Civil Law And Banking Fraud Liability Claims In Europe .
Civil Law and Banking Fraud Liability Claims in Europe
1. Introduction
Banking fraud liability in Europe concerns the civil consequences when fraudulent conduct causes financial loss through a bank account, payment card, electronic banking system, transfer, direct debit, online banking platform, or other payment service.
European banking-fraud disputes commonly involve:
unauthorised bank transfers;
stolen payment cards;
phishing;
identity theft;
account takeover;
forged payment instructions;
fraudulent direct debits;
mobile-payment fraud;
social-engineering scams;
fraudulent powers of attorney;
insider fraud;
failures in authentication or security;
fraud committed by third parties using banking infrastructure.
The most important European framework is the Payment Services Directive 2 (PSD2), Directive (EU) 2015/2366, together with national civil, banking and consumer law. PSD2 establishes a structured allocation of responsibility between the payment-service provider and the customer for unauthorised transactions. In particular, Article 73 generally requires immediate refund of an unauthorised transaction, while Article 74 addresses circumstances in which the payer bears losses, including fraud or intentional/grossly negligent failure to comply with security obligations. (Eur-Lex)
A central principle is:
The fact that a transaction was authenticated does not necessarily prove that the customer authorised it or acted fraudulently.
The CJEU has repeatedly placed significant importance on the payment provider's burden of proof and the distinction between authentication and authorisation. (Eur-Lex)
2. Meaning of Banking Fraud Liability
Banking fraud liability may arise when:
Fraudulent conduct + banking transaction + legal duty + loss + causation = potential civil liability
The fraud may be committed by:
an external fraudster;
an employee of the bank;
an agent;
a customer;
a third-party payment beneficiary;
an intermediary;
a cybercriminal;
an organised criminal group.
The bank's civil liability depends on the particular relationship and applicable statutory regime.
3. Major Types of Banking Fraud
A. Unauthorised payment fraud
A fraudster obtains access to a customer's account and makes transactions without the customer's consent.
Examples:
stolen card;
stolen credentials;
account takeover;
malware;
phishing.
This is the classic PSD2 liability situation.
B. Phishing fraud
The customer receives a fraudulent message directing them to a fake banking website.
The customer enters:
username;
password;
one-time code;
authentication credentials.
The fraudster then uses those credentials to make payments.
A major legal question is:
Does the customer's disclosure of credentials constitute gross negligence sufficient to shift the loss to the customer?
The answer depends on the applicable PSD2 rules and facts; it is not automatically yes merely because the customer interacted with a fraudster.
C. Social-engineering fraud
The fraudster manipulates the customer into authorising a payment.
For example:
Fraudster impersonates bank employee → customer believes the instruction is genuine → customer authorises transfer.
This raises a difficult distinction between:
Unauthorised transaction
The customer did not legally authorise the transaction.
and
Authorised payment induced by deception
The customer technically consented to the payment, but was deceived about its purpose or recipient.
The distinction is extremely important under PSD2.
4. PSD2 Liability Structure
The PSD2 framework generally divides the risk between the payment service provider and payer.
Payment service provider
Generally responsible for an unauthorised payment transaction and required to refund the payer, subject to the Directive's conditions.
Payer
May bear losses in specified circumstances, particularly where the payer:
acted fraudulently; or
intentionally or with gross negligence failed to comply with security obligations.
The Directive therefore does not create unlimited bank liability.
Nor does it make every customer who has been deceived automatically responsible for the loss.
5. Authentication vs Authorisation
This is one of the most important principles.
Authentication
The bank establishes that a particular payment instrument or security credential was used.
Authorisation
The customer actually gave consent to the payment transaction.
These are not necessarily the same thing.
The CJEU has explained that merely showing use of a payment instrument is not necessarily sufficient to establish that the payer authorised the transaction or acted fraudulently. (Eur-Lex)
Thus:
Authenticated ≠ automatically authorised.
6. Burden of Proof
Under the earlier Payment Services Directive 2007/64, which remains directly relevant to many older transactions, Article 59 placed significant evidential responsibility on the payment service provider.
Where the customer disputes authorisation, the provider had to prove that the transaction:
was authenticated;
was accurately recorded;
was entered into the accounts;
was not affected by a technical breakdown or other deficiency.
