Modulr Finance Ranked Second-Worst in Britain for Receiving Scam Money, Regulator Data Shows
The scam-money league table: how Britain’s invisible payments giant — the firm behind HyperJar, Pockit and payroll apps — became one of the top receivers of fraud funds. A regulator’s own data, a dozen Ombudsman rulings, company filings and the published statements of Modulr’s own partners show how the “delegated infrastructure” model leaves ordinary people locked out, unpaid and unprotected — even as the company’s public rating says “Excellent.”
Behind HyperJar, Pockit, Plutus and the payroll runs of thousands of UK businesses sits a company most of its users have never heard of: Modulr. In its data for 2023, Britain’s payments regulator ranked it second-worst in the country for receiving scam money, and named the likely cause in its own words: “fewer onboarding checks… or weaknesses in inbound transaction monitoring.”
The story in brief
The public record shows what that looks like in practice. An account opened before its security checks were run. A scam victim blamed for her own £8,000 loss until the Ombudsman ordered Modulr to repay every penny. And in a European court case, the firm’s own exhibit: an applicant who scored 3 out of 100 on Modulr’s automated compliance system, was onboarded anyway after a manual downgrade of the risk rating — and went on to receive a charity’s stolen funds. Modulr filed no police report, and for months told the victim it could not share information about the account because of customer confidentiality — a confidentiality it then discarded itself, placing the same customer’s file into a public court record the moment it sued the victim.
For the people whose wages, deposits and benefits travel these rails, the terms are stark: no FSCS protection, no explanation owed when funds are frozen — and a public “Excellent” rating built from business clients, while every negative review Modulr flagged was removed, none because it was untrue. The FCA restricted Modulr’s growth for nine months. Modulr’s filed accounts never mention it.
Scam proceeds that vanish into an account bearing Modulr’s sort code.
When victims of online scams trace where their money went, they rarely expect the trail to end at a financial institution they have never heard of. Increasingly, in the UK and Europe, it does.
Modulr Finance — operating as Modulr FS Limited in the UK, regulated by the Financial Conduct Authority, and Modulr Finance B.V. in the Netherlands, regulated by De Nederlandsche Bank — is an Electronic Money Institution that provides the payment rails, account numbers and sort codes behind dozens of consumer apps, payroll tools and fintech platforms. By its own description it processes over £100 billion in payments a year. Its latest UK accounts show it safeguarding £745 million of customer money.
Most of the people whose money moves across those rails have never signed a contract with Modulr, and many discover its existence only when something goes wrong: an account frozen without explanation, a salary run that doesn’t arrive, or scam proceeds that vanish into an account bearing Modulr’s sort code.
This article sets out what the public record — regulator data, Financial Ombudsman decisions, Companies House filings, and the published statements of Modulr’s own partners — actually shows.
The regulator’s own league table
The most striking evidence comes not from victims but from the Payment Systems Regulator.
Each year the PSR publishes firm-level data on Authorised Push Payment (APP) fraud — scams in which victims are deceived into sending money — including a ranking of the firms whose accounts receive the most scam money relative to their size. The PSR’s charts carry the label “Higher figure is worse.”
In the report covering 2023 (PSR APP scams performance report, July 2024), Modulr Finance Ltd appears among the twenty smaller firms receiving the highest rates of scam money in the United Kingdom:
- £1,210 of APP scam money received per £1 million of transactions — the 5th highest rate of the twenty firms measured.
- 2,571 APP scam payments received per million transactions — the 2nd highest of the twenty. Only PayrNet ranked worse.
- Modulr had not appeared in the top twenty at all in the 2022 data.
The regulator’s report states: “The four firms with the highest volumes (PayrNet, Modulr, Zempler Bank and Kroo Bank) all have similar scam rates of between 2,000 and 3,000 APP scams payments per million transactions.”
On why some firms receive so much fraud, the PSR offers its own explanation: “The reasons for some firms having higher rates of receiving scams could include fewer onboarding checks… or weaknesses in inbound transaction monitoring.”
The consequences for others in that cohort have been severe. The same report records that after the PSR’s first publication, “the Financial Conduct Authority (FCA) imposed restrictions on Dzing Finance to stop payments activity”; the FCA later restricted Guavapay’s onboarding.
Fairness requires the sequel: in the PSR’s report covering 2024 (published February 2026), Modulr’s rates fell sharply — it ranked 9th by value and 6th by volume. That is a genuine improvement. It also means that for two consecutive reporting years, a regulator has named Modulr among the twenty firms in Britain whose accounts disproportionately receive the proceeds of fraud.
