Your bank has to reimburse you. You still have to prove it.
Since 7 October 2024 in-scope UK payment firms must reimburse victims of authorised push payment fraud up to £85,000, with the cost shared equally between the firm that sent the money and the firm that received it. You have 13 months from the last authorised payment to claim, and a decision is due within 5 business days, or by the 35th business day if the firm stops the clock. None of that produces a copy of the website that convinced you to pay.
Works on Chrome and Edge. From $4.99 (about £3.90) as a one-off, or a 7-day trial that requires a credit card.
APP fraud reimbursement in the United Kingdom is mandatory. Since 7 October 2024 in-scope payment firms must reimburse consumers, micro-enterprises and charities up to £85,000 for authorised push payment fraud over Faster Payments and CHAPS, on a claim made within 13 months of the last payment. The regime does not prove the fraud for you. ProofSnap captures the evidence that does.
Your own payment firm must reimburse within 5 business days, or stop the clock while it seeks information and close the claim before the end of the 35th business day, and it then recovers half the cost from the firm that received the money (Payment Systems Regulator, 2024). Firms may apply an optional £100 excess, but not to vulnerable consumers. What none of that decides is the factual question of whether you were defrauded and whether you fell below the consumer standard of caution. That is argued from what was on your screen at the time. Reimbursement is not automatic, and UK banks reimbursed 61 per cent of APP fraud losses in 2025 (UK Finance, Annual Fraud Report 2026), so roughly two pounds in every five never came back. ProofSnap captures the page in about forty seconds and produces a package of 11 to 15 files carrying the full-page screenshot, the saved source, the URL, the UTC capture time, a SHA-256 hash of every file, an RSA-4096 signature and an eIDAS qualified timestamp. From $4.99 (about £3.90) as a one-off purchase, with no subscription.
By Radim Motycka, Founder and Lead Engineer, ProofSnap · · Independently verifiable via Trust Verifier
Why claims get refused
Why APP fraud claims get refused: the entitlement is new, the evidence problem is not
Reimbursement is not automatic. Firms can and do refuse, and the grounds they use are all about what you saw and what you were told. UK banks reimbursed 61 per cent of APP fraud losses in 2025 (UK Finance, Annual Fraud Report 2026).
The fraudulent site disappears first
A refusal is argued from documents, and the documents in an investment fraud are hosted by the fraudster. The portal, the terms page and the withdrawal screen all go offline at the same moment, usually within days of the last payment.
A plain screenshot proves nothing about when
An image file carries whatever date its metadata says, and metadata is trivially editable. If the firm or the Financial Ombudsman Service has to take your word for when a page looked like that, you are asserting rather than proving.
Refusals turn on what you were shown
A firm may argue you ignored a warning or acted with gross negligence. That is a factual argument about the screen in front of you at the moment you authorised the payment, and it is decided on records rather than recollection.
The rules that now govern your APP fraud claim
These are the fixed points of the regime. They tell you what you are entitled to and how long you have.
Up to £85,000, with the cost shared 50/50
The maximum reimbursement is £85,000 per claim over Faster Payments and CHAPS (Payment Systems Regulator, 2024). The cap applies to everyone, vulnerable consumers included; what does not apply to a vulnerable consumer are the excess and the consumer standard of caution. You claim from your own payment firm, the one that sent the money, and that firm then recovers half the cost from the firm that received it. Above the cap the Financial Ombudsman Service can award more, up to £455,000 for cases referred on or after 1 April 2026 (Financial Ombudsman Service, 2026).
13 months to claim
A firm can decline a claim submitted more than 13 months after the final payment relating to that claim. That is a generous window compared with most deadlines, and it is still a deadline.
5 business days, or 35 with the clock stopped
The firm must reimburse within 5 business days. Where it needs more information it can stop the clock, as many times as necessary, but it must close the claim before the end of the 35th business day after you reported it. Anything you can hand over on day one shortens that.
Gross negligence is where the argument happens
Consumers, micro-enterprises and charities are in scope, and a firm may apply an optional £100 excess to everyone except vulnerable consumers. A firm can refuse only where you were complicit or where you fell below the consumer standard of caution through gross negligence, which the Payment Systems Regulator treats as a higher bar than common law negligence. That argument is about the warning you were shown and the site you were looking at, which is exactly the material that disappears.
