If today you have typed your credentials into a link that claimed to come from ING, or read a code over the phone to someone who introduced themselves as your bank, what you do in the next few hours decides two things, whether the money actually leaves the account and whether you will later be able to prove that you did not authorise it. A transaction ordered by a third party using your credentials is, in law, an unauthorised transaction, and the payment services rules oblige the bank to refund it, with the sole exception of cases where it finds gross negligence on the customer’s part. That exception is the ground on which the dispute is fought afterwards, and it is won or lost with the evidence you keep from the very first moment. Throughout all of this ING is the impersonated bank, and nothing you have been told or sent comes from it.
How to recognise the message
The pattern repeats with few variations. A text message warns that your account has been blocked or that access has been restricted, that there is a charge or transfer you do not recognise, quoting a specific amount down to the cents so it looks like it came from a statement, or that a new device has been linked to your account. There is always an urgent action to take, verify your identity, cancel the transaction, unlink the phone, and there is always a means to take it, a shortened link or a domain that resembles the official one without being it, or a phone number to call. In other variants the call comes with no prior text, from someone claiming to be from the security department who knows your name and sometimes the last digits of your card.
| Variant | How it arrives | What it asks for | What the scammer obtains |
|---|---|---|---|
| Account blocked or access restricted | Text with a shortened link to a domain that is not the official one | That you enter a cloned website and type your username and password | Your login credentials |
| Unrecognised charge or transfer | Text quoting a specific amount and a number to call | That you call and “cancel” the transaction by giving data and codes | Your credentials and the signing codes |
| New device linked | Text or call warning that someone has added a phone | That you “unlink” that phone by giving the code you receive | The code with which they link their own phone |
| Call from the supposed security department | Call, sometimes after the text, using your name and details | That you move the money to a “safe account” or install a remote access app | A transfer made by you yourself, or control of your phone |
All four variants are after the same thing, that you hand over what a technical attack cannot obtain, the password, the signing code or the transfer order.
Why it looks real
ING has no branch network and the relationship with the customer is conducted through the app and by phone. The scammer exploits precisely that. There is no branch to walk into and ask, and receiving a text or a call from the bank is the normal way of dealing with it. On top of that, fraudulent messages can appear in the same thread as legitimate alerts, because the sender name can be spoofed, and the caller sometimes knows details about you obtained from earlier data leaks. Time pressure does the rest. You are told the money will leave in minutes, that they can see the transaction on screen and that only they can stop it if you cooperate now. Nobody thinks straight with that clock running, which is why hanging up and calling the bank yourself is worth more than any checklist of warning signs.
What no bank ever does
This is not something particular to ING, it applies to every bank in Spain. No bank asks you by text, email or phone for your full login password, nor for the code sent to your phone to sign a transaction, nor for your card PIN. No bank asks you to move money to a “safe account” while it investigates a fraud, because a block is applied internally without moving a single euro. No bank asks you to install a remote access application or to share your screen. And no bank sends you a link by text so that you can verify your identity. If you are asked for any of those things, the person asking is the scammer, whatever name appears on the screen.
What to do right now
If you have only received the message, do not tap the link, do not call the number and do not reply. Check whatever you want to check from the official app or by calling the number printed on the back of your card. Keep the text with a screenshot showing the sender and the date, because that message is evidence and may help identify who sent it.
If you have already handed over your credentials, read out a code or made a transfer, the first hours are the ones that count. Call the number on the back of your card immediately, report what happened, ask for your credentials and card to be blocked and for an attempt to be made to hold the transfer, because some of these transactions can be stopped if the receiving account has not yet been emptied. Ask for written confirmation of the time of your call. After that, delete nothing. Not the text, not the call log, not the app notifications, not the emails. Do not factory reset your phone even if someone tells you it is the prudent thing to do, because it holds the traces of what happened. If you installed an application at the scammer’s request, switch off the data connection and do not uninstall it until someone has made a copy of its contents. And stop taking calls from that number, including those promising to help you get the money back, which are usually the second act of the same scam.
At the firm, when someone calls us at that point, the first thing we do is secure the evidence and, on the same day, organise the notification to the bank and the criminal complaint, which is the work we describe on our cybercrime page.
