Bank Phishing in Spain: Civil Liability of Banks and Applicable Case Law
Victims of bank phishing in Spain have strong legal protections. Under PSD2 and Spanish law (RDL 19/2018), banks must reimburse unauthorised transactions immediately unless they prove the client acted fraudulently or with gross negligence. The Supreme Court (STS 571/2025) confirms this quasi-objective liability standard.
Bank phishing — the fraudulent practice of impersonating a trusted financial institution to steal customers' banking credentials — has become one of the most prevalent forms of cybercrime in Spain. Variants include email phishing, SMS-based *smishing*, phone-based *vishing*, and SIM card duplication (*SIM swapping*).
For victims, the critical question is: who bears the financial loss — the customer or the bank?
Spanish law and recent Supreme Court jurisprudence provide a clear answer: the bank must reimburse the customer, unless it can prove fraud or gross negligence on the customer's part.
The Legal Framework: PSD2 and RDL 19/2018
The European Payment Services Directive (PSD2 — Directive 2015/2366/EU) and its Spanish transposition, Royal Decree-Law 19/2018 (RDL 19/2018), establish a regime of quasi-objective liability for payment service providers (banks).
The key provisions are:
- Article 45 RDL 19/2018: The payment service provider must reimburse the full amount of any unauthorised transaction immediately, unless it has reasonable grounds to suspect fraud.
- Article 46 RDL 19/2018: The customer's liability is limited to a maximum of €50 when the unauthorised operation results from the use of a lost or stolen payment instrument, provided there is no fraud or gross negligence by the customer.
- Article 41 RDL 19/2018: Banks must implement Strong Customer Authentication (SCA) — typically two-factor authentication — for electronic transactions.
The burden of proof lies with the bank: it must demonstrate that the transaction was correctly authenticated, properly recorded, and not affected by any technical failure. The mere fact that the bank's records show the transaction was processed does not prove that the customer authorised it.
The Criminal Dimension
From a criminal law perspective, phishing constitutes computer fraud (*estafa informática*) under Article 249 of the Spanish Criminal Code. The perpetrator obtains an unlawful transfer of assets through fraudulent manipulation of computer systems.
However, the criminal characterisation of phishing as a third-party offence is precisely what supports the civil liability of the bank: the customer was deceived by a criminal, not by the bank. The bank's liability arises from its contractual duty to safeguard the customer's funds and ensure the security of its payment systems.