Online banking scams: the CJEU may change the rules on who pays for cyber-fraud in Europe

Spanish and European banks are awaiting a Court of Justice of the EU (CJEU) ruling that could reshape how liability for online banking scams is allocated between banks and their customers. We review the scope of the upcoming decision, the PSD2 framework, recent Spanish Supreme Court case law (STS 571/2025), and the practical steps a victim of online fraud in Spain should take to recover the funds.

A pending CJEU ruling that could reshape European banking

European banks are awaiting a Court of Justice of the European Union (CJEU) judgment that may significantly redraw the "rules of the game" on online banking scams, phishing, smishing and digital fraud. The core question is straightforward: when a customer is tricked by a third party and technically authorises a banking transaction, who bears the loss — the customer or the bank?

The stakes are high. Industry data shows social-engineering frauds in digital banking have surged in recent years, and many banks routinely refuse refunds on the grounds that the transaction was confirmed by the customer with their credentials. The expected CJEU ruling could narrow that defence dramatically.

> Practical note: if you have been the victim of a banking cyber-scam in Spain, do not simply accept the bank's refusal. The European framework presumes your right to a refund unless the bank proves gross negligence or fraud on your side.

The legal framework: PSD2 and Spanish RDL 19/2018

The Payment Services Directive (PSD2), transposed in Spain by Royal Decree-Law 19/2018, sets a key principle for unauthorised payment transactions:

  • The payment service provider (the bank) must refund the unauthorised transaction immediately, no later than the end of the next business day.
  • The burden of proof lies with the bank: it must show that the operation was duly authenticated, accurately recorded, and not affected by a technical failure.
  • The bank is only released from liability when it proves fraud or gross negligence by the user.

The CJEU has consistently reinforced this consumer-friendly approach across PSD2 and Directive 93/13/EEC on unfair contract terms.

What the pending European ruling is really about

The case before the CJEU asks, in essence, whether a transaction can be deemed "authorised" — and therefore non-refundable — where the customer:

  1. Entered their credentials or validated an OTP/SMS, but
  2. Did so as a result of sophisticated fraud (bank website impersonation, spoofed phone numbers, urgent fake security alerts).

Banks argue that, if the transaction was digitally signed by the customer, it is not an "unauthorised transaction" in the technical sense. Consumer associations and several national courts argue the opposite: consent vitiated by deceit is not valid authorisation, and the bank must bear the loss unless it proves gross negligence.