EU Banks May Be Required to Immediately Refund Phishing Victims
European Union banks could soon be obligated to immediately refund customers who fall victim to phishing scams, even if the customer bears some responsibility for the fraudulent transaction. This potential shift in liability stems from a recent opinion issued by Athanasios Rantos, Advocate General of the Court of Justice of the EU (CJEU).
The Case and the Advocate General’s Opinion
The case originated in Poland, involving a dispute between a customer and PKO BP S.A. Bank. The customer was tricked into entering their banking credentials on a fake website after responding to a phishing attempt related to an online auction. A fraudulent payment was then made from their account. While the customer reported the incident promptly, the bank refused to reimburse the lost funds, citing the customer’s negligence as the reason for denial.
Advocate General Rantos argues that, under the EU’s Payment Services Directive (PSD2), banks should prioritize immediate refunds to victims of unauthorized transactions. The Advocate General’s opinion, delivered on March 5, 2026, states that a bank cannot automatically refuse a refund based on alleged customer negligence [1].
Two-Step Process for Liability
However, the opinion doesn’t entirely absolve customers of responsibility. Banks will still be able to recover losses if they can demonstrate that the customer acted with either intentional misconduct or gross negligence in violating security protocols. This process is envisioned as a two-step system:
- Immediate Refund: The bank must first refund the unauthorized transaction amount without delay, unless there’s a strong suspicion of fraud on the customer’s part, which must be reported to the relevant national authority.
- Loss Recovery: The bank can then attempt to recover the funds from the customer if it can prove gross negligence or intentional wrongdoing [2]. If the customer refuses to reimburse the amount, the bank would necessitate to pursue legal action.
Implications and Next Steps
This opinion is a significant development for consumer protection in the EU. Currently, many victims of phishing and other payment scams face lengthy delays and denials of reimbursement while banks investigate and attempt to shift the blame. This ruling could streamline the process and provide quicker relief to those affected by fraud.
It’s important to note that the Advocate General’s opinion is not a final ruling. The CJEU judges will now deliberate on the case and their final decision will be binding on all EU courts. However, the Advocate General’s recommendations typically carry significant weight [3].
Recent Cybersecurity Threats
This news arrives amid a surge in sophisticated cyberattacks. Recent reports indicate that hackers are actively exploiting vulnerabilities in widely used software. For example, a zero-day exploit for a Windows Remote Desktop Services vulnerability (CVE-2026-21533) is reportedly being sold for $220,000 [2]. An Iran-linked hacking group, Seedworm, has infiltrated US organizations, raising concerns about potential large-scale cyber operations [2].
Related reading