What the APP fraud reimbursement regime does not cover
The mandatory regime is narrower than most articles about it suggest. It reaches authorised push payments between two accounts held in the United Kingdom, sent over Faster Payments or CHAPS. Everything below sits outside it, which does not mean you have no claim, only that you are arguing under a different rulebook where your own evidence matters even more.
| Payment | In the regime? | Where the claim goes instead |
|---|---|---|
| Faster Payments or CHAPS, UK account to UK account, in sterling | Yes | Your sending firm, then the Financial Ombudsman Service |
| International transfer to an account held outside the United Kingdom | No | The firm's own goodwill policy, then the Financial Ombudsman Service |
| Debit or credit card payment | No | Chargeback, or section 75 of the Consumer Credit Act 1974 on a credit card |
| Cash or cheque | No | Action Fraud and, where a party can be identified, the civil courts |
| Payment to buy cryptocurrency | Only sometimes | In scope where the receiving account is held in the United Kingdom; a transfer you make out of your own wallet is not |
| Civil dispute with a real supplier that underdelivered | No | Contract claim in the civil courts |
Scope taken from the Payment Systems Regulator's consumer guidance on APP fraud reimbursement protections, as at 3 August 2026. Where a payment falls outside the regime the evidence question does not go away. It gets harder, because nothing obliges anybody to reimburse you and the whole argument runs on what you can show.
Five things to capture, in order, before you report the fraud
Capture in order of how fast each item disappears, and capture each page as its own record so that every one carries its own URL and its own timestamp. The whole sequence takes about five minutes.
- 1The fraudulent site or trading dashboard, while you are still signed in. The portal showing your balance growing is the most persuasive document in the whole claim and the first thing switched off.
- 2The payment page or invoice carrying the account details. Sort code, account number and account name are what your firm and the receiving firm will work from.
- 3The chat thread, including the profile of whoever contacted you. WhatsApp and Telegram messages are deleted for both sides, and a deleted account takes the guarantee and the pressure to send more with it.
- 4The advertisement or listing that started it. Social advertisements are rotated and pulled quickly, and the advertisement is often what shows the approach was fraudulent from the start.
- 5Any warning screen your bank showed you at the moment of payment. If a firm argues you ignored a warning, the warning itself becomes the document in dispute.
Do not delete or block until you have captured. Blocking the account sometimes removes your own access to the history, and deleting the thread removes it for good. Capture first, report second.
How the capture works: three steps, about forty seconds
No forensic training required. The proof is in the package, not in your testimony about how careful you were.
Capture before you report or block
Open each page and capture it. The full page is saved along with the source, so the account details or the balance on the dashboard are preserved as text, not just as pixels.
The package proves its own age
Every file is hashed, the manifest is signed, and the manifest hash carries an eIDAS qualified timestamp plus a Bitcoin blockchain anchor. Nobody can credibly claim you made the capture after the fact.
Claim, and keep the ZIP
Attach the PDF evidence report to your reimbursement claim and to your Action Fraud report. If the claim is refused and you escalate to the Financial Ombudsman Service, the same package goes with it.
What lands in the evidence package
Between 11 and 15 files depending on your plan, delivered as one ZIP that anyone can check without installing anything.
Full-page screenshot
The whole page, not just the visible window, stitched and hashed.
Saved page source
The document as rendered at capture time, including the head, meta tags and structured data.
Extracted page text
Searchable plain text, so a quote can be found and cited without retyping.
Technical metadata
URL, page title, HTTP response headers, browser, operating system and the capture time in UTC.
Signed manifest
SHA-256 for every file, signed with an RSA-4096 key whose public key ships in the package.
Blockchain timestamp
The manifest hash anchored to Bitcoin via OpenTimestamps, so the capture time cannot be backdated.
Chain of custody and forensic log
A record of what happened during the capture, in the order it happened.
Evidence report as PDF
A readable summary you can attach to an application, a notice or a report.
Verification instructions
Written steps plus scripts, so the other side can re-check the hashes offline.
Anyone can verify it, including the other side. Drop the ZIP onto the public Trust Verifier and the hashes, the signature and the timestamp are checked in the browser. Nothing is uploaded and nothing depends on ProofSnap still existing.
How an eIDAS qualified timestamp reaches a UK court
The United Kingdom is not in the European Union, so the timestamp does not arrive as EU law. It arrives as United Kingdom domestic law. Regulation (EU) No 910/2014 was kept on the domestic statute book at exit and, since 1 January 2024, is described as assimilated law rather than retained EU law. Article 41(2) is the operative provision:
"A qualified electronic time stamp shall enjoy the presumption of the accuracy of the date and the time it indicates and the integrity of the data to which the date and time are bound."