Who is fronting the rails
Consumers almost never open an account with Modulr directly. They meet it through front-facing brands that plug into Modulr’s API:
- Accounting and payroll: Sage (Salary and Supplier Payments), Xero, BrightPay and IRIS route employer payment runs across Modulr rails; Wagestream’s earned-wage product uses Modulr as one of its two e-money providers.
- Consumer money apps: HyperJar, the budgeting app, states in its own terms that “HyperJar Limited… is a registered EMD agent of Modulr FS Limited” and that “Your account and related payment services are provided by Modulr FS Limited.” Pockit’s accounts run on Modulr today (a January 2026 Ombudsman decision names “Modulr FS Limited trading as Pockit Limited”). The rewards-card platform Plutus ran on Modulr until the relationship collapsed — of which more below.
- Marketplaces and B2B platforms: Motorway’s instant-payment product and business platforms such as wamo sit on Modulr accounts under three-party agreements.
The legal architecture matters. The brand owns the customer relationship; Modulr holds the money. When something goes wrong, each can point at the other — and in the documented cases below, each does.
An FCA Freedom of Information response (FOI2025_00746, data as at 9 September 2025) records Modulr FS Limited with 24 authorised agents.
What the Ombudsman record actually shows
The Financial Ombudsman Service has published at least a dozen final decisions naming Modulr FS Limited as respondent, across the HyperJar, Pockit and Plutus brands. Most went Modulr’s way — that should be said plainly. But the cases Modulr lost, and the language of some it won, document specific and serious failings.
The £8,000 Apple Pay case
In DRN-5940246 (February 2026), a scammer impersonating Mrs M’s bank talked her into moving money into her HyperJar account “to keep it safe,” then set up a new Apple Pay token and drained over £8,000. Modulr refused to reimburse her, arguing she had been “grossly negligent” in sharing one-time passcodes. The FOS investigator disagreed; Modulr rejected that finding and forced the case to a full ombudsman decision — and lost. Ombudsman Stephanie Mitchell found that while Mrs M “may have been careless,” her actions did not amount to gross negligence, and ordered Modulr to reimburse the payments in full with 8% interest. (Modulr had earlier paid £100 for its initial handling of the claim.)
Checks after the account was already open
In DRN-5469727 (October 2025), Mr B opened a HyperJar account so his daughter, who has health issues, could pay her care-home expenses. The decision records as fact: “As part of its account opening process, HyperJar completed security and credit reference checks. These checks were completed after Mr B’s account had been opened.” HyperJar’s explanation, recorded by the ombudsman, was that it “wasn’t able to complete all its security checks prior to Mr B opening his account, due to it not being a member of the relevant organisation at the time.” The account was then closed without notice. The ombudsman upheld the complaint. In plain terms: the account went live first, and the checks came afterwards — the precise sequencing the PSR identifies as a cause of high fraud receipt.
A fraud marker over £195
In DRN-4420910, Modulr closed Mr W’s account over a disputed £195 payment and registered a CIFAS fraud marker against his name — a flag that follows a person for six years. He discovered it only when his employer questioned him after a screening check, and told the FOS it had forced him onto a more expensive mortgage. The decision records that Modulr “suggested Mr W should contact the buyer to get the fraud claim withdrawn” — that is, told the accused to negotiate with his accuser. The FOS investigator found the marker should be removed; Modulr refused the finding and escalated. On this occasion the ombudsman ultimately sided with Modulr and the marker stayed. The point is not the outcome but the pattern: twice in these decisions, Modulr’s response to an adverse investigator finding was to fight rather than put things right — and in the £8,000 case, fighting lost.
“No direct relationship with its customers”
In DRN-3866497 (2023), a man who lost around £29,000 to a cryptocurrency scam found himself in the gap the delegated model creates. The ombudsman recorded: “Modulr said that Mr M should direct his complaint to B. It said it provided B with its payment infrastructure, but that it has no direct relationship with its customers. B itself said it fell outside of this service’s jurisdiction because it’s not regulated by the Financial Conduct Authority.” The complaint was not upheld — but the recorded defence is the delegated-infrastructure model in a single sentence: the regulated firm says talk to the brand; the brand says it is not regulated.
“Under no obligation to explain”
In DRN-5031487, a HyperJar customer’s £520 was returned to source and his account closed when he could not produce a bank statement belonging to someone else — the friend who had sent him money. The ombudsman sided with the firm, noting: “HyperJar is also under no obligation to explain why it conducted a review.” That is an accurate statement of the law, and it is exactly why customers describe these episodes as a wall of silence.
