EU Court Adviser Says Banks Should Fully Reimburse Phishing Victims
The European Union's revised Payment Services Directive (PSD2) requires refunds for unauthorized transactions, but member states differ in their interpretations of “authorization” and “gross negligence.” Banks often refuse reimbursement on the grounds that customers disclosed their login credentials. The European Banking Authority said fraudulent transfers totaled €2.2 billion in 2024, with victims bearing about 85% of the losses, making the allocation of liability a significant issue.
On March 5, 2026, Advocate General Athanasios Rantos argued in Case C-70/25 that PKO BP S.A. should first fully reimburse a Polish customer for funds stolen through phishing. A bank may not initially deny reimbursement on grounds of gross negligence unless it has reason to suspect that the customer committed fraud. It may still sue to recover the funds if it later proves that the customer acted intentionally or with gross negligence. The opinion is not binding, and no date has been set for the final ruling.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.