The bank that received your money and the bank it left from are governed by two different sets of rules, and a good share of claims fail because each bank is asked for what only the other one owes. Your relationship with your own bank, the one that executed the transfer, is governed by payment services regulation, which is what determines when an unauthorised transaction has to be refunded. The scammer’s bank, the one that opened the receiving account and kept it running, has no contract with you at all. What binds it is Law 10/2010 on the prevention of money laundering, and that law imposes duties towards the State, not towards the person who has been defrauded. Asking the receiving bank for “a refund of the transfer” as if it were your bank leads nowhere, and asking your own bank to explain why the receiving account existed leads nowhere either. The question I am asked at the firm, whether you can claim against the bank where the scammer’s account sits, has an affirmative answer, but the route runs through non-contractual liability under article 1902 of the Spanish Civil Code and requires proof of specific negligence.
What can be demanded from each bank
Your own bank is claimed against under payment services regulation. That regulation obliges it to refund unauthorised payment transactions, subject to exceptions tied to the customer’s conduct, and the claim has its own rules on evidence and time limits which I do not set out here, because framing that claim properly is precisely the lawyer’s job. I explain the general scope of that obligation in this other article.
That regulation cannot be invoked against the receiving bank, because you are not its customer and have given it no payment order. What it can be reproached with, where the facts support it, is having opened or maintained an account without meeting the due diligence duties the law imposes on it, and having allowed through that omission the money to be collected and vanish. That is a claim in damages, with its own evidence and its own limitation period, which I address below.
Unauthorised transfers and transfers authorised under deception
Who is liable depends on this distinction, so it comes before anything else.
An unauthorised transfer is one you did not order. Someone accessed your online banking with your credentials, obtained through phishing, a fake text message or an unlawful intrusion into your email, and ordered the payment in your name. Here payment services regulation places the refund obligation on your own bank, unless it can prove fraud or gross negligence on your part.
A transfer authorised under deception is one you ordered yourself, with your signature or your credentials, because you were made to believe something false. You paid for a car that did not exist, a fabricated accommodation booking, an invoice whose IBAN had been swapped by an intruder in the supplier’s email, or you moved your money to a “safe account” following instructions from someone posing as your bank. The transaction is formally valid, your bank executed it correctly and the route against it is far narrower. In this second group the liability of the receiving bank carries real weight, because it is often the only solvent party that took part in the fraud.
If you paid and the goods never arrived, before discussing banks you need to rule out a plain civil breach of contract with no prior deception, which is not a crime.
The receiving bank’s due diligence
Law 10/2010 obliges institutions to formally identify whoever opens an account and verify their documents (article 3), to identify the beneficial owner where the formal holder acts on behalf of another (article 4), to establish the purpose and nature of the business relationship (article 5), to monitor that relationship on an ongoing basis so that transactions are consistent with the customer’s profile (article 6) and to apply all those measures with an intensity proportionate to the risk (article 7). Article 17 adds the special examination of any transaction which, by its amount or nature, may be linked to money laundering, and its reporting to SEPBLAC where appropriate.
Accounts that receive scam proceeds tend to show a recognisable pattern. They were opened recently, often remotely and with documents of doubtful authenticity, they show no activity consistent with a private individual or a business, they suddenly receive one or several transfers from people with no connection to the holder, and they are emptied within minutes through cash withdrawals, onward transfers abroad or cryptocurrency purchases. That is, as the legislator described it, the very situation ongoing monitoring and special examination are designed to catch.
The legal difficulty is that those duties are owed to the State. Their breach is punished administratively and does not on its own give the victim a right to recover from the bank. That is why the claim is not built directly on Law 10/2010 but on article 1902 of the Civil Code, which obliges anyone who causes damage to another through negligent act or omission to repair it. The anti-money-laundering law serves to set the standard of care the bank was held to and, once it is shown that the bank fell short of it and that the loss flowed from that omission, the damage is attributed to the bank. This is the culpa in vigilando the courts refer to, which they have accepted in some cases and rejected in others depending on the evidence obtained about how the account was opened and how the money moved.
