SIM swap fraud bank refund in Spain: account emptied, bank and operator liable
Last updated 2026-10-01 · Reviewed by Jaime Piñeira Pardo, registered with the ICAM bar, no. 138826
The short answer
After SIM swap fraud in Spain, claim against both: a bank refund of the unauthorised transactions, and compensation from the mobile operator for handing your SIM to a third party (article 82 GDPR). Notify the bank without delay and, at the latest, within thirteen months of the debit (article 43 of Royal Decree-Law 19/2018); if it refuses, it must prove that you were grossly negligent. After the prior claim, both are sued before the Tribunal de Instancia (the first-instance court) for your domicile.
One Friday, shortly before the shops closed, your mobile lost its signal: the screen only showed “Emergency calls only”. You assumed it was a fault and left it until Monday. At that very moment someone had just obtained a duplicate of your SIM card at one of your operator's shops, using an identity card bearing your details and another person's photo. With the text messages now arriving on that phone, they reset your online banking password, linked the bank's app to a new mobile, raised the limits and that night made six instant transfers and several Bizum payments (the Spanish mobile payment system) totalling 18,400 euros. They also took out a pre-approved loan of 6,000 euros in your name, which was siphoned off the same way. The bank replies that everything was validated with your credentials and with the code sent to your number. The operator says the duplicate was issued in accordance with its protocol.
The case, in five lines
- What is brought
- Action against the bank for a refund of unauthorised payment transactions (articles 43 to 46 of Royal Decree-Law 19/2018), with a declaration that the loan taken out without your consent is not binding on you, joined with an action for damages against the mobile operator that issued the duplicate (article 82 GDPR and article 1101 of the Civil Code).
- Before which court
- The Tribunal de Instancia (the first-instance court) for your domicile, in its civil section, with appeal to the Audiencia Provincial (the provincial appeal court). If your bank is established in another EU Member State and serves you in Spain, as a consumer you may likewise sue it in the courts of your domicile (articles 17 and 18 of the Brussels I bis Regulation).
- Deadline
- Against the bank, notification without undue delay and, at the latest, within thirteen months of the debit date (article 43.1 of Royal Decree-Law 19/2018): once that limit has passed, the right to rectification is lost. The claim for a refund becomes time-barred five years after the date on which the bank should have refunded you (article 1964.2 of the Civil Code). Against the operator, five years if the claim is brought for breach of the line contract (articles 1101 and 1964.2 of the Civil Code), but only one year from when you learned of the damage if the claim is non-contractual (articles 1902 and 1968.2 of the Civil Code).
- Who can bring it
- Claimants: the holder of the account from which the money was taken, and any joint holders, against the bank; the holder of the duplicated line and whoever suffered the damage, against the operator. Defendants: the bank where the account is held and the operator that issued the duplicate, sued in the same proceedings because both actions arise from the same facts (article 72 of the Civil Procedure Act, LEC).
- Financial risk
- If the court finds that you acted with gross negligence, article 46.1 of Royal Decree-Law 19/2018 makes you bear all the losses as against the bank. If it dismisses the claim against one of the two defendants, it may order you to pay that defendant's costs (article 394 LEC). And contributory negligence on your part, such as having disclosed details in an earlier scam, may reduce the compensation owed by the operator.
Two parties liable for the same fraud: the bank and the operator
In a SIM swap, two different links in the chain fail, and each has its own legal regime. The operator handed your line to someone who was not you, and the bank accepted as genuine orders validated with a code that no longer reached your phone. As against the bank, Royal Decree-Law 19/2018 applies: it obliges the bank to refund unauthorised transactions and places on it the burden of proving your gross negligence. As against the operator, the line contract and the GDPR apply.
Suing only the bank is tempting, because its liability is the clearest, but it is a strategic mistake. The bank's usual defence is to argue that you were grossly negligent, for example because weeks earlier you entered your credentials on a fake website. If the court accepts that, article 46.1 makes you bear all the losses as against the bank. The operator's liability does not depend on that: without the duplicate, the password alone would not have been enough to move a single euro out of your account.
