“My Openbank account has been hacked” is how almost everyone arrives at the firm, and in legal terms it is inaccurate. Nobody broke through a technical barrier to get into your bank. A text message or a phone call pretending to come from the bank persuaded you to hand over your credentials or to approve a transaction, and the Spanish Criminal Code calls that fraud, Article 248, punishable with six months to three years in prison, or a fine where the amount defrauded does not exceed 400 euros. The distinction has consequences. In criminal proceedings, classifying the facts as fraud rather than intrusion determines what is investigated and against whom. Before the bank, recognising that there was deception rather than someone else’s access is what allows you to argue that you did not authorise the transaction, which is exactly what the bank will dispute. It should be clear from the outset that Openbank is the impersonated bank here, not the fraudster.
What the message impersonating Openbank looks like
The wording changes every few weeks, so what helps is knowing the pattern rather than memorising a specific text. Almost all of them announce a problem that requires immediate action. The most common ones refer to unusual activity on your card, a login from an unrecognised device, a charge you do not recognise or an account blocked for security reasons. The message ends with a link, often shortened, leading to a domain that is not the bank’s official one even though it copies the name and the design. On that cloned site you are asked for your username, your full password, your card details or the code you have just received by text.
The second variant is the phone call. Someone claiming to be calling from Openbank about a security matter tells you there is a transaction in progress and that it has to be stopped. They ask you to read out the code that has just arrived, to install an application so a technician can check your phone, or to move your balance to a “safe account” while the incident is resolved. Often the call follows an earlier text, or the other way round, so that one lends credibility to the other. In some cases the number on screen looks like the bank’s, because caller ID can also be spoofed.
Why it looks real
Openbank is a bank without branches. The entire relationship with the customer runs through the app, the website and the phone, and the fraudster exploits precisely that. Nobody expects a call from a branch, so a text or a call does not seem out of place. The fake message can also appear in the same conversation thread as your legitimate alerts, because the alphanumeric sender of a text message is easily spoofed. The recipient sees one more alert below the earlier ones and has no reason to be suspicious.
There is a third element, which is time. The whole message is built so that you act before you think, which is why it talks about blocked accounts, charges in progress and unknown devices. The correct response to any of those alerts, real or not, takes two minutes and does not go through the link in the message.
What no Spanish bank ever does
This is not something specific to Openbank. It applies to every bank in Spain and rules out most attempts without further analysis. Your full login password and your signing key are never requested by text, phone or email. The one-time code sent to your phone exists precisely so that only you know it, so no genuine employee will ask you for it. There is no such thing as moving money to another account to protect it, nor a technician who needs to install remote-control software on your phone. And genuine security alerts do not carry a link to “verify your identity”.
If the message contains any of those requests, you already know what it is. If in doubt, close the message, do not touch the link and check the state of your account by logging into the official app or calling the number printed on the back of your card or shown inside the app itself. Never the number given in the message or by the person who called you.
What to do in the first hours
If you have already tapped the link, entered details or taken the call, what you do in the first hour decides much of what can be recovered and what can be proved later. The sensible order is to cut off first, document second and report as soon as possible.
Cutting off means blocking the card and changing your credentials from the official app, and telling the bank, through the official number, that there have been transactions you did not authorise. The sooner that communication is on record, the better for everything that follows. If you installed an application at the request of the supposed technician, disconnect the phone from the internet and do not use it to access the bank until it is clean.
The second step is documenting, which means deleting nothing. Keep the text with the number or sender that sent it, take screenshots of the fake website with the address visible if it is still open, note the time and number of the call, and download the statement showing the movements you do not recognise. All of that will be the evidence in the police report and in the claim.
| What happened | What was taken | First step today |
|---|---|---|
| You entered your card details on the fake site | Card charges, sometimes in a series of small amounts | Block the card and report the unrecognised charges to the bank |
| You gave your login password and a text code | An ordinary or instant transfer from the account | Change your credentials and report the unauthorised transaction to the bank |
| You approved a Bizum you were told would “cancel” something | A Bizum payment to a private individual | Tell the bank immediately and file a police report, because the recipient is usually an identifiable money mule |
| You installed remote-control software or registered a device | Ongoing access to the account and later transactions | Disconnect the phone, change credentials from another device and remove the intruding device |
The route to recovery is not the same in each row, which is why it matters to know exactly what kind of transaction was made. A card charge, an instant transfer and a Bizum are different payment transactions, with different recipients and different chances of reversal.
