CEO fraud and when the bank must refund

What crime CEO fraud is in Spain, why banks usually refuse a refund, when they are liable anyway and what to do in the first hours to recover the money.

Above 250,000 euros defrauded, fraud in Spain is punished with four to eight years in prison (Article 250.2 of the Criminal Code). Above 50,000 euros and up to that figure, the sentence is one to six years (Article 250.1.5). The 900,000 euros that a Catalan company transferred after being deceived by someone imitating the voice of its chief executive therefore fall within the most serious bracket of the offence. That figure sets the sentence of a perpetrator who almost never ends up in the dock. The question that decides whether the company ever sees its money again is settled elsewhere, in whether the transfer counts as authorised or not. A judgment of a Barcelona court reported on 9 September 2026, according to Cinco Días, has just ordered a bank to refund those 900,000 euros, and what matters is why.

What CEO fraud is and why it keeps working

CEO fraud, also known as business email compromise or BEC, consists of impersonating an executive with decision-making power so that an employee with access to the company’s treasury orders an urgent, confidential payment to an account controlled by the fraudsters. The deception is prepared in advance. Before calling or writing, the perpetrators study the company in the commercial registry, on its corporate website and on professional networks, work out who gives orders, who pays and who is travelling, and learn how these people write to one another. With that material they build a credible approach, an email from a near-identical domain, a WhatsApp message from a new number “because my company phone is broken” or, as in the Barcelona case, a call in which the caller ID shows the real number of head office because the calling number has been spoofed.

Pressure is the active ingredient. There is urgency, an acquisition closing today or a deadline expiring this afternoon; there is confidentiality, so that nobody else in the company may know; and there is a reason why the executive cannot do it personally. That combination disables the usual controls because the employee believes that bypassing them is precisely what is being asked from above. Once the money leaves, it goes to an account opened in a third party’s name, often in another country, from which it is dispersed within hours.

The variants change with the technology. Email is still the most common, WhatsApp has gained ground and voice cloning is now used to imitate an executive. That is exactly what happened in the Catalan case, where the voices of the parent company’s chief executive and of the subsidiary’s general manager and finance director were all imitated. It must be distinguished from supplier fraud, where the fraudster gets into the correspondence with a genuine supplier and changes the account number on a genuine invoice. There the payment is legitimate and only its destination is diverted; in CEO fraud the whole payment is invented. The difference matters later, because in supplier fraud the dispute usually turns on who bears the loss as between customer and supplier, whereas in CEO fraud there is no supplier to claim against and everything concentrates on the bank and on the destination accounts.

The Barcelona case, 900,000 euros and a bank found liable

The facts, as Cinco Días describes them, are these. A Catalan company, subsidiary of a German parent, received a call in which the phone displayed head office’s number. On the line, someone imitating the voice of the parent company’s chief executive asked, with great urgency, for a confidential payment of 900,000 euros that he could not process himself because he was travelling. To reinforce the story, emails arrived purporting to come from the external lawyer who handled the parent company’s legal affairs. Given the amount, the subsidiary’s directors asked their bank branch for help. The initial destination was an account in Hong Kong; when the transfer ran into technical problems, the fraudster switched the destination on the spot to an account in Portugal, and the people who dealt with the company, staff at one of the bank’s call centres and not its usual relationship manager, guided it through the technical problems and helped complete the transfer. Shortly afterwards, the general manager and the finance director called the real parent company and discovered the deception.

The court found no lack of diligence on the part of the company’s employees. According to Cinco Días, the judgment reasons that “an average consumer of banking products would have fallen victim to the offence, only a highly diligent or suspicious course of action could have detected that a property offence was being suffered”, and places liability on the bank as the party responsible for the security of the funds, “a conclusion which is nothing but the counterpart of a system that allows funds to be transferred in tenths of a second from one place to another with no possibility of recovery”. It adds that “this is the price” of the computerisation of banking services and that the usual branch manager would have noticed how odd the transaction was, which did not happen with call centre employees “who lack knowledge of the company’s history and way of operating”. The company’s lawyer, Diego Zapatero of Asoban Abogados, told the newspaper that the bank “actively cooperated in its own detriment”, that its liability is “quasi-objective” and that when the destination changed from Hong Kong to Portugal “the bank should have set off every alarm”. That last part is one party’s position, not the court’s.

