Revolut told the Payment Systems Regulator’s authorised push payment fraud taskforce that it will bind outbound Faster Payments above £1,000 to cryptographically registered handsets from October, extending device fingerprints already used for wallet provisioning after ombudsman rulings showed coached one-time passcode sharing still defeats “in-app approval” marketing.
What the taskforce heard
In a closed briefing on Tuesday, Revolut’s financial crime chief walked regulators through 1,240 APP cases closed in the first half of 2026 where victims approved payments on phones they had just enrolled via SMS links. Scammers posed as bank fraud desks, guided victims through screen sharing, then triggered wallet provisioning flows that generate OTPs on the victim’s existing device. Revolut argued device binding—pairing payment initiation to a hardware-backed key generated at onboarding—closes that gap without breaking reimbursement rules that took effect in October 2024.
Competing neobanks cautioned that binding can strand customers who swap handsets weekly or rely on family devices in multigenerational households. Revolut said recovery will require in-branch-style video checks at its support centres in Canary Wharf and Vilnius, with median unlock times under four hours for documented identity matches.
How binding changes the app
Starting 14 October, the mobile app will refuse to sign payment messages unless the Secure Enclave or StrongBox key that registered the account is present. Adding a new phone will mandate an existing-device approval plus a NFC tap on a mailed card for retail customers; business accounts must use dual admin approvals on the web dashboard before keys replicate. Google Pay and Apple Pay provisioning will inherit the same root key, addressing ombudsman case DRN-5363526 where fraudsters moved cards to a second device after coaxing OTPs.
Revolut will still send push warnings when payee names mismatch Confirmation of Payee responses, but binding is meant to stop remote puppeteering even when victims click “yes” under duress. Critics note binding does not help if malware captures keys on the primary device—a risk Revolut acknowledges but says is rarer than social engineering in its UK cohort.
Regulatory context
PSR policy statement PS25/5 requires sending payment service providers to reimburse eligible Faster Payments APP fraud, with cost sharing between sending and receiving banks. Device binding is not a statutory requirement, but the taskforce is cataloguing controls that reduce “gross negligence” disputes. Revolut’s slides, seen by InfoHandle, estimate binding could cut disputed liability by eighteen percent among customers aged 55–70 who dominate coached OTP cases.
The Financial Conduct Authority has not endorsed binding as a minimum standard, telling firms to evidence proportionality. High-street banks told the taskforce they worry binding fragments user experience if only one app adopts it; Revolut counters that its digital-only base expects app-first security and that branch-led banks can keep call-centre overrides.
What victims’ lawyers say
Consumer solicitors welcomed binding but warned that reimbursement fights will shift to whether victims “voluntarily” enrolled new devices during scams. Ombudsman decisions already treat Face ID unlocks as customer involvement; binding hardens that presumption. Advice charities want cooling-off periods after new device enrollment during which outbound limits drop to £100 until a calendar day passes without fraud flags.
Revolut agreed to pilot such a cooling-off for vulnerable customers flagged by adult social care referrals in two London boroughs. If metrics show fewer losses without spiking false declines, the PSR may recommend wider adoption in its December progress report.
What is still unknown
Revolut has not published implementation guides for third-party accountants who initiate bulk payments via API. Open banking aggregators asked whether binding keys will be attestable through FAPI profiles; Revolut said API work trails the retail rollout. Loss figures tied to the briefing remain confidential, though UK Finance industry totals show APP fraud still exceeds card fraud by value despite reimbursement.
Receiving banks argued binding on the sender side does nothing when mule accounts sit inside the same neobank. Revolut pledged enhanced outbound velocity checks to crypto exchanges but declined to detail thresholds. Taskforce members expect those metrics in October when binding goes live.
Practical steps for customers
Revolut’s help pages already describe OTP flows for wallet setup; binding adds a visible “trusted device” panel listing enrolled hardware. Customers should treat any call asking them to approve a new device as a hang-up event, using in-app chat started from the home screen rather than callback numbers read aloud by strangers. Joint account holders must enroll separately—binding is per user, not per account.
For small businesses, payroll administrators should disable SMS fallback for administrators and require hardware security keys on the web console before October. Revolut said it will run webinars with the Scottish Business Resilience Centre in September because invoice redirection scams spike when universities return.
Industry read-through
If binding cuts ombudsman uphold rates, larger banks may copy the control ahead of 2027 PSR reviews. If it spikes lockouts among vulnerable users, politicians will press for statutory cooling-off language in the Crime and Policing Bill amendments. Revolut’s bet is that handset keys are easier to explain to juries than opaque machine-learning scores—and that taskforce airtime buys goodwill even when reimbursement bills keep climbing.








