CEO fraud or invoice fraud: when the bank is liable in Spain
Last updated 2026-10-01 · Reviewed by Jaime Piñeira Pardo, registered with the ICAM bar, no. 138826
The short answer
In Spain, bank liability for CEO fraud or invoice fraud is claimed against the company's own bank. For euro transfers within the EU ordered since 9 October 2025, the bank had to check the payee's name against the IBAN and warn you if they did not match; if it failed to, it must refund. Notify the bank now, and in any event within thirteen months of the debit. The court claim, before the civil section of the Tribunal de Instancia (Spain's first-instance court), is time-barred after five years.
Your company, a distributor with thirty employees, receives a change of bank details notice in the same email thread its usual supplier uses to send its invoices, with an account ownership certificate that looks genuine and a new IBAN from another EU country. The accounts team updates the supplier record and pays two invoices, totalling 48,600 euros, through online banking. Three weeks later the supplier demands payment: it had never changed its account, and its email had been compromised. Nobody remembers any warning on the bank's screen, and at the branch you are told that the order was given by your company with its own credentials and that the IBAN was correct. In the CEO fraud variant, with an urgent and confidential email from the chief executive, the questions are the same, with one decisive difference.
The case, in five lines
- What is brought
- Contractual liability action against the company's bank (arts. 1101 and 1104 of the Civil Code), for the refund required by Article 5c(8) of Regulation (EU) 260/2012 if the name and IBAN check was not carried out or failed, or for lack of the required diligence. In addition, a tort action (art. 1902 of the Civil Code) against the bank holding the destination account and, if the breach was on its side, against the supplier.
- Before which court
- The civil section of the Tribunal de Instancia (the first-instance court) for the bank's domicile, or for the place where the relationship arose if the bank has a branch there (art. 51.1 of the Civil Procedure Act, LEC); a jurisdiction clause in a standard-form contract is not valid (art. 54.2 LEC). Above 15,000 euros, ordinary proceedings, with appeal to the Audiencia Provincial (the provincial appeal court). Against a bank in another EU Member State, jurisdiction is set by the Brussels I bis Regulation.
- Deadline
- Notice to the bank without undue delay and, at the latest, thirteen months from the debit date (art. 43 of Royal Decree-law 19/2018), or the different period set in the contract, which article 34 allows to be agreed with a non-consumer. The action against the company's own bank is time-barred after five years (art. 1964.2 of the Civil Code); the tort action against the destination bank or the supplier, one year after the company learnt of the loss (art. 1968.2 of the Civil Code). Both limitation periods are interrupted by an out-of-court claim (art. 1973 of the Civil Code).
- Who can bring it
- Claimants: the paying company, acting through its management body, and its insurer to the extent it has paid out (art. 43 of the Insurance Contract Act, LCS). Defendants: the company's bank; the bank holding the destination account, for its own fault; the supplier whose email was compromised, if the breach was on its side; and the holder of the account that received the money.
- Financial risk
- If the claim is dismissed in full, the company pays the costs, with professional fees capped at one third of the amount in dispute (art. 394.3 LEC), unless the case raised serious doubts of fact or law; if the bank refused to negotiate beforehand, the company is exempt from costs, save in cases of abuse (art. 394.4 LEC). Where both sides were at fault, the court may reduce the award (art. 1103 of the Civil Code). A precautionary attachment requires security, which covers any loss caused if the measure is lifted.
A payment order induced by deception is not an unauthorised transaction
This is the first mistake, and the costliest. In CEO or invoice fraud nobody stole the credentials: one of your employees was tricked into entering the IBAN and signing the order. Framing it as an unauthorised transaction (the phishing route, in which the bank must refund by the end of the next business day at the latest) runs up against the bank's records, which will show that the order was placed through your online banking with the credentials of the person entitled to give it.
The legal starting point is uncomfortable. Article 59 of Royal Decree-law 19/2018 states that, where an order is executed in accordance with the unique identifier, it is deemed correctly executed with regard to the payee specified by that identifier, and that if the identifier provided is incorrect the bank is not liable for defective execution. For years that rule shut the door: the IBAN prevailed, even if the name typed was your supplier's and the account belonged to someone else.