What the Criminal Code says
Deceiving someone into handing over their credentials and using them to dispose of their money is the offence of fraud under article 248 of the Spanish Criminal Code, punishable with six months to three years in prison. If the amount taken does not exceed 400 euros, the conduct is punished with a fine as a minor offence. Where the amount is high the law provides for heavier penalties, and in practice most of these frauds are investigated as a full offence, because the sums that leave an account in an afternoon of a hijacked session are rarely small.
Three more things about the criminal side matter to you. The first is where to report it. Frauds committed remotely can be investigated in the place where the victim holds the account and suffered the debit, so if you live in A Coruña the complaint and the investigation stay here even if the scammer or the receiving account are in another province or outside Spain. The second is the time limit. Fraud is time-barred after five years as a full offence and after one year as a minor offence, so there is no need to rush the complaint, but there is a need to rush the evidence, which is what gets lost. The third is what happens when the case is closed. Many of these investigations end in a provisional dismissal because the perpetrator is not identified or is beyond the reach of the Spanish courts. That dismissal closes nothing as regards the bank, whose duty to refund does not depend on anyone being convicted, and the case can be reopened if new information emerges, for example when the holder of the receiving account is identified.
The refund by the bank
The criminal complaint and the claim against the bank are two separate routes, and the second is the one that returns the money. The payment services rules oblige the bank to refund the amount of transactions the customer did not authorise, and a transfer ordered by a scammer using credentials obtained by deception is an unauthorised transaction even though it was executed with your password and from your phone. In these cases the bank usually replies that the customer acted with gross negligence by giving out the credentials, and that argument is what decides the outcome. How the transaction is notified, what is submitted, how that argument is answered and when to move from the internal claim to court is the lawyer’s job, and no two cases are alike. I have explained in more detail what can be demanded in the bank’s refund after phishing and in bank impersonation scams and what to do.
What you can do today is avoid handing the bank arguments. Do not sign any document from the bank in which you acknowledge having authorised the transaction or having voluntarily given out your credentials. Describe the facts as they happened, but do not accept in writing the legal characterisation the bank puts on them.
If your account has been used to move another victim’s money
There is a variant in which the person affected does not lose money but receives it. Someone persuades you to accept a deposit and forward it in exchange for a commission, or to open an account in your name for a supposed job. Anyone who does that is acting as a money mule, and the money passing through their account comes from a fraud like the one I describe. The consequence is being investigated for money laundering, and claiming you did not know is not enough, because the law also punishes reckless conduct. If you recognise yourself in this situation, move no more money and find a lawyer before you give a statement, because what you say at the first appearance is what the judge will read.
When to call the firm
Doing this on your own carries a specific risk. A poorly worded explanation to the bank, a form signed without reading it or a reset phone can put in writing the gross negligence the bank needs in order to refund nothing, and that cannot be fixed afterwards. At the firm we practise criminal defence and bring claims against banks in these matters, and in a case like this we secure the evidence, file the criminal complaint and frame the claim against the bank so that the negligence argument does not succeed, which is what we describe under cybercrime. You can call us on +34 677 841 007 or write to us through contact. When you call, have to hand the screenshots of the text with the sender visible, the number you were called from, the statement showing the transactions you do not recognise, the time you notified the bank and what you were told. That is enough to start.
Frequently asked questions
Does ING have to refund me if I entered my credentials on the link in the text?
The payment services rules oblige the bank to refund transactions the customer did not authorise, and a transfer ordered by the scammer using your credentials was not authorised by you. The bank usually replies that there was gross negligence in giving out the credentials, and that is where the claim is decided. Whether it succeeds depends on how the facts are evidenced and how the claim is framed, and that is the lawyer’s job.
Is there any point reporting it if the scammer is in another country?
Yes. The complaint fixes the facts and the date, it is the document the bank will ask you for, and it allows the court to order the receiving account blocked and to find out who opened it. Even if the case is closed because the perpetrator is not identified, the complaint remains the basis of the claim against the bank and the case can be reopened if new information emerges.
I have been told to delete the text and reset my phone for security. Should I?
No. The text, the call log, the notifications and whatever remains on the phone are the evidence of how the deception happened. Change your credentials from the official app, ask the bank for a block and keep the phone as it is until someone has made a copy of its contents.
Do I need a lawyer to claim against the bank?
It depends on the amount and on the bank’s response. If the bank refunds the money after your notification, or the sum is small and the cost of claiming exceeds it, it is not worth it. If the bank refuses citing gross negligence, if the amount is significant or if there is a transfer you made yourself under deception, the claim turns on the evidence and on how it is framed, and there a lawyer is worth having.