The money from an online scam leaves the account in seconds and comes back, when it does, by two routes that have nothing to do with each other. One is criminal, against the fraudster, and it tends to be slow because the perpetrator is outside Spain or hidden behind a chain of intermediary accounts. The other is against your own bank, and it is the one that returns the money in most of the matters we handle at the firm. Confusing the two, or waiting for the first before starting the second, is the most common way of losing money that could have been recovered.
Two routes for the same money
The criminal complaint goes after the perpetrator. It gets an investigation opened, it can get destination accounts frozen if it arrives in time and, if there is a conviction, it leads to a civil liability order. But a fraudster operating from another country under a false identity rarely ends up in a Spanish dock, and when he does he seldom has anything to pay with.
The claim against the bank goes after no one. It rests on the fact that Spanish payment services legislation obliges the bank to refund transactions the customer did not authorise, except in the statutory cases of fraud or gross negligence by the customer. That obligation exists whether or not the fraudster is ever found. This is the route where the money is actually at stake and the one that demands the most care, because what the customer says and signs in the first days shapes everything that follows. How that claim is framed and with which arguments is the lawyer’s job, not this article’s.
The offence in the Criminal Code
Since the reform introduced by Organic Law 14/2022, in force from 12 January 2023, online fraud is punished under Article 249 of the Spanish Criminal Code with six months to three years’ imprisonment. Two forms matter to the victim of an online scam.
Article 249.1.a) punishes anyone who, by means of computer manipulation or a similar device, obtains an unconsented transfer of an asset to the detriment of another. This is computer fraud in the strict sense, the kind that needs to deceive no person because it deceives the system. Phishing that steals credentials and executes a transfer, access to online banking with stolen log-in details.
Article 249.1.b) punishes the fraudulent use of credit or debit cards, or of the data they carry, to carry out transactions to the detriment of the holder or a third party. Online purchases with a card whose details were copied, charges made with a cloned card.
Where the fraud relies on deceiving a person into paying themselves, the applicable offence is classic fraud under Article 248, with the same penalty. If the amount defrauded does not exceed 400 euros it is a minor offence and the penalty is a fine. If it exceeds 50,000 euros, or affects a large number of people, Article 250 applies and the sentence is one to six years’ imprisonment plus a fine. Above 250,000 euros, four to eight years.
These figures matter for two reasons. One is limitation, which is tied to the penalty. The other is that a court does not treat a minor 200-euro fraud the same as an organisation that has emptied hundreds of accounts, and in the second case individual complaints are joined and the investigation has somewhere to go.
The forms we see most
Phishing, smishing and vishing
An email, text message or call imitating the bank, the postal service, the tax agency or the traffic authority, asking you to confirm details or click a link. With the credentials obtained, the fraudster logs into online banking and orders transfers, or calls the victim posing as the security department and asks them to approve a transaction in the app “to cancel a charge”. Here most transactions are unauthorised, and this is the ground where the bank has the most to refund.
Altered IBAN on an invoice
Someone intercepts the email exchange between a company and its supplier and, on the genuine invoice, changes the account number. The payment goes out normally to an account that is not the supplier’s. The transfer is authorised by the person ordering it, so there is little room against your own bank. The work concentrates on the claim against the receiving bank, on the criminal complaint and on the apportionment of liability with the supplier whose email was compromised.
CEO fraud
A variant aimed at companies. An email that appears to come from the managing director orders the finance department to make an urgent, confidential transfer. Beyond the criminal route, there are usually employment and insurance consequences worth reviewing before any internal step is taken.
Investments and cryptocurrency
Platforms with a polished website, an account manager who calls, and a dashboard where the balance keeps growing. When the victim wants to withdraw, “taxes” or “release fees” appear that must be paid first. Every transfer is ordered by the victim, so the bank claim is difficult unless the bank breached its own duty to flag anomalous transactions or payments to entities warned against by the CNMV, the Spanish securities regulator. The CNMV’s list of unauthorised firms is useful evidence.
Wallapop, Vinted, Instagram
A purchase that never arrives, a seller who asks to leave the platform and pay by Bizum or transfer, fake “arrange delivery” links that actually capture the card. Platforms are not liable for fraud between users as a general rule, but they hold data they only hand over on a court order, and that is one more reason to report even when the amount is small.