Yet the same article imposes two duties that article 34 does not allow to be excluded by contract. The payer's bank must make reasonable efforts to recover the funds, with the cooperation of the payee's bank, and if it fails it must give you, on written request, all the information it holds that is relevant for you to bring a legal claim. A bank that took two days to ask the destination bank for the money back, or that refuses to give the account holder's details, already has a specific breach to explain.
Since 9 October 2025 the bank must check the name against the IBAN
Regulation (EU) 2024/886 inserted Article 5c into Regulation 260/2012, binding on banks in the euro area since 9 October 2025. Before you can authorise a transfer, your bank must check whether the IBAN matches the payee name entered (known as Verification of Payee, or VoP), whatever the channel, including at a branch. If they do not match, it must warn you that the money may go to an account that does not belong to the person you think; if they are a close match, it must show you the actual account holder's name.
Paragraph 8 of Article 5c allocates liability with a clarity that article 59 lacked. A bank that carried out the check is not liable for the transfer to an unintended payee. One that did not, or did it badly, and thereby caused a defective transaction, must refund without delay and restore the account. If the failure lay with the destination bank in answering the query, that bank must compensate the payer's bank, which is why the refund is claimed from your own bank. Any other loss may be compensated under the law governing the contract.
Two limits are worth knowing from the outset. The check is required for euro transfers between institutions located in the EU: a dollar payment to Hong Kong does not go through that filter. And if your employee saw the warning that the name did not match and authorised the transfer anyway, the bank has complied and this route is closed. That is why the case starts by asking the bank for the record of the check: what name was entered, what result the system returned and what the person who signed the order saw on screen.
CEO fraud and invoice fraud cases are not won on the same argument
In invoice fraud, your employee types the name of your usual supplier next to the new IBAN. As the destination account is usually in a third party's name, the check should have returned a mismatch, and if the bank did not run it, or the warning never reached the screen, the paragraph 8 refund is the core argument. If the fraudster opened the account in your supplier's name with forged documents, the check will return a match and the problem moves to the destination bank.
In CEO fraud, by contrast, the fake chief executive gives your employee the exact name of the shell company holding the account, and the check returns a match. There the claim rests on the diligence required of a professional, which article 1104 of the Civil Code measures by the nature of the obligation and the circumstances of the persons, time and place. A first transfer to a new payee abroad, for an amount that breaks the account's pattern and ordered in a rush, is exactly the kind of signal a bank's fraud controls exist to detect.
It is a harder argument, and that is worth knowing before suing. A company is expected to have its own controls, such as dual authorisation or a call-back to a number already on file, and if it skipped them the court will weigh the fault of both. Article 1103 of the Civil Code allows liability arising from negligence to be moderated, so the loss may end up being shared. Preparing the claim with that in mind, and proving the bank's failings first, is what makes it winnable.
What a business banking contract may have taken away, and what it cannot
A company is not a consumer, and article 34 of Royal Decree-law 19/2018 takes advantage of that: if the user is neither a consumer nor a microenterprise, the contract may exclude, wholly or partly, among other provisions, the burden of proof that article 44 places on the bank and the bank's liability for defective execution under articles 60 and 61. That exclusion may be buried in a clause nobody read, so the first step is to read the framework contract and the online banking terms.
The exception favours small businesses. Under article 3.25, a microenterprise is one that, on the date of the payment services contract, employed fewer than ten persons and whose annual turnover or annual balance sheet total did not exceed two million euros, and those exclusions cannot be agreed with it. What can be agreed with any business is a notice period different from the thirteen months of article 43: if it is shorter, that is the one to watch.
The name and IBAN check is a different matter: it is imposed by a directly applicable EU regulation, which only allows a non-consumer to opt out of the service when submitting multiple payment orders as a bundle, with the right to opt back in at any time. If your company pays by batch files, you must check whether it signed that opt-out and whether the bank warned it, as paragraph 7 requires, of the risk that the money ends up in an account not held by the payee indicated. Outside that case, the regulation does not provide for the contract to exclude the refund.
