You open your banking app and realise that thousands of euros have disappeared. The day before, you received a text message or email from your bank, a parcel delivery service or a payment app. You clicked on a link, entered a code and thought you were simply confirming a payment or checking your account. It is only later that the harsh reality dawns on you: you have fallen victim to phishing. Unfortunately, this scenario is becoming increasingly common these days. Aside from the criminal law aspect, the question arises: who should be held responsible here – the victim or the bank?
Phishing and internet fraud have now become a rampant problem in our digitalised society. In Belgium alone, no less than 49 million euros were stolen in 2024. Extra vigilance is required in the coming weeks, as cybercriminals are exploiting the Football World Cup. The popularity of the World Cup is being exploited on a massive scale for ticket fraud, fraudulent live streams and the theft of login details. Leading up to the tournament, more than 13,000 World Cup-related domain names have already been registered, a significant proportion of which have been identified as malicious or suspicious. Research shows that scammers have already set up hundreds of fake websites that, at first glance, closely resemble official FIFA channels or well-known hospitality services. Supporters desperately searching for scarce tickets are lured via Facebook, Instagram or Telegram groups into clicking on malicious links or making urgent payments.
As a victim, you might assume that the bank simply has to refund the stolen money in cases of phishing. After all, the money has disappeared from your account without your consent. Yet in practice, banks often refuse to intervene. The legal framework surrounding phishing and bank fraud is, in fact, more nuanced than is often thought, and the criminal law aspect must not be overlooked. Filing a complaint with the police and/or the examining magistrate is always worthwhile, as this is the only way potential perpetrators networks can be better traced and the ‘dark numbers’ in statistics reduced.
In just about every phishing case, the same question ultimately arises regarding the bank’s liability. This centres on the following aspects: did the customer authorise the payment themselves or not? And if not, did the victim exercise sufficient caution? In this article, we explain how the law and recent case law answer these questions.
When is the bank obliged to refund fraudulent payments immediately?
If you are a victim of phishing, in practice the bank all too often gives the standard response: ‘You have been careless or grossly negligent, so we will not refund you’. However, this position is too simplistic. In a recent and much-discussed ruling by the Commercial Court in Antwerp, it was confirmed in summary proceedings that the law applies a strict principle: “reimburse first, then argue”. As e-commerce and IT lawyers, we regard this ruling as an important tool in proceedings against banks – not to initiate summary proceedings immediately in every case, but to remind the bank of its legal obligation and, where necessary, to have this enforced by the court. In a judgment by the Dutch-speaking Commercial Court in Brussels, the summary proceedings were dismissed on the grounds of lack of urgency. This demonstrates once again that such cases always require nuance and a tailored strategy.
The basic rule has, in any event, been made clear in the judgment of the Antwerp Commercial Court referred to above and is, in fact, set out in black and white in the law. Article VII.43 of the Economic Law Code (WER) obliges your bank, in the event of an unauthorised payment transaction, to refund the amount immediately (and no later than the end of the next working day) and to restore the payment account to the state it was in prior to the transaction. The bank may only refuse this immediate refund if it has lawful, reasonable grounds to suspect that the victim committed the fraud themselves, and it reports this in writing to the FPS Economy. In principle, the bank should not be allowed to misuse the discussion regarding any negligence to block the provisional refund. The bank must first refund the money and may then attempt to prove that the loss was the victim’s own fault.
Authorised vs. unauthorised transactions: why the PIN code doesn’t prove everything
Phishing often leaves victims feeling a great sense of shame, but is that really justified? The techniques are becoming increasingly sophisticated and, in some cases, it is even impossible to spot a phishing attempt. Given these developments, there is a growing need to focus on the bank’s responsibility rather than the individual responsibility of the victim. Can we still expect, in this day and age, for the user to be regarded as the key player in security? Or is it rather the bank that should take responsibility for enabling a system that prioritises accessibility and speed without providing the necessary security? Case law certainly seems to be increasingly protecting the victim’s position, but it often depends on the specific circumstances.
In which cases, then, must the bank definitively reimburse fraudulent payments? The basic rule is simple: a payment transaction is only permitted if the payer has consented to its execution. If that consent is lacking, then legally it constitutes an unauthorised payment transaction and there is a high likelihood that the bank will be required to pay.
Banks often defend themselves by arguing that a transaction is ‘authorised’ as soon as the correct security codes (such as your PIN code, itsme signature or card reader) have been used. Case law is increasingly ruling against the banks on this point. Article VII.42,§2 of the WER explicitly states that the mere technical use of a payment instrument is not sufficient proof that the user has actually authorised the payment.
