The European Court of Justice’s Advocate General Athanasios Randos has issued an opinion requiring banks to promptly refund money to victims of phishing scams , even when there is negligence on the part of the customer. The ruling is expected to fundamentally change the way banks deal with cyberfraud cases in the European Union .

The opinion was issued in response to a request for a preliminary ruling from the Koszalin Regional Court in Poland, in a dispute between the bank PKO BP SA and one of its customers. The case concerned a phishing scam, where the customer advertised a product for sale on an auction platform and was approached by a fraudster who sent him a malicious link to a page resembling the bank’s login interface.
The customer entered his bank account credentials on the fake website, which the fraudster then used to make an unauthorized payment. The victim reported the transaction to both the bank and the police the next day, but the fraudsters were not identified and the bank refused to refund the lost amount. As a result, the customer sued the bank.
See also: Spiderman: New phishing kit targets European banks
European Court of Justice: Immediate refund
Randos states that under the EU Payment Services Directive (PSD2), a bank cannot refuse to issue an immediate refund to victims unless it has reasonable grounds to suspect fraud by the customer. The European Court of Justice states that “EU law requires the bank, as a first step, to immediately refund the amount of the unauthorised transaction, unless it has good reason to suspect fraud.”

However, it is clarified that the process does not end there, as banks still have the right to seek recovery of losses from the customer if they can prove gross negligence or intent that led to the security breach. According to the opinion, “if the bank proves that the customer failed, intentionally or through gross negligence, to fulfill one of the obligations relating in particular to personal data security, it may require the customer to bear the corresponding losses.”
Statistics show that payment fraud across the EEA amounted to €3.4 billion in 2022 and €3.5 billion in the following years. Strong Customer Authentication (SCA) implemented since 2020 has reduced fraud rates for authenticated transactions, but manipulated payments, such as phishing, continue to increase.
See also: Authorities dismantled the infrastructure of the phishing service Tycoon2FA
Practical implications for banks and consumers
The European Court of Justice has important practical implications. Banks will have to strengthen fraud monitoring and implement mandatory recipient checks, such as the Confirmation of Payee (CoP) provided for by PSD3. They will also have to promptly refund money for unauthorized or manipulated transactions, unless they can prove excessive negligence on the part of the customer.

Similar cases have arisen in other European countries. In Spain, the Supreme Court ruled in favor of a woman who was scammed through phishing and SIM swapping, with the bank Ibercaja found liable for failing to detect suspicious activity, despite the customer's direct reports.
See also: Microsoft: OAuth phishing attacks are evolving
It is important to clarify that this opinion does not constitute a decision of the European Court of Justice , but rather an indication of the direction that the court may take when the matter reaches this stage. The Advocate General's opinion is a legal recommendation to the judges of the ECJ , but the final decision of the European Court of Justice will be binding on all EU courts .
Source: www.bleepingcomputer.com
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