The reverse is also true: the operator being at fault does not release the bank as against you. Article 45 obliges the payer's payment service provider to refund, and the grounds on which it may refuse do not include a third party having facilitated the fraud; whatever the bank has to take up with the operator, it will take up separately. The general mechanics of the refund are covered in our guide on bank phishing. This one focuses on what changes when the fraud comes in through the SIM.
A code sent to someone else's SIM does not prove that you authorised anything
The bank's answer is usually that each transaction was validated with your username, your password and the code that reached your number by text message. Article 44.2 of Royal Decree-Law 19/2018 says that the recorded use of the payment instrument is not necessarily sufficient to prove that the transaction was authorised by the payer, nor that the payer acted fraudulently or with gross negligence. In a SIM swap, the argument is weaker still: the code reached your number, but not your phone.
When a bank validates by text message, the possession element of strong customer authentication is your phone with its SIM card, and that card is precisely the one the operator put into someone else's hands. The authentication worked because it had already been compromised. The Tribunal Supremo (the Spanish Supreme Court) confirmed this in 2025 in a SIM swap case: the fact that the transactions were validated with the username and the text-message code did not prove the customer's gross negligence, and the bank, which must prove it under article 44.3, had to refund what was taken.
Two more rules work in your favour. Under article 46.1, you do not even bear the first fifty euros where it was not possible for you to detect the misappropriation of the instrument before the payment, and a mobile with no signal on a Friday afternoon gives no warning that someone is getting into your online banking. Under article 46.3, save where you have acted fraudulently, you bear no consequences for anything done after your notification, so the time of your first call to the bank marks a cut-off point that should be pinned down precisely.
Where the case against the bank is won: the enrolment of the new phone
Hardly any SIM swap empties an account in one go. Before moving money, the fraudster resets the password with a text message, links the bank's app to a new phone, raises the limits and adds payees. Each of those steps is an action through a remote channel that may imply a risk of fraud, and article 68.1.c) requires strong customer authentication for them, which the law defines as authentication based on independent elements: breaching one must not compromise the others. If the same text message could also be used to change the password, the two elements were in fact one, and it was the one the fraudster already controlled.
Paragraph 3 of the same article requires adequate security measures to protect the confidentiality and integrity of the credentials, and the European regulatory technical standards it refers to require transactions to be monitored taking into account, among other factors, known fraud scenarios. SIM swapping has been one for years. A new device, a password change, a limit increase and night-time transfers that empty the account within a few hours are the textbook pattern, and a bank that fails to stop it will struggle to show that its service had no deficiency at all.
That is why the decisive evidence is not your account of events but the bank's records. Article 44.4 obliges it to keep for at least six years the documentation and records evidencing compliance with its obligations and to hand them to the user on request: the IP address and device of each access, the time the new phone was enrolled, the elements used at each step and the alerts that were triggered. With them, the IT forensic expert reconstructs the night minute by minute. And if you are blamed for ignoring the warning that the payee's name did not match, remember that the warning was seen by whoever was inside your online banking.
The operator is liable even if the fraudster carried a fake ID
The operator's defence is always the same: the duplicate was requested with a document that looked genuine and the protocol was followed. Article 32 of the GDPR requires it to implement technical and organisational measures ensuring a level of security appropriate to the risk, and here the risk is known and serious, because the phone number has become the key to online banking. The Agencia Española de Protección de Datos (the Spanish Data Protection Agency) has fined several operators for issuing duplicates to people who were not the holder, holding that they processed the customer's data without a lawful basis (article 6.1 GDPR).
In the civil proceedings, the burden of proof lies with the operator too. Article 82.3 exempts it only if it proves that it is not in any way responsible for the event giving rise to the damage. The Court of Justice of the European Union has held that the controller is not exonerated merely because the damage was caused by a third party, that it is for the controller to prove that its security measures were appropriate, and that the court must examine them in concrete terms. The decisive questions are which document was required, how it was checked and whether a warning was sent to the original SIM before it was cancelled.