The use of the payment instrument itself was not necessarily enough to prove authorisation or fraud. (Eur-Lex)
The same general architecture is reflected in later CJEU jurisprudence concerning payment-service liability.
7. Important Case Law
1. DM and LR v Crédit Agricole — C-337/20
CJEU, 2 September 2021
Facts
The dispute concerned unauthorised payment transactions and the consequences of failing to notify the bank within the statutory period.
Principle
The CJEU held that the liability regime for unauthorised payment transactions under Directive 2007/64 was linked to the customer's obligation to notify the payment service provider.
The notification period was 13 months from the debit of the transaction. A user who failed to notify within that period could not use that statutory regime to obtain reimbursement. (Eur-Lex)
Importance
The case establishes:
Unauthorised-transaction liability depends not only on the fraud but also on timely notification.
It also confirms that the statutory regime is designed around a balance between:
provider information duties; and
customer notification duties.
8. ZG v Beobank — C-351/21
CJEU, 16 March 2023
This is one of the most important European banking-fraud decisions.
Facts
A Belgian customer had a debit card. Several transactions were made after an initial payment in Valencia, Spain. The customer disputed two subsequent transactions as unauthorised.
Legal issue
The case concerned the bank's obligations in relation to information about the recipient of the payment and the liability regime for unauthorised transactions.
Principle
The CJEU held that the payment service provider must provide information enabling the payer to identify the person who benefited from the transaction.
The Court also stressed that the PSD liability regime is harmonised and that national courts cannot simply create a competing liability regime for the same operative event in a manner incompatible with EU law.
Importance
The case demonstrates that banks have important information and transparency duties in fraud disputes.
9. UA v Eurobank Bulgaria — C-409/22
CJEU, 11 July 2024
Facts
The dispute involved payment transactions allegedly made on the basis of a power of attorney.
The account holder disputed that valid consent had been given.
Principle
The CJEU held that a formally regular power of attorney, even one bearing an apostille, does not by itself establish that the account holder consented to the payment transaction.
The payment service provider must establish that the user expressed agreement to the transaction in the form of consent required by the payment arrangement. (Eur-Lex)
Importance
The case gives a very important rule:
Formal validity of an authorisation document is not necessarily proof of payment authorisation.
This is particularly relevant to:
forged powers of attorney;
identity fraud;
corporate banking fraud;
agent fraud;
elderly-client fraud;
cross-border banking transactions.
10. Veracash — C-665/23
CJEU, 1 August 2025
This is a particularly important recent authority.
Facts
A customer disputed withdrawals made using a payment card and maintained that the card had not been received or used by him.
The customer did not notify the payment institution immediately.
Principle
The CJEU held that where a customer becomes aware of an unauthorised payment transaction but delays notification with intent or gross negligence, the customer can lose the right to obtain reimbursement of the transaction even if notification occurs within the overall 13-month period. (curia)
Importance
The case demonstrates that there are two distinct time considerations:
the overall statutory notification period; and
the requirement to notify without undue delay once the customer becomes aware of the fraud.
11. DenizBank AG v Verein für Konsumenteninformation — C-287/19
CJEU, 11 November 2020
Facts
The case concerned contactless bank cards, payment instruments and the PSD2 framework.
Principle
The CJEU examined:
the meaning of a payment instrument;
contactless payments;
low-value payment instruments;
information obligations;
liability allocation;
consumer protection.
The case confirms that the concept of payment instrument under PSD2 must be interpreted in accordance with the Directive's technological and legal framework. (Infocuria)
Importance
It demonstrates that European banking-fraud liability must adapt to new payment technologies.
12. Beobank and the Full-Harmonisation Principle
The importance of Beobank extends beyond the facts.
The CJEU stressed that the liability regime for unauthorised payment transactions under Directive 2007/64 was fully harmonised.
Consequently, a national court cannot simply replace the EU statutory allocation of risk with a different national liability theory concerning the same operative event if that would undermine the EU regime.
This matters greatly in civil litigation because a claimant cannot necessarily avoid the PSD framework simply by relabelling the claim as:
negligence;
breach of contract;
general banking duty;
information failure.