That evidence is not in your hands. It sits in the account-opening file, the transaction logs and the institution’s internal alerts, and it is only obtained through criminal proceedings or the appropriate judicial measure. At the firm we handle bank fraud and cybercrime matters, and assessing whether the receiving bank can be sued, and with what realistic prospects, is the first thing we do before recommending that anyone spend a euro on litigation.
Verification of the payee’s name
Since 9 October 2025, Regulation (EU) 2024/886 requires banks to check, before executing a euro transfer, that the beneficiary name you type matches the holder of the destination IBAN, and to warn you if it does not match or matches only in part. This measure strikes directly at swapped-IBAN invoice fraud and at sales collected in a third party’s name, because the money no longer travels blind.
It has two consequences for the claim. If your bank did not run the check, or ran it badly, and you paid the wrong person, the failure is attributable to the bank. If the check was run, the bank warned you that the name did not match and you confirmed the order anyway, that warning will be used against you. Keep the warning, or record its absence, because it is a fact that decides the matter one way or the other.
Recalling the transfer and accounts abroad
An executed transfer cannot be cancelled. What exists is the interbank recall request, which your bank passes to the receiving bank and which the latter honours only if the funds are still in the account and, in practice, if the holder consents or the account has already been frozen. For transfers with an incorrect unique identifier, article 59 of Royal Decree-Law 19/2018 obliges your bank to make reasonable efforts to recover the funds and, failing that, to provide you with the information it holds so that you can bring a claim. That provision is designed for IBAN errors, but it is the reference relied on to demand that the bank act quickly rather than simply tell you to report the matter to the police.
Speed is everything. Scam proceeds are withdrawn or forwarded the same day, and a recall that arrives the following week finds an empty account. If the receiving account is in another European Union country, the receiving bank remains subject to EU anti-money-laundering rules and both the civil and criminal routes remain open, though slower and more expensive. If it is outside the Union, recovery depends on international judicial cooperation and the outlook is, broadly speaking, poor unless the sums involved justify the effort.
The offence of fraud and its penalties
Article 248 of the Spanish Criminal Code punishes as fraud the use of sufficient deception to cause error in another and induce them to dispose of property to their own or a third party’s detriment. Article 249 sets the penalty and also punishes the non-consensual transfer obtained through computer manipulation or a similar device, which is the offence committed when a transfer is made with your stolen credentials. Article 250 contains the aggravated forms, which raise the penalty where the fraud concerns a dwelling, exceeds certain amounts, affects a large number of people or was committed by abusing personal relationships or business or professional credibility.
| Scenario | Criminal Code article | Penalty |
|---|---|---|
| Fraud of up to 400 euros | 249 | Fine of one to three months (minor offence) |
| Fraud of more than 400 euros | 249 | Imprisonment of six months to three years |
| Fraud of more than 50,000 euros or affecting a large number of people | 250.1 | Imprisonment of one to six years and a fine of six to twelve months |
| Fraud of more than 250,000 euros | 250.2 | Imprisonment of four to eight years and a fine of twelve to twenty-four months |
| Intentional money laundering by the mule account holder | 301.1 | Imprisonment of six months to six years and a fine of one to three times the amount |
| Money laundering through gross negligence | 301.3 | Imprisonment of six months to two years and a fine of one to three times the amount |
The complaint is filed with the Policía Nacional or the Guardia Civil, and the case is investigated by the court of the place where the offence was committed. In transfer scams the Supreme Court has settled on the criterion that this place is where the victim held the account from which the money left, so an A Coruña resident defrauded by someone who collected the money in Valencia or Lithuania reports it in A Coruña and the case is investigated here.
As for time limits, basic fraud becomes time-barred after five years and aggravated fraud under article 250 after ten (article 131 of the Criminal Code). The civil action under article 1902 against the receiving bank becomes time-barred one year after you were in a position to bring it, although that year does not run while criminal proceedings remain open. That combination often dictates the order in which steps are taken.
What you can do today without a lawyer
What you do in the first hours does not replace the claim, but it decides what evidence will survive. Keep the transfer receipts showing the full destination IBAN and the beneficiary name exactly as you typed it. Do not delete the emails, WhatsApp or Telegram messages or the advertisements, and take screenshots with the date and time visible before the scammer removes them. Note the phone numbers, profiles and email addresses used. Notify your bank of the transaction through a channel that leaves a written record, not only by phone. If your online banking was accessed, change your credentials from a different device and do not install anything you are told to install from an unknown number.
