Banking · Oct 7, 2026 · 15 min read

Phishing and unauthorised payments in Spain: when the bank must give the money back

Olga Caballero & Co. Olga Caballero & Co.Law firm · Tenerife & Fuerteventura

A message arrives in the same thread as every genuine message your bank has ever sent you: an unusual charge has been detected, and you can cancel it here. The page behind the link looks like the bank's. You type your password. A quarter of an hour later payments you never made have left the account, and a week after that an email tells you that nothing will be refunded, because the operations were «correctly authorised with your personalised security credentials». That is the bank's first answer in most of these cases. It is not the law's. Spanish payment law starts from the opposite end: a payment is authorised only if you consented to it, an unauthorised payment must be refunded by the end of the next business day, and it is the bank, not the customer, that has to prove fraud or gross negligence. This note reads the rule as it stands in October 2026 — the statute, the Supreme Court's ruling of April 2025, two Canary appeal rulings and the Banco de España's own figures — and says where the protection stops. Quotations are in Spanish with the reading in English.

«Authorised» means consented, not «typed with your codes»

The rule is article 36 of Real Decreto-ley 19/2018, the payment services act: Las operaciones de pago se considerarán autorizadas cuando el ordenante haya dado el consentimiento para su ejecución — payment transactions are considered authorised when the payer has given consent to their execution — and A falta de tal consentimiento la operación de pago se considerará no autorizada — without that consent the transaction is considered unauthorised. A payment that a stranger makes with credentials he tricked out of you was made with your codes and without your consent.

The Supreme Court said so in terms in its ruling 571/2025, of 9 April 2025: «unauthorised transactions» include those started with the user's name and password and confirmed with the code the bank sent by SMS, whenever the user denies having authorised them. The contract cannot say otherwise. The regime is imposed on both parties, and a clause by which the customer accepts as his own every operation made with his keys does not displace it.

The refund: by the end of the next business day

Once the bank knows of an unauthorised payment it must return the money de inmediato y, en cualquier caso, a más tardar al final del día hábil siguiente a aquel en el que haya observado o se le haya notificado la operación — immediately and, in any event, no later than the end of the business day after it noticed the transaction or was told of it (article 45.1) — and put the account back as it would have been. There is one way out: the bank may hold the refund if it has reasonable grounds to suspect fraud on the customer's part and communicates those grounds in writing to the Banco de España. «We are investigating» is not that communication.

Your part: tell the bank at once, and never later than thirteen months

The customer has two duties (article 41): to take todas las medidas razonables a fin de proteger sus credenciales de seguridad personalizadas — all reasonable steps to protect his personalised security credentials — and to notify the bank without undue delay of the loss, theft or unauthorised use of the instrument. The right to a refund depends on the second. The bank must be told sin demora injustificada, en cuanto tenga conocimiento de cualquiera de dichas operaciones — without undue delay, as soon as he becomes aware of any such transaction — and in any case dentro de un plazo máximo de trece meses contados desde la fecha del adeudo — within a maximum of thirteen months from the date of the debit (article 43.1).

Thirteen months is the outer wall, not the date to aim for: every hour between the fraud and the call is an hour the bank will later use against you. After your notice the losses are the bank's unless you acted fraudulently (article 46.3), and the bank must keep a channel open at all times, free of charge, for that notice (article 42.1.c).

Who has to prove what

Here the statute is at its most useful. When a customer denies having authorised a payment, it is for the bank to show that the transaction was authenticated, accurately recorded and entered in the accounts, and that it was not affected by a technical breakdown or some other deficiency of its service (article 44.1). Even then, the record that the instrument was used no bastará, necesariamente, para demostrar que la operación de pago fue autorizada por el ordenante — will not necessarily be enough to prove that the transaction was authorised by the payer — nor that he acted fraudulently or with gross negligence (article 44.2). And the last word is the bank's burden too: it is for the provider probar que el usuario del servicio de pago cometió fraude o negligencia grave — to prove that the payment service user committed fraud or gross negligence (article 44.3).

The Supreme Court drew the consequences in ruling 571/2025. The bank's liability tiene carácter cuasi objetivo — is quasi-strict — in two senses: told of an unauthorised payment, it answers unless it proves fraud; and when the customer denies the payment, a log showing that the right codes were used does not release it. «Deficiency of the service», the Court added, is not only a computer failure: it covers cualquier falta de diligencia o mala praxis en la prestación del servicio — any lack of diligence or bad practice in providing the service — measured by the standard of an expert trader, not of an ordinarily careful person, and good practice includes systems that notice an abnormal pattern of payments and stop it.

The case shows what that means. In the night of 17 to 18 March 2021 fifteen transfers left an account in Zaragoza — ten through Bizum, five through online banking — €83,692.73 with the fees, confirmed with codes sent to a telephone line whose SIM card had been duplicated that afternoon in a shop in another region. The customer had been telling his branch for three weeks that he was receiving codes for transfers he had not ordered. The bank recovered €27,218.10 from the receiving banks and refused the rest; three courts in turn ordered it to pay the remaining €56,474.63. No puede considerarse como normal e irrelevante que una persona que jamás efectúa operaciones de madrugada, de repente, proceda a llevar a cabo hasta diecisiete operaciones seguidas y por un importe tan elevado — it cannot be regarded as normal and irrelevant that a person who never makes transactions in the small hours suddenly carries out as many as seventeen in a row, and for so high an amount.

