Does the bank have to give my money back after a phishing scam?

If your account has been emptied through phishing or a bank impersonation scam, the payment services law requires the bank to refund unauthorised transactions unless you were grossly negligent. Here is when you have a case.

A message that looks like it came from your bank, a link, your login details, and within minutes the account is at zero. Once the initial shock passes, almost everyone asks the same question and almost no one knows the answer: is the bank required to give that money back?

Often, yes. Even though the first thing you hear when you call your bank is likely to be the opposite.

What the law says

Payments and charges to your account are governed by the Payment Services Law (Royal Decree-Law 19/2018), and its starting point is straightforward: a transaction you did not authorise is one the bank must refund. There is also a detail that works in your favour, namely that the burden of proof is not on you. If you deny having authorised the charge, it is the bank that has to show the transaction was properly authenticated and that you consented to it. The fact that “your credentials were used” is not enough, because in a phishing scam the person operating the account is a third party who has impersonated you.

The battleground: “gross negligence”

This is where the bank digs in. It will tell you that you were negligent, and a good part of the matter turns on that label. But a lapse is not gross negligence, and the courts read that concept narrowly and in the customer’s favour. Falling for a well-crafted fake website or text message, as part of an elaborate deception, does not automatically make the victim the guilty party. Holding that line, and knowing which arguments to hold it with, is usually what decides whether you get your money back.

Why the technical side matters

Against the “you entered the code, we’re not refunding anything” that comes as standard, what wins these cases is looking underneath: how the transaction was actually authenticated, whether the strong authentication required by the rules was applied, what the bank’s records show, and whether its security systems did their job. That is the ground we work on; you can see our cybercrime practice area.

About the clock

A practical point that often gets forgotten: report the unauthorised transaction as soon as you notice it. Deadlines are running, and every day of delay weakens the claim.

Frequently asked questions

If I entered the codes myself, can the bank still refund me?

Yes, it can. Being tricked by a third party into entering your codes does not mean you “authorised” the transaction in the sense of the law, nor does it automatically turn your conduct into gross negligence. The bank has to prove that the transaction was correctly authenticated and consented to.

How long do I have to make a claim to the bank?

You should report the unauthorised transaction without delay, as soon as you notice it. Deadlines matter and delay harms your claim, so the sensible course is to act at once and get advice as early as possible.

The bank has already said no. Can I do anything?

Yes. An initial refusal from the bank is common and does not close the door. You can pursue a claim and, where appropriate, take the matter to court, where the burden of proving that the transaction was authorised still falls on the bank.

Does this also apply to fraudulent card purchases or Bizum payments?

The same payment services rules cover unauthorised transactions by card, transfers and other payment instruments. Each case has nuances that are worth analysing.