Civil Law And Banking Fraud Liability Claims In Europe .

Civil Law and Banking Fraud Liability Claims in Europe

1. Introduction

Banking fraud liability in Europe concerns the civil consequences when fraudulent conduct causes financial loss through a bank account, payment card, electronic banking system, transfer, direct debit, online banking platform, or other payment service.

European banking-fraud disputes commonly involve:

unauthorised bank transfers;

stolen payment cards;

phishing;

identity theft;

account takeover;

forged payment instructions;

fraudulent direct debits;

mobile-payment fraud;

social-engineering scams;

fraudulent powers of attorney;

insider fraud;

failures in authentication or security;

fraud committed by third parties using banking infrastructure.

The most important European framework is the Payment Services Directive 2 (PSD2), Directive (EU) 2015/2366, together with national civil, banking and consumer law. PSD2 establishes a structured allocation of responsibility between the payment-service provider and the customer for unauthorised transactions. In particular, Article 73 generally requires immediate refund of an unauthorised transaction, while Article 74 addresses circumstances in which the payer bears losses, including fraud or intentional/grossly negligent failure to comply with security obligations. (Eur-Lex)

A central principle is:

The fact that a transaction was authenticated does not necessarily prove that the customer authorised it or acted fraudulently.

The CJEU has repeatedly placed significant importance on the payment provider's burden of proof and the distinction between authentication and authorisation. (Eur-Lex)

2. Meaning of Banking Fraud Liability

Banking fraud liability may arise when:

Fraudulent conduct + banking transaction + legal duty + loss + causation = potential civil liability

The fraud may be committed by:

an external fraudster;

an employee of the bank;

an agent;

a customer;

a third-party payment beneficiary;

an intermediary;

a cybercriminal;

an organised criminal group.

The bank's civil liability depends on the particular relationship and applicable statutory regime.

3. Major Types of Banking Fraud

A. Unauthorised payment fraud

A fraudster obtains access to a customer's account and makes transactions without the customer's consent.

Examples:

stolen card;

stolen credentials;

account takeover;

malware;

phishing.

This is the classic PSD2 liability situation.

B. Phishing fraud

The customer receives a fraudulent message directing them to a fake banking website.

The customer enters:

username;

password;

one-time code;

authentication credentials.

The fraudster then uses those credentials to make payments.

A major legal question is:

Does the customer's disclosure of credentials constitute gross negligence sufficient to shift the loss to the customer?

The answer depends on the applicable PSD2 rules and facts; it is not automatically yes merely because the customer interacted with a fraudster.

C. Social-engineering fraud

The fraudster manipulates the customer into authorising a payment.

For example:

Fraudster impersonates bank employee → customer believes the instruction is genuine → customer authorises transfer.

This raises a difficult distinction between:

Unauthorised transaction

The customer did not legally authorise the transaction.

and

Authorised payment induced by deception

The customer technically consented to the payment, but was deceived about its purpose or recipient.

The distinction is extremely important under PSD2.

4. PSD2 Liability Structure

The PSD2 framework generally divides the risk between the payment service provider and payer.

Payment service provider

Generally responsible for an unauthorised payment transaction and required to refund the payer, subject to the Directive's conditions.

Payer

May bear losses in specified circumstances, particularly where the payer:

acted fraudulently; or

intentionally or with gross negligence failed to comply with security obligations.

The Directive therefore does not create unlimited bank liability.

Nor does it make every customer who has been deceived automatically responsible for the loss.

5. Authentication vs Authorisation

This is one of the most important principles.

Authentication

The bank establishes that a particular payment instrument or security credential was used.

Authorisation

The customer actually gave consent to the payment transaction.

These are not necessarily the same thing.

The CJEU has explained that merely showing use of a payment instrument is not necessarily sufficient to establish that the payer authorised the transaction or acted fraudulently. (Eur-Lex)

Thus:

Authenticated ≠ automatically authorised.

6. Burden of Proof

Under the earlier Payment Services Directive 2007/64, which remains directly relevant to many older transactions, Article 59 placed significant evidential responsibility on the payment service provider.