What the customer can be made to bear: €50, everything, or nothing

Situation Who bears the loss (rule)
A card or device lost or stolen, used before you could report it You, up to €50; the bank, the rest (Article 46.1)
You could not have noticed the loss or theft, or it was caused by the bank's own staff or agents The bank, all of it (Article 46.1, letters a and b)
The bank did not require strong customer authentication The bank, unless you acted fraudulently (Article 46.2)
Payments made after you reported the loss or theft The bank, unless you acted fraudulently (Article 46.3)
You acted fraudulently, or breached your duties deliberately or with gross negligence You, all of it (Article 46.1)

The €50 is the customer's share when a lost or stolen instrument is used: the payer may be made to bear hasta un máximo de 50 euros — up to a maximum of 50 euros. The cap disappears, and the whole loss falls on the customer, only if he incurred it por haber actuado de manera fraudulenta o por haber incumplido, deliberadamente o por negligencia grave, una o varias de las obligaciones que establece el artículo 41 — by acting fraudulently or by failing, deliberately or with gross negligence, to fulfil one or more of the obligations laid down in article 41. And where the bank did not require strong customer authentication — two independent elements out of something you know, something you have and something you are — el ordenante solo soportará las posibles consecuencias económicas en caso de haber actuado de forma fraudulenta — the payer bears the financial consequences only if he acted fraudulently (article 46.2).

«Gross negligence»: what the courts have made of it

Everything, then, turns on two words. The European directive behind the Spanish statute gives the measure, and the Supreme Court quotes it: la negligencia grave tiene que significar algo más que la mera negligencia — gross negligence has to mean something more than mere negligence — conduct showing a significant degree of carelessness, such as keeping the credentials beside the card in a form anyone could read. Being deceived by a well-made forgery is not on that level, and the Canary courts have said so twice, in cases whose facts every client will recognise.

In Las Palmas (Provincial Court, ruling 207/2025, of 4 April 2025) the message arrived by SMS under the bank's own name: an unusual charge, a link to cancel it. The customer typed his online password on the page behind the link; two card purchases followed, €3,286 in all; the bank refused the refund because the operations had been «correctly authorised». The court confirmed the judgment against the bank. The certificate the bank itself had filed recorded that the device or entity authenticating the customer was not identified, and la entidad bancaria actuó sin tomar las medidas de diligencia y seguridad exigidas y la consecuencia del incumplimiento es la obligación de devolver el importe de la operación — the bank acted without taking the diligence and security measures required, and the consequence of the breach is the obligation to return the amount of the transaction.

In Santa Cruz de Tenerife (Provincial Court, ruling 177/2024, of 23 April 2024) the customer had gone further: on the telephone with someone posing as a telephone company's operator he passed on the codes the bank was sending him, and a burst of card purchases followed, made almost at once from cities on opposite sides of the world; the claim was for €44,227.28. The bank called it gross negligence. The court did not. The negligence the statute requires is cercana al concepto de falta de diligencia inexcusable, razón por la cual su apreciación debe ser de carácter restrictivo — close to the concept of an inexcusable lack of diligence, which is why it must be appreciated restrictively — and a bank that proves no system able to notice such a burst of operations, right after the access password and the card limits had been changed, cannot unload the loss on a customer who was too trusting.

Not every case ends that way. The directive itself says that all the circumstances must be weighed, and a different set of facts can produce a different result.

When you made the transfer yourself

A different fraud needs a different rule. If you were deceived into ordering the payment — the supplier's invoice with a changed account number, the «bank employee» who talks you into moving your savings to a «safe account» — the statute's refund rule does not fit as it stands: it is written for payments made without your consent, and a payment you ordered yourself, however deceived, is on its face an authorised one. The Banco de España's complaints report files it as an operation «authorised by means of deception» and refers the customer to the police, the consumer authorities or the courts. In court, what remains is the general law of contract, in which your own conduct is weighed against the bank's. The Supreme Court's ruling 787/2026, of 25 May 2026, shows the measure: a company whose treasury employee was tricked into ordering seven transfers to China by someone impersonating a director recovered half of its €1,566,951.50 — €783,475.75 — because the bank had ignored the written protocol the company had given it, and the company answered for its employee's part in the deception.

Since 9 October 2025 one tool works before the money leaves. For transfers in euros, banks in the euro area must check the name of the payee against the account number before you authorise, and tell you when the two do not match, with the warning that autorizar la transferencia podría dar lugar a la transferencia de fondos a una cuenta de pago de la que no sea titular el beneficiario indicado por el ordenante — authorising the transfer could lead to the funds being transferred to a payment account not held by the payee indicated by the payer (Regulation (EU) 260/2012, article 5c, added in 2024). If the bank fails to make the check and the payment goes wrong because of it, the bank must refund the amount without delay; if it warned you and you went ahead, it is not liable for the transfer to the account you typed. A mismatch warning on a «new account number» that arrived by email is the moment to telephone the supplier on the number you already had.