“Modulr should have intervened”
Even in a case Modulr won — DRN-5539450 (October 2025) — the ombudsman made an express finding about its monitoring: “I think that two large payments made to a new payee in quick succession was unusual for Mrs B’s account. So I think that Modulr should have intervened and asked questions about the payments that were being made.” The complaint failed only because the ombudsman concluded the scam company looked so legitimate that questions would not have prevented the loss.
The money that disappears into the rails
Because Modulr’s sort codes sit beneath consumer brands, people who are scammed often discover the name “Modulr” only on their bank statement, after the money is gone. They are not Modulr customers, and so — as the £29,000 decision above records — the firm says it cannot deal with them.
The senders: scam victims who were never customers
Public reviews on Modulr’s own Trustpilot page, all labelled by Trustpilot as unprompted, document the experience from the sending side. In August 2023, a reviewer identified as Mr Walsh wrote: “Modulr was inadvertently paid a deposit by me twice – £1827 x 2. A recall was asked for by Barclays but the request has been totally ignored. So where has the money gone?” In June 2023, Laura Evans: “I’ve paid money into an account used by this company, its left my account but the person has not received it on their end.” In April 2023, Brendan Ross: “Scammed for a deposit on a puppy the guy used this bank..” In October 2022, Debi Davey called Modulr “a institution that lets scammers deposit people’s hard earned money into.”
Three of those four reviewers call Modulr “this bank.” It is not a bank — a distinction with sharp consequences, explained below.
The account holders: frozen funds
On the account-holder side, the pattern is frozen funds. A HyperJar customer wrote on the consumer-complaints site PissedConsumer in November 2025 that the insurance payout for his stolen car had been frozen twice despite his supplying every document requested: “This has caused me serious stress and anxiety, as I look after my sick mum and need to buy the car to take her to her appointments.” An Apple App Store reviewer wrote in June 2023, under the headline “Stay Clear – Will Steal Your Money,” that house-deposit money sent by a friend was detained pending proof of source: “if you’re going to suspend someone’s account without warning and take their money, this is something that they should prioritise and deal with within 24 hours maximum.” That reviewer’s experience — third-party transfer in, funds detained, prove-the-source demand, account closed — matches the fact pattern of Ombudsman decision DRN-5031487 in every particular.
The payroll: 47 families
And on the payroll side, where Modulr’s rails carry wages: in May 2024, Marie Morrell wrote on Trustpilot: “I transferred the money for our payroll, and I have 47 team members that I can’t pay. I’ve emailed and left 4 messages and had no response. They seem not to care that I have 47 families that are impacted by not receiving their monthly wage.” Modulr’s public reply confirmed that support was closed for the weekend.
For balance: HyperJar’s app holds a 4.8/5 rating from some 30,000 App Store reviews, and Pockit 4.2/5 from 17,000. The experiences above are a minority. But they are the minority the delegated model is worst at helping — and, as the next section shows, when the money is big enough, it is not only consumers who say so.
The partner that walked: Plutus
In February 2026, the rewards-card platform Plutus published a migration FAQ explaining to its own customers why it had left Modulr. In Plutus’s words:
“We terminated our contract with Modulr in October. This was due to services not being delivered as promised in the contract… After this, we faced unilateral restrictions, including restrictions on customer funds. We worked with our legal team to ensure all customer funds were returned.”
“All pending gift card purchases stuck since November 2025 have now been settled. Our team worked hard to recover these funds from Modulr… If you still have funds stuck at Modulr, please check your email and follow the steps to submit a claim.”
Modulr’s own website corroborates that retail money was caught in the middle: it hosts a page titled “Plutus Customer Support” telling Plutus’s customers, “You will be able to retrieve any remaining funds held in your account by submitting a request to the Modulr Customer Support Team.”
Plutus is an interested party in a commercial dispute, and its account is one side of the story; Modulr has published no response. But the core fact is established by both companies’ own websites: ordinary customers’ balances and purchases were stuck between a consumer brand and its e-money issuer for months, and a claims process for “remaining funds” exists to this day.
An Ombudsman decision from the same relationship, DRN-5450737, records a Plutus customer locked out of his account in “sleep mode,” unable to reach his £20 balance and roughly £24 in rewards without paying a £6.99 monthly subscription. The complaint was not upheld; the terms permitted it. That is rather the point.