The precise interaction with national law depends on the facts and applicable EU provision.
13. CRCAM — C-337/20
The Crédit Agricole case is particularly important for the relationship between statutory payment liability and general civil law.
The CJEU explained that the statutory payment-services regime is based on a balance between:
Bank's information obligation
and
Customer's obligation to report unauthorised transactions.
If the customer does not comply with the statutory notification requirement, the customer cannot simply invoke the statutory refund mechanism through general law to bypass that requirement. (Eur-Lex)
14. Case-Law Summary Table
| Case | Year | Main principle | Banking-fraud relevance |
|---|---|---|---|
| CRCAM, C-337/20 | 2021 | Timely notification of unauthorised transactions | Customer's notification duty |
| DenizBank, C-287/19 | 2020 | Payment instruments and contactless payments | Technological payment fraud |
| Beobank, C-351/21 | 2023 | Information about payment beneficiary; harmonised liability regime | Bank information duties |
| Eurobank Bulgaria, C-409/22 | 2024 | Formal power of attorney does not itself prove consent | Identity/authorisation fraud |
| Veracash, C-665/23 | 2025 | Grossly negligent delay in notification can defeat reimbursement | Customer conduct and fraud losses |
| Tukowiecka, C-70/25 | Pending; AG Opinion 2026 | Phishing and immediate-refund question under PSD2 | Modern phishing fraud |
Important: Tukowiecka should currently be treated as a pending CJEU case with an Advocate General's Opinion, not as a final judgment. The case concerns a phishing victim and whether a bank may refuse immediate reimbursement because of alleged gross negligence. (Infocuria)
15. Phishing Fraud
Phishing presents one of the most difficult modern banking-fraud problems.
Typical structure:
Fraudulent message
↓
Fake banking website
↓
Customer enters credentials
↓
Fraudster obtains authentication information
↓
Fraudster initiates payment
↓
Customer disputes transaction
The bank may argue:
“The customer disclosed the credentials and therefore acted with gross negligence.”
The customer may respond:
“The transaction itself was never authorised.”
The legal question depends upon the applicable PSD2 provisions and evidence.
16. Strong Customer Authentication
PSD2 introduced strong customer authentication (SCA) requirements for many electronic payment transactions.
SCA generally relies on at least two elements belonging to different categories, such as:
knowledge;
possession;
inherence.
Examples include:
password + mobile device;
card + PIN;
device + biometric authentication.
However:
Strong authentication is a security mechanism, not conclusive proof that the customer genuinely intended the transaction.
The distinction between authentication and consent remains central.
17. Customer Gross Negligence
The customer may bear losses where the statutory conditions concerning fraud or intentional/grossly negligent failure to comply with security obligations are satisfied.
Gross negligence is more serious than ordinary carelessness.
Factors potentially relevant include:
whether the customer ignored obvious warnings;
whether credentials were deliberately disclosed;
whether the customer responded to a suspicious request;
whether the fraudster impersonation was sophisticated;
whether the customer reasonably believed the communication was genuine;
whether the bank provided adequate warnings;
whether the customer reported the fraud promptly.
The factual circumstances therefore matter substantially.
18. Bank's Security Duties
A bank's obligations may include:
authentication;
transaction monitoring;
fraud detection;
secure payment infrastructure;
customer notification;
transaction information;
blocking mechanisms;
reporting channels;
appropriate security procedures.
However, a bank is not necessarily an insurer against every form of fraud.
The statutory payment regime establishes the specific allocation of risks.
19. Fraud Detection Systems
Modern banks use:
AI fraud detection;
behavioural analytics;
device fingerprinting;
transaction monitoring;
geolocation;
velocity controls;
anomaly detection;
risk scoring.
A bank may face civil questions where its security systems fail to operate as legally required.
For example:
Multiple abnormal transactions
unusual geographic location
unusual transaction size
multiple rapid transfers
could raise questions concerning the bank's fraud-monitoring procedures.
But the claimant must establish the legal duty and applicable liability framework; an algorithm's failure alone does not automatically create damages liability.
20. Authorised Push Payment (APP) Fraud
APP fraud is particularly difficult.