Where the customer disputes authorisation, the provider had to prove that the transaction:

was authenticated;

was accurately recorded;

was entered into the accounts;

was not affected by a technical breakdown or other deficiency.

The use of the payment instrument itself was not necessarily enough to prove authorisation or fraud. (Eur-Lex)

The same general architecture is reflected in later CJEU jurisprudence concerning payment-service liability.

7. Important Case Law

1. DM and LR v Crédit Agricole — C-337/20

CJEU, 2 September 2021

Facts

The dispute concerned unauthorised payment transactions and the consequences of failing to notify the bank within the statutory period.

Principle

The CJEU held that the liability regime for unauthorised payment transactions under Directive 2007/64 was linked to the customer's obligation to notify the payment service provider.

The notification period was 13 months from the debit of the transaction. A user who failed to notify within that period could not use that statutory regime to obtain reimbursement. (Eur-Lex)

Importance

The case establishes:

Unauthorised-transaction liability depends not only on the fraud but also on timely notification.

It also confirms that the statutory regime is designed around a balance between:

provider information duties; and

customer notification duties.

8. ZG v Beobank — C-351/21

CJEU, 16 March 2023

This is one of the most important European banking-fraud decisions.

Facts

A Belgian customer had a debit card. Several transactions were made after an initial payment in Valencia, Spain. The customer disputed two subsequent transactions as unauthorised.

Legal issue

The case concerned the bank's obligations in relation to information about the recipient of the payment and the liability regime for unauthorised transactions.

Principle

The CJEU held that the payment service provider must provide information enabling the payer to identify the person who benefited from the transaction.

The Court also stressed that the PSD liability regime is harmonised and that national courts cannot simply create a competing liability regime for the same operative event in a manner incompatible with EU law.

Importance

The case demonstrates that banks have important information and transparency duties in fraud disputes.

9. UA v Eurobank Bulgaria — C-409/22

CJEU, 11 July 2024

Facts

The dispute involved payment transactions allegedly made on the basis of a power of attorney.

The account holder disputed that valid consent had been given.

Principle

The CJEU held that a formally regular power of attorney, even one bearing an apostille, does not by itself establish that the account holder consented to the payment transaction.

The payment service provider must establish that the user expressed agreement to the transaction in the form of consent required by the payment arrangement. (Eur-Lex)

Importance

The case gives a very important rule:

Formal validity of an authorisation document is not necessarily proof of payment authorisation.

This is particularly relevant to:

forged powers of attorney;

identity fraud;

corporate banking fraud;

agent fraud;

elderly-client fraud;

cross-border banking transactions.

10. Veracash — C-665/23

CJEU, 1 August 2025

This is a particularly important recent authority.

Facts

A customer disputed withdrawals made using a payment card and maintained that the card had not been received or used by him.

The customer did not notify the payment institution immediately.

Principle

The CJEU held that where a customer becomes aware of an unauthorised payment transaction but delays notification with intent or gross negligence, the customer can lose the right to obtain reimbursement of the transaction even if notification occurs within the overall 13-month period. (curia)

Importance

The case demonstrates that there are two distinct time considerations:

the overall statutory notification period; and

the requirement to notify without undue delay once the customer becomes aware of the fraud.

11. DenizBank AG v Verein für Konsumenteninformation — C-287/19

CJEU, 11 November 2020

Facts

The case concerned contactless bank cards, payment instruments and the PSD2 framework.

Principle

The CJEU examined:

the meaning of a payment instrument;

contactless payments;

low-value payment instruments;

information obligations;

liability allocation;

consumer protection.

The case confirms that the concept of payment instrument under PSD2 must be interpreted in accordance with the Directive's technological and legal framework. (Infocuria)

Importance

It demonstrates that European banking-fraud liability must adapt to new payment technologies.

12. Beobank and the Full-Harmonisation Principle

The importance of Beobank extends beyond the facts.

The CJEU stressed that the liability regime for unauthorised payment transactions under Directive 2007/64 was fully harmonised.

Consequently, a national court cannot simply replace the EU statutory allocation of risk with a different national liability theory concerning the same operative event if that would undermine the EU regime.

This matters greatly in civil litigation because a claimant cannot necessarily avoid the PSD framework simply by relabelling the claim as:

negligence;

breach of contract;

general banking duty;

information failure.

