“I got a text from BBVA saying my account had been blocked, I opened the link, typed in my credentials and half an hour later the account had been emptied. Can I get the money back?” In most cases yes, and by two separate routes that do not exclude each other. Whoever deceived you has committed the offence of fraud under article 248 of the Spanish Criminal Code, punishable with six months to three years in prison, and BBVA, which here is the impersonated bank and not the fraudster, is your payment service provider and is bound by the regulations that require unauthorised transactions to be refunded. Whether that refund arrives depends to a large extent on how the facts are evidenced and on not wasting the first few hours.
How to recognise the fake text or call
The pattern repeats with few variations. A text message arrives, sometimes inside the same thread where you receive the bank’s genuine notifications, announcing an urgent problem. The most common pretexts are that the account has been blocked for security reasons, that access from a new device has been detected, that there is a charge or transfer you do not recognise and must cancel, or that you need to verify your identity to keep your access. The message includes a link, often shortened, leading to a page that mimics the bank’s but whose domain is not the official one. A glance at the address bar shows the domain does not match BBVA’s, even if the design is identical.
The telephone version works the same way with different packaging. Someone introducing themselves as a member of the security or fraud department calls you, often from a number that shows on screen as the bank’s own because caller ID can be spoofed, and tells you about a suspicious charge or an attempted login. To “cancel it” they need you to confirm the code you have just received by text, or to move your balance to a “safe account” while the incident is resolved, or to install an application that lets them “help you” from your computer. Each of those requests is the scam itself.
The two stages are frequently combined. The text with the link captures the username and password, and the later call obtains the one-time code with which the fraudster orders the transfer from your own online banking. That second step is what turns stolen credentials into lost money.
| Method | Usual hook | What they ask for | What they obtain |
|---|---|---|---|
| Text with a link (smishing) | Account blocked, new device, verify identity | Username and password on a cloned site | Access to your online banking |
| Call from the “security department” (vishing) | Charge or transfer you do not recognise | The one-time code received by text | Confirmation of a transfer they order |
| Call with a “safe account” | Your money is at risk | That you transfer the balance yourself | A transfer made by your own hand |
| Call with a remote-control app | They need to “check” your device | Installing a remote-access application | Control of your phone or computer and of the codes |
Why it looks real
The deception works because several signals people associate with authenticity can be faked. The sender name on a text can be manipulated so that the phone groups it with the bank’s legitimate messages, so the fake alert appears directly below a genuine notification from two weeks ago. The incoming caller number can also be spoofed. The fraudsters sometimes hold personal data of yours obtained in other breaches, such as your full name, the last digits of a card or your address, and use it to gain trust. The tone, wording and urgency copy those of a real security alert, and the time pressure is designed to make you act before thinking. None of this makes you a careless person, although the bank, once you claim, may try to present it that way.
What no bank ever does
There are things no Spanish bank, BBVA included, does as a matter of practice, and they work as an immediate rule of exclusion. A bank does not ask for your full access password by phone or by message. It does not ask for the one-time code sent to you by text, because that code exists precisely so that only you know it. It does not ask you to move your money to another “safe” account to protect it, because if it detects a risk it blocks the transaction or the account without the customer having to transfer anything. It does not ask you to install a remote-control application on your phone or computer. If what you are being asked falls into any of those four categories, you are speaking to a fraudster. Hang up and do not answer that number again.
If you are still unsure whether an alert is genuine, the only reliable check is to end the communication and call, yourself, the number printed on the back of your card or shown inside the official app, or to open the app on your own and see whether the alert appears there. Never use the number or the link provided in the message itself, because they lead straight back to the fraudster.
What to do in the first hours
If you received the message and did not enter anything, there is no loss to claim. Keep the text anyway and do not delete it, because if someone close to you later falls for the same campaign, or if the bank ever questions whether the fraud existed, that message has value. Report the attempt to the bank through the official channel when you can.
If you entered your credentials, gave a code, made the transfer or installed an application, the clock starts at that moment. Call the number on the back of your card or the one in the official app immediately, ask for your access credentials and cards to be blocked, and state that transactions you did not authorise have taken place. The sooner that report is on record, the better the chances that the bank holds or attempts to reverse the funds, and the less room it has later to argue that you were slow.
Keep everything. The text with date and time, screenshots of the site you visited if it is still open, the call log with the number and duration, the transaction records exactly as they appear in your account, the name the caller used and any later email or message. If you installed a remote-control application, do not factory-reset the device until what was on it has been documented, because that application is the evidence of how the transaction was carried out. You should disconnect it from the internet and stop using it for banking until it is clean. Change your email password too, because email is the usual route to regaining access to everything else.
Some things make the case worse. Do not keep talking to the caller, even if they insist they are going to “help you recover” the money. Do not accept help from anyone who contacts you afterwards offering to recover the loss in exchange for an upfront payment, because that is a second scam aimed at victims of the first. Do not sign or agree by phone to any statement with the bank about what happened before you know what it implies.
Report the matter to the Policía Nacional or the Guardia Civil with all that documentation. A police report is not a legal requirement for claiming against the bank, but in practice the bank will ask for it, and the court is the only route to identifying the holder of the receiving account and prosecuting the offence.
If you gave your credentials or made the payment, getting the money back
The distinction that decides the claim against the bank is whether the transaction was authorised by you or not. Payment services regulations require the bank to refund transactions the customer did not authorise. Where the fraudster logged into your online banking with the captured credentials and ordered the transfer himself, the transaction was not authorised by you even though the credentials were yours, and that is the clearest situation.