Two warnings before drawing conclusions. This is a first instance judgment and it can be appealed. And the newspaper itself notes that it departs from other rulings in similar cases which found for the banks. Anyone who reads the headline and assumes the bank refunds the money in CEO fraud is mistaken. What the judgment shows is that, on certain facts, it can.

Authorised by deception or unauthorised, the line that decides the claim

I will explain why most rulings favour the bank. In phishing, in SIM swapping or in unauthorised access to online banking, the money is moved by a third party without the customer’s involvement. Those are unauthorised transactions, and for them the payment services rules impose a very demanding refund obligation on the bank, which I covered when discussing when the bank must refund phishing losses. The Supreme Court applied that regime in Judgment 571/2025 of 9 April, Civil Chamber, reporting judge Manuel Almenar Belenguer, ECLI:ES:TS:2025:1671, in the case of an Ibercaja customer who suffered fraudulent transfers of 56,474.63 euros on 17 and 18 March 2021 through a SIM card duplicated without his authorisation. The Court of First Instance No. 7 of Zaragoza and the Provincial Court of Zaragoza held the bank liable for breach of the distance banking contract, and the Supreme Court dismissed the bank’s cassation appeal and upheld the ruling.

That is not what happens in CEO fraud. The transfer is ordered by the company itself, with its own credentials, signatures and authorised signatories, even if it does so under deception. Article 36.1 of Royal Decree-Law 19/2018 on payment services treats a transaction as authorised when the payer has given consent, and consent vitiated by a deception unrelated to the bank is still consent for these purposes. That is why the protective regime for unauthorised transactions does not apply directly. On top of that, a company that is not a micro-enterprise has less of a safety net than a private individual, because Article 34.1 of the same law allows the bank to agree with it that several of the protective rules will not apply, and corporate banking contracts usually take advantage of this.

The third piece is Article 59. An order executed in accordance with the unique identifier, the IBAN, is deemed correctly executed, and the bank does not have to check that the beneficiary name the company typed matches the real holder of the account. The judgments that absolve banks are built on that article. A recent example is Judgment 528/2025 of 7 November of the Fourth Section of the Provincial Court of Asturias (ROJ SAP O 3805/2025), which absolved the receiving bank in a 50,000 euro CEO fraud, with an invoice and account changed by email, because the bank executed the order in accordance with the IBAN and because the ordering company was negligent in not checking an odd email that changed the account. The Provincial Court applied the doctrine of the judgment of the Court of Justice of the European Union of 21 March 2019 (Case C-245/18, Tecnoservice) and Supreme Court Judgment 507/2025 of 27 March, which limits the bank’s liability to correct execution in accordance with the IBAN except, among other cases, where, once the error is reported without delay, the bank fails to take the measures that the diligence of an expert merchant would require to allow reversal or to minimise the loss.

With those three articles on the table, the question of whether the bank has to refund the money in CEO fraud starts with an answer unfavourable to the company. In our firm, when a company comes to us with a fraud of this kind, the first thing we do is reconstruct minute by minute what the bank did during that transaction, because that is where the only open door lies, and from that reconstruction we tell the client whether there is a case or not. It is part of what we do in cybercrime.

When the bank is liable regardless

The remaining door is the contractual liability of the company’s own bank for lack of diligence in that specific transaction, based on Articles 1101 and 1104 of the Civil Code. The bank is not liable for having executed an order with a correct IBAN. It is liable if, in the way it processed the order, it fell short of the diligence required of a professional holding its customer’s funds in custody. That is what the Barcelona court applied, and the facts it weighed mark out what to look for in any similar case. Bank employees actively guided the transaction instead of merely receiving an order. The destination country changed on the spot, from Hong Kong to Portugal, in a transfer of almost a million euros. And the people handling it did not know the company’s history or its way of operating, when the usual relationship manager did.

