The bank calls and your account is emptied

How long you have to claim, when the bank must refund you, unauthorised versus authorised-by-deception payments, and the penalties for vishing in Spain.

The civil action to demand that the bank refund a payment you did not authorise is time-barred after five years under article 1964.2 of the Spanish Civil Code, and the period runs from the day the action could first be brought, which in these cases is the date of the debit on the account or, if later, the moment you became aware of it. That period is real, but it is rarely the one that matters. Payment services regulations require the customer to notify the bank of an unauthorised transaction without undue delay once aware of it, and that notification, far more pressing than the civil limitation period, decides the outcome of most claims. Someone who alerts the bank the same afternoon is in a different position from someone who does so weeks later, even though the five years of the Civil Code run equally for both.

On the criminal side, the fraud committed by the person who called you is time-barred after five years in its basic form and after ten in its aggravated form (article 131 of the Spanish Criminal Code), counted from the day the money left your account. Those are generous periods. What does not wait is the evidence, which degrades within hours, and the trail of the money, which is lost within days when the destination is a third party’s account from which it is forwarded or withdrawn at an ATM.

How telephone fraud works

Vishing is fraud by phone call. In the most widespread variant the call arrives with the bank’s genuine number on screen, because the number has been falsified using the technique known as «spoofing», and the speaker introduces himself as the fraud department. He tells you that suspicious charges have been detected, that they need to be cancelled and that to do so he needs you to confirm the code that has just arrived by SMS. That code is precisely the key that authorises the transfer they are executing at that very moment. The call is often preceded by an SMS that slips into the same thread as the bank’s genuine messages, with a link to a copy of the bank’s website where your login details have already been harvested. In a second variant, worse for the victim, the supposed adviser convinces you that the account has been compromised and that you must move the balance to a «safe account» he dictates to you, or split it into several Bizum payments, so that it is you who orders the transactions. In a third, you are asked to install a remote-access application so they can «check the handset», and from there they operate your mobile banking for you.

All of this is fraud. Article 248 of the Criminal Code, in its classic form of sufficient deception inducing an act of disposal, covers the safe-account variant. The computer fraud offence in article 249.1.a), which punishes the non-consensual transfer of assets by means of computer manipulation or a similar device, covers the transactions the fraudster executes with your codes, and article 249.1.b) covers those made with your card details. The penalty depends on the amount and the circumstances.

Conduct Article of the Criminal Code Penalty Limitation period
Fraud of up to 400 euros 249.2 Fine of one to three months One year
Basic or computer fraud 249.1 Imprisonment of six months to three years Five years
Aggravated fraud (over 50,000 euros or a large number of victims, among other cases) 250.1 Imprisonment of one to six years and a fine of six to twelve months Ten years
Fraud of over 250,000 euros 250.2 Imprisonment of four to eight years and a fine of twelve to twenty-four months Ten years
Money laundering by whoever lends their account (money mule) 301.1 and 301.3 Imprisonment of six months to six years, or six months to two years if by gross negligence Ten years for the intentional form, five for the negligent one

These penalties are for the perpetrator, who almost never ends up in the dock because he operates from outside Spain through third parties’ accounts. What matters to you is that the criminal classification of what happened does not alter your rights against the bank, which are governed by a different set of rules and a different logic.

Unauthorised payment and payment authorised under deception

Your claim against the bank depends above all on who gave the payment order. If the fraudster, using the codes he extracted from you over the phone, ordered the transfer or the card payment, the transaction is unauthorised, even though it was authenticated with your credentials and even if the bank tells you otherwise. Payment services regulations, which transpose into Spanish law the European directive known as PSD2, oblige the bank to refund unauthorised transactions and only allow it to refuse where the customer acted fraudulently or with gross negligence. That gross negligence is the boilerplate answer of almost every bank. The case law does not simply equate falling for an elaborate deception with gross carelessness, and the Supreme Court confirmed in 2025, in its doctrine on bank fraud, that the sophistication of the fraud and the apparent legitimacy of the communication weigh against that argument. Where the line falls in each case, and with what elements the customer’s position is sustained, is the lawyer’s job, and it is a large part of what we do at the firm in the field of cybercrime. If the deception came by email or SMS rather than by phone, the analysis is the same as I set out regarding phishing, and the practical steps when a caller impersonates your bank are covered in this earlier post.

If it was you who pressed the button because you were persuaded to move the money to a safe account or to send several Bizum payments, the transaction is authorised, even though the authorisation was born of deception. Payment services regulations do not oblige the bank to refund it. The claim then shifts to the ground of the bank’s diligence in the face of manifestly anomalous activity, with a more uncertain outcome that depends heavily on the circumstances, including whether alerts were triggered, whether the destination was a newly opened account, or whether the pattern of the transaction broke with the customer’s history. These cases are examined one by one, and not all of them have a way through against the bank.

The same distinction applies to card charges you do not recognise, duplicate charges and debits the bank itself makes by mistake. If you did not order the payment, it is an unauthorised transaction. If the mistake is the bank’s, it is also liable for breach of the account contract under the general rules of the Civil Code on obligations, with the corresponding interest.