Article 41(2), Regulation (EU) No 910/2014 as it forms part of assimilated law in the United Kingdom
A timestamp issued by an EU provider still counts here because Article 24A, inserted by the Electronic Identification and Trust Services for Electronic Transactions (Amendment etc.) (EU Exit) Regulations 2019 (S.I. 2019/89), provides that for the purposes of Articles 25(2), 27, 35(2), 37, 41(2) and 43(2) a service qualified in an EU member state is treated as qualified. ProofSnap's qualified timestamps are issued by Disig a.s., a Qualified Trust Service Provider on the EU Trusted List, so they land inside Article 41(2) as a matter of UK domestic law.
Two honest limits
The presumption is narrow. It covers the date, the time and the integrity of the data bound to them. It does not authenticate the exhibit, prove what the page meant or prove that you were the person looking at it. In England and Wales you still put the package before the court through a witness statement, and the Civil Evidence Act 1995, by virtue of section 16(4), extends only to England and Wales. Scotland runs on the Civil Evidence (Scotland) Act 1988 and Northern Ireland on the Civil Evidence (Northern Ireland) Order 1997.
The recognition is revocable. Section 131 of the Data (Use and Access) Act 2025 gives the Secretary of State the power to amend or revoke Article 24A and so remove recognition of EU qualified services. As at 3 August 2026 that section is not in force and no regulations have been made under it, so Article 24A stands. It is worth rechecking before you rely on it in a contested matter.
Three ways to get the evidence
Prices are charged in USD. Approximate sterling figures are shown for orientation only, and your card issuer sets the actual rate.
One dispute
$4.99 once
about £3.90
A SnapPack is a single up-front purchase for a set number of captures. No subscription, no auto-renewal, no trial. Best when you have one problem and you want it documented today.
Get a SnapPackOngoing matters
$8.99/month
about £7
For anyone who captures regularly: practitioners, property managers, HR teams, investigators. The 7-day free trial requires a credit card. Cancel any time during the trial and you are not charged.
Start the 7-day trialWe do it for you
$44.99 per URL
about £35
Send us the link and our team captures the package for you, with nothing to install. Useful when the capture should not come from a party to the dispute.
See the capture servicePrices are charged in US dollars; the sterling figures are approximate and your card issuer sets the actual rate. ProofSnap is not a law firm and does not give legal advice. This reflects the position as at 3 August 2026. Qualified timestamps are issued by Disig a.s., a Qualified Trust Service Provider on the EU Trusted List, and recognition of EU qualified status in the United Kingdom rests on Article 24A of the assimilated eIDAS Regulation, so the timestamp carries the Article 41(2) presumption here as a matter of UK domestic law. Section 131 of the Data (Use and Access) Act 2025 contains a power to narrow that recognition which has not been brought into force.
Official sources
Every figure and deadline on this page comes from the following primary sources. Check them yourself rather than taking our word for it.
- Payment Systems Regulator: APP fraud reimbursement protections the entitlement, the maximum, the excess and who is covered. As at 30 July 2026 the rules sit with the Payment Systems Regulator, which is being consolidated into the FCA subject to legislation before Parliament.
- Action Fraud the national reporting centre for fraud and cybercrime in England, Wales and Northern Ireland.
- Financial Ombudsman Service where a refused claim goes next, decided on the papers.
- Financial Ombudsman Service: time limits 6 months from the firm's final response, and normally 6 years from the event.
- Article 24A, Regulation (EU) No 910/2014 as it forms part of assimilated law the provision that treats an EU qualified trust service as qualified for the purposes of Article 41(2) in the United Kingdom, inserted by S.I. 2019/89.
- Section 131, Data (Use and Access) Act 2025 the power to remove recognition of EU standards, not in force as at 3 August 2026.
- UK Finance, Annual Fraud Report 2026 the source of the 2025 figures quoted on this page, including the 61 per cent of APP fraud losses reimbursed.
One detail worth getting right: most UK banks want a suspicious email forwarded to them rather than captured as an image, because the forwarded message carries its headers. Forward the email as they ask, and use a capture for the website, the dashboard and the chat, where forwarding is not possible.
Questions people actually ask about APP fraud reimbursement
Thirteen months to claim. Thirteen days before the site is gone.
Five minutes of capturing today is the difference between a claim and a case.