The precise interaction with national law depends on the facts and applicable EU provision.

13. CRCAM — C-337/20

The Crédit Agricole case is particularly important for the relationship between statutory payment liability and general civil law.

The CJEU explained that the statutory payment-services regime is based on a balance between:

Bank's information obligation

and

Customer's obligation to report unauthorised transactions.

If the customer does not comply with the statutory notification requirement, the customer cannot simply invoke the statutory refund mechanism through general law to bypass that requirement. (Eur-Lex)

14. Case-Law Summary Table

CaseYearMain principleBanking-fraud relevance
CRCAM, C-337/202021Timely notification of unauthorised transactionsCustomer's notification duty
DenizBank, C-287/192020Payment instruments and contactless paymentsTechnological payment fraud
Beobank, C-351/212023Information about payment beneficiary; harmonised liability regimeBank information duties
Eurobank Bulgaria, C-409/222024Formal power of attorney does not itself prove consentIdentity/authorisation fraud
Veracash, C-665/232025Grossly negligent delay in notification can defeat reimbursementCustomer conduct and fraud losses
Tukowiecka, C-70/25Pending; AG Opinion 2026Phishing and immediate-refund question under PSD2Modern phishing fraud

Important: Tukowiecka should currently be treated as a pending CJEU case with an Advocate General's Opinion, not as a final judgment. The case concerns a phishing victim and whether a bank may refuse immediate reimbursement because of alleged gross negligence. (Infocuria)

15. Phishing Fraud

Phishing presents one of the most difficult modern banking-fraud problems.

Typical structure:

Fraudulent message

↓

Fake banking website

↓

Customer enters credentials

↓

Fraudster obtains authentication information

↓

Fraudster initiates payment

↓

Customer disputes transaction

The bank may argue:

“The customer disclosed the credentials and therefore acted with gross negligence.”

The customer may respond:

“The transaction itself was never authorised.”

The legal question depends upon the applicable PSD2 provisions and evidence.

16. Strong Customer Authentication

PSD2 introduced strong customer authentication (SCA) requirements for many electronic payment transactions.

SCA generally relies on at least two elements belonging to different categories, such as:

knowledge;

possession;

inherence.

Examples include:

password + mobile device;

card + PIN;

device + biometric authentication.

However:

Strong authentication is a security mechanism, not conclusive proof that the customer genuinely intended the transaction.

The distinction between authentication and consent remains central.

17. Customer Gross Negligence

The customer may bear losses where the statutory conditions concerning fraud or intentional/grossly negligent failure to comply with security obligations are satisfied.

Gross negligence is more serious than ordinary carelessness.

Factors potentially relevant include:

whether the customer ignored obvious warnings;

whether credentials were deliberately disclosed;

whether the customer responded to a suspicious request;

whether the fraudster impersonation was sophisticated;

whether the customer reasonably believed the communication was genuine;

whether the bank provided adequate warnings;

whether the customer reported the fraud promptly.

The factual circumstances therefore matter substantially.

18. Bank's Security Duties

A bank's obligations may include:

authentication;

transaction monitoring;

fraud detection;

secure payment infrastructure;

customer notification;

transaction information;

blocking mechanisms;

reporting channels;

appropriate security procedures.

However, a bank is not necessarily an insurer against every form of fraud.

The statutory payment regime establishes the specific allocation of risks.

19. Fraud Detection Systems

Modern banks use:

AI fraud detection;

behavioural analytics;

device fingerprinting;

transaction monitoring;

geolocation;

velocity controls;

anomaly detection;

risk scoring.

A bank may face civil questions where its security systems fail to operate as legally required.

For example:

Multiple abnormal transactions

  •  

unusual geographic location

  •  

unusual transaction size

  •  

multiple rapid transfers

could raise questions concerning the bank's fraud-monitoring procedures.

But the claimant must establish the legal duty and applicable liability framework; an algorithm's failure alone does not automatically create damages liability.

20. Authorised Push Payment (APP) Fraud

APP fraud is particularly difficult.

Example:

Fraudster impersonates a genuine supplier → business believes the invoice is genuine → business itself instructs bank to transfer €100,000.