The contested case is the transfer you made yourself to the “safe account” following instructions from someone posing as the bank, or the code you yourself gave over the phone. The bank will tend to classify that as an authorised transaction, or as gross negligence by the customer, in order to refuse the refund. Whether that argument succeeds depends on how the deception is evidenced, on the specific circumstances of the transaction and on the bank’s own prior conduct, and that is where the claim stops being a form and becomes a legal matter. How it is framed is the lawyer’s job. I have covered in more detail what the bank is obliged to refund in this article on bank impersonation scams and in this one on phishing refunds.
That the money left via Bizum or an instant transfer does not change the bank’s obligation. It changes the practical difficulty of recovering it at the destination, because the funds move in seconds, but the claim is brought in the same way.
If the bank rejects the claim alleging that you were negligent, or does not reply, the road does not end there. There is a further path, administrative and judicial, and what was stated and submitted in the first claim conditions everything that follows. An improvised complaint by phone in which the customer says they “gave the codes” becomes the bank’s argument for the rest of the proceedings. At the firm we conduct these claims from the first communication to the bank, so that what is on record from the outset is what will later be needed, within our cybercrime practice.
The criminal route, the fraud offence under article 248
Whoever deceived you committed the offence of fraud under article 248 of the Spanish Criminal Code, which punishes with six months to three years in prison anyone who, for gain, uses sufficient deception to cause another person to err and induces them to carry out an act of disposal to their own or a third party’s detriment. Where the amount defrauded does not exceed 400 euros, the penalty is a fine and the matter is handled as a minor offence. The complaint is directed against the perpetrators, not the bank, and serves for the court to require the receiving bank to disclose the details of the account that took the money.
You can file the report at the police station or Guardia Civil post in your own town even if the receiving account is in another province or another country. In fraud committed remotely, the investigation usually falls to the courts of the place where the victim suffered the loss, which for someone in A Coruña means the case is handled close to home.
The limitation period for fraud is counted in years, so someone who took weeks to realise or to make up their mind has not lost the criminal route. What is lost over time is evidence, because connection logs and receiving-account data are retained for a limited period, which is why an early report is worth more than a late one.
Many of these cases are provisionally closed because the perpetrator, who operates from outside Spain or through third parties’ accounts, is not identified. A provisional closure is not an acquittal, it can be reopened if new information emerges and, above all, it does not affect the claim against the bank, which is independent of whether anyone is ever convicted. A closed criminal case does not release the bank from refunding. Where the holder of the receiving account is identified, the criminal proceedings allow the money to be claimed from that person as civil liability.
If your account has received another victim’s money
Part of the money from these scams passes through accounts of private individuals who hand them over, sometimes for a commission and sometimes convinced they are working with a company or with someone they met online. Anyone who receives a victim’s money and forwards it where instructed can end up under investigation for money laundering, and the law also punishes the negligent form, that of the person who did not know but had reason to suspect. If your account has received a transfer you were not expecting and someone asks you to forward it, do not. If you already did and a summons arrives, you need criminal defence from the first moment, and that is among the defence work we undertake at the firm.
What is at stake if you handle it alone
If you claim on your own, the specific risk is that what you tell the bank in the first call or the first letter becomes the argument used to refuse the refund, in particular any sentence that sounds like admitting you authorised the transaction or handed over the credentials “voluntarily”. A badly framed claim drags that burden through every later stage, and a police report without proper documentation ends up closed without anyone having been identified. At the firm we conduct the claim against the bank and the criminal route in a coordinated way, from the first communication through to court if necessary, within our cybercrime and criminal law practices. You can call +34 677 841 007 or write through contact. When you call, have to hand the text or the call log with date and time, the transaction records as they appear in your account with amount and destination account, the date and time you reported the fraud to the bank and through which channel, a copy of the police report if already filed, and any written reply the bank has given you.
Frequently asked questions
Can I get the money back if it was me who typed in the code or confirmed the transfer after the text?
In many cases yes. The fact that you entered your credentials on a fake site does not make the transfer the fraudster then ordered an authorised one, and that is the most favourable situation. Where it was you who made the transfer or gave the code over the phone following the fake employee’s instructions, the bank will argue that you authorised the transaction or were negligent, and the outcome depends on how the deception is evidenced and on the specific circumstances. It is not automatic, but it is not lost from the outset either.
Do I have to file a police report before claiming against BBVA?
The law does not require a police report as a condition for claiming against the bank, but in practice the bank will ask for it and it is in your interest to have it. The urgent step is to report the fraud to the bank through the official channel and ask for a block, because every hour counts there. The report to the Policía Nacional or the Guardia Civil is filed afterwards, with all the documentation, and is the only route for a court to identify the account that received the money.
What happens if BBVA tells me I was negligent and refuses to refund me?
That is the bank’s usual reply and it is a defence, not a final decision. Keep that written response, because from there a further path opens in which precisely what is argued is whether there was gross negligence or a deception any reasonable customer would have fallen for. How that allegation is rebutted is the core of the legal work in these matters, and it should not be improvised with another call to the bank.
Is it worth claiming with a lawyer?
It depends on the amount and on the bank’s response. If you lost a few dozen euros and the bank has already refunded them after your report, nothing more is needed than the police report, which you can file yourself. If the sum is significant for your finances, if the bank has refused the refund or is not replying, or if you made the transaction yourself after being deceived by a call, then yes, because the outcome will depend on how the claim is framed and not on repeating the same argument. And if what happened is that you sent money to someone you know over a personal dispute, this is not the right channel.