The claim covers the material loss the bank does not make good, the expenses and the interest, and also non-material damage: the distress of seeing the account empty, the days without a phone line, the hours lost on complaints. The same Court of Justice has made clear that the infringement alone is not enough and the damage must be proven, but that the damage need not exceed a threshold of seriousness. And the evidence held by the operator disappears quickly: the shop's CCTV footage is, as a rule, deleted within one month of being recorded (article 22.3 of Organic Law 3/2018, LOPDGDD), so its preservation is requested on day one.
Thirteen months to notify the bank and, against the operator, beware of the one-year limit
Article 43.1 of Royal Decree-Law 19/2018 makes rectification conditional on your reporting the unauthorised transaction without undue delay, as soon as you become aware of it, and in any event within a maximum of thirteen months from the debit date. That limit operates as a strict expiry period (caducidad): once it passes, the right is lost even if everything else is perfect, unless the bank had not provided or made available to you the information on the transaction. But the deadline that really matters is the first one: every hour of silence gives the bank ammunition to argue negligence.
Once notified, the bank had to refund at the latest by the end of the next business day (article 45.1). If it does not, the court action to claim the refund is a personal action subject to the five-year limitation period in article 1964.2 of the Civil Code, counted from when the refund could be demanded. It is a comfortable period on paper and a misleading one in practice: the footage, the call recordings and the memory of the employee who handed over the card are lost much sooner, and a case brought in the fourth year arrives without the evidence that would have won it.
Against the operator, the calculation changes. If you are the line holder, the claim arises from the breach of your contract (article 1101 of the Civil Code) and you have five years. But if the line was in someone else's name, your partner's or your company's, there is no contract between you and the operator and the claim is non-contractual (article 1902 of the Civil Code), with a one-year limitation period from when you learned of the damage (article 1968.2 of the Civil Code). As there is no settled case law on the limitation period for GDPR compensation, we treat one year as the safe limit and interrupt the limitation period with a written claim (article 1973 of the Civil Code).
Before suing: the claim that counts as MASC (mandatory ADR) and where the case is filed
Article 5 of Organic Law 1/2025 requires that, in civil matters, an appropriate dispute resolution mechanism (MASC) be attempted before going to court. For consumers, the seventh additional provision treats that as met by the prior out-of-court claim to the business they contracted with, where it does not answer within the period set by its special legislation or the answer is unsatisfactory. With the bank, that period is fifteen business days for its customer service department (article 69 of Royal Decree-Law 19/2018). With the operator, the written claim to its customer service department serves the same purpose.
The law requires the subject matter of the negotiation to be the same as that of the lawsuit, and this is where cases are lost. The prior claim must contain everything that will later be sought: the refund of each transaction with its value date, a declaration that the pre-approved loan is not binding on you, because without your consent there is no contract (article 1261 of the Civil Code), and, against the operator, the material and non-material damage. If the line was not in your name, the seventh additional provision does not apply to the claim against the operator, and the requirement is met through another mechanism, such as a documented negotiation between the parties' lawyers or a confidential binding offer.
A complaint to the Banco de España (the Spanish central bank) is optional. Its decision also satisfies the requirement, but it takes months and does not bind the bank, as we explain in our guide on the Banco de España's report. The claim is filed before the civil section of the Tribunal de Instancia for your domicile, against both at once, because both actions arise from the same facts (article 72 LEC). If your bank is established in another EU Member State and directs its business to Spain, as many neobanks do, articles 17 and 18 of the Brussels I bis Regulation allow you, as a consumer, to sue it before the courts of your own domicile.
How we run the case, step by step
- 1
We block the line and your online banking within the first hour
From another phone, the line is blocked with the operator and, with the bank, the online banking, the cards and Bizum, noting the exact time of each notification and its incident number. Anything executed after the bank has been notified is at the bank's expense unless you acted fraudulently (article 46.3), so that time is the first piece of evidence in the case.
- 2
We draft the police report and ask for the evidence to be preserved
We prepare the report with the full chronology: loss of signal, shop and time of the duplicate if already known, transactions and loan. We ask that the operator be ordered to preserve the footage and the duplicate file, because some data, such as the handset in which the duplicate SIM was used, can only be obtained in the criminal proceedings.