And do not pay anyone who offers to recover the money. The “fund recovery firms” that contact victims a few days after the fraud are part of the same fraud, and the second payment is lost just like the first.
The mule account and civil liability arising from the offence
Between the scammer and you there is almost always an account holder who lent or sold their IBAN, the intermediary the courts call a mule. That person is liable for money laundering (article 301), in many cases also as an accessory to the fraud, and is frequently the only identifiable party, because they are traced through the ownership of the account.
Articles 109 to 116 of the Criminal Code provide that anyone convicted of an offence is obliged to make restitution, repair and compensate the damage caused, and that this civil liability is declared in the criminal judgment itself. If the mule is convicted, the judgment orders them to repay you the amount and that order is enforced against their assets. The practical limit is obvious, because someone who rents out their account for two hundred euros is usually insolvent. That is why the action against the receiving bank is the complement and, at times, the only real source of recovery.
If the person reading this is the one who agreed to receive money into their account in exchange for a commission, or to “help” someone they met online, the situation is reversed. Gross negligence under article 301.3 does not require knowing the money was stolen, it is enough that you ought to have suspected it, and the summons as a suspect usually arrives months after the matter has been forgotten. There, the criminal defence is exercised from day one, not from the trial.
What happens when the case is shelved
Most computer fraud cases end in a provisional dismissal for want of a known perpetrator, especially when the account is abroad or the holder has disappeared. That dismissal closes nothing for good. The case is reopened if new facts emerge, and the civil action against the receiving bank remains intact, with its one-year period counted from when the dismissal becomes final and is notified to you. Whatever the investigation managed to gather about the receiving account, even if it is not enough to convict anyone, is the documentary basis for the civil claim, and that is why it pays to join the criminal proceedings as a private prosecutor even when the criminal prognosis is poor.
Those who pursue this on their own tend to make two mistakes that cannot be undone. They ask the receiving bank for what it cannot give and let the civil action’s year slip by while waiting for news from the criminal case, or they accept their own bank’s rejection letter without having framed the claim in the terms the regulation requires. At the firm we determine which bank is liable and through which route, we join the criminal proceedings to obtain the evidence on the receiving account and, where there is a basis for it, we sue the receiving bank under article 1902. If you have been scammed by bank transfer, call +34 677 841 007 or write through the contact page. Have to hand the transfer receipt with the destination IBAN and the exact date, your communications with the scammer, your bank’s reply if you already have one and the police report if you have already filed it. The detail of what we do in bank fraud and cybercrime is on the practice area page.
Frequently asked questions
Can I claim against the scammer’s bank even though I am not its customer?
Yes, through non-contractual liability under article 1902 of the Spanish Civil Code. You are not a customer and have no contract, so you cannot invoke payment services regulation, but you can claim for the damage if it is proven that the bank breached its due diligence duties under Law 10/2010 when opening or maintaining the account, and that this omission allowed the money to disappear. The courts have accepted this in some cases and rejected it in others, and everything turns on the evidence obtained about the receiving account.
Can the bank cancel the transfer once it has been sent?
No. An executed transfer is irrevocable. What your bank can do is ask the receiving bank to return the funds, and the receiving bank only does so if the money is still in the account. In scams the account is emptied within hours, so the request is only useful if made the same day.
What if the money was sent to an account in another country?
If the account is in the European Union, the receiving bank is subject to the same EU anti-money-laundering rules and a claim is possible, though slower and more expensive. Outside the Union, recovery depends on international judicial cooperation and, unless large sums are involved, the outlook is poor. The complaint is still filed in Spain, at the place from which the money left.
Is it worth claiming, and do I need a lawyer for this?
It depends on the amount and the route. If you lost less than 400 euros, report it so that the facts are on record, but it is not worth paying a lawyer to litigate against any bank. If the transfer was unauthorised, the claim against your own bank has good prospects and is worth framing properly from the outset. If you made the transfer yourself under deception and the amount is significant, the action against the receiving bank requires evidence that can only be obtained through proceedings, and there a lawyer is indispensable because the one-year limitation period and the evidence that disappears allow no second chance.