Who Will Repay Me?
A brief look into the European practice of reimbursing fraud victims
Most of our shopping nowadays is online. Packages come in, returns go out. So it would not be out of the ordinary to receive a text message with parcel locker’s PIN or an occasional call from a courier to confirm a delivery or even a call to clarify an address for an online marketplace bought book, where the sender missed some digits writing down your address. It happens.
Recently a friend of mine recounted how her bakery's business account was drained of 15 thousand euros through her business partner who thought she was confirming her parcel delivery. As usual, there was a call from a 'courier', authorisation codes sent to her ID app, payments confirmed and money in a few payments gone to Italy as 'consulting fees'.
The payment for her small bakery business was unusual - they typically only had small domestic payments, with regular partners and without any prior history of international payments. She approached her bank but the bank was non-responsive: authorisation had happened with the ID app’s PIN2 (highest authorisation level - comparable to qualified e-signature) and there was nothing that could be done. But is there?
When I heard the story, my first impression was: “Yep, high level authorisation has happened and it will be hard to litigate such a case”. She was adamant that the bank was bound by a 'duty of care' and the bank should have understood that payments were not within reasonably expected company payment behaviour.
It has been a while since I worked with fraud cases professionally but I remember from my time in UK FinTech that the UK had built a framework for shifting fraud liability from the victims onto the institutions themselves. Meaning, in practice, institutions had an obligation to reimburse fraud victims within 5 business days unless the institution could prove that it was a 1st-party fraud (victim is part of the fraud committed) or prove gross negligence. Apparently, there have been a few cases in Europe in the last two years where the bank’s duty of care, reimbursement and customer negligence question has been raised. Primed by my friend’s case I took a brief look at those cases.
National courts
When you start to do research on this topic, the first case that immediately pops up is Spanish Supreme Court Judgment No. 571/2025. Short breakdown of the case and ruling:
The bank used two-factor verification: 1) the customer had to enter his password, and 2) an SMS message with a security code would be sent to the customer as a second factor.
During a phishing attack criminals obtained the customer’s password. To bypass the SMS security code criminals performed SIM swapping (duplication of the victim’s mobile SIM card). As a result, criminals gained access to the account and transferred 83 thousand euros out of the victim’s account.
The bank refused to reimburse the victim claiming that the account was accessed and payments were validated using two-factor verification and that the customer himself failed to reasonably protect his credentials.
The Supreme Court ruled in the customer’s favour with logic:
If a customer is a victim to deception, it cannot be counted as gross negligence.
Correct credentials alone cannot be automatic proof that the account holder authorised the transfer and if the customer denies the transfer, the burden of proof to prove the transfer was legitimate lies with the bank.
The risk of phishing fraud forms part of the professional risk borne by the bank and cannot be automatically shifted to the customer. The bank has to exercise professional diligence.
When I read the case, SMS verification immediately stood out to me. Its weaknesses as a two-factor identification method are numerous and my subconscious mind nagged me that the bank would have a stronger position in court if stronger second-factor verification method had been used.
So, I went looking for a case where strong customer authentication had happened. My search led me to Belgian case No. C.25.0390.N and as my intuition foretold me, the case becomes much harder when strong authentication has been performed. It is a little bit longer, as it involves two rulings but it is worth a read:
In January 2020 bank’s customer received a text message that he had a small tax debt that he needed to pay. The message included a hyperlink to a fake page, where the customer entered his credentials. Unbeknownst to the customer, he gave away his credentials and consented to the installation and activation of the bank’s authorisation app on a new device which belonged to the criminal. Using the new device, the customer was defrauded of 24 thousand euros.
In 2025 Brussels court ruled that the bank was not liable to reimburse the customer due to the customer being grossly negligent, based on findings that the customer had to understand that he did not use official identification verification methods for government services (like e-ID or the app 'Itsme') and ignored warning messages about a new device being connected.
The customer filed a petition to a higher court against the ruling.
In June 2026 Belgium’s highest court overturned the previous judgement based on the interpretation of ‘gross negligence’. What stands out - we get the same thing as in Spain - the bank bears the burden of proof to establish gross negligence. And further, the Court separated negligence from gross negligence with a definition that for gross negligence there needs to be a conduct involving a significant degree of carelessness that a reasonable, normally careful person would never engage in. Whereas falling for a convincing psychological trap or making an error in judgement under deception constitutes ordinary carelessness.
