The £160,000 APP fraud case demonstrates why FCA authorisation does not guarantee victim compensation—and why claims against receiving payment providers remain difficult, technical and prohibitively expensive.
A major reversal for the victims
On 21 July 2026, the UK Court of Appeal handed Moorwand Ltd an important victory in Moorwand Ltd v Hamblin & Ors. The court overturned a 2025 High Court decision that had required the FCA-regulated electronic money institution to restore £160,000 to the account of a company used by fraudsters.
The Court of Appeal instead reinstated the original dismissal of the claim. Importantly, the judgment did not find that Moorwand had participated in the scam or acted dishonestly. The legal question was narrower: whether the payment provider had sufficient reason to suspect that the person controlling its customer’s account was misappropriating money belonging to that customer.
Moorwand remains an active UK company and is currently listed by the FCA as an authorised electronic money institution under reference number 900709.
The fraud structure
The case arose from an authorised push payment, or APP, investment scam.
A fraudster had incorporated a company called RND Global Limited using the identity of an innocent individual, John Stanfield. False or manipulated identity documents, addresses and corporate information were then used to establish a payment relationship with Moorwand, which at the time operated the UPayCard electronic-wallet platform.
RND presented itself as a marketing and consulting business. Moorwand subsequently opened sterling, euro and Bitcoin wallets for the company.
The court record contains significant onboarding warning signs. In an internal communication, a Moorwand employee reportedly said that one of the documents submitted during onboarding “looks fake”. Nevertheless, the accounts were opened without the apparent discrepancy being satisfactorily resolved.
The victims, Gareth and Patricia Hamblin, were persuaded to invest through a supposed foreign-exchange trading operation known as Central Exchange Market, or CEX. The scheme promised substantial returns from high-speed currency trading.
On 10 July 2017, the Hamblins transferred £160,000 to a bank account held for Moorwand with a Danish bank. Moorwand credited the funds to RND’s electronic wallet.
The money was then rapidly dissipated. Transactions included Bitcoin purchases, a luxury watch costing approximately £34,500 and a payment of £40,000 to a vehicle-related business. The investment returns never materialised. RND was subsequently dissolved, while the individual whose identity had been used to form the company had no involvement in the fraud.
An innovative—but highly complicated—recovery strategy
The victims faced a fundamental legal obstacle. After the UK Supreme Court’s decision in Philipp v Barclays Bank, a bank or payment provider will generally not breach its so-called Quincecare duty merely by executing a payment instruction personally authorised by a customer—even where that customer has been deceived by a fraudster.
Moreover, the payment provider receiving the funds does not normally owe that duty directly to the fraud victim. Moorwand’s contractual duties were owed to its own customer, RND, rather than to the Hamblins. The Hamblins therefore developed an unusual derivative-action structure.
They restored RND to the Companies Register, established that the £160,000 was held by RND on constructive trust for them and then pursued Moorwand in RND’s name. Their argument was that the fraudster controlling the account had no actual authority to instruct Moorwand to transfer away money that RND held on trust for the victims.
Moorwand, they argued, should have been “put on inquiry” by the defective onboarding documentation, the identity inconsistencies and the nature of the subsequent transactions.
This transformed the claim from a direct action by scam victims into a claim nominally brought by Moorwand’s own customer.
The temporary High Court victory
The claim was initially dismissed after trial in 2024. The trial judge concluded that although Moorwand’s onboarding and regulatory controls displayed deficiencies, those shortcomings did not establish that Moorwand had reason to suspect that the payment instructions involved a misappropriation of RND’s funds.
In April 2025, Mr Justice Marcus Smith reversed that decision. He considered that the onboarding problems and unresolved identity concerns should have placed Moorwand on inquiry. The High Court ordered Moorwand to reconstitute RND’s account by crediting it with £160,000.
The order was not technically an award of damages directly to the Hamblins. The money was to be restored to RND’s account, from where the victims hoped to recover it as beneficiaries of the constructive trust.
The High Court nevertheless rejected a separate claim based directly on the Payment Services Regulations. Regulatory non-compliance did not, by itself, create the private remedy sought by the victims.
Why the Court of Appeal overturned the decision
The Court of Appeal did not conclude that Moorwand’s onboarding was satisfactory. Nor did it decide that AML and know-your-customer deficiencies are irrelevant to private litigation. Instead, the appeal turned heavily on the limits of appellate review.