Example:
Fraudster impersonates a genuine supplier → business believes the invoice is genuine → business itself instructs bank to transfer €100,000.
The bank may argue:
The payment was authorised.
The customer may argue:
Consent was obtained through fraud.
This creates a legal distinction between:
Transaction authorisation
The payment instruction came from the account holder.
and
Transaction purpose
The account holder did not intend to transfer money to the fraudster.
The legal treatment of APP fraud varies across European jurisdictions and has also developed through national statutory and regulatory reforms. It should not automatically be treated as identical to an unauthorised-payment claim under PSD2.
21. Fraudulent Direct Debits
Fraud may occur through unauthorised direct debits.
The legal analysis may concern:
whether the mandate existed;
whether consent was given;
whether the payment was properly authenticated;
refund rights;
notification;
bank obligations;
merchant/creditor responsibility.
The payment-services framework can provide significant protections, but the exact statutory mechanism depends on the payment type.
22. Corporate Banking Fraud
Corporate fraud creates additional complexity.
Example:
Employee fraudulently instructs bank to transfer company funds.
Questions include:
Was the employee authorised?
Was the payment instruction genuine?
Was the employee acting within apparent authority?
Did the bank reasonably rely on the instruction?
Was there an internal-control failure?
Did the company negligently disclose credentials?
Does PSD2 apply directly?
Does national company/agency law apply?
The Eurobank Bulgaria reasoning concerning proof of consent is especially relevant to questions of authority and authorisation. (Eur-Lex)
23. Forged Signatures and Powers of Attorney
Bank fraud may involve:
forged signatures;
forged corporate resolutions;
fraudulent powers of attorney;
stolen identity documents;
false certificates.
The Eurobank Bulgaria case is particularly useful because the CJEU rejected the idea that formal regularity alone proves that the account holder consented to the payment. (Eur-Lex)
Thus:
Documentary authenticity and actual payment authorisation are separate questions.
24. Identity Theft
Identity theft can involve:
opening fraudulent bank accounts;
obtaining loans;
changing account details;
withdrawing funds;
creating fraudulent payment instructions.
Civil claims may involve:
bank;
fraudster;
credit-information provider;
payment provider;
other financial institution.
Evidence may include:
KYC documents;
authentication logs;
IP addresses;
device information;
call recordings;
transaction records;
biometric information;
digital signatures.
25. Bank Employee Fraud
Where a bank employee commits fraud, potential liability may arise through:
employment/agency principles;
vicarious liability under national law;
contractual banking duties;
negligence;
regulatory obligations.
The bank's liability will depend on whether the employee was acting within the scope of employment and the applicable national law.
PSD2's unauthorised-payment regime may also apply where the transaction falls within its scope.
26. Bank Negligence and Fraud Prevention
A claimant may allege that a bank:
failed to detect suspicious transactions;
failed to apply required authentication;
failed to provide security mechanisms;
failed to notify the customer;
failed to block a clearly abnormal transaction;
failed to provide adequate information.
But the claim must be connected to the applicable statutory regime.
The Beobank judgment illustrates that information duties and reimbursement liability must be analysed within the harmonised payment-services framework rather than simply treated as unrestricted national negligence claims.
27. Causation
Banking fraud disputes require careful causation analysis.
For example:
Bank security failure
↓
Fraudulent payment
↓
Financial loss
This is comparatively straightforward.
But:
Customer voluntarily authorises transfer after fraudster's deception
↓
Money transferred
↓
Fraud discovered
↓
Bank argues transaction was authorised
creates a more difficult question concerning the statutory classification of the transaction.
28. Damage
Potential recoverable losses may include:
Direct financial loss
Money removed from the account.
Interest
Interest lost or incurred because of the fraud.
Bank charges
Fraud-related fees where legally recoverable.
Consequential loss
Potentially recoverable under applicable national law.
Business losses
For corporate customers, additional losses may arise from interruption of operations.
Non-material damage
Potentially relevant under national law in appropriate circumstances, although not automatically recoverable under the PSD2 refund regime itself.
29. Notification Requirement
Prompt notification is critical.