The first few hours

Hang up and call the bank yourself on its official number, the one on the back of your card or in the app, never the number that called you or the one in the SMS. Block your cards and credentials and ask the bank to try to hold or recall the transfer while the money is still in the destination account. From that point on, the priority is not to destroy evidence. Keep the SMS exactly as it arrived, with the full thread it was inserted into. Take screenshots of the call log showing the number, the time and the duration. Do not reset your phone or uninstall any application you were made to download without first documenting its existence. Download the transaction receipts showing the destination IBAN, the amount and the exact time.

Report the matter to the Policía Nacional or the Guardia Civil within the first twenty-four to forty-eight hours, with those receipts. The report serves the investigation and also accompanies the claim against the bank. Do not sign or accept in the app any statement acknowledging that you authorised the transaction, or any partial settlement offered as a favour, without having it reviewed. And be wary of anyone who calls afterwards offering to recover the money in exchange for an advance payment, because that is a second scam aimed at the victims of the first. How the claim against the bank is built from there, what is argued and in what order, is the part I leave to the firm.

Where to report it and what happens when the case is shelved

The Second Chamber of the Supreme Court, in resolving jurisdictional disputes in computer fraud cases, has been assigning these matters to the court of the place where the victim holds the account from which the money left, not the fraudster’s domicile or the destination account. If your account is in A Coruña, the investigation belongs to the courts of A Coruña, regardless of where the call was made from.

Many of these cases end in provisional dismissal (article 641 of the Spanish Criminal Procedure Act), because the perpetrators operate from abroad using SIM cards and third parties’ accounts. That shelving has three consequences that concern you. It is not an acquittal, and the case is reopened if new information emerges, which is common when the holder of the receiving account is identified. It does not affect your claim against the bank, which proceeds under payment services regulations and, if necessary, through the civil courts, by way of the oral procedure for claims up to 15,000 euros since Royal Decree-Law 6/2023 and the ordinary procedure above that figure. And if the holder of the destination account is identified, that holder is civilly liable for the loss (articles 109 et seq. of the Criminal Code) even if he merely lent the account.

If your account was the destination account

Telephone fraud needs Spanish accounts to receive the money and forward or withdraw it. It gets them through fake job offers, through commissions for «handling payments» or by asking someone to lend their account for a few days. Whoever does so becomes a money mule and is liable for money laundering under article 301 of the Criminal Code, with imprisonment of six months to six years in the intentional form and six months to two years where gross negligence is found (article 301.3), in addition to civil liability towards the victim for everything that passed through the account. If you have been summoned to give a statement over something like this, do not attend without a lawyer, and do not give explanations over the phone to anyone presenting themselves as the police or as the bank itself.

Claiming on your own carries a specific risk. The bank will answer with gross negligence as its boilerplate argument, and if your claim frames the facts wrongly, inadvertently acknowledges that the transaction was authorised, or arrives late, that error follows you afterwards before the supervisor and the court. At the firm we conduct the defence of the injured party in the criminal proceedings, joining as private prosecutor where appropriate, and we bring the claim against the bank and, if it is rejected, the civil action, as part of our work in cybercrime and civil law. You can call +34 677 841 007 or write through the contact page. Have to hand the statement showing the transactions, the screenshots of the SMS and the call log, the police report if you have already filed it, and any written reply from the bank, because with that the first assessment is made on the same call.

Frequently asked questions

Does the bank have to refund my money if I was the one who gave the code over the phone?

If the fraudster used the code to order a transaction you did not want to make, the transaction is unauthorised and payment services regulations oblige the bank to refund it, unless there was gross negligence on your part. Giving a code to someone who called you from the bank’s real number after an SMS inserted into the genuine thread is not, in itself, regarded as gross negligence. Every case has nuances, and that is where the claim is won or lost.

What changes if I made the transfer or the Bizum payment myself because I was deceived?

The legal basis changes. The transaction is authorised, even though the authorisation was born of deception, and payment services regulations do not oblige the bank to refund it. The claim turns instead on whether the bank acted with the diligence required in the face of anomalous activity, and the outcome depends on the specific circumstances. Against the fraudster and against the holder of the receiving account, the civil claim arising from the offence remains open.

Can I claim interest in addition to the amount stolen?

Yes. Statutory interest accrues on any amount refunded late from the date of the debit, and if the bank has charged fees or overdraft interest as a result of the unauthorised transaction it must also return them. Additional losses, for example a payment you could not meet because you were left without funds, can be claimed if they are proven.

Do I need a lawyer to claim against the bank, or is it worth doing it myself?

It depends on the amount and on the bank’s response. If it is a few hundred euros and the bank refunds the money after you notify it, which is usual for small amounts, you do not need anyone. If the bank has already refunded everything, or if the money went to a real seller who failed to deliver the goods, the bank is not the party to claim against either. It is worth going to a lawyer when the bank refuses the refund alleging gross negligence, when the amount runs to several thousand euros, or when you ordered the transaction yourself under deception, because in those three cases the framing of the claim and the evidence decide the outcome and the initial mistake is hard to correct later.