Skip to content
Banking & Current Account Apps

Fake Banking App Scam UK: Two Types, Three Checks

A fake banking app scam works two ways in the UK: a faked payment screen shown to sellers, and a cloned app that harvests your login. How to spot both.

By the Abel team · Updated 2026
Fake Banking App Scam UK: Two Types, Three Checks
Photo: Banca móvil by Torsten Dettlaff (CC BY-SA 4.0), via Wikimedia Commons

The phrase “fake banking app scam” covers two completely different crimes in the UK, and the advice for one is useless against the other. In the first, nobody touches your phone: a buyer shows you a convincing payment screen on their own handset and walks off with your goods. In the second, an app on your phone pretends to be your bank, or quietly runs a second copy of the real one, and collects your login. Knowing which is which tells you where to look, because the giveaway in each case is in a different place.

Type one: the app that fakes a payment to your face

This is the version the police have been warning about, and it targets sellers rather than bank customers.

The West Midlands Regional Organised Crime Unit set out the mechanics in a public alert on 27 May 2025. You list something on a marketplace, a buyer arranges to collect, and at the handover they ask you to type your sort code and account number into an app on their phone. The app is built to mimic a banking transfer, and it produces a screen confirming the payment has gone. Nothing has gone anywhere. When the money fails to appear, the buyer often makes a show of phoning their bank and reports that transfers are taking up to two hours today.

That two-hour line is the clever part, because it is not obviously a lie. Pay.UK, which runs the Faster Payment System, says funds are “usually available almost immediately, although they can sometimes take up to two hours”. A seller who knows a little about payments will accept it as plausible and hand over the item.

Dr Tim Day of the Chartered Trading Standards Institute told LBC in April 2025 that around 500 reports of crimes involving fake banking apps had reached Action Fraud over the previous three years. The cases that made the news were ordinary handovers: Anthony Rudd in Salisbury lost £1,000 of tools, and said the payment screen “looked absolutely genuine”. Wiltshire Police could not identify the suspect.

There is only one defence, and it does not involve inspecting the buyer’s phone:

  • Check your own account, in your own app, before the goods leave your hands. A payment that exists shows up as received or at least pending on your side. Your bank can confirm it; a screen you are being shown cannot.
  • Do not accept a screenshot, a notification, or a “reference number” as proof. All three are trivial to fake and none of them is a record held by your bank.
  • Never let the buyer set the pace. Rushing you past the confirmation step is the whole method. Declining a sale costs you nothing.
  • Prefer a payment route with its own confirmation, such as the marketplace’s own checkout, or meet at a bank branch for cash.

The other red flags the alert lists are worth remembering: a recently created account with lots of similar-sounding positive feedback, and a buyer who wants to change the agreed meeting place.

Type two: the cloned app that wants your login

The second family is malware, and it arrives on your phone rather than the fraudster’s. The technique has moved on from simple lookalikes.

On 11 September 2026 Malwarebytes documented how the Android banking trojan Gigabud handles this. Victims are talked into sideloading a fake airline, tax or government app from a phishing page or a message. Once installed, it asks for Accessibility and screen overlay permissions, checks which banking apps are on the device, and installs a tool the researchers call Vwork, itself based on the open-source Shelter project. Vwork sets up an Android work profile and clones the victim’s real banking app into it, so fraudulent activity happens in a second instance of the genuine app rather than in a fake one. That is deliberate: it sidesteps the checks a bank runs on the device it thinks it is talking to.

So the old advice to “look for spelling mistakes in the app” no longer covers it. The signals that still work are these:

  • Where it came from. Android malware in this class is almost always sideloaded from a link, not installed from Google Play. Any message, advert or support agent asking you to install an APK file is a scam, without exception.
  • What it asks for. A genuine banking app does not need Accessibility services or permission to draw over other apps. Those two requests are how overlay fraud and remote control work. Refuse them and report the app.
  • Whether there are two of it. A duplicate of your banking app, or a work profile you did not create, is a serious signal. Delete nothing, and phone your bank first.

The three checks before you log in to any money app

These take under two minutes and they catch impostors in both families.