Under the earlier Directive, Article 58 required notification of unauthorised or incorrectly executed transactions no later than 13 months after the relevant debit. (Eur-Lex)
The Veracash judgment additionally demonstrates the importance of the requirement to act without undue delay once the customer becomes aware of the transaction. (curia)
Therefore:
A customer should not wait merely because the statutory outside period has not expired.
30. Evidence in Banking-Fraud Litigation
Important evidence includes:
Banking records
transaction history;
account statements;
payment instructions;
beneficiary information.
Authentication records
OTP logs;
PIN authentication;
biometric records;
device authentication;
SCA records.
Technical records
IP address;
device ID;
geolocation;
session logs;
fraud-monitoring alerts.
Communication records
SMS;
email;
bank messages;
telephone recordings.
Identity records
KYC documents;
signatures;
powers of attorney.
Customer evidence
police reports;
fraud notifications;
chronology;
correspondence with bank.
31. Banking Fraud and Data Protection
Banking fraud often involves personal data.
A fraud investigation may involve:
transaction monitoring;
IP addresses;
device information;
biometric data;
identity information.
This can raise GDPR issues concerning:
lawful processing;
security;
access rights;
data retention;
automated decision-making.
However, a GDPR violation and a PSD2 reimbursement claim are separate legal questions.
32. Banking Fraud and Money Laundering
Fraudulent transfers can overlap with anti-money-laundering obligations.
A bank may be required to:
conduct customer due diligence;
monitor transactions;
identify suspicious activity;
report suspicious transactions.
But AML obligations should not automatically be converted into a private damages claim.
A claimant must establish the applicable private-law basis and causation.
33. Bank's Liability vs Fraudster's Liability
The fraudster may be the primary wrongdoer.
But:
Fraudster liability ≠ bank liability
The bank's liability depends on:
payment-services legislation;
contract;
negligence;
authentication obligations;
information duties;
national banking law.
A victim may therefore have potentially separate claims against:
fraudster;
payment provider;
intermediary;
beneficiary bank;
insurer.
34. Defences Available to Banks
A bank may argue:
A. Transaction was authorised
The customer gave valid consent.
B. Customer acted fraudulently
The fraud was actually committed by the account holder.
C. Gross negligence
The customer seriously failed to protect security credentials.
D. Late notification
The statutory notification requirements were not satisfied.
E. No causal connection
The alleged bank failure did not cause the loss.
F. Transaction outside PSD2
The transaction or relationship may fall outside the relevant statutory scope.
G. Customer's own conduct
The customer voluntarily instructed the payment.
H. Limitation period
The claim was brought outside the applicable limitation period.
35. Defences Are Not Automatic
A bank cannot simply say:
“The correct PIN/OTP was used, therefore the customer authorised the transaction.”
The CJEU's jurisprudence rejects such a simplistic approach.
Under the earlier Directive, the payment provider had the evidential burden concerning authentication, accurate recording and absence of technical deficiency; use of a payment instrument alone was not necessarily sufficient to establish authorisation or fraud. (Eur-Lex)
36. Modern Phishing: Important 2026 Development
A particularly current issue is Tukowiecka, C-70/25.
The case concerns a Polish customer who was deceived by a fake website and disclosed banking credentials to a fraudster.
The Advocate General's Opinion of 5 March 2026 considered whether a bank could refuse the immediate refund required under PSD2 merely because the customer was allegedly grossly negligent. The case was still pending before the CJEU at the time of the Opinion. (curia)
Therefore, for a current legal analysis, it is important not to describe the Advocate General's Opinion as the final law of the CJEU.
37. Civil-Law Framework
Banking fraud claims can therefore involve several layers:
Contract law
Bank-account agreement and payment-service contract.
Payment-services law
PSD2 and national implementing legislation.
Tort/delict law
Negligent conduct causing financial loss.
Consumer law
Unfair contractual terms and information rights.
Agency law
Authority of employees and agents.
Company law
Corporate payment instructions and director/employee authority.
Data protection law
Personal data and security.
Criminal law
Fraud and cybercrime.
The claimant must identify which regime actually provides the remedy.
38. European Cross-Border Issues
Banking fraud frequently crosses borders.
Example:
Customer in France → French bank → fraudster in Spain → beneficiary bank in Germany → funds transferred to another country.
