Quincecare, APP Fraud and the Search for a Remedy: More Questions Than Answers Following Moorwand v Hamblin

A person holding a smartphone receives a warning alert, with red exclamation symbols in the background.

In October 2024, the Payment Systems Regulator introduced a mandatory reimbursement framework requiring UK payment service providers to compensate victims of authorised push payment fraud.

20.08.2026

Against that backdrop, recent case law including Philipp v Barclays Bank which we discussed in July 2023, Larsson v Revolutwhich we commented on in August 2024 and the first instance judgment in Moorwand v Hamblin which we considered in July 2025 continues to test the limits of civil remedies available to fraud victims, particularly the scope of the Quincecare duty and its potential application to modern payment institutions.

The latest chapter in the continuing evolution of the so called Quincecare duty and its application in authorised push payment (“APP”) fraud cases has just been written by the recent Court of Appeal decision revisiting the Moorwand judgment from last summer. While the appeal ultimately turned on a fact-specific assessment of whether the payment services provider was "on inquiry", the judgment in Moorwand Ltd v Hamblin & Ors [2026] EWCA Civ 942 raises several important questions that may shape future litigation involving fraud victims, fintech providers and payment institutions. 

Perhaps most significantly, the case highlights a potential route by which APP fraud victims may seek to overcome the limitations imposed on claims by the Supreme Court in Philipp v Barclays Bank UK plc [2023] UKSC 25. At the same time, it leaves unresolved some fundamental issues concerning the application of Quincecare principles to modern payment systems and electronic money institutions.

The Quincecare Duty After Philipp

The Quincecare duty derives from the principle that a financial institution must refrain from executing payment instructions where it has reasonable grounds to suspect that an agent of its customer is attempting to misappropriate the customer's funds. 

Traditionally, the duty has operated as an aspect of a bank's broader duty to exercise reasonable skill and care in carrying out payment instructions. 

The scope of the duty was significantly narrowed by the Supreme Court in Philipp. The Court confirmed that where a customer personally authorises a payment, the bank's primary obligation is to execute that instruction. The duty does not require banks to protect customers from the consequences of their own decisions, even where those decisions have been induced by fraud. 

That ruling appeared to close the door on many APP fraud claims against sending banks. Since APP fraud involves victims voluntarily instructing payments to fraudsters, albeit under false pretences, the victim's bank will generally not owe a Quincecare duty in relation to those transactions.

The Facts Behind Moorwand

The claim arose from a sophisticated investment fraud. 

The claimants were persuaded to transfer £160,000 to an account operated by a company that had been incorporated using a stolen identity. The account was provided by Moorwand, an FCA-regulated Electronic Money Institution (“EMI”) offering payment and crypto-wallet services. The funds were subsequently dissipated through bitcoin purchases and other transfers. 

As the claimants were not customers of Moorwand, they could not pursue a direct claim against the institution. Instead, they sought to bring a derivative claim through the corporate vehicle used by the fraudsters, arguing that the company itself had a claim against Moorwand for breach of its Quincecare obligations. 

Although the Court of Appeal ultimately restored the trial judge's finding that Moorwand had not been put on inquiry and therefore had not breached any duty, the broader significance of the case lies elsewhere. 

A Potential New Route for APP Fraud Victims?

The most noteworthy aspect of the decision is the Court's willingness to leave intact the possibility of a derivative claim being pursued in these circumstances.

Following Philipp, a victim who authorises a payment typically cannot sue their own bank under Quincecare principles. However, Moorwand suggests that where the proceeds of fraud pass through a corporate vehicle, claimants may seek to stand in the shoes of that company and rely on its rights against the receiving institution. 

If that approach survives scrutiny in future cases, it could create a significant distinction between different types of APP fraud. The availability of a remedy may depend less on the nature of the fraud itself and more on the structure chosen by the fraudster to receive the funds.

Such an outcome could have important consequences for banks, payment service providers and fintech businesses. It may also encourage further attempts to develop proprietary and derivative claims as an alternative means of obtaining recovery following APP fraud.