The bank may argue:

The payment was authorised.

The customer may argue:

Consent was obtained through fraud.

This creates a legal distinction between:

Transaction authorisation

The payment instruction came from the account holder.

and

Transaction purpose

The account holder did not intend to transfer money to the fraudster.

The legal treatment of APP fraud varies across European jurisdictions and has also developed through national statutory and regulatory reforms. It should not automatically be treated as identical to an unauthorised-payment claim under PSD2.

21. Fraudulent Direct Debits

Fraud may occur through unauthorised direct debits.

The legal analysis may concern:

whether the mandate existed;

whether consent was given;

whether the payment was properly authenticated;

refund rights;

notification;

bank obligations;

merchant/creditor responsibility.

The payment-services framework can provide significant protections, but the exact statutory mechanism depends on the payment type.

22. Corporate Banking Fraud

Corporate fraud creates additional complexity.

Example:

Employee fraudulently instructs bank to transfer company funds.

Questions include:

Was the employee authorised?

Was the payment instruction genuine?

Was the employee acting within apparent authority?

Did the bank reasonably rely on the instruction?

Was there an internal-control failure?

Did the company negligently disclose credentials?

Does PSD2 apply directly?

Does national company/agency law apply?

The Eurobank Bulgaria reasoning concerning proof of consent is especially relevant to questions of authority and authorisation. (Eur-Lex)

23. Forged Signatures and Powers of Attorney

Bank fraud may involve:

forged signatures;

forged corporate resolutions;

fraudulent powers of attorney;

stolen identity documents;

false certificates.

The Eurobank Bulgaria case is particularly useful because the CJEU rejected the idea that formal regularity alone proves that the account holder consented to the payment. (Eur-Lex)

Thus:

Documentary authenticity and actual payment authorisation are separate questions.

24. Identity Theft

Identity theft can involve:

opening fraudulent bank accounts;

obtaining loans;

changing account details;

withdrawing funds;

creating fraudulent payment instructions.

Civil claims may involve:

bank;

fraudster;

credit-information provider;

payment provider;

other financial institution.

Evidence may include:

KYC documents;

authentication logs;

IP addresses;

device information;

call recordings;

transaction records;

biometric information;

digital signatures.

25. Bank Employee Fraud

Where a bank employee commits fraud, potential liability may arise through:

employment/agency principles;

vicarious liability under national law;

contractual banking duties;

negligence;

regulatory obligations.

The bank's liability will depend on whether the employee was acting within the scope of employment and the applicable national law.

PSD2's unauthorised-payment regime may also apply where the transaction falls within its scope.

26. Bank Negligence and Fraud Prevention

A claimant may allege that a bank:

failed to detect suspicious transactions;

failed to apply required authentication;

failed to provide security mechanisms;

failed to notify the customer;

failed to block a clearly abnormal transaction;

failed to provide adequate information.

But the claim must be connected to the applicable statutory regime.

The Beobank judgment illustrates that information duties and reimbursement liability must be analysed within the harmonised payment-services framework rather than simply treated as unrestricted national negligence claims.

27. Causation

Banking fraud disputes require careful causation analysis.

For example:

Bank security failure

↓

Fraudulent payment

↓

Financial loss

This is comparatively straightforward.

But:

Customer voluntarily authorises transfer after fraudster's deception

↓

Money transferred

↓

Fraud discovered

↓

Bank argues transaction was authorised

creates a more difficult question concerning the statutory classification of the transaction.

28. Damage

Potential recoverable losses may include:

Direct financial loss

Money removed from the account.

Interest

Interest lost or incurred because of the fraud.

Bank charges

Fraud-related fees where legally recoverable.

Consequential loss

Potentially recoverable under applicable national law.

Business losses

For corporate customers, additional losses may arise from interruption of operations.

Non-material damage

Potentially relevant under national law in appropriate circumstances, although not automatically recoverable under the PSD2 refund regime itself.

29. Notification Requirement

Prompt notification is critical.