Companies are less protected than consumers

The rules above protect consumers in full, and micro-enterprises almost in full. A larger business can be asked to sign them away: where the user is neither, the parties may agree that articles 44 and 46 — the burden of proof and the limits of the customer's liability — do not apply; and any user that is not a consumer, a micro-enterprise included, may be bound to a period other than the thirteen months (article 34.1). Read your company's banking contract before the fraud, not after.

The route: the bank, the Banco de España, the court

Three steps, in this order. The bank's customer service comes first, in writing. For payment services it must answer a más tardar quince días hábiles después de la recepción de la reclamación — no later than fifteen business days after receiving the complaint — and within a month at the outside if it explains the delay (article 69).

The Banco de España comes second, if the bank refuses or stays silent: its conduct department takes complaints online or on paper, and a consumer has a year from the complaint to the bank to file one. Two facts about that route should be known before choosing it. Its report should arrive within four months, and it no tiene carácter vinculante — is not binding (Orden ECC/2502/2012, article 12): the bank may decline to follow it. And in this subject its record is mixed. In 2025 the Banco de España received 30,970 complaints; 30 % of them concerned payments made in a context of deception or fraud, about 18 % more than the year before, two thirds by card and one third by transfer — and in card complaints, its own report says, decisions in favour of the banks predominate, in files that are mostly about fraudulent payments which had passed strong authentication. The supervisor looks at whether the bank followed the rules of good practice; the courts apply the burden of proof described above.

The court is the third step, and the one in which the rulings quoted here were obtained. A report to the police is not a fourth: it is a step the bank will ask for on the first day, it fixes the date and the facts, and what the criminal investigation then does is a separate matter that this note does not cover.

What to do in the first hour, and in the first fortnight

  • Call the bank and block everything. The card, online banking, Bizum; ask for the reference of the call.
  • Put it in writing the same day. Say that you did not authorise the payments, list them, and ask for the refund under article 45, by a channel that leaves proof.
  • Report it to the police and keep the copy. The bank will ask for it.
  • Do not sign anything that says you «authorised» the operations. A claim form is not an admission, so read what it says.
  • Keep the telephone as it is. The messages, the call log and the link are evidence.
  • If your SIM card stopped working, write to the telephone operator too. A duplicate SIM is how the code reached someone else.
  • Count fifteen business days. Then choose between the Banco de España and the court with the papers in hand.

The bank's first letter says the codes were yours. The statute asks a different question: did you consent — and can the bank prove that the fault was gross, and yours?

What our banking team does

We review the file against the statute and the rulings above — the time of each payment, what the bank's records actually prove, what you told the bank and when — write the claim to the bank and, where it refuses, take the case to court. The consultation is a paid one, quoted in advance, and nobody can promise what a court will decide. Bank claims do not all look alike: our notes on floor clauses and on the IRPH index cover two others. The service is described on our banking law page, and the contact page has both offices' hours.

Common questions

The bank says the payments were authenticated with my credentials. Is that the end of it?

No. Authentication proves that the right codes were used, not that you consented. The statute says the bank's record is not necessarily enough to prove authorisation (article 44.2), and the Supreme Court held in April 2025 that payments made with the user's password and SMS code are unauthorised if the user denies them, unless the bank proves fraud or gross negligence.

How long do I have to claim?

Tell the bank the day you find out. The statute requires notice without undue delay and sets an outer limit of thirteen months from the debit; a consumer then has a year from the complaint to the bank to go to the Banco de España. Waiting helps only the other side.

I clicked the link and typed my password. Was that gross negligence?

Not by itself, on the rulings read for this note. Gross negligence means something more than mere negligence and is appreciated restrictively; the courts in Las Palmas and Santa Cruz de Tenerife refused to find it in customers deceived by a forged bank message and by a false operator on the telephone, and looked instead at what the bank's systems had failed to notice. Each case is decided on its own facts.

Does this protect my company's account?

Almost in full if the company is a micro-enterprise: of the rules described here, only the thirteen-month period can be changed by its contract. A larger company's contract may also have excluded the rules on the burden of proof and on liability, and a fraud in which an employee ordered the transfer is judged under general contract law, where the company's own carelessness counts.

Is the Banco de España's report binding on the bank?

No. It is a reasoned opinion that should arrive within four months; the bank has to say whether it accepts it, and it may not. A court judgment is the only decision that obliges the bank to pay.

General information on Spanish law as it stands in October 2026 (Real Decreto-ley 19/2018, arts. 34, 36, 41 to 46 and 69; Regulation (EU) 260/2012, art. 5c; Orden ECC/2502/2012), not advice on your case: liability for a fraud depends on its exact facts and dates.

This note is general information, not legal advice. For advice on your specific situation, consult a lawyer.

Wondering how this applies to your case?

A first consultation in person or by video, in any of our twelve working languages.

Book a consultation
#Bank claims #Phishing #Unauthorised payments Share