- Home
- Legal articles
- Phishing
- Phishing in online banking: Who is liable for unauthorized payments?
After a phishing attack, the question arises as to whether the bank has to refund the debited amount. The decisive factors are the authorization of the payment and the accusation of gross negligence.
A deceptively genuine email from the supposed bank, a text message with a link or a call from a supposed bank employee – phishing has many forms. The perpetrators' goal is always to obtain access data and authorizations in order to initiate transfers to the detriment of the account holder.
Once the money has been drained, the perpetrators usually cannot get it back. For those affected, it then depends on whether the account-holding institution has to reimburse the amount. The law regulates this issue in the regulations on payment services in the Civil Code (BGB).
The principle: reimbursement of unauthorized payments
The starting point is § 675u BGB. Thereafter, the payment service provider is not entitled to reimbursement of its expenses in the event of an unauthorized payment transaction. He must immediately reimburse the customer for the payment amount and restore the account to the level it would have been in without the debit.
A payment is only authorized if the account holder has agreed to it. If third parties have triggered a transfer using stolen data, this is usually missing. More difficult are cases in which those affected have given permission themselves under the influence of deception. Whether an authorization exists depends on the circumstances – for example, what was shown to the customer during the approval process.
When customers are liable themselves
The bank can counter the claim for reimbursement with its own claim for damages in accordance with Section 675v of the German Civil Code (BGB). If the damage is due to the misuse of a payment instrument, the law initially provides for a limited contribution from the customer of a maximum of 50 euros. However, the customer is liable for the entire damage if he acted with fraudulent intent or violated his duty of care intentionally or through gross negligence.
These obligations include protecting personalized security features from unauthorized access and immediately reporting misuse. In practice, the dispute usually revolves around the question of whether the customer's behavior can be classified as grossly negligent.
Gross negligence – a question on a case-by-case basis
Anyone who seriously violates the required level of care and fails to take obvious considerations is grossly negligent. A simple mistake is not enough. When making the assessment, courts take the following aspects into account, among others:
- How professional and credible was the deception?
- Were there any recognizable warning signals, such as unusual sender addresses or linguistic anomalies?
- Were release codes passed on over the phone or on a third-party website?
- What information about the amount and recipient was displayed in the release process?
- Has the bank given a specific and current warning about the fraud scam being used?
The burden of proof lies with the bank in essential points. According to Section 675w of the German Civil Code (BGB), simply recording that a payment instrument including authentication was used is not necessarily sufficient to prove authorization or a gross breach of duty by the customer.
What to do after a phishing incident
- Access to online banking and have affected cards blocked immediately, for example via the bank or the central blocking emergency number.
- Immediately inform the bank of the unauthorized payment and request the refund in writing.
- Secure evidence: Do not delete emails, text messages, call logs and screenshots.
- File a criminal complaint with the police.
- Record the process in writing from memory as soon as possible.
Speed is also necessary for legal reasons: Once the blocking notice has been given, the customer is no longer liable for further abusive orders, provided that they do not act with fraudulent intent. In addition, claims are excluded if the bank is not informed of the unauthorized payment transaction no later than 13 months after the debit was made (§ 676b BGB).
Conclusion
The law initially assigns the risk of unauthorized payments to the payment service provider. As a rule, full liability on the part of the customer only comes into consideration in cases of intent or gross negligence, and whether this accusation is justified can only be assessed based on the specific process. If the bank refuses a refund, it may make sense to legally examine the reasons.
Frequently asked questions
In the event of an unauthorized payment transaction, the amount must be refunded immediately in accordance with Section 675u of the German Civil Code (BGB). In practice, however, institutions often refuse reimbursement citing gross negligence on the part of the customer. Whether this objection is valid depends on the individual case.
This cannot be answered in general terms. What is important is, among other things, whether you were able to recognize which payment you were approving and how the deception took place. Even in such cases, a claim for reimbursement may exist in whole or in part.
It is not a legal requirement for the claim to reimbursement. However, it usually makes sense because it documents the incident and banks often expect corresponding proof.
Related services
