Law firm guidesBanking and finance

Your account was emptied by phishing: the bank must refund it

Last updated 2026-09-01 · Reviewed by Jaime Piñeira Pardo, registered with the ICAM bar, no. 138826

The short answer

Notify the operation without delay and demand the refund in writing. Article 45.1 of Royal Decree Law 19/2018 obliges the provider to repay the amount immediately and at the latest by the end of the next business day. If it refuses, under article 44 it is the provider that must prove the operation was authenticated or that you were grossly negligent.

You received a message that looked like your bank's, warning of a suspicious access, from the same sender and in the same thread where your usual codes arrive. You clicked, entered your credentials and, straight afterwards, someone called identifying themselves as the security department and asked you to confirm a cancellation. Within twenty minutes four transfers left the account for twelve thousand euros. At the branch you are told the operations carry your own code and that nothing can be done.

The case, in five lines

What is brought
Claim for the refund of unauthorised payment operations under article 45 of Royal Decree Law 19/2018 and, if the provider refuses, a civil claim for repayment together with the loss caused.
Before which court
The Civil section of the Tribunal de Instancia (the first instance court) for the payment service user's domicile, with appeal to the Audiencia Provincial (the provincial appeal court).
Deadline
Notification to the provider must be given without delay, and article 45.1 obliges it to refund the amount at the latest by the end of the business day following the day it observed or was notified of the operation. The later court claim is a personal action subject to the five years of article 1964.2 of the Civil Code.
Who can bring it
The payer, that is the holder of the account the money left, and any co holders. Where the account belongs to a company, the company itself acting through its management body.
Financial risk
If the court finds gross negligence, article 46.1 makes you bear all the losses and the claim is dismissed, with a possible order to pay costs. The fifty euro cap applies only where the payment instrument was lost, stolen or misappropriated.

The operation carrying your code does not mean that you authorised it

That is the standard answer at the branch and the law dismantles it expressly. Article 44.2 of Royal Decree Law 19/2018 states that the provider's record of the use of the payment instrument is not necessarily sufficient to prove that the operation was authorised by the payer, nor that the payer acted fraudulently or breached their obligations deliberately or through gross negligence.

The distinction is the heart of the case: authentication is not authorisation. That the system checked some credentials only shows that somebody entered them. Who entered them and in what circumstances is another matter, and it is exactly the one the provider must clear up when the customer denies having authorised the payment.

The burden of proof is reversed, and that changes the whole case

Article 44.1 says that where a user denies having authorised an operation already executed, or alleges that it was incorrectly executed, it falls to the provider to show that the operation was authenticated, accurately recorded and entered in the accounts, and that it was not affected by a technical failure or another deficiency of the service supplied. It is not for you to explain how they got into your account.

Article 44.3 completes the picture: it falls to the payment service provider to prove that the user committed fraud or gross negligence. In other words, the bank cannot simply assert that you were careless, it has to prove it with concrete facts, and the mere existence of a well imitated fraudulent message proves no carelessness at all.

There is also a record keeping duty that works in your favour. Article 44.4 requires the provider to keep the documentation and records evidencing compliance with its obligations and to hand them to the user on request, for at least six years. Asking for them in writing is the first move of the case, because that is where the evidence the bank would rather not produce comes from.

The refund deadline is the next business day, not when its enquiry ends

Article 45.1 is specific: once an unauthorised payment operation has been executed, the payer's provider shall refund the amount immediately and, in any event, at the latest by the end of the business day following the day it observed or was notified of the operation. It adds that it shall restore the account to the state it would have been in had the operation not taken place.

The only exception the provision allows is that the provider has reasonable grounds to suspect fraud and communicates those grounds in writing to the Banco de España, in the form, with the content and within the periods that it determines. Suspecting in silence or opening an internal file is not enough: the exception requires that formal communication to the supervisor.

The same article closes a detail that is often forgotten: the value date of the credit to the payer's account shall be no later than the date on which the refunded amount was debited. The refund must also leave you whole as to interest and any overdraft it caused, and that is claimed expressly where the account was left in the red.

Without strong authentication, you answer only if you acted fraudulently

Article 46.2 is one of the most useful and least invoked rules: if the payer's payment service provider does not require strong customer authentication, the payer bears the financial consequences only if they acted fraudulently. Checking how each transfer was validated therefore becomes the central technical point of the case.

The third paragraph adds that, save for fraudulent conduct, the payer bears no financial consequence for use of the instrument after the notification. And the fourth provides that if the provider has no adequate means for the loss or theft to be notified at any time, the payer is not liable for the consequences, save for fraud.

That is why it matters so much to document the exact time of your call or of your alert through the app, and also whether the incident line was working, how long they took to answer and what they told you. That record decides which operations fall outside your liability because they were executed after the alert.

Gross negligence is a high bar, and the bank has to clear it

Article 46.1 provides that the payer may be required to bear up to a maximum of fifty euros of the losses arising from unauthorised operations resulting from the use of a lost, stolen or misappropriated payment instrument. Only those who acted fraudulently or breached their obligations deliberately or through gross negligence lose that cap.

Gross negligence is not any lapse of care. In a fraud that replicates the bank's visual identity, arrives in the same message thread where legitimate codes are delivered and is completed with a call from a spoofed number, arguing that the victim was grossly negligent requires far more than pointing out that they entered their credentials.

Article 46.1 itself exempts the payer entirely in cases of theft, loss or misappropriation where the operations were carried out remotely using only the payment data printed on the instrument, provided there was no fraud or gross negligence in safekeeping and the matter was notified without delay. That rule covers many remote card charges.