The first-instance judge had heard the witnesses, considered the expert evidence and concluded that the circumstances did not establish sufficient suspicion that the fraudster was misappropriating RND’s money. The Court of Appeal held that this was an evaluative finding that was open to the trial judge and should not have been replaced merely because another judge might have reached a different conclusion.
The Court of Appeal expressly recognised that the original conclusion was favourable to Moorwand. It also acknowledged that, had the question been considered entirely afresh, the contrary conclusion reached by Mr Justice Marcus Smith could have been sustainable.
That distinction is crucial. The appeal judgment is not a judicial endorsement of weak onboarding procedures. It is primarily a ruling about the high threshold for overturning a trial judge’s assessment of evidence.
The Court of Appeal also left several potentially important questions unresolved, including:
- how authority should be analysed where an entire company is created and controlled through identity fraud;
- whether contractual warranties given to the payment provider would defeat or reduce the claim;
- how automated payment processing and algorithmic monitoring affect the traditional Quincecare analysis;
- and how regulatory payment-services obligations interact with common-law duties.
The derivative-action route therefore remains legally possible in principle. The Moorwand judgment does not eliminate it, but it demonstrates how evidentially demanding that route will be.
Regulatory failures are not automatically civil liability
The case exposes a central problem for scam victims.
An FCA-supervised payment institution may have breached onboarding, customer-due-diligence, transaction-monitoring or suspicious-activity-reporting expectations without automatically becoming liable to reimburse a third-party victim.
The underlying facts behind those regulatory deficiencies can be relevant evidence. But victims must still establish a recognised private-law cause of action, prove the necessary duty and demonstrate that the payment provider should have suspected a misuse of its own customer’s funds.
In practical terms, showing that an EMI should have conducted more enhanced due diligence is not the same as proving that it was legally required to stop a particular payment.
The FCA nevertheless expects payment firms to identify and control money-mule accounts, maintain effective onboarding and monitoring systems and act promptly when fraud is reported. Under the newer APP reimbursement regime, receiving payment providers also have a direct financial incentive to prevent fraudulent accounts because they generally bear 50% of the reimbursement cost.
A £160,000 dispute producing almost £1 million in costs
Perhaps the most disturbing feature of the Moorwand proceedings is their economic disproportionality.
The Court of Appeal noted that the trial and two appeals had generated combined legal costs approaching £1 million—more than six times the original £160,000 loss. The court described the situation as deeply troubling.
For ordinary fraud victims, this is the practical message of the case: even an innovative and legally arguable claim may require years of litigation, company-restoration proceedings, trust claims, expert evidence, insolvency analysis and multiple appeals.
A legal remedy that costs substantially more than the amount stolen is not an effective remedy for most consumers.
Would the new UK reimbursement rules change the result?
The mandatory UK APP fraud reimbursement regime has improved the position for many victims, but it would not retrospectively assist the Hamblins.
The rules apply to qualifying payments made from 7 October 2024 through the UK Faster Payments System or CHAPS. Individuals, microenterprises and certain charities can generally claim reimbursement of up to £85,000, subject to exclusions and a possible £100 excess.
The sending payment provider normally reimburses the customer and then recovers 50% from the receiving payment provider. International transfers, cards, cash, crypto transfers and certain payments made outside the covered systems remain outside the core regime.
According to the Payment Systems Regulator, approximately 89% of the value of in-scope APP scam losses was reimbursed during the first 15 months of the regime, representing around £243 million. However, high-value cases, historic scams, cross-border payment structures and crypto-connected transactions can still fall into significant protection gaps.
FinTelegram assessment
Moorwand v Hamblin should not be read as a declaration that receiving payment providers are immune from civil claims.
It should instead be understood as a warning about the fragmented UK framework facing scam victims:
- FCA authorisation is not insurance against fraud losses.
- Regulatory deficiencies do not automatically establish private liability.
- The victim usually has no direct contractual relationship with the receiving payment provider.
- Creative derivative or trust-based claims may be possible, but they are procedurally complex and financially dangerous.
- The statutory APP reimbursement regime has improved consumer protection, but only within defined payment systems, time periods and monetary limits.
For payment institutions and EMIs, the compliance lesson is equally clear. Onboarding anomalies must be resolved and documented, particularly where identity documents appear manipulated or the proposed business model involves crypto assets, high-value transfers or rapid wallet movements.
A payment provider may ultimately defeat a civil claim and still face uncomfortable questions about whether its customer-acquisition, AML and fraud-monitoring systems enabled the scam infrastructure.
For victims, the Moorwand litigation represents a sobering reality: following the money to a regulated payment provider does not necessarily mean that the money can be recovered from it.




