- Home
- Legal articles
- Phishing
- Gross negligence in online banking: What matters in a dispute with the bank
If the bank refuses to reimburse you after a case of fraud, it is usually citing gross negligence. What the term means, who has to prove it and which circumstances count.
After a case of fraud in online banking, many of those affected receive a short letter from their bank: A refund will be rejected because the customer has acted with gross negligence. This is doubly stressful - on top of the financial damage comes the accusation that you are responsible for it yourself.
However, such a letter initially only reflects the bank's legal opinion. Whether the accusation is valid depends on legal standards that are much stricter than the term suggests in everyday life.
Why the accusation has so much weight
In the event of an unauthorized payment transaction, the bank must generally refund the amount in accordance with Section 675u of the German Civil Code (BGB). In accordance with Section 675v of the German Civil Code (BGB), it can counter this with its own claim for damages if the customer has intentionally or grossly negligently violated his duty of care. The customer may then be liable for the entire damage. In the case of simple negligence, on the other hand, the legally limited involvement remains. The classification of fault often determines who ultimately bears the damage.
What obligations are meant arise primarily from § 675l BGB: Customers must protect their personalized security features - such as access data and release codes - from unauthorized access and immediately report any loss or misuse as soon as they become aware of it.
The benchmark: more than a mistake
According to the general understanding of civil law, gross negligence only occurs if the required care was violated to an unusually high degree - i.e. if what should have been obvious to everyone in the specific case was ignored. There is also a personal side: the behavior no longer has to be subjectively excusable. Carelessness, a moment of being overwhelmed or a mistake under time pressure are not enough in themselves.
The perspective is also important. In retrospect, many scams seem transparent. Legally, however, it depends on the situation in which the person concerned found themselves: What information did they have, how credible did the perpetrators appear, how much time was there to think?
Circumstances that are typically disputed
Courts assess whether the threshold for gross negligence has been exceeded based on an overall assessment. The following questions regularly play a role:
- Were access data or release codes passed on – and if so, how and supposedly to whom?
- What exactly did the release process indicate: the amount and recipient of a transfer or another process, such as registering a new device?
- How elaborate was the deception, for example through a simulated website or a manipulated telephone number display?
- Did the perpetrators already know personal details or account information that would make the contact appear credible?
- Had the bank previously clearly and understandably warned against exactly this approach?
None of these points decide on their own. The passing on of a release code over the telephone is often viewed critically by courts; Nevertheless, the overall picture – for example in the case of a particularly professional deception – can be different in individual cases.
Who has to prove what?
The bank alleging gross negligence must present and prove the facts from which the allegation arises. The mere fact that the payment instrument was technically used correctly and the authentication was recorded is not necessarily sufficient according to Section 675w of the German Civil Code (BGB).
At the same time, customers are expected to describe the process in a comprehensible way from their perspective. Therefore, the first statement to the bank has considerable weight. Inaccurate or hasty formulations - for example in a telephone conversation shortly after the incident or in a claims form - are often later used against those affected.
The behavior of the bank is also considered
Not only the customer's behavior is taken into account in the evaluation. It may be important whether the institution has required strong customer authentication - if it is missing, the customer is generally not liable for damages according to Section 675v of the German Civil Code (BGB) as long as he has not acted with fraudulent intent. The question of whether the release process clearly and understandably displayed the process can also play a role. The extent to which this reduces the bank's claim depends on the individual case.
Conclusion
Gross negligence is a high standard and not automatic. Rejection by the bank is not the last word - nor does the strict standard result in a secure claim. The exact process, the design of the approval process and the evidence are crucial. Anyone who has received a rejection can have the reasons examined legally. Please note § 676b BGB: Unauthorized payments must be reported to the bank immediately, at the latest 13 months after the debit.
Frequently asked questions
No, the rejection initially only reflects the bank's assessment. The bank must explain and prove the circumstances from which a gross breach of duty should arise. Whether she succeeds can only be judged based on the actual process.
Courts are often critical of the passing on of release codes, but there is no hard and fast rule. Among other things, it depends on how the deception was designed and what the approval process actually indicated. A reliable assessment requires examining all circumstances.
Report the misuse immediately and have access blocked. Describe the process truthfully and as precisely as possible; avoid making assumptions about things you don't remember for sure. If you have detailed written statements, it may make sense to seek advice beforehand.
Related services
