Which? warns that criminals are increasingly convincing individuals to authorise payments themselves, complicating refunds and exposing vulnerabilities in existing fraud safeguards amid a rapidly evolving landscape of digital scams.
Consumer group Which? has warned that a newer form of card fraud is leaving victims with less protection than many expect, as criminals increasingly persuade people to authorise payments themselves rather than stealing card details outright. The warning matters because card fraud is often treated as a problem of unauthorised spending, yet this tactic can blur the line between a scam and a payment that the customer technically approved, making refunds harder to secure. Which? says that, for some victims, that distinction can turn a straightforward fraud claim into a far more difficult dispute.
The concern is that fraudsters are adapting the playbook that has already driven losses in authorised push payment scams, where victims are tricked into sending money directly from their bank accounts. According to Which?, criminals may call while posing as bank security staff, police officers or regulators, claim an account is under attack and then pressure the victim to approve a card payment or share a one-time passcode. In some cases, they may ask the person to move money to a so-called safe account, or use stolen card details to add the card to a digital wallet and spend through the victim’s own authorisation process. Which? says this is a reminder that fraud prevention has not stood still even as banks have tightened checks around transfers.
The organisation’s warning also reflects the wider fraud threat seen across 2026, with Which?’s own recent reporting pointing to phishing emails, fake social media adverts, data breaches, subscription scams, SMS fraud and digital wallet attacks as part of a broader and fast-changing landscape. The Metropolitan Police advises people to treat unsolicited calls about bank or card problems with caution and to verify any request by using a trusted number rather than one provided by the caller. MoneyHelper and the Financial Conduct Authority give similar advice, urging consumers to be alert to pressure, urgency and requests for sensitive information, especially one-time passcodes.
Lisa Webb, a consumer law expert at Which?, said the scam is “particularly dangerous” because card payments do not benefit from the automatic reimbursement rules that apply to authorised push payment fraud. She said victims should make a claim to their card provider and, if necessary, escalate to the Financial Ombudsman Service with a full account of how they were manipulated. UK Finance said criminals commonly use impersonation tactics and harvested personal data to get around security checks, and warned consumers never to share one-time passcodes with anyone they were not expecting to hear from.
Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.