The court records
In ongoing European court proceedings between Modulr and a non-profit organisation, court filings reviewed for this article show a pattern that will be familiar from the cases above — confidentiality invoked against the victim, then set aside when it suited the firm.
When the non-profit traced substantial fraudulently diverted funds to an account on Modulr’s infrastructure and asked for cooperation in freezing and recovering them, Modulr declined, citing financial-privacy law and client confidentiality. When Modulr later initiated proceedings seeking to restrain the charity’s public statements, its own filings placed material from the customer file into the court record. To date, no court has granted any restraint on the charity’s publication: the initial injunction application was refused, and the subsequent claim was dismissed by the district court.
What the firm’s own exhibit showed
The onboarding documentation submitted in those proceedings — filed by Modulr’s side to demonstrate the adequacy of its checks — showed beneficial-ownership, identity-verification and risk-assessment fields left blank or recorded as “N/A” at the time high-value transactions were processed; showed that the platform’s own automated compliance score for the account holder was manually overridden; and showed that onboarding had been delegated to a third-party agent, with due diligence recorded as completed weeks after the account was already open. Readers will recognise the shape: it is the same sequencing the Financial Ombudsman recorded in DRN-5469727, and the same weakness — “fewer onboarding checks” — that the PSR names as a cause of high scam receipt.
Who told the authorities
Then there is the question of who told the authorities. Every criminal report on the record in this case — to the police, to Action Fraud — was filed by the victim. In its own written answers, the institution identified no report by it to the police at any time. The only filing it identified on its side was a confidential compliance filing — made weeks after the victim’s notification, and months after the account had been emptied and closed; a filing of that kind is not a crime report and triggers no contact with any victim. Asked directly in correspondence whether it had notified its regulator of the matter, the institution answered: “No.” Asked where the money disbursed from the account had gone, it did not answer at all.
Not a bank: what “Excellent” doesn’t tell you
Modulr’s Trustpilot profile shows a TrustScore of 4.5 — “Excellent” — from 156 reviews. Trustpilot’s own transparency page for the company shows how that number is built. All figures below are Trustpilot’s own, as displayed on 30 July 2026.
Over the past twelve months, Modulr received 45 reviews: 9 organic and 36 carrying Trustpilot’s “Verified” badge, meaning the reviewer supplied proof of a genuine commercial relationship — in Modulr’s case, overwhelmingly business clients and integration partners. Modulr’s profile is a claimed, paid subscription, held since August 2023; Trustpilot notes the company “may use AI-assist with replies.”
The flagging record
Then there is the flagging record. In the same twelve months, Trustpilot’s data shows:
- Modulr flagged 6 of its reviews, a total of 7 times.
- All six flagged reviews were 1-star. No 5-, 4-, 3- or 2-star review was flagged.
- All six were removed. None remains online.
- The number removed because Trustpilot found the review actually breached its guidelines as flagged: zero. Five came down because the reviewer did not respond to Trustpilot’s resolution process; one because the reviewer did not resolve the issue.
In other words: every negative review the company flagged was removed, and not one removal followed a finding that the criticism was untrue. The reviews disappeared by attrition — unpaid individuals dropping out of a process initiated by a paying subscriber. Meanwhile the negative reviews from 2022 and 2023 quoted above, predating the flagging window, remain online, as does the most recent one-star review, posted in July 2026: “My funds are blocked for absolutely no reason… Modulr is the worst system for a trustee partner.”
The rating is real. What it measures is the satisfaction of the businesses Modulr invoices — not the experience of the people whose wages, deposits and benefits travel its rails.
Not a bank: the protection gap
The distinction those reviewers miss — “this bank” — is the one that matters most if anything ever goes seriously wrong.
- No FSCS protection. Money in Modulr-issued accounts is electronic money, not a bank deposit. The FCA’s own register entry for the firm carries the warning: “If this firm goes out of business owing you money you will not be able to claim compensation from the FSCS.” HyperJar’s terms say the same: e-money products “are not covered by the Financial Services Compensation Scheme (FSCS).” Bank deposits are protected up to £85,000; these balances are not.
- Safeguarding instead. Customer funds are held in segregated accounts at commercial banks — £745 million of them, per Modulr’s latest accounts. Safeguarding is real protection, but it is not insurance.
- Insolvency costs come off the top. If an e-money institution fails, the costs of the insolvency practitioner distributing the safeguarded pool are deducted from that pool before customers are repaid — meaning delay, and potentially a shortfall, in a way FSCS claims do not involve.