Even when a payment has been technically confirmed, this does not in itself prove that the customer actually gave their consent. A transaction is only considered authorised if you have subjectively, consciously and freely consented to the specific payment instruction (the exact amount and the specific payee). In phishing, cybercriminals deceive you: you think you are logging in to track a parcel or verify your bank account, not that you are authorising a fraudulent transfer. Because that conscious intention is lacking, phishing can legally be classified as an unauthorised transaction.
When does ‘gross negligence’ apply in the case of bank fraud?
Consumer protection is not absolute. In the case of an unauthorised transaction, the customer normally bears a loss of up to 50 euros before reporting the fraud, after which the bank must compensate for the remainder of the loss. However, the bank may refuse to refund the full amount or may reclaim it if it can demonstrate that the customer acted fraudulently or was grossly negligent.
Users of payment instruments also have legal obligations of their own. They must take care to protect their bank card and personal security details and take immediate action if anything goes wrong. In phishing cases, the issue therefore often centres on whether the victim behaved as a reasonably prudent person would in the same circumstances.
The legal threshold for gross negligence is relatively high. A simple mistake or slight carelessness is not sufficient. The bank must prove that the behaviour clearly deviates from what a reasonably prudent person would do. In practice, phishing attacks these days are organised in a highly professional manner. Websites, emails and text messages sometimes look exactly like communications from genuine banks or companies. Where a victim could not reasonably have detected the fraud before the payment was made (for example, in the case of a visually perfect replica of a payment environment), the consumer can count on a full exemption from liability.
However, case law shows that judges are more likely to regard certain behaviours as a serious, inexplicable error than others. Such behaviour includes, for example, stubbornly ignoring successive, explicit warnings from the bank; entering secret (response) codes on an external website with an obviously suspicious URL without checking it first; or directly passing on SMS codes or itsme activation codes over the telephone. Whether or not a definitive refund is granted therefore often depends on details such as the content of messages, the warning signs, the speed of the response and the manner in which the fraud was carried out.
Phishing targeting a business account: why businesses are less protected than consumers
It is crucial to note that the strict protection rules outlined above apply primarily to consumers (private individuals).
For businesses and the self-employed, the situation is often different. The law (Art. VII.29 of the WER) allows banks to deviate from the protection rules set out in the Economic Law Code (WER) in contracts with professional clients. In business banking terms and conditions, the bank’s liability in the event of fraud is therefore often drastically limited or completely excluded. As a result, businesses usually have considerably less legal protection than private individuals in phishing cases – a harsh reality that many companies only discover once their business account has been plundered. However, a solution is sometimes available in such cases too. This was the case, for example, in a judgement by the Dutch-speaking Commercial Court of Brussels, where the victim was able to demonstrate that, in this particular instance, personal funds had been fraudulently transferred via a business account.
Step-by-step guide to dealing with phishing and how can we help?
Anyone who falls victim to phishing must act as quickly as possible to safeguard their rights. Here is a short guide for phishing in Belgium.
- Block your cards and accounts immediately by contacting Card Stop (078 170 170) and your bank’s fraud helpline.
- Report the incident to the police: make sure you receive a copy of the police report with the reference number.
- Do not delete any evidence: keep all text messages, emails and screenshots of the fake link. Deleting the phishing email can sometimes make technical investigations by the bank and police impossible and may work to your disadvantage.
It is also important to formally give your bank notice of default and demand an immediate refund. We would be happy to assist you with this.
As a victim of phishing, you should not be too quick to accept a refusal from the bank. In practice, the argument of gross negligence is sometimes invoked very quickly, whilst the legal reality is often more nuanced. The fact that a code was entered or a transaction was technically confirmed does not automatically mean that, legally speaking, the payment was authorised. Nor does every mistake mean that a victim has automatically acted with gross negligence. Every phishing case hinges on the concrete facts. The way in which the fraud was organised, the warnings that were visible, the communication channels used and the victim’s response all play a decisive role in this.
If a refund is refused, it is often worth having that decision critically reviewed. Not every refusal is legally justified, and not every phishing case is as clear-cut as banks sometimes make it seem.
Legal assistance with phishing in your region
Has your bank account been emptied and is the bank refusing to cooperate? Do not simply accept this dismissal. The legal team at Sirius Legal has extensive experience in successfully filing criminal complaints, conducting negotiations and bringing legal proceedings against banks.
- Looking for a solicitor specialising in phishing in the Antwerp region? Our experts in Mechelen will analyse the chances of success in your case against the bank.
- Victim of phishing in Limburg? At our office in Hasselt, we assist both businesses and private individuals in claiming back unauthorised payments.
Schedule an appointment
Useful links
A list of useful websites in Belgium:
- The Safeonweb website, where you can report fraudulent messages and view the latest phishing warnings.
- Card Stop, where you’ll find the telephone number and further information
- FPS Economy and FPS Finance, government information pages on bank fraud, phishing, quishing and unauthorised payments
- Complaints procedure at Ombudsfin