The destination bank and the real supplier: separate fronts, each with its own deadline
The bank that opened the destination account has no contract with your company: it is only liable under article 1902 of the Civil Code if its fault is proved and that fault caused the loss. Law 10/2010 on the prevention of money laundering requires it to identify the account holder from reliable documents (art. 3), to carry out ongoing monitoring of the business relationship (art. 6) and to give special scrutiny to unusual transactions or those showing signs of fraud (art. 17), but invoking it is not enough: you must prove, for instance, that the account was opened with forged documents or was emptied within hours without anyone examining it.
That action is time-barred one year after your company learnt of the loss (art. 1968.2 of the Civil Code), and it is the most treacherous deadline, because it is tempting to wait for the criminal case while the year runs. The limitation period is interrupted by an out-of-court claim (art. 1973 of the Civil Code) or by the request to negotiate under article 7 of Organic Law 1/2025. If that bank is in another EU Member State, the general rule is to sue it where it is domiciled (art. 4 of the Brussels I bis Regulation): according to the Court of Justice of the EU (CJEU), a loss merely reflected in a Spanish account is not enough, on its own, to sue in Spain, and the special jurisdiction rules for consumers (arts. 17 and 18) do not cover a company.
With the supplier the problem is the reverse: it is still demanding payment of the invoice. Article 1162 of the Civil Code requires payment to the creditor or to someone authorised to receive it on its behalf, and the fraudster was not. Your company can rely on article 1164, which releases a debtor who pays in good faith to the person in possession of the credit, or claim against the supplier for its lack of security. The IT expert evidence decides it: if the email came from the supplier's genuine mailbox, the argument gains strength against it; if it came from a look-alike domain, or the compromised mailbox was your own company's, the risk falls on you.
What cannot wait: recovery, insurance and prior negotiation
The first hours are worth more than the best lawsuit. You must ask your bank in writing to request the return of the funds from the destination bank and record the time; if the money is still in the account, the receiving bank may hold it while it examines the transaction, although returning it usually requires its customer's consent or a court order. The fraud is reported to the police, and we draft the report. If funds are traced, a precautionary attachment against the holder can be sought before the claim is filed (arts. 727 and 730.2 LEC), with security.
If the company has cyber or crime (fraud) insurance with social engineering cover, the loss must be notified within seven days of becoming known, unless the policy allows longer (art. 16 LCS). An insurer that pays is subrogated to the claims against the bank up to the amount paid, and your company is liable for any harm it causes to that right (art. 43 LCS). That is why no partial refund with a waiver should be signed with the bank without involving the insurer.
Before suing, article 5 of Organic Law 1/2025 requires recourse to an appropriate dispute resolution method on the same subject matter. The shortcut in its seventh additional provision, which treats the requirement as met by the prior complaint to the institution, is headed ‘Litigios en materia de consumo’ (consumer disputes), and a company should not rely on it: a formal negotiation should be opened instead, with proof of receipt (art. 10). It is not needed for a precautionary attachment sought before the claim or for preliminary inquiries (art. 5.3). With no answer within thirty calendar days, the negotiation ends without agreement; and if the bank refused to negotiate, your company is exempt from costs save for abuse (art. 394.4 LEC).
How we run the case, step by step
- 1
Today: written notice to the bank and a request to recall the funds
We notify your bank of the fraud in writing, recording the time, and ask it to recall the funds from the destination bank immediately and to block any further payment to that IBAN. That notice triggers the duty to recover under article 59 and is what counts for the notice deadline.
- 2
Police report and forensic copy of the emails
We draft the report, which the company files at a police station, a Guardia Civil post (Spain's national gendarmerie) or the duty court. At the same time, the IT expert we work with makes a forensic copy of the mailboxes and the email headers before anyone touches the computers: that copy is what shows where the breach occurred.
- 3
Notice to the insurer within seven days
If there is a cyber or crime (fraud) policy, we notify the loss within the period in article 16 LCS or any longer one set by the policy, and we coordinate with the insurer any negotiation with the bank, so as not to prejudice its subrogation rights.