What the bank did decides the outcome. Whether the transaction triggered internal alerts that nobody dealt with, whether questions were asked or not, whether the amount was unusual for that account, whether there was a change of beneficiary or of country and how the bank reacted, whether the bank knew its customer and used that knowledge. Weighed against this is the company’s own conduct, because clear negligence at the origin, such as failing to check an odd email in the Asturias case, closes the route. None of this can be improvised when the claim is drafted. It has to be documented from day one, while the bank can still be asked for the transaction records and while people still remember who said what. How that claim is framed, what is demanded, in what order and with what evidence, is the lawyer’s job.

What crime it is and what sentence it carries

CEO fraud is fraud under Article 248 of the Criminal Code, a sufficient deception that induces an act of disposal of property to the detriment of the victim or a third party. The basic sentence is six months to three years in prison, and only where the amount does not exceed 400 euros is it reduced to a fine. Above 50,000 euros, Article 250.1.5 comes into play, with one to six years in prison, and above 250,000 euros Article 250.2 applies, with four to eight years. Whoever receives the money in their account and forwards it, the so-called money mule, may be liable for money laundering under Article 301, and this is so even where they did not know for certain where the money came from, because Article 301.3 punishes laundering committed through gross negligence with six months to two years in prison.

Conduct Article of the Criminal Code Sentence
Fraud not exceeding 400 euros 248 Fine
Basic fraud 248 Six months to three years in prison
Fraud exceeding 50,000 euros 250.1.5 One to six years in prison
Fraud exceeding 250,000 euros 250.2 Four to eight years in prison
Laundering through gross negligence (money mule) 301.3 Six months to two years in prison

In practice the perpetrator is almost never identified. What is identified is the destination account and its holder, and that is where funds get frozen and part of the money recovered, as well as where the person who lent their account is traced. For the company, the criminal complaint serves to attempt the freezing of that account, to obtain the identity of its holder and to place on formal record, as against the bank and the insurer, that the transaction was fraudulent. It can be filed in the place from which the transfer was ordered, which is where the loss occurred, without having to go to the place of the destination account or of the fraudster. With these sentences, the limitation period for the offence is counted in years and is not what is pressing. What is pressing is that the money is dispersed within hours.

The first hours, what to do and what not to touch

Everything that can be recovered of the money is decided in the first hours, and during that stretch the company acts alone. First, call the bank and request the recall of the transfer. Within the SEPA area, as with Portugal, this is possible if the destination account has not yet been emptied; outside it, as with Hong Kong, it almost never succeeds. Next, notify the bank in writing, without delay, that the transaction is fraudulent, and keep the acknowledgement of that notification, because the date of that notice will be argued over later. The criminal complaint follows, and it must include the emails with full headers and not merely the forwarded text, any recordings, the transfer receipts and the entire conversation with the supposed executive, including the earlier messages that seemed harmless, and it must expressly request the freezing of the destination account and the identification of its holder. If the company has a cyber risk policy with cover for transfer fraud, notify the insurer that same day, because policies set a notification period and delay is the easiest excuse for not paying. How that evidence is preserved matters, and I have written before about why electronic evidence decides cases.

Do not delete anything. Not the email from the fake domain, not the WhatsApp chat, not the call log of the phone that received the call, not the drafts of the payment order. Do not forward the original emails to anyone outside the company; export them with headers and keep them on separate media. Do not call back the number that called you and do not reply to the fraudster’s email, because you will give away information and warn them that the transaction has been discovered. And do not sign anything the bank puts in front of you in those days without reading it carefully, because confirmation documents or acknowledgements of the order turn up later in the litigation. After that come the written claim to the bank and, if it is rejected, the civil action. Do not do that part on your own.

The employee who ordered the payment and the directors

One of the first questions a director asks is whether the loss can be passed on to the employee who executed the order. For an employee to answer with their own assets for damage caused at work, something more than a mistake is needed; there must be gross negligence or conduct outside the instructions received, and the courts are restrictive. The Barcelona court’s reasoning cuts against that claim, because if an average banking consumer would have fallen for the deception, the employee can hardly be reproached for not having been “highly diligent or suspicious”. It is a different matter if the employee bypassed a written two-step verification protocol that the company had in place and that the employee knew about. There the conduct changes in nature and may carry disciplinary consequences, with dismissal a possibility in the clearest cases, as well as opening the door to a damages claim. Without a prior protocol, claiming against the employee is usually a poor investment and also weakens the company’s position against the bank, because it admits that the negligence was in-house.