- 3
We file a claim with the bank covering everything that will be sought later
A letter to the customer service department seeking the refund of each transaction with its value date, a declaration that the loan is not binding on you and disclosure of the technical records under article 44.4. The bank has fifteen business days to answer; its silence or refusal opens the way to court.
- 4
We file a claim with the operator and request its file on the duplicate
We demand compensation and, under the right of access in article 15 GDPR, the record of the duplicate: channel, shop, time, document provided, employee and checks carried out. It must answer within one month (article 12.3 GDPR). That letter interrupts the limitation period and counts as the prior claim. A complaint to the Agencia Española de Protección de Datos can run in parallel, but never instead of it.
- 5
We commission the IT forensic report
An IT forensic expert the firm works with cross-checks the bank's and the operator's records and establishes the sequence: activation of the duplicate, password change, enrolment of the new device, limit increase and transactions. If everything happened after your SIM stopped working and from devices that are not yours, the negligence argument is left without foundation.
- 6
We sue both in a single set of proceedings
Before the civil section of the Tribunal de Instancia for your domicile, we seek a refund from the bank, compensation from the operator and a ruling that both are jointly and severally liable for the damage they caused together, as well as disclosure of any records not yet handed over. If they refuse without justification, the court may give evidential weight to our version of their content (article 329 LEC).
The evidence that decides the case
- The operator's duplicate file, with time, channel, shop, document presented and checks performed. If the activation coincides with the minute your mobile lost its signal and precedes the first access to your online banking, the causal chain is proven.
- The bank's technical records: IP, device identifier, time the new phone was enrolled, password change, limit increase and authentication elements used at each step, which article 44.4 obliges it to keep and hand over.
- The IT forensic report cross-checking both sets of records and showing that no transaction came from your devices or your connection, and that the bank authorised high-risk actions with the code the duplicate SIM was receiving.
- The shop's CCTV footage and the copy of the document used to request the duplicate, which only exist if someone asked for them to be preserved before they were deleted.
- Your screenshots of the mobile with no signal, showing the time, the log of your calls to the operator and the bank, and the new SIM issued to you afterwards, which date the attack and show how quickly you reacted.
- The police report, the bank statements showing each transaction and the pre-approved loan contract, whose only signature is a code sent to the already duplicated number.
What closes the door
- Mistaking the loss of signal for a fault and waiting until Monday. It is the sign of the attack: whatever is executed after you notify the bank is at the bank's expense, and every hour without notifying it gives the bank arguments to allege negligence.
- Writing in the claim, or admitting on a recorded call, that you “gave” codes or passwords. The bank will present it as an admission of gross negligence. The facts should be stated precisely, without characterising them.
- Claiming only against the bank and discovering a year later that the action against the operator, if it was non-contractual, is already time-barred. The written claim to the operator should be sent at the outset.
- Suing without having first claimed from both exactly what is sought in the lawsuit. Without the same subject matter, the requirement of article 5 of Organic Law 1/2025 is not met and the court will not admit the lawsuit.
- Waiting for the criminal case to end. Many are closed for lack of a known perpetrator, and neither the bank nor the operator is any less liable because the fraudster is not found; meanwhile the deadlines run and the footage is deleted.
- Paying without protest the instalments of the loan the fraudster took out, or signing an acceptance of a partial refund. The bank will present it as acceptance of what happened.