For a layman like me, the reasoning behind the ruling was becoming too vague. After all - the customer did ignore warnings about a new device and entered credentials into a fake website. Luckily court addressed this issue as well. The logic behind the initial gross negligence claim from the bank’s side was based on the interpretation that the customer 'could see the warning' but no evidence was presented as to what was actually shown on the customer’s screen when he entered his credentials and accepted the new device. In other words, if the bank wanted to build a defence based on customer being grossly negligent, they should have provided exactly what he saw on his screen not an assumption of what he could or was supposed to see.
There again I was a little puzzled - how can one then prove that his customer was grossly negligent in a similar case. Here, the gap is probably filled by Spain’s ruling noting that the risk of phishing fraud forms part of the professional risk borne by the bank and the bank has to exercise professional diligence: if a bank’s monitoring system flagged payments/suspicious new device activity and an employee called the customer to warn them about it and the customer ignored the risk and proceeded with the verbally warned activities, then it would constitute gross negligence. At least that is how this layman has understood this.
Court of Justice of the European Union
In the opening paragraphs I mentioned the UK’s framework for reimbursing victims of fraud. Make no mistake, Europe has its own framework under the Second Payment Services Directive (PSD2). Its Article 73 states:
Member States shall ensure that [...] in the case of an unauthorised payment transaction, the payer’s payment service provider refunds the payer the amount of the unauthorised payment transaction immediately, and in any event no later than by the end of the following business day, after noting or being notified of the transaction...
This reimbursement framework was seldom tested and a debate arises about what is meant by 'unauthorised payment' (if this question had been resolved upon the adoption of PSD2 this blog post wouldn’t exist).
However, in March 2026 the Court of Justice of the European Union published the opinion of Advocate General Athanasios Rantos in preliminary ruling case C-70/25 ending the debate. So, what was the case and its ruling?
A polish bank’s customer posted a listing on an online marketplace. A potential buyer contacted her and provided an hyperlink to a webpage which imitated her bank’s webpage. On this fake page customer entered her credentials which the criminal used to access her real bank account and drain it.
The customer very soon understood that she had been defrauded and promptly informed the bank about the fact. The bank refused to reimburse her loss stating that as she herself provided credentials to the criminals, it constituted gross negligence. The customer was not o.k. with the bank’s decision and went to a Polish court.
The Polish court in turn referred the matter to the the Court of Justice of the European Union. The Advocate General ruled that a refund can be withheld only if the bank has a reasonable grounds to suspect fraud by the customer herself (and has notified the police about it). Furthermore, PSD2 leaves no discretion to introduce additional stipulations to the immediate refund obligation.
All is well in Europe
Court judgements are clear and with the latest Advocate General’s ruling there is little room for interpretation of the PSD2 - victims must be reimbursed. Currently we are transitioning from the Payment Services Directive to the Payment Service Regulation (many have probably noticed payee verification upon making transfers - a part of the new PSR) which sets out clear rules for refunds coupled with the requirement of real-time monitoring leaving no room for interpretation between member states with full application in late 2027.
This brief overview of reimbursement cases cannot do justice to the complexity of the topic. On the surface, it seems straightforward enough. Rulings on these cases are very recent. With the PSR coming into effect shortly, one can look forward hopefully that a robust helpline for fraud victims is being built.
The Financial Crime Intelligence Lab is a true passion project, put together in our spare time - usually early in the morning, late at night, or over weekends when we really should be doing something else. We built this space to provide deep, rigorous analysis, mostly because we noticed much of the industry coverage rarely scratches the surface, and frankly, to satisfy our own curiosity.
We hope you found this breakdown engaging. If you have any thoughts, differing perspectives, or just want to point out exactly where we went wrong, please leave a comment below.
If you appreciate the effort that goes into this, do consider subscribing. Your support helps us reach more compliance pros, legal experts, and investigators - allowing us to grow the platform, refine our own understanding, and continue documenting the endless uphill battle of trying to make sense of the fight against financial crime.
Thank you for reading.