What Does the Judgment Mean for EMIs and Fintech Firms?

Another noteworthy feature of the case is that it proceeded on the basis that Quincecare principles could apply to an EMI in much the same way as they apply to a traditional bank. The point was not directly challenged and therefore was not determined by the Court of Appeal. Nevertheless, the case demonstrates that EMIs cannot assume they sit entirely outside the Quincecare framework.  

The judgment also confirms that deficiencies in customer onboarding and anti-money laundering processes may be relevant to the overall assessment of whether a firm was put on inquiry. However, such failings will not automatically establish a breach. The question remains intensely fact-sensitive and will depend on whether the institution had reasonable grounds to suspect misappropriation of funds at the point the payment instructions were executed. 

Importantly, the Court left unanswered how Quincecare obligations should operate in an age of automated payments, algorithmic decision-making and digital financial services. As payment processing increasingly occurs without direct human involvement, future courts will inevitably be required to consider what systems and controls are sufficient to discharge any duty of inquiry.

Why This Matters

APP fraud remains one of the most significant fraud risks facing consumers and businesses. While regulatory reimbursement schemes continue to evolve, claimants and their advisers remain keen to identify viable civil remedies.

Moorwand is significant because it demonstrates that the boundaries of Quincecare liability are still being tested despite the Supreme Court's decision in Philipp. The judgment suggests that creative causes of action, including derivative and proprietary claims, may provide alternative avenues for recovery in certain circumstances.

For financial institutions, fintech providers and EMIs, the case is a reminder that robust onboarding procedures, transaction monitoring and fraud controls remain critical. It also signals that the courts are continuing to grapple with how traditional legal principles should apply to modern payment ecosystems.

Key Takeaways

  • The Court of Appeal found that Moorwand was not "put on inquiry" and therefore had not breached any Quincecare duty.
  • The decision leaves open the possibility that APP fraud victims may pursue derivative claims through corporate entities used by fraudsters.
  • The judgment highlights a potential route around some of the limitations imposed by Philipp.
  • Quincecare principles may extend beyond traditional banks and have relevance for EMIs and other fintech businesses.
  • AML and onboarding failures may form part of the factual context when assessing whether a firm was put on inquiry, although they are not determinative.
  • Significant questions remain unanswered, particularly regarding automated payment processing, digital financial services and the future scope of Quincecare  obligations. 

As APP fraud litigation continues to develop, Moorwand may prove less important for what it decided than for the avenues it left open. The courts have not yet had the final word on the relationship between Quincecare, fintech innovation and fraud recovery.

Key Contacts

Related Articles

  • FOS Redress Reforms: What the Expanded Powers to Dismiss Complaints Mean for Firms and Consumers
    Expert Comment
    FOS Redress Reforms: What the Expanded Powers to Dismiss Complaints Mean for Firms and Consumers
    The Financial Ombudsman Service (“FOS”) has just announced a package of reforms aimed at modernising its role as a dispute resolution service for complaints about financial services’ businesses in the UK. They include new powers to dismiss complaints that are considered unsuitable for determination by the Ombudsman.
  • FCA review highlights gaps in financial crime controls
    Expert Comment
    FCA review highlights gaps in financial crime controls
    The Financial Conduct Authority (“FCA”) has published the findings of its review into financial crime controls across the asset management and alternatives sector, drawing on engagement with 242 firms during 2025/26.
  • Fraud in the Digital Age: what the independent review means for victims of fraud
    Expert Comment
    Fraud in the Digital Age: what the independent review means for victims of fraud
    Fraud continues to evolve at a remarkable pace. As technology becomes increasingly embedded in everyday life, fraudsters are finding new ways to exploit businesses and individuals through online scams, cyber-enabled deception, investment fraud and sophisticated impersonation techniques.

Recognised for excellence. Chosen for care.

  • Legal 500 Top Tier Firm UK 202
  • alt tzt
  • Sunday Times Best Places to Work 2025
  • Kings Award Logo
  • ePrivateClient Top Law Firms 2025