Romance scam
A relationship through social media or dating apps, weeks or months of conversation, and then a medical emergency, a plane ticket, a customs charge. Amounts tend to be high and split across many transfers. The difficulty is evidential, because the victim wanted to pay, and the evidence is built from the complete conversation history.
Bizum
Two forms. The first is a payment request disguised as a payment sent, the so-called reverse Bizum, where the victim believes they are accepting money and is in fact approving a payment. The second is a Bizum ordered by a third party who has taken control of the phone or the app. Only the second is an unauthorised transaction in the proper sense, and that difference decides the claim.
Fake holiday rentals
Listings copied from real flats, with genuine photos, priced slightly below market, and an owner who is abroad and asks for a deposit by transfer. The victim discovers the fraud on arrival. Report it, keep evidence of the listing and the conversation, and check whether the payment went through the platform or outside it.
Identity theft and SIM swapping
Using personal data obtained elsewhere, the fraudster gets a duplicate SIM card and receives the bank’s verification codes, or takes out loans and financing in the victim’s name. Here there is also the possibility of claiming against the mobile operator and against the lender that granted the loan without verifying identity.
The first hours
The order matters more than the speed of each step.
Call the bank on the number printed on your card or on its official website, never on the number given to you by whoever called, and ask for your credentials to be blocked and the transactions reversed. Note the time, the employee’s name and the incident number. If the transfer is recent, the bank can attempt a recall from the receiving bank, and it sometimes works while the money has not yet left the intermediary account.
Delete nothing. Not the text message, not the email, not the call log, not the WhatsApp conversation. Do not factory-reset the phone even if you suspect it is infected. Preserve the evidence first, clean the device afterwards.
Do not sign or accept in writing anything the bank puts to you in the first days without reading it calmly. Some communications include an account of events in which you acknowledge having handed over your credentials, and that account is later used against you.
Change your passwords from a device other than the compromised one, switch on two-step verification and alert your mobile operator if you suspect a SIM duplicate.
Report the matter to the Policía Nacional or the Guardia Civil with all of the above. The report is needed for the bank claim, for the insurer if there is one and for any later action.
What the bank must refund and what it need not
The distinction that decides everything is whether you authorised the transaction or not. A transfer ordered by a third party using your credentials, a purchase with your card that you did not make, a Bizum sent from an app someone else controlled, are unauthorised transactions and the bank has a legal obligation to refund them. A transfer you ordered because you were deceived, however crude the deception, is an authorised transaction, and against the bank the only question is whether it breached its own monitoring duties.
Banks frequently reject the first claim citing gross negligence, with arguments such as the customer entering credentials on a fake website or approving the transaction in the app. Whether that rejection becomes final depends on how it is answered, with what evidence and at what point. At the firm we first review the bank’s complete file, including the technical logs of the transaction, before deciding what future the claim has.
Evidence you should keep
Screenshots of the message or email showing the sender’s full address or number. The exact URL of the link. The account statement with the transactions marked. The whole conversation, exported, not just photographed. Proof of your call to the bank and its written reply. The listing, profile or platform where it all began. The payee’s details, whether IBAN, name or Bizum phone number. And the police report with its reference number.
With that, a lawyer can assess at a first consultation which route makes sense and what realistic prospect of recovery there is.
Where to report and which court has jurisdiction
The complaint is filed at any Policía Nacional station or Guardia Civil post, or directly with the duty court. For small amounts and simple facts the police station is usually enough. For corporate fraud or large sums we prefer to draft the complaint or the formal criminal petition ourselves, because the initial account determines how the investigation is run.
The fraudster is not in A Coruña, the destination account may be in Lithuania and the server anywhere. The settled position of the Spanish Supreme Court is that fraud is completed where the act of disposal of assets takes place, in other words where the victim orders the payment or where the account the money leaves is held. In practice, the investigating court of your own judicial district. If the police station tells you to report in another city, that is wrong.
Complaint or formal criminal petition
A complaint (denuncia) brings the facts to the authority’s attention and there the complainant’s involvement ends, unless they later join the proceedings. A formal criminal petition (querella) is filed through a lawyer and court agent and makes the victim a party from the outset, with access to the file, the ability to request investigative steps and the right to appeal a dismissal. For a 300-euro fraud a querella is not worth it. For CEO fraud or an investment scam running to tens of thousands of euros, being inside the proceedings or outside them is the difference between freezing orders and data requests being made in time, or not being made at all.