Under the earlier Directive, Article 58 required notification of unauthorised or incorrectly executed transactions no later than 13 months after the relevant debit. (Eur-Lex)

The Veracash judgment additionally demonstrates the importance of the requirement to act without undue delay once the customer becomes aware of the transaction. (curia)

Therefore:

A customer should not wait merely because the statutory outside period has not expired.

30. Evidence in Banking-Fraud Litigation

Important evidence includes:

Banking records

transaction history;

account statements;

payment instructions;

beneficiary information.

Authentication records

OTP logs;

PIN authentication;

biometric records;

device authentication;

SCA records.

Technical records

IP address;

device ID;

geolocation;

session logs;

fraud-monitoring alerts.

Communication records

SMS;

email;

bank messages;

telephone recordings.

Identity records

KYC documents;

signatures;

powers of attorney.

Customer evidence

police reports;

fraud notifications;

chronology;

correspondence with bank.

31. Banking Fraud and Data Protection

Banking fraud often involves personal data.

A fraud investigation may involve:

transaction monitoring;

IP addresses;

device information;

biometric data;

identity information.

This can raise GDPR issues concerning:

lawful processing;

security;

access rights;

data retention;

automated decision-making.

However, a GDPR violation and a PSD2 reimbursement claim are separate legal questions.

32. Banking Fraud and Money Laundering

Fraudulent transfers can overlap with anti-money-laundering obligations.

A bank may be required to:

conduct customer due diligence;

monitor transactions;

identify suspicious activity;

report suspicious transactions.

But AML obligations should not automatically be converted into a private damages claim.

A claimant must establish the applicable private-law basis and causation.

33. Bank's Liability vs Fraudster's Liability

The fraudster may be the primary wrongdoer.

But:

Fraudster liability ≠ bank liability

The bank's liability depends on:

payment-services legislation;

contract;

negligence;

authentication obligations;

information duties;

national banking law.

A victim may therefore have potentially separate claims against:

fraudster;

payment provider;

intermediary;

beneficiary bank;

insurer.

34. Defences Available to Banks

A bank may argue:

A. Transaction was authorised

The customer gave valid consent.

B. Customer acted fraudulently

The fraud was actually committed by the account holder.

C. Gross negligence

The customer seriously failed to protect security credentials.

D. Late notification

The statutory notification requirements were not satisfied.

E. No causal connection

The alleged bank failure did not cause the loss.

F. Transaction outside PSD2

The transaction or relationship may fall outside the relevant statutory scope.

G. Customer's own conduct

The customer voluntarily instructed the payment.

H. Limitation period

The claim was brought outside the applicable limitation period.

35. Defences Are Not Automatic

A bank cannot simply say:

“The correct PIN/OTP was used, therefore the customer authorised the transaction.”

The CJEU's jurisprudence rejects such a simplistic approach.

Under the earlier Directive, the payment provider had the evidential burden concerning authentication, accurate recording and absence of technical deficiency; use of a payment instrument alone was not necessarily sufficient to establish authorisation or fraud. (Eur-Lex)

36. Modern Phishing: Important 2026 Development

A particularly current issue is Tukowiecka, C-70/25.

The case concerns a Polish customer who was deceived by a fake website and disclosed banking credentials to a fraudster.

The Advocate General's Opinion of 5 March 2026 considered whether a bank could refuse the immediate refund required under PSD2 merely because the customer was allegedly grossly negligent. The case was still pending before the CJEU at the time of the Opinion. (curia)

Therefore, for a current legal analysis, it is important not to describe the Advocate General's Opinion as the final law of the CJEU.

37. Civil-Law Framework

Banking fraud claims can therefore involve several layers:

Contract law

Bank-account agreement and payment-service contract.

Payment-services law

PSD2 and national implementing legislation.

Tort/delict law

Negligent conduct causing financial loss.

Consumer law

Unfair contractual terms and information rights.

Agency law

Authority of employees and agents.

Company law

Corporate payment instructions and director/employee authority.

Data protection law

Personal data and security.

Criminal law

Fraud and cybercrime.

The claimant must identify which regime actually provides the remedy.

38. European Cross-Border Issues

Banking fraud frequently crosses borders.

Example:

Customer in France → French bank → fraudster in Spain → beneficiary bank in Germany → funds transferred to another country.