- 4
Request for the payee check record and the destination account details
We request in writing the verification of payee record, the framework contract, any opt-out from the check for batch payments and, under article 59, the details needed to claim against the account holder. The customer service department must answer within fifteen business days (art. 69 of Royal Decree-law 19/2018). If the bank does not provide the details, preliminary inquiries can be sought (art. 256 LEC), although their use against a third party is disputed.
- 5
Precautionary attachment if the money is traced
If funds remain in the destination account or in another to which they were moved, we seek a precautionary attachment against its holder without waiting for the prior negotiation, which is not required for these interim measures. Security is provided and the claim is filed within the period in article 730.2 LEC.
- 6
Prior negotiation and claim before the civil section
We open the formal negotiation with each future defendant (your own bank, the destination bank and, where appropriate, the supplier), with proof of receipt. Failing agreement, we sue before the civil section of the Tribunal de Instancia (the first-instance court), within one year for the tort action and five years for the contractual one.
The evidence that decides the case
- Your bank's record of the check: the name entered, the result returned (match, close match, no match or verification not possible), the warning displayed and the time of signature. If there was no check or the warning did not appear, the paragraph 8 refund is the core of the claim; if it did appear, that route is closed.
- The IT expert report on the headers and the access logs of the mailboxes: it shows whether the email came from the supplier's real mailbox, from a look-alike domain or from your own company's email, and therefore who is likely to bear the loss.
- The framework contract, the online banking terms and any opt-out from the check for bundled payments, with the warning the bank gave about its consequences: they decide which articles of Royal Decree-law 19/2018 were validly excluded and which notice period applies.
- The headcount and the annual accounts at the date of the contract with the bank: fewer than ten persons and turnover or a balance sheet of up to two million euros make the company a microenterprise, against which the exclusions in article 34 are not available.
- The account's payment history, to show that the transfer broke the pattern: first payment to that payee, another country, an unusual amount, urgency. It is the basis of the diligence argument when the check returned a match.
- The recovery timeline: the time of your notice, the time the bank requested the return of the funds and the destination bank's answer. An unjustified delay turns the duty to recover under article 59 into a specific breach.
What closes the door
- Framing the case as an unauthorised transaction. The order was given by your employee with the company's credentials, the bank will prove it and the case is lost for choosing the wrong route.
- Wiping the computers, deleting the emails or switching email provider before the forensic copy. Without the headers it cannot be proved where the breach was, which is what allocates the loss.
- Letting the notice period to the bank lapse: thirteen months from the debit at most, or the shorter period the contract may have set for a business that is not a consumer.
- Waiting for the criminal case to progress before claiming against the destination bank or the supplier. The tort action is time-barred after one year and the police report is not a safe way to stop that clock.
- Suing without a documented prior attempt to negotiate, trusting that the complaint to customer service counts as it would for a consumer. The claim may be declared inadmissible.
- Signing a partial refund with the bank that waives the rest, without involving the insurer. It closes off the rest of the claim and may make the company liable to the insurer for prejudicing its subrogation rights.
