Skip to content

Accounts & payments

Phishing: Money lost after a fake email, SMS or call

We classify the process legally and check which claims you may have following a phishing attack.

Overview

What this is about

Typical situations and warning signs

  • You entered credentials on a page that looked like your bank's page via a link in an email or text message.
  • A caller pretended to be an employee of your bank and asked you to provide a TAN or confirm approval in the app.
  • You have been asked to confirm your details due to a supposed account suspension or a “new security procedure”.
  • Shortly after such a message, transfers or card payments were made that you did not initiate.
  • Your bank has informed you that a new device or a new TAN procedure has been registered, even though you did not request this.
  • Your account's transfer limit has been increased without your intervention.
  • The bank refuses to reimburse you and accuses you of gross negligence.

Immediate steps

What you can do now

These steps make sense in most cases – regardless of whether you instruct us.

  1. Have your account and cards blocked

    Have online banking access and cards blocked immediately - directly at your bank or via the blocking emergency number 116 116. Note the date, time and person you spoke to.

  2. Inform the bank and request a refund

    Report the affected payments to your bank immediately and request reimbursement in writing. Describe the process objectively and truthfully and only sign pre-formulated statements once you have understood their content.

  3. Secure evidence

    Retain emails, text messages, chat histories and call logs and take screenshots of the fake pages. Don't delete anything, even if the message makes you uncomfortable afterwards.

  4. Change access data and check devices

    Change online banking and email account passwords from a secure device. Check your devices for malware and only remove programs that were installed at the request of the perpetrators after documentation.

  5. Report the matter to the police

    Report it to the police, including online via your state's internet watchdog. The file number is often required by the bank and can be helpful for further clarification.

  6. Unsure what to do first in your case?

Legal assessment

Possible areas of review

  • Authorization of payment

    We check whether the payments were made with your consent. If the perpetrators have acted with intercepted data themselves, there is usually no authorization - then a claim for reimbursement in accordance with Section 675u of the German Civil Code (BGB) can be considered. If you have given a release yourself, you need to clarify exactly what it referred to.

  • The defence of gross negligence

    According to Section 675v BGB, the bank can refuse reimbursement if you have grossly negligently breached your duty of care. Whether this is the case depends on the individual case - for example, how professional the deception was and what clues you could recognize.

  • Strong customer authentication

    We check whether the bank has required strong customer authentication for payments and for upstream steps such as registering a new device. If it is missing, the objection of gross negligence according to Section 675v Paragraph 4 BGB can be excluded.

  • Burden of presentation and proof on the bank

    In the event of a dispute, the bank must prove that the payment was authenticated and properly recorded. Mere recording is not necessarily sufficient to prove authorization or gross negligence.

  • Notification and deadlines

    Unauthorized payments must be reported to the bank immediately upon becoming aware of them. According to § 676b BGB, claims are generally excluded if notification is not made no later than 13 months after the charge.

Who may be liable

Possible opposing parties

  • Your account-holding bank

    In the case of unauthorized payments, a claim for reimbursement against your own payment service provider should be considered. Whether it takes action depends in particular on the objection of gross negligence.

  • Holder of the recipient account

    The money often flows into accounts of so-called financial agents. Claims for unjust enrichment or tortious acts may be possible against the account holder - provided that the account holder can be identified and is solvent.

  • Recipient bank

    Liability of the bank where the recipient account is held can only be considered under strict conditions, for example if there are recognizable and serious suspicions. We are checking whether there is any evidence for this.

  • The perpetrators

    In principle, there are claims for damages against the perpetrators. In practice, they can only be enforced if the investigation leads to an identifiable and tangible person.

Whether and against whom claims actually exist depends on the individual case and can only be assessed after reviewing the documents.

Preserve evidence

Documents you should keep

Do not delete anything – not even out of anger or shame. Your account of events is enough for the initial enquiry; documents can be submitted later.

  • Original phishing message (email with headers, SMS, messenger message)
  • Screenshots of the fake website including the address
  • Call list with phone numbers, date and time
  • Account statements and sales details of the affected payments
  • Notifications from the bank about new devices, TAN procedures or limit changes
  • Correspondence with the bank, especially rejection letters
  • Confirmation of blocking with date and time
  • Criminal complaint and police file number

Our approach

How we handle your case

  1. Step 1: Describe your case

    Using the form, you describe to us in a few minutes what happened. You can submit documents later.

  2. Step 2: Legal assessment

    We review your details, classify the facts and examine against whom claims may be available.

  3. Step 3: Strategy

    You receive an honest assessment of prospects, risks and costs – and decide for yourself whether to instruct us.

  4. Step 4: Representation

    We implement the agreed strategy: towards banks, payment service providers and other parties involved, and in court if necessary.

FAQ

Frequently asked questions about Phishing

General guidance – it does not replace advice on your individual case.

That depends on the individual case. In the event of unauthorized payments, the law generally requires the bank to reimburse the payment, but the bank may be able to claim gross negligence under certain circumstances. We cannot and do not want to give a guarantee - we will check how the prospects should be assessed in your case.

Knowledge centre

More about Phishing

Case review

Tell us what happened.

We will assess which claims may be available and which next steps may make sense.

Your details are treated in confidence. An enquiry does not yet establish a client relationship.

We are here for you.

By telephone, by email or via the case review – in confidence and initially without obligation.

Call usHave your case reviewed