Biometrics: Seeing What Others Miss
Behavioral biometrics shifts the analytical question. Instead of confirming who the user is, it asks whether the user is behaving normally for themselves. Are they moving with their usual confidence, or showing distress? Is this hesitation, or panic? Are they acting on their own judgment, or responding to external instruction?
These signals surface before the transaction completes - while there is still time to intervene - and they are extraordinarily hard to fake at scale.
A scammer can steal a password. They cannot steal the way a person behaves when they are calm.
The Future of Fraud Prevention Is Behavioral
Credentials get stolen. Devices get spoofed. Rules get bypassed. But behavior under manipulation tells a revealing story, and reading that story in real time changes what prevention can be.
It means stopping scams without blaming the victim, without wrecking the user experience, and without burying every payment in friction. That is the layer the industry has been missing - and it is the layer we build.
Inon S. Ohana
Co-Founder & CEO of Vara Security
See the behavioral layer in action.
Watch Vara read a session under manipulation - and intervene before the money moves.