The other side is the liability of directors towards the company and its shareholders. A director has a duty to manage with the diligence of an orderly businessperson, and that includes payment controls proportionate to the size of the company. If a company with significant treasury has no dual authorisation, no second-channel verification and no instructions to staff, and loses a substantial sum as a result, the shareholders may ask whether the loss has someone answerable for it inside the company. It is an action rarely seen in this type of fraud, but it exists, and it is one more reason for the protocol to be written and approved before it is needed.

Prevention, what costs little and avoids almost everything

Any urgent or confidential payment is verified through a channel different from the one the request came through, and to a number that was already in the address book before that day, never to the one shown in the email or message received. Large amounts require dual authorisation without exception, and the exception is precisely what the fraudster will ask for. Any change of account or destination country is treated as an alarm and not as a technical hiccup. And treasury staff are trained with real cases, because an employee who has heard how a calling number is spoofed or a voice cloned reacts differently. None of these measures costs money and any one of them would have stopped the Barcelona case.

Handling this on your own carries two specific risks. The first is losing the hours in which recall and freezing are still possible, which is when money actually gets recovered. The second is framing the claim against the bank as if it were phishing, under the wrong rules, so that the bank rejects it with Article 59 in hand while nobody has documented the failures of diligence that are the only real basis. In our firm we conduct these matters on both tracks, the criminal track against the destination accounts and their holders and the civil track against the bank where its conduct in the transaction allows it, and we also defend the company when the bank or the insurer tries to shift the negligence onto it; I explain this on the cybercrime page. If this has happened to your company, call +34 677 841 007 or write through our contact page. Have to hand the transfer order with date and time, the complete emails and messages that led to the payment, the name of the person who dealt with you at the bank and through which channel, the written notification to the bank with its acknowledgement, the criminal complaint if already filed and the company’s insurance policy.

Frequently asked questions

Does the bank have to refund the money in a CEO fraud?

Not automatically. The transfer was ordered by the company itself, so the law treats it as authorised even though there was deception, and the refund regime for unauthorised transactions does not apply directly. The bank is liable when, in that specific transaction, it acted without the required diligence, for example by guiding an unusual transfer without asking questions or ignoring a change of destination country, and provided the company was not itself negligent. The Barcelona judgment held the bank liable on that basis, but it is a first instance ruling and most published decisions find for the banks.

How long do I have to claim and to report the crime?

The legal time limits for notifying the bank, claiming for breach of contract and prosecuting the offence are counted in months and years, and none of them is the real problem. The problem is the money, which is dispersed from the destination account within hours. Notify the bank in writing the same day, request the recall and file the criminal complaint in the following days. Every day that passes reduces what can be frozen.

Is there any point reporting it if the money is already in a foreign account?

Yes. The perpetrator is almost never identified, but the destination account and its holder are, and the complaint allows you to request the freezing of that account and to trace whoever lent it, who may be liable for money laundering even if they claim to have known nothing. Within the SEPA area there are real chances of recovering part of the money if you act fast; outside it, as with Hong Kong, almost none. The complaint is also the formal record of the fraud that the bank and the insurer will demand from you.

Is it worth claiming against the bank or is it throwing money away?

It depends on what the bank did in that transaction. It is worth it when there are concrete facts to document, bank employees who took part in the transfer, an amount far outside the normal pattern of that account, a change of beneficiary or of country on the spot, alerts that nobody dealt with. It is not worth it when the company ordered a transfer that was normal within its operations to a valid IBAN without the bank being involved in any way, or when there was clear negligence within the company, such as paying to an account changed by an email nobody checked. In those cases Article 59 of the payment services rules sides with the bank and the cost of litigation is not justified. We will tell you which case yours is before anything is filed.