Issues include:
jurisdiction;
applicable law;
cross-border evidence;
freezing of funds;
recognition/enforcement;
beneficiary-bank obligations.
EU private international law and national procedural law become important.
39. Practical Legal Test
A European court can analyse a banking-fraud claim as follows:
Step 1 — Identify the transaction
Was it:
card payment?
bank transfer?
direct debit?
cash withdrawal?
electronic payment?
Step 2 — Was it authorised?
Did the customer actually consent?
Step 3 — Apply PSD2
Does the transaction fall within the Directive?
Step 4 — Examine authentication
How did the bank authenticate the transaction?
Step 5 — Determine burden of proof
What must the bank establish?
Step 6 — Examine customer conduct
Was there:
fraud?
intent?
gross negligence?
ordinary negligence?
Step 7 — Examine notification
When did the customer discover the transaction?
Step 8 — Establish causation
Who caused the loss?
Step 9 — Calculate damages
What amount is legally recoverable?
Step 10 — Consider additional national claims
Contract, tort, consumer, agency or other applicable law.
40. Example
Suppose a customer receives a fake bank message.
The customer clicks a fraudulent link and enters:
username;
password;
OTP.
The fraudster then transfers €50,000.
The customer reports the transaction the next morning.
The bank refuses reimbursement, saying:
“The customer gave the OTP, so the payment was authorised.”
The legal analysis would ask:
Was the transaction actually authorised?
What evidence proves consent?
What authentication occurred?
Was the transaction recorded correctly?
Did the bank comply with PSD2?
Did the customer act fraudulently?
Did the customer act with gross negligence?
Was notification prompt?
Does the statutory refund mechanism apply?
The answer cannot be determined merely from the fact that an OTP was used.
41. Case-Law Principles at a Glance
| Principle | Leading authority |
|---|---|
| Provider bears important proof obligations regarding unauthorised transactions | CRCAM, C-337/20 |
| Payment instrument use alone does not necessarily prove consent | Eurobank Bulgaria, C-409/22 |
| Bank must provide information identifying payment beneficiary | Beobank, C-351/21 |
| Payment-services liability regime can be fully harmonised | Beobank / CRCAM |
| Payment technology is covered by the PSD framework | DenizBank, C-287/19 |
| Delay in reporting an unauthorised transaction can defeat reimbursement | Veracash, C-665/23 |
| Fraud/gross negligence can shift losses to payer under statutory conditions | CRCAM / Veracash |
| Phishing and immediate-refund questions remain an important developing issue | Tukowiecka, C-70/25, pending |
42. Key Legal Distinctions
Fraud vs unauthorised transaction
Fraud may cause an unauthorised transaction, but not every fraudulent payment is legally classified in exactly the same way.
Authentication vs authorisation
Authentication: credentials/instrument verified.
Authorisation: customer consented to transaction.
Ordinary negligence vs gross negligence
Gross negligence has materially greater consequences under the PSD framework.
Regulatory breach vs private liability
A bank's regulatory breach does not automatically determine the amount of private compensation.
Fraudster liability vs bank liability
The fraudster's wrongdoing does not automatically establish the bank's liability.
43. Conclusion
Banking Fraud Liability Claims in Europe are increasingly governed by a sophisticated interaction between EU payment-services law and national civil law.
The central rule is:
For an unauthorised payment, the European payment-services regime generally places the initial financial risk on the payment service provider, while allowing the loss to shift to the payer in specified circumstances such as fraud or intentional/grossly negligent failure to comply with security obligations. (Eur-Lex)
The most important issues are:
Authorisation → Authentication → Burden of Proof → Customer Conduct → Notification → Causation → Refund → Damages
The principal authorities are:
DenizBank, C-287/19
CRCAM, C-337/20
Beobank, C-351/21
Eurobank Bulgaria, C-409/22
Veracash, C-665/23
Tukowiecka, C-70/25 — currently pending, with an Advocate General's Opinion but no final CJEU judgment as of September 2026. (Infocuria)
Together, these authorities establish the central European framework for determining when a bank must refund fraudulent transactions, when a customer may bear the loss, how authorisation is proved, and how modern phishing and electronic-payment fraud should be analysed under European civil and payment-services law.

comments