Spanish Court Orders Bank to Return Money Defrauded through Smishing

A Spanish court has issued a significant ruling ordering a bank to return money defrauded from a customer through smishing, a form of phishing via text message. The court found that the bank's failure to implement adequate cybersecurity measures allowed cybercriminals to carry out multiple fraudulent transactions. The plaintiff reported the unauthorized charges promptly and visited the bank branch to cancel the card, but the bank delayed its response, resulting in unauthorized transactions totaling EUR2,122.99.

Key Takeaways:

  • The court analyzed the applicable regulations, including Royal Decree-Law 19/2018 on payment services, which establishes that users must protect their credentials and promptly report any unauthorized use.
  • The court concluded that no fraud or gross negligence on the part of the user was proven, and the entity failed to demonstrate that the transactions were authorized, making it responsible for the return of the amounts.
  • The ruling highlights the importance of cybersecurity measures in the financial sector, referring to Regulation (EU) 2022/2554 (DORA) and the NIS2 Directive.
  • The court evaluated the evidence presented, including the plaintiff's testimony and documentation provided by the bank, and concluded that the transactions were not authorized by the plaintiff.
  • The court found that the bank failed to provide sufficient evidence of user fraud or gross negligence and that the user reported the unauthorized access promptly.
  • The ruling emