· Información legal
Phishing and Bank Fraud: Who Is Liable for Your Financial Losses?
Phishing scams have become one of the leading causes of bank fraud in Spain. Emails that appear to originate from a financial institution, SMS messages reporting a supposed account freeze, telephone calls in which criminals impersonate bank employees, and fraudulent applications used to obtain online banking credentials are among the most common techniques employed to trick customers into unknowingly authorising payment transactions or disclosing their electronic banking passwords.
Until relatively recently, it was common for financial institutions to reject any claim on the grounds that the transaction had been correctly authenticated using the customer’s personal credentials. However, the regulations governing payment services and, in particular, the recent case law of the Spanish Supreme Court have substantially altered this approach.
What has changed regarding the liability of financial institutions?
Today the question is no longer simply whether the customer entered their credentials or whether the transfer was authenticated by means of a two-factor verification system. What truly matters is determining whether the financial institution complied with the duty of care imposed on it by the applicable regulations and whether it adopted the security measures necessary to prevent a clearly anomalous transaction from being executed.
Supreme Court Judgment 571/2025: the turning point
In this regard, the Judgment of the Spanish Supreme Court (First Civil Chamber) no. 571/2025, of 9 April (Appeal no. 1151/2023) represents an important turning point. The ruling recalls that, where a user denies having authorised a payment transaction or maintains that it was executed incorrectly, it falls to the payment service provider to demonstrate that the transaction was authenticated, accurately recorded and properly accounted for, but also that it «was not affected by a technical failure or other deficiency in the service, with the mere recording of the transaction being insufficient to demonstrate that it was authorised or that the user acted fraudulently or deliberately or through gross negligence breached their obligations».
The significance of this judgment lies in the fact that the Supreme Court broadens the concept of «deficiency in the service», holding that it encompasses any failure of due diligence or malpractice in the provision of payment services. Consequently, it is no longer sufficient for the bank to demonstrate that the transfer was carried out using the customer’s credentials; it must also show that its security systems functioned correctly and that it took all reasonably required measures to detect a potentially fraudulent transaction.
The good practices required by the judgment
The judgment itself identifies what those good practices are. Among them, it highlights the implementation of automated systems capable of detecting unusual transactions by reference to factors such as the repetition of transfers carried out within a short period of time, the amount of the transactions, the time at which they are executed, the identity of the recipients, or the account’s transaction history. It likewise requires that monitoring mechanisms be reinforced whenever there are alerts indicating an increased risk of phishing attacks.
Particularly noteworthy is the fact that the Supreme Court expressly rejects the notion that the mere electronic recording of the use of a payment instrument is sufficient to establish that the transaction was authorised by the customer. In the words of the judgment itself:
«The mere fact that the provider has recorded the use of the payment instrument will not, in itself, be sufficient to demonstrate that the payment transaction was authorised by the payer, nor that the payer acted fraudulently or deliberately or through gross negligence breached one or more of their obligations, with the burden of proving that the payment service user committed fraud or gross negligence resting with the provider.»
The Provincial Court of Cantabria and the burden of proof
This Supreme Court judgment does not represent an isolated criterion, but rather the culmination of a line of case law that had already been shaped by various Provincial Courts. Thus, the Judgment of the Provincial Court of Cantabria no. 679/2022, of 19 September, held that a financial institution cannot reverse the burden of proof by merely asserting that the transactions were authenticated and recorded, since it falls to the bank to establish the user’s lack of due care «without resorting to mere conjecture that has not been proven».
The Provincial Court of Salamanca and the opening of accounts using a forged identity document
Along the same lines, the Judgment of the Provincial Court of Salamanca no. 311/2024, of 10 June (Appeal no. 466/2023) attributed liability to the bank on the grounds that the fraud originated in the opening of an account using a forged identity. The Provincial Court considered that even a minimal check of the name and identity document would have detected the identity fraud, finding that the obligations of control imposed by Law 10/2010 on the prevention of money laundering and the financing of terrorism had been breached, a circumstance that proved decisive in enabling the fraud to be committed.
CEO fraud: the case before the Provincial Court of Madrid
Case law has also addressed so-called CEO fraud, a type of scam that is particularly prevalent in the business environment. The Judgment of the Provincial Court of Madrid (Section 11) no. 74/2022, of 28 February (Appeal no. 35/2021) examined a case in which an administrative employee authorised an international transfer after being deceived by an email that appeared to come from the company’s management. The Provincial Court concluded that the bank had failed to comply with the verification protocols previously agreed with the customer and had not reacted despite the presence of multiple objective indicators that the transaction was out of the ordinary, such as the amount of the transfer, its international destination, the involvement of an unauthorised person, and the failure to follow the usual authorisation procedure. In such cases, given the complexity of a claim against the bank, it is advisable to seek the assistance of a commercial lawyer who can assess the most appropriate course of action.
Other precedents on CEO fraud
This line of case law is further supported by well-established precedents, including the Judgment of the Provincial Court of Madrid (Section 14) no. 386/2017, of 21 December (Appeal no. 498/2017), the Judgment of the Provincial Court of Alicante (Section 8) no. 107/2018, of 12 March (Appeal no. 622/2017), the Judgment of the Provincial Court of Madrid (Section 9) no. 178/2015, of 4 May, and the Judgment of the Provincial Court of Zaragoza of 14 May 2013, all of which consistently affirm that the liability of payment service providers is quasi-objective in nature and that it falls to the bank to establish both the security of its systems and the existence of fraudulent conduct or gross negligence on the part of the customer.
In summary
In summary, the judicial trend is now clear. Unless the financial institution can demonstrate that the user acted fraudulently or was grossly negligent, it will be the bank that must bear the financial consequences of unauthorised payment transactions, particularly where it cannot establish that it adopted all the required security and control measures to prevent a fraud that, in many cases, could have been detected before the money left the customer’s account. If you have been a victim of this situation, seeking the assistance of a bank phishing lawyer will help you assess whether the institution truly met these obligations.