How we run the case, step by step

  1. 1

    We notify without delay and record the exact time

    The alert to the bank is given through whatever channel exists and documented at once: screenshots of the app, a record of the call and a written confirmation. The time of the alert separates earlier operations from later ones, which have different consequences.

  2. 2

    We report the fraud to the police

    The report describes the message received, the call and the transfers that left the account, and attaches the screenshots. It evidences the fraud against the bank and gets the matter investigated, besides fixing a certain date.

  3. 3

    We demand the refund under article 45

    We claim in writing the immediate refund and, at the latest, by the end of the next business day, with the account restored to its former state and the correct value date. The claim cites the provision and fixes the day the breach starts from.

  4. 4

    We request the technical records of the operations

    We require the authentication logs, the device and address from which the payments were ordered and the record of whether strong authentication was applied. Article 44.4 obliges the provider to keep that documentation and hand it over on request.

  5. 5

    We sue for repayment if the bank refuses

    The claim seeks the sum taken, the interest and the loss caused by the resulting overdraft, and places on the bank the burden of proving the authentication or the gross negligence required by articles 44 and 46.

The evidence that decides the case

  • Screenshots of the fraudulent message or email, showing it arrived in the same thread as the bank's genuine alerts.
  • The phone call log, with the spoofed number and the length of the conversation with the fake security department.
  • The statement showing the disputed operations, their exact times and the moment you gave the alert to the bank.
  • The authentication logs produced by the provider, which reveal whether strong authentication was applied to each operation.
  • The police report with its reference number and the list of amounts claimed.
  • The written reply from the customer service department, which usually admits the date the fraud was notified.

What closes the door

  • Waiting a few days to see whether the money comes back on its own. Article 45.1 measures the refund deadline from when the bank observed or was notified of the operation, so delaying the alert delays everything else.
  • Accepting the explanation over the phone that the operation carries your own code. Article 44.2 says that such a record is not necessarily sufficient to show that you authorised it.
  • Signing an acceptance document for a partial refund. It usually carries a waiver of the rest of the claim and closes off the amounts not repaid.
  • Not reporting it out of embarrassment. Without a police report the external evidence of the fraud is lost and the bank uses that gap to argue the operation was consented to.

The law that applies

  • Art. 44 del RDL 19/2018. Where the user denies having authorised an operation already executed, it falls to the provider to show it was authenticated, accurately recorded and entered in the accounts and that there was no technical failure. The record of the use of the instrument is not necessarily sufficient to prove authorisation, fraud or gross negligence, and the provider must prove those points, keeping the documentation for at least six years. BOE-A-2018-16036
  • Art. 45 del RDL 19/2018. Obliges the payer's provider to refund the amount of the unauthorised operation immediately and at the latest by the end of the business day following the day it observed or was notified of it, and to restore the account to its former state, unless it has reasonable grounds to suspect fraud and communicates them in writing to the Banco de España. The value date of the credit shall be no later than that of the debit. BOE-A-2018-16036
  • Art. 46 del RDL 19/2018. Caps at fifty euros what the payer may bear for unauthorised operations with a lost, stolen or misappropriated instrument, with exceptions; makes the payer bear all the losses only where they acted fraudulently or breached their obligations deliberately or through gross negligence; and provides that, where strong authentication was not required, the payer answers only for their own fraud. BOE-A-2018-16036
  • Art. 1964.2 CC. Subjects personal actions with no special period to a five year prescription from when performance of the obligation can be demanded. It is the period for the court claim for repayment where the provider fails in its duty to refund and the courts have to be used. BOE-A-1889-4763

Each article checked against the consolidated text published in the BOE (the Spanish official gazette).

Frequently asked questions

The bank says the transfers carry my code. Does that settle it?

No. Article 44.2 of Royal Decree Law 19/2018 says expressly that the record of the use of the payment instrument is not necessarily sufficient to prove that the operation was authorised by the payer, nor that the payer acted fraudulently or with gross negligence. Authenticating credentials and authorising a payment are different things, and the bank must prove the second.

How quickly does it have to give my money back?

Article 45.1 obliges it to refund the amount immediately and, in any event, at the latest by the end of the business day following the day the bank observed the operation or was notified of it. The only exception is that it has reasonable grounds to suspect fraud and communicates them in writing to the Banco de España, in the form and within the periods it determines.

I did give away the codes. Is that gross negligence?

Not automatically, and in any event it is the bank that must prove it: article 44.3 says so. All the circumstances are weighed, including that the message replicated the bank's identity, arrived in the same thread as genuine alerts and was completed with a call from a spoofed number. Giving data while being deceived is not the same as a grossly negligent breach.

What if the bank never asked me for a second verification?

It is a very strong argument. Article 46.2 provides that if the payer's payment service provider does not require strong customer authentication, the payer bears the financial consequences only where they acted fraudulently. That is why the technical records of each operation are requested: showing that strong authentication was absent resolves much of the case.

Are they also liable for operations made after my alert?

Article 46.3 provides that, save for fraudulent conduct, the payer bears no financial consequence for use of the instrument after the notification. Hence the importance of documenting the exact time of the alert: as a rule, every charge after that moment falls outside your liability.

This guide explains how the action works in general. It does not replace the study of your own case: deadlines depend on when things happened and on what you have done since.

Tell us about your case.

A lawyer studies it and tells you whether there is a claim, how long you have left and what can be sought. Your matter is quoted afterwards, because every case is different.

Other cases in this area