The law that applies
- Art. 43 del RDL 19/2018. Allows rectification of an unauthorised transaction only if the user reports it to the provider without undue delay, as soon as they become aware of it, and in any event within a maximum of thirteen months from the debit date. That period does not apply where the provider did not provide or make available to the user the information on the transaction. BOE-A-2018-16036
- Art. 44 del RDL 19/2018. Where the user denies having authorised a transaction already executed, the provider must show that it was authenticated, accurately recorded and entered in the accounts, and that it was not affected by a technical breakdown or another deficiency of the service. The recorded use of the instrument is not necessarily sufficient to prove authorisation, fraud or gross negligence, which the provider must prove, and the provider must also keep and supply its records for at least six years. BOE-A-2018-16036
- Art. 46 del RDL 19/2018. Caps at fifty euros what the payer bears for a lost, stolen or misappropriated instrument, unless the payer could not detect it before the payment, and makes the payer bear all the losses only where they acted fraudulently or breached their obligations deliberately or through gross negligence. If strong customer authentication was not required, the payer is liable only for their own fraud, and bears nothing for use after their notification save for fraudulent conduct. BOE-A-2018-16036
- Art. 68 del RDL 19/2018. Requires strong customer authentication when the payer accesses their payment account online, initiates an electronic payment or carries out through a remote channel any action that may imply a risk of fraud, with elements dynamically linking remote payments to a specific amount and payee, and requires adequate security measures to protect the confidentiality and integrity of the credentials. BOE-A-2018-16036
- Art. 32 RGPD. Requires the controller and the processor to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking particular account of the risks of unauthorised disclosure of, or access to, personal data. 32016R0679
- Art. 82 RGPD. Grants anyone who has suffered material or non-material damage as a result of an infringement of the Regulation the right to receive compensation from the controller or processor, which is exempt only if it proves that it is not in any way responsible for the event giving rise to the damage. 32016R0679
- Arts. 1101 y 1964.2 CC. Make liable for damages those who, in performing their obligations, are guilty of fraud, negligence or delay or in any way contravene their terms, and subject personal actions with no special period to a five-year limitation period from when performance of the obligation can be demanded. BOE-A-1889-4763
- Art. 5 y DA 7.ª LO 1/2025. Require, in civil matters, a prior attempt at an appropriate dispute resolution mechanism, with the same subject matter in the negotiation and in the lawsuit, save in the matters excepted. In individual consumer actions, the requirement is met by the prior claim to the business contracted with, left unanswered within the legal period or answered unsatisfactorily, or by the Banco de España's decision on the complaint. BOE-A-2025-76
Each article checked against the consolidated text published in the BOE (the Spanish official gazette).
Frequently asked questions
The mobile operator says someone requested the duplicate SIM with my ID. Does that exempt it from liability?
Not by itself. Article 32 of the GDPR requires security appropriate to the risk, and article 82.3 exonerates the operator only if it proves it is not in any way responsible. The Court of Justice of the European Union has held that the controller is not exempt simply because the damage was caused by a third party, and the Agencia Española de Protección de Datos (the Spanish Data Protection Agency) has fined operators for handing duplicates to people who were not the holder.
I entered my bank login details on a fake website weeks before the SIM swap. Will I lose the case?
Not necessarily. It is for the bank to prove gross negligence (article 44.3 of Royal Decree-Law 19/2018), and all the circumstances of the deception are taken into account. Moreover, with the password alone the fraudster could not operate the account: they needed the codes received through the duplicate SIM. That is why the operator is also sued, since its liability does not depend on what you did earlier, although your conduct may reduce the compensation.
The fraudster also took out a loan in my name. Do I have to repay it?
A contract requires the consent of the person bound by it (article 1261 of the Civil Code), and you never gave yours: the loan was signed with a code sent to a SIM held by someone else. The bank is asked to declare that the loan is not binding on you and, if it refuses, the court is asked to do so. In the meantime, do not pay any instalments without stating in writing that you do so under protest.
How long do I have to claim after SIM swap fraud?
You must notify the bank without delay and, at the latest, within thirteen months of the debit (article 43.1 of Royal Decree-Law 19/2018). The claim against the bank becomes time-barred after five years (article 1964.2 of the Civil Code). Against the operator, it is five years if you are the line holder, but only one if the claim is non-contractual (article 1968.2 of the Civil Code), so it is wise to send it a written claim as soon as possible.
My bank is a neobank based in another EU country. Do I have to sue it there?
No. If the bank directs its business to Spain, articles 17 and 18 of the Brussels I bis Regulation allow you, as a consumer, to sue it before the Tribunal de Instancia (the first-instance court) for your own domicile. The prior claim goes to its customer service department, and the operator, which is usually Spanish, is sued in the same proceedings.
This guide explains how the action works in general. It does not replace the study of your own case: deadlines depend on when things happened and on what you have done since.