EU Banks Must Immediately Refund Phishing Victims, Even If It’s Your Fault: Court Advisor Opinion

San Francisco, CA – Consumers across the European Union may soon see faster reimbursements for funds lost to online fraud, following a significant opinion released by a top legal advisor at the European Court of Justice (ECJ). Advocate General Athanasios Rantos has suggested that banks should be required to immediately refund victims of unauthorized transactions, even in cases where the customer’s own actions contributed to the loss. This potential shift in responsibility could have a substantial impact on both consumers and financial institutions operating within the EU.

The case originated in Poland, stemming from a dispute between PKO BP S.A. Bank and one of its customers who fell victim to a sophisticated phishing scam. The customer, attempting to sell an item online, was tricked into entering their banking credentials on a fraudulent website disguised as their bank’s legitimate login page. This allowed a fraudster to execute an unauthorized payment. Despite reporting the incident promptly to both the bank and the police, the customer’s claim for a refund was initially denied, prompting legal action. The core of the dispute centered on whether the bank could legitimately refuse reimbursement due to the customer’s perceived negligence in falling for the phishing attempt.

Advocate General Rantos’s opinion, delivered on March 6, 2026, interprets the EU’s Payment Services Directive (PSD2) – specifically Directive 2015/2366 – as prioritizing swift action to protect consumers. According to the official press release from the CJEU, the directive dictates that banks must, as a first step, refund the full amount of the unauthorized transaction unless they possess “good reason to suspect fraud” and can communicate this suspicion in writing to the relevant national authority. This represents a significant leaning towards consumer protection, potentially reshaping the landscape of liability for online fraud within the EU.

The European Union flag, representing the jurisdiction impacted by the Advocate General’s opinion.

The PSD2 Directive and the Shifting Burden of Proof

The Payment Services Directive 2 (PSD2), implemented in 2018, aimed to modernize payment services and enhance consumer protection within the EU. It established a framework for regulating payment institutions and promoting innovation in the financial sector. A key component of PSD2 concerns liability for unauthorized transactions. Prior to this opinion, banks often relied on clauses attributing responsibility to customers if negligence was involved. Rantos’s interpretation suggests a more proactive approach, placing the initial burden of refunding the customer on the bank, with the possibility of later recovery under specific circumstances.

However, the Advocate General’s opinion doesn’t represent a complete removal of customer responsibility. Banks retain the right to seek reimbursement from the customer if they can demonstrate “gross negligence or intention” on the part of the customer that directly led to the security breach. This means that if a bank can prove a customer flagrantly disregarded security protocols – for example, sharing their PIN with someone or ignoring repeated security warnings – they may be able to recover the lost funds. The bank would then need to pursue legal action to obtain payment from the customer. This two-step process – immediate refund followed by potential recovery – is central to Rantos’s proposed interpretation of PSD2.

What Constitutes “Gross Negligence”?

Defining “gross negligence” will likely be a key point of contention as this case progresses. Legal experts anticipate that the CJEU will need to provide further clarification on what level of carelessness justifies shifting the financial burden back to the consumer. The full text of the Advocate General’s opinion details that this negligence must relate to “personalised security data,” such as PINs, passwords, or other authentication methods. Simply falling for a sophisticated phishing scam, even if preventable with greater vigilance, may not automatically qualify as gross negligence.

This distinction is crucial. The opinion acknowledges the increasing sophistication of online fraud techniques. Phishing attacks are becoming increasingly difficult to detect, even for tech-savvy individuals. Attributing blame solely to the customer for falling victim to a well-crafted scam could be seen as unfair. The Advocate General’s stance suggests a recognition of this evolving threat landscape and a desire to protect consumers from bearing the full cost of increasingly complex fraudulent activities.

Impact on Banks and Consumers

If the CJEU adopts Rantos’s opinion, the implications for banks across the EU could be significant. Banks may need to adjust their internal procedures to ensure swift refunds are processed, potentially requiring increased staffing and investment in fraud detection systems. They may also face increased financial losses in the short term, as they will be required to refund unauthorized transactions more readily. However, proponents of the change argue that it will incentivize banks to invest more heavily in security measures to prevent fraud in the first place, ultimately benefiting both themselves and their customers.

For consumers, the ruling, if upheld, offers a greater degree of financial protection against online fraud. It reduces the risk of being left to bear the full cost of unauthorized transactions, even if they inadvertently contributed to the security breach. This could foster greater confidence in online banking and payment systems, encouraging wider adoption of digital financial services. However, it’s important to remember that consumers will still be held accountable for demonstrably negligent behavior, and maintaining strong security practices remains paramount.

The Next Steps in the Legal Process

It’s crucial to understand that the Advocate General’s opinion is not a binding ruling. It serves as a legal recommendation to the judges of the CJEU. The court is now expected to deliberate on the case and issue a final judgment in the coming months. While the CJEU is not obligated to follow the Advocate General’s opinion, it typically does so in a significant majority of cases. A final ruling is anticipated before the end of 2026.

The case, originating from the District Court in Koszalin, Poland, highlights the growing need for clarity on liability for online fraud within the EU. The CJEU’s decision will set a precedent for similar cases across all member states, shaping the future of consumer protection in the digital financial landscape. Financial institutions and consumers alike are closely watching the proceedings, awaiting a resolution that balances the need for security with the imperative of protecting individuals from the financial consequences of increasingly sophisticated cybercrime.

The ruling will likely prompt a review of existing fraud prevention strategies and customer agreements across the EU banking sector. Banks may need to enhance their customer education programs, providing clearer guidance on how to identify and avoid phishing scams and other fraudulent activities. The decision could accelerate the adoption of stronger authentication methods, such as multi-factor authentication, to mitigate the risk of unauthorized access to accounts.

As the digital world continues to evolve, so too must the legal frameworks that govern it. This case underscores the importance of adapting regulations to address the ever-changing threats posed by cybercriminals and ensuring that consumers are adequately protected in the online environment.

The Advocate General’s opinion represents a potentially significant step towards a more consumer-friendly approach to online fraud liability within the EU. The final ruling from the CJEU will be closely watched by stakeholders across the financial industry and will undoubtedly shape the future of digital banking and payment security for years to arrive.

Stay tuned to World Today Journal for further updates on this developing story as the CJEU prepares to deliver its final judgment.

Leave a Comment