Limitation periods
Fraud above 400 euros, with a maximum sentence of three years, is time-barred after five years (Article 131 of the Criminal Code). Minor fraud, of 400 euros or less, is time-barred after one year. The aggravated forms under Article 250, with maximum sentences above five years, are time-barred after ten.
The civil action against the bank is governed by contractual liability, which is time-barred after five years (Article 1964 of the Spanish Civil Code). None of these periods is the problem in practice. The problem is that the technical evidence is lost long before, and that a late claim is met with the answer that the customer did not report the incident promptly.
If you lent your account, you have gone from victim to suspect
A share of those arrested for computer fraud in Spain have defrauded no one. They are people who agreed to receive money in their account and forward it for a commission, or who opened an account “for a friend”, or who fell for a fake job offer. They are the so-called money mules.
The criminal consequence is real. Whoever receives the proceeds of a fraud and moves them on can be charged with money laundering (Article 301 of the Criminal Code), punishable by six months to six years’ imprisonment and a fine of one to three times the amount, or with laundering by gross negligence (Article 301.3), punishable by six months to two years, if they did not know but should have suspected. They can also be treated as an accessory to the fraud itself. And in civil terms they are liable to the victim for the amount that passed through their account, which is what happens in most convictions, because the mule is the only link that has been identified.
If this has happened to you, the defence consists of proving that you were deceived yourself, and that is built with the same evidence a victim would use. What you do not do is turn up to give a statement at the police station without a lawyer and without having prepared your account.
When the case is shelved
Most online fraud complaints end in a provisional dismissal because the perpetrator is unknown. That does not close the bank route, which is independent, nor does it close the criminal one, which can be reopened if new information emerges, for instance the receiving bank identifying the mule. The dismissal order is also a useful document against the bank and the insurer, because it proves the matter was reported and the money could not be recovered by other means.
When a claim is worth it and how long it takes
The claim against the bank carries no court costs and, properly framed, is resolved in months. It is almost always worthwhile, even for a few hundred euros, because the work is proportionate to the amount and the bank often backs down without any need for litigation.
If the bank stands by its refusal, court is the next step, and that is a question of strategy rather than paperwork. The amount at stake, the quality of the evidence and whatever the bank itself put in writing when it refused all weigh on the decision. We make that assessment case by case before taking any step, because it determines whether the matter is worth litigating or better closed earlier.
The criminal route, when it succeeds, takes years and depends on someone with assets being identified. It is essential for freezing funds, obtaining data and for corporate fraud. As a way of getting the money back, it comes last.
If you have been the victim of an online scam, or have been called to give a statement about money that passed through your account, the firm handles these matters from the first claim to the courtroom. You can see how we work in cybercrime and criminal law, or contact us.
Frequently asked questions
I was scammed online and the bank says I was negligent, is that the end of it?
No. The initial rejection is the standard reply from almost every bank and closes nothing. There are further steps to take, and the arguments the bank uses to justify that refusal are often weak once checked against its own technical logs. What you should do is stop writing to the bank on your own after that first rejection, because every communication is kept on file, and take the file to a lawyer.
Is it worth claiming if I was scammed out of 300 euros?
Yes, against the bank, if you did not authorise the transaction, because the claim costs nothing and banks refund small amounts more readily. Reporting to the police is also worthwhile, even if the case is shelved, because it joins other complaints about the same destination account. What is not worth it at that amount is a formal criminal petition or a lawsuit with a lawyer.
I lent my account to receive a transfer and now the police are calling me, am I a victim or a suspect?
A suspect, regardless of whether you were deceived too. You can be charged with money laundering or with assisting the fraud, and in any event held civilly liable for the money that passed through your account. Give your statement with a lawyer present and with all the evidence of how you were recruited, because that is your defence.
Does an online scam become time-barred?
Yes. After five years if the amount exceeds 400 euros, after one year if it does not, and after ten years in the aggravated forms under Article 250 of the Criminal Code, for instance when it exceeds 50,000 euros. In practice the time limit is rarely the problem. The technical evidence disappears long before.