The law that applies
- Art. 5 quater del Reglamento (UE) 260/2012, introducido por el Reglamento (UE) 2024/886. Requires the payer's bank to check, before authorisation and through any channel, whether the IBAN matches the payee name given, and to notify any mismatch with a warning of the risk. A non-consumer may opt out only for bundled orders. A bank that complied is not liable; one that failed to must refund without delay. It has applied in the euro area since 9 October 2025. 32024R0886
- Arts. 3.25, 34 y 43 del RDL 19/2018. A microenterprise is one which, when contracting, employs fewer than ten persons and does not exceed two million euros of turnover or balance sheet. If the user is neither a consumer nor a microenterprise, the contract may exclude, among others, articles 44, 46, 60 and 61; and a period other than the thirteen months from the debit that article 43 allows for reporting the transaction and obtaining its rectification may be agreed with any non-consumer. BOE-A-2018-16036
- Art. 59 del RDL 19/2018. An order executed according to the unique identifier is deemed correctly executed with regard to its payee, and if the one provided is incorrect the bank is not liable for defective execution. But the payer's bank must make reasonable efforts to recover the funds, with the cooperation of the payee's bank, and, if it cannot recover them, give the payer, on written request, the information relevant to bringing a legal claim. BOE-A-2018-16036
- Arts. 1101, 1103 y 1104 CC. Anyone guilty of wilful misconduct (dolo), negligence or delay in performing their obligations must compensate the loss. Fault is the omission of the diligence the nature of the obligation requires according to the persons, time and place, and liability arising from negligence may be moderated by the courts: it is the basis for sharing the loss when the company was also at fault. BOE-A-1889-4763
- Arts. 1902 y 1968.2 CC. Whoever by act or omission causes harm to another through fault or negligence must make it good, and that action is time-barred one year after the injured party learnt of it. This is the deadline for claims against the bank holding the destination account and anyone without a contract with the company. BOE-A-1889-4763
- Arts. 1162 y 1164 CC. Payment must be made to the person in whose favour the obligation was created or to another authorised to receive it on that person's behalf; payment made in good faith to the person in possession of the credit releases the debtor. It is the framework for the dispute with the real supplier who demands payment of the invoice again. BOE-A-1889-4763
- Arts. 5 y 7 LO 1/2025. In civil matters a claim requires prior recourse to an appropriate dispute resolution method on the same subject matter, which includes direct negotiation between the parties or their lawyers; it is not required for interim measures before the claim or for preliminary inquiries. The request to negotiate interrupts the limitation period, which starts running afresh if there is no first meeting or written answer within thirty calendar days of receipt. BOE-A-2025-76
- Arts. 16 y 43 de la Ley 50/1980 (LCS). The loss must be notified within seven days of becoming known, unless the policy allows longer; otherwise the insurer may claim damages for the failure to notify. Once it has paid, the insurer is subrogated to the claims against those responsible up to that limit, and the insured is liable for harm it causes to that right. BOE-A-1980-22501
Each article checked against the consolidated text published in the BOE (the Spanish official gazette).
Frequently asked questions
Our bank says the IBAN was correct and that we authorised the payment. Is that the end of it?
Not necessarily. Since 9 October 2025, for euro transfers within the EU, the bank had to check the name entered against the IBAN holder and warn you if they did not match. If it did not, or the warning never appeared, Article 5c(8) of Regulation 260/2012 obliges it to refund without delay. If it warned you and your employee went ahead, you can still argue lack of diligence and delay in trying to recover the money.
We are a company with eight employees. Does the law treat us like a large company?
Not entirely. If, when you signed the contract with the bank, you employed fewer than ten people and your turnover or balance sheet did not exceed two million euros, you are a microenterprise: the bank cannot contract out of the burden of proof or its liability for defective execution. It can, however, agree a notice period other than the thirteen months with any business, so check the contract today.
Who do we claim against: our bank, the destination bank or the supplier?
Usually your own bank first: if the check failed, the refund is claimed from it even if the error was the destination bank's. The destination bank is liable only if its fault is proved, with a one-year deadline and, if it is in another EU country, generally by suing it there. The supplier comes in if the breach was in its email. All of them are assessed at once, because the deadlines differ.
The transfer was in dollars to a Hong Kong account. Does Verification of Payee apply?
No. Verification of payee is required for euro transfers between institutions in the EU. Outside that scope, the claim rests on the diligence required of the bank faced with an anomalous transaction and on how quickly it tried to recover the funds. It is a harder case, which is why the first few hours matter even more.
We have cyber insurance. Do we claim from the insurer or from the bank?
Both, in coordination. The loss is notified to the insurer within seven days or the longer period in the policy; if it pays, it is subrogated to the claims against the bank up to what it has paid, and your company still claims the excess and the uncovered amount. Do not agree a partial refund and waiver with the bank without involving the insurer: it prejudices the insurer's subrogation rights.
This guide explains how the action works in general. It does not replace the study of your own case: deadlines depend on when things happened and on what you have done since.