If you already gave your credentials or approved a payment
This is the core problem and also the part almost nobody explains. Payment services legislation obliges the bank to refund transactions the customer did not authorise. The fact that you typed your credentials into a fake website, or read a code over the phone to someone you believed was the bank, does not automatically make the transaction authorised. Authorising means consenting to a specific transaction knowing what you are doing, and a victim of deception is not consenting to what is actually being executed.
What will happen in practice is that the bank replies that the transaction was validated with your credentials and that the responsibility is therefore yours. That is the battleground in the vast majority of these cases, and it is won or lost on the evidence of how the deception occurred, when it was reported and how the claim was framed from the very first letter. Building that is the lawyer’s job, and it is what we do at the firm when someone comes to us with a text or a call of this kind, within our cybercrime practice. I have written about what the bank must refund after a bank impersonation scam in this article, and about refunds after phishing in this one.
If the bank refuses, there is a further complaint route and, ultimately, the courts. Neither can be improvised, and both are decided by what was done and kept in the first few days.
The police report, where to file it and what it is for
A report to the Policía Nacional or the Guardia Civil is not a decorative formality. It is the record that you have been the victim of an offence under Article 248 of the Criminal Code, and the claim against the bank rests on it. Bring the screenshots, the statement and the details of the call. The report also opens the possibility of identifying the destination account and its holder.
As for which court investigates, these offences are committed from anywhere, sometimes from outside Spain, but the loss occurs where your account is. In general, the investigation can be taken on by the court of the place where you suffered the loss, which in practice is usually where you live. Filing the report in A Coruña is not an obstacle.
The limitation period for basic fraud is five years. Where the amount does not exceed 400 euros, it is a minor offence and the period is one year. Neither is a problem if you act in the first weeks, but it becomes one when the victim lets the matter go out of embarrassment or because the amount seems small.
The person who received the money also has a problem
The money leaving your account usually goes to the account of a private individual who has handed it over in exchange for a commission, or who has in turn been deceived with a job offer or a relationship. This is the money mule. Anyone who lends their account to receive and forward money of unknown origin risks being investigated as a suspect rather than a mere witness, and the excuse of not knowing where the money came from holds up poorly once several transactions have gone through. I mention it because people in that situation also come to the firm, and because for the victim, identifying that account is often the only realistic route to recovering something through a civil claim when the perpetrator is beyond the courts’ reach.
What happens when the case is closed
Many of these cases end with a provisional dismissal because the perpetrator is not identified or is outside Spain. That does not mean the matter is over for you. Closure of the criminal case does not affect the bank’s obligation to refund what was not authorised, and the investigative steps already taken, including the identification of the destination account, remain usable as evidence in the claim against the bank and, where appropriate, in a civil action against whoever received the money.
What we do at the firm
Those who claim on their own tend to make two mistakes that later cost them the case. The first is describing the facts to the bank in a way that has the victim admitting to having authorised the transaction, without knowing what that implies. The second is accepting the first refusal as final. At the firm we review how the deception occurred, which transactions were made and what you reported and when, we file the police report and we bring the claim against the bank with the evidence in order from the start, within our cybercrime practice. You can call +34 677 841 007 or write through the contact page. When you call, have to hand the text or the details of the call, any screenshots you took, the statement showing the unrecognised transactions, and the date and time you notified the bank.
Frequently asked questions
Is Openbank obliged to refund my money if I fell for the fake text?
Payment services legislation obliges any bank to refund a transaction the customer did not authorise. The fact that you were deceived by a third party impersonating Openbank does not make the transaction authorised. The bank may object on the grounds that the transaction was validated with your credentials, and that is where the case is decided, on the evidence of how the deception took place.
What if I entered my credentials or the code on the fake website myself? Do I lose the right to claim?
You do not lose it automatically. Typing your credentials into a website imitating your bank is precisely what this deception consists of, and a claim remains possible. The bank will try to argue that there was serious carelessness on your part, and whether that succeeds depends on the specific circumstances and on how the claim is framed from the first letter.
Where do I report it and in what order, the bank, the police or the Bank of Spain?
First tell the bank, through the official number, that there are unauthorised transactions, and block your card and credentials. Then file a report with the Policía Nacional or the Guardia Civil with the screenshots and the statement. The formal claim against the bank and, if it is rejected, the subsequent routes come afterwards and rest on those first two steps.
Do I need a lawyer to get the money back?
It depends on the amount and on the bank’s response. If they are small card charges and the bank refunds them when you report them, you do not need anyone. If the bank refuses the refund, if the transaction was a transfer or a Bizum of several hundred or thousand euros, or if you are being told that you authorised the transaction, the claim becomes a dispute about evidence in which going without a lawyer usually ends in a refusal that is harder to reverse later. For very small amounts where the bank refuses, the cost may not be worth it, and we will tell you so on the first call.