The gap between US and UK protection here is enormous — and it hinges on one detail: did someone else move the money, or did they trick you into moving it yourself?
It depends heavily on which kind of fraud happened, and this distinction matters more in the US than almost anywhere else in consumer finance. If someone else accessed your account and moved money without your knowledge — classic unauthorized access — US federal law (Regulation E) caps your liability at $50 if you report within two business days, or $500 within 60 days. But if you were deceived into approving the transfer yourself (a scam that tricks you into hitting "send"), Regulation E's protection is much weaker, because the transaction was technically authorized by you. The UK closed exactly this gap in October 2024: payment providers must now reimburse victims of this second type of fraud too, up to £85,000, regardless of who was deceived into clicking send.
| United States | United Kingdom | |
|---|---|---|
| Legal basis | Electronic Fund Transfer Act (EFTA) / Regulation E | Payment Systems Regulator (PSR) mandatory APP fraud reimbursement, in force since 7 October 2024 |
| Unauthorized access (someone else moved your money) | Liability capped at $50 if reported within 2 business days, $500 within 60 days; banks must investigate within 10 business days | Covered similarly — genuinely unauthorized transactions have long been the bank's responsibility |
| You were tricked into approving the payment yourself (a scam) | Much weaker protection — since you technically authorized it, Reg E's strongest safeguards may not clearly apply, and outcomes vary significantly by bank and payment method | Mandatory reimbursement up to £85,000, cost split 50/50 between the sending and receiving payment provider, unless you acted with gross negligence |
| Excess/deductible | N/A | Sending provider can apply an excess of up to £100, except for customers classed as vulnerable, who cannot be charged any excess |
| Timeline for reimbursement | Investigation generally within 10 business days; provisional credit if longer is needed | Must be refunded within 5 business days of the claim, or within 35 days if the case needs extended investigation |
The UK's reform is genuinely unusual by global standards — it was the first country to make this kind of reimbursement mandatory rather than voluntary, and regulators in Australia, Singapore, and the EU are watching the results closely as a model. In the US, the equivalent gap — being deceived into approving your own payment via Zelle or a similar app — remains a significant weak spot in consumer protection, and has drawn direct criticism from US lawmakers for years without a comparable federal fix as of 2026.
Classic hacking, a cloned card, or stolen login credentials used by a third party you never interacted with. This is genuinely unauthorized fraud in both countries, and protection is comparatively strong and well-established on both sides of the Atlantic.
A fake "your account is compromised, transfer your funds to this safe account" call, a romance scam, or a fraudulent invoice you paid believing it was real — in all of these, you personally hit "send." In the US, this is where protection weakens considerably. In the UK, this is now exactly the scenario the 2024 reform was built to cover.
Both countries allow for reduced liability protection if you're found to have acted with gross negligence — for example, sharing a one-time passcode with someone claiming to be your bank. This is a genuinely disputed area case by case, and worth pushing back on if the pressure you were under was itself part of the scam.
In the US specifically, your liability cap under Reg E depends heavily on how fast you reported the unauthorized activity — $50 within two business days versus $500 within 60 days is a meaningful difference, so speed genuinely changes your financial exposure.
UK: "You were deceived into authorizing this payment, but our investigation found no gross negligence on your part — we're reimbursing the full amount within our statutory timeline."
Treating "you clicked send" as automatically disqualifying, without properly investigating whether you were the victim of deception that meets the UK's reimbursement standard — or, in the US, dismissing a claim as "authorized" without a genuine review of how the authorization was obtained.
Use our Unauthorized Transaction Report Letter generator to formally notify your bank or fintech and start the investigation clock immediately.
Explore Crypto & Fintech tools →