New FCA rules — Policy Statement PS25/12, published August 2025, with a supplementary safeguarding regime in force from 7 May 2026 — tighten reconciliation, audit and record-keeping duties across the sector, a signal that the regulator shares the concern.
The regulator and the silence in the accounts
On 4 October 2023, the FCA imposed a requirement on Modulr FS Limited halting the onboarding of new agents and distributors — the very layer of the business (HyperJar, Pockit, Plutus) that produced the cases in this article. Modulr framed it as voluntary: “we have agreed to temporarily pause onboarding certain new customer segments in the UK,” it said at the time. The restriction was lifted in July 2024 on terms that remain instructive; in the wording reported identically across the trade press: “The firm has agreed with the Authority that it will not without providing prior written notification to the Authority of at least 10 business days, on-board any new agent and/or distributor.”
For the record, as at the date of publication: no fine or censure of Modulr by the FCA or DNB appears on the public record, and no restriction currently shows on either register entry. Whether either regulator is examining the firm is not something the public is permitted to know — the FCA does not disclose whether it is investigating any firm, citing section 348 of the Financial Services and Markets Act.
What the filed accounts don’t say
What is harder to explain is the company’s own disclosure. Modulr’s FY2023 strategic report — signed on 30 June 2024, while the FCA requirement was still in force — does not mention the requirement. It states instead: “We engage in open and transparent dialogue with regulators to ensure compliance with all applicable laws, regulations, and licensing requirements.” The FY2024 report likewise contains no reference to the requirement, although it does record consequences: “The implementation of these requirements resulted in some Partners being offboarded as they were unable to meet these new requirements.”
The direction of travel is visible elsewhere in the filings. Modulr posted a £10.5 million pre-tax loss for 2024 on £52.8 million of revenue, against an accumulated deficit of £100.4 million (its auditor’s opinion is clean, with no going-concern qualification). Its audit and risk committees moved from quarterly to bimonthly meetings. A new principal risk appeared in the FY2024 accounts: “Financial Crime.” And in September 2025, Tech.eu reported that Modulr had “ceased active marketing” into “crypto, remittance, and consumer banking,” citing “increasing complexities, risks and costs” — a quiet retreat from precisely the consumer-facing business that generated the harm documented here.
The reimbursement fine print
Since October 2024, the PSR’s mandatory reimbursement rules give APP scam victims a right to be repaid, ordinarily within five business days. But the fine print matters at Modulr:
- The £100 excess. The rules permit firms to deduct up to £100 per claim (waived for vulnerable customers). Modulr’s published policy applies it.
- The “on-us” exclusion. Modulr’s policy excludes payments between two Modulr accounts from the statutory right — significant for a firm whose rails host both consumer brands and, as the PSR’s data shows, a disproportionate share of fraud-receiving accounts. When victim and fraudster are both on Modulr rails, the mandatory scheme’s mechanics do not straightforwardly apply.
If your money is stuck
- Complain in writing to the brand and to Modulr (support@modulrfinance.com), stating that you require a final response. For payment-services complaints, firms must normally respond within 15 business days (35 in exceptional circumstances).
- If it is fraud, act immediately: call 159 (the anti-scam hotline that connects you to your own bank), and report to Action Fraud.
- Escalate. UK customers can take a final response — or silence after the deadline — to the Financial Ombudsman Service, free of charge. Customers of Modulr Finance B.V. in the EEA can escalate to KIFID in the Netherlands.
- If you are not a Modulr customer but sent money to a Modulr-hosted account, your claim runs through your own bank (ask for the APP reimbursement scheme) — as the cases above show, Modulr will tell non-customers it cannot deal with them.
Under the publisher’s right-of-reply policy, any person or company named in this article — including Modulr Finance — may respond; substantive responses will be published alongside this article. Contact: fraudactiongroup at gmail.com.
All sources were accessed and verified on 30 July 2026. Financial Ombudsman decisions are quoted from the published PDFs; PSR figures from the regulator’s published reports; Companies House figures from Modulr’s filed accounts; Trustpilot figures from the company’s public profile and transparency pages on the date shown.Write Here...
Share your experience
Asociacion de Defensa contra el Fraude - Fraud Defence Association. Contact: www.fraudsters.eu. Public Interest Disclosure Notice: This website is a non-commercial, public interest investigation into systemic failures in the UK fintech sector, specifically regarding merchant identity theft and Anti-Money Laundering (AML) oversight. All documents published herein are for the purpose of transparency and consumer protection. We are not affiliated with Modulr Finance, WAMO or Stripe Payments UK.