1. Read the developer name, not the app name. In Google Play and the App Store the publisher line is far harder to fake than a logo or a title. Monzo Bank Limited publishes Monzo. If the developer is an unfamiliar individual or a generic studio name, stop. Tapping the developer name also shows you their other apps, which frequently gives the game away.

2. Look the firm up on the FCA register, and match the number. Every bank and e-money firm operating legitimately in the UK is on the Financial Services Register with a reference number. Clone operations copy a real firm’s name and register number onto their own website and app listing, so compare the contact details on the register entry with the ones you have been given. The FCA also publishes a warning list of unauthorised firms worth searching before you install anything that handles money.

3. Reach your bank through a route you chose. If a call, text or in-app message prompts you to install or update anything, hang up and dial 159. The short code connects you to your own bank’s fraud line, it cannot be spoofed the way a phone number can, and Stop Scams UK says it now covers more than 99% of UK retail current accounts, including Barclays, HSBC, Lloyds, Monzo, Nationwide, NatWest, Revolut, Santander, Starling and TSB.

If it has already happened

For a faked payment at a handover, report it to Action Fraud at actionfraud.police.uk or on 0300 123 2040, and tell the marketplace. Be realistic about recovery: you gave away goods rather than money, so this is theft to be investigated rather than a bank transfer to be reimbursed, and the reimbursement rules for authorised push payment fraud do not apply to you. The value of reporting is that it feeds the intelligence picture on apps that are still circulating.

For a suspected clone or trojan on your own phone, assume the credentials are gone. Call your bank on 159 from a different phone, ask for the account to be secured, then change your banking passwords from a device you trust rather than the infected one. Do not simply uninstall and carry on, because permissions granted to malware can outlast the app that requested them.

Checking whether the firm behind an app is a licensed bank at all is a related habit worth having: our guide to whether digital banks are safe explains what the licence actually protects, and are budgeting apps safe covers the read-only access model that the legitimate apps use.

Frequently asked questions

How do I know if a banking app is fake? Check the publisher line rather than the app name, confirm the firm’s entry and reference number on the FCA’s Financial Services Register, and be suspicious of anything you were sent a link to install. A genuine UK banking app comes from an official app store and never needs Accessibility or screen-overlay permissions.

Can a fake banking app show a payment that never happened? Yes, and this is the most common fake banking app scam in the UK. The app runs on the fraudster’s phone and produces a realistic confirmation screen at a handover. The only proof of payment is the money appearing in your own account, viewed in your own banking app.

Are fake banking apps on Google Play or the App Store? Occasionally, but most of the dangerous ones are sideloaded from links, phishing sites and messaging apps instead. Malwarebytes reported in September 2026 that the Gigabud trojan spreads by persuading people to install a fake airline, tax or government app from outside the store.

What should I do if a buyer’s payment app says the money will take two hours? Keep the item. Pay.UK does allow Faster Payments up to two hours, which is why the excuse sounds credible, but a real payment normally shows as received or pending straight away. Check your own account and hand nothing over until your bank confirms it.

Does 159 cost anything and which banks use it? The price depends on your provider, but in most cases it is charged like a standard national-rate 01 or 02 number and comes out of inclusive minutes. It is also inbound only, so a call claiming to be from 159 is a scam. Stop Scams UK says it reaches more than 99% of UK retail current accounts, including Barclays, HSBC, Lloyds, Halifax, Monzo, Nationwide, NatWest, Revolut, Santander, Starling, TSB and Virgin Money.

Will my bank refund me if I was tricked by a fake banking app? If you sent money to a fraudster, the mandatory reimbursement rules for authorised push payment fraud may apply and you should raise it with your bank at once. If you handed over goods against a faked payment screen, no money left your account, so there is nothing for the bank to reimburse and it is a police matter.

More from Abel
The Statement

One clear email a fortnight on UK money apps.

New rates, app updates worth knowing about, and the rare deal that actually beats leaving your cash where it is. No noise, unsubscribe anytime.

We never share your address. Independent, reader-funded reviews.