Issues include:

jurisdiction;

applicable law;

cross-border evidence;

freezing of funds;

recognition/enforcement;

beneficiary-bank obligations.

EU private international law and national procedural law become important.

39. Practical Legal Test

A European court can analyse a banking-fraud claim as follows:

Step 1 — Identify the transaction

Was it:

card payment?

bank transfer?

direct debit?

cash withdrawal?

electronic payment?

Step 2 — Was it authorised?

Did the customer actually consent?

Step 3 — Apply PSD2

Does the transaction fall within the Directive?

Step 4 — Examine authentication

How did the bank authenticate the transaction?

Step 5 — Determine burden of proof

What must the bank establish?

Step 6 — Examine customer conduct

Was there:

fraud?

intent?

gross negligence?

ordinary negligence?

Step 7 — Examine notification

When did the customer discover the transaction?

Step 8 — Establish causation

Who caused the loss?

Step 9 — Calculate damages

What amount is legally recoverable?

Step 10 — Consider additional national claims

Contract, tort, consumer, agency or other applicable law.

40. Example

Suppose a customer receives a fake bank message.

The customer clicks a fraudulent link and enters:

username;

password;

OTP.

The fraudster then transfers €50,000.

The customer reports the transaction the next morning.

The bank refuses reimbursement, saying:

“The customer gave the OTP, so the payment was authorised.”

The legal analysis would ask:

Was the transaction actually authorised?

What evidence proves consent?

What authentication occurred?

Was the transaction recorded correctly?

Did the bank comply with PSD2?

Did the customer act fraudulently?

Did the customer act with gross negligence?

Was notification prompt?

Does the statutory refund mechanism apply?

The answer cannot be determined merely from the fact that an OTP was used.

41. Case-Law Principles at a Glance

PrincipleLeading authority
Provider bears important proof obligations regarding unauthorised transactionsCRCAM, C-337/20
Payment instrument use alone does not necessarily prove consentEurobank Bulgaria, C-409/22
Bank must provide information identifying payment beneficiaryBeobank, C-351/21
Payment-services liability regime can be fully harmonisedBeobank / CRCAM
Payment technology is covered by the PSD frameworkDenizBank, C-287/19
Delay in reporting an unauthorised transaction can defeat reimbursementVeracash, C-665/23
Fraud/gross negligence can shift losses to payer under statutory conditionsCRCAM / Veracash
Phishing and immediate-refund questions remain an important developing issueTukowiecka, C-70/25, pending

42. Key Legal Distinctions

Fraud vs unauthorised transaction

Fraud may cause an unauthorised transaction, but not every fraudulent payment is legally classified in exactly the same way.

Authentication vs authorisation

Authentication: credentials/instrument verified.

Authorisation: customer consented to transaction.

Ordinary negligence vs gross negligence

Gross negligence has materially greater consequences under the PSD framework.

Regulatory breach vs private liability

A bank's regulatory breach does not automatically determine the amount of private compensation.

Fraudster liability vs bank liability

The fraudster's wrongdoing does not automatically establish the bank's liability.

43. Conclusion

Banking Fraud Liability Claims in Europe are increasingly governed by a sophisticated interaction between EU payment-services law and national civil law.

The central rule is:

For an unauthorised payment, the European payment-services regime generally places the initial financial risk on the payment service provider, while allowing the loss to shift to the payer in specified circumstances such as fraud or intentional/grossly negligent failure to comply with security obligations. (Eur-Lex)

The most important issues are:

Authorisation → Authentication → Burden of Proof → Customer Conduct → Notification → Causation → Refund → Damages

The principal authorities are:

DenizBank, C-287/19

CRCAM, C-337/20

Beobank, C-351/21

Eurobank Bulgaria, C-409/22

Veracash, C-665/23

Tukowiecka, C-70/25 — currently pending, with an Advocate General's Opinion but no final CJEU judgment as of September 2026. (Infocuria)

Together, these authorities establish the central European framework for determining when a bank must refund fraudulent transactions, when a customer may bear the loss, how authorisation is proved, and how modern phishing and electronic-payment fraud should be analysed under European civil and payment-services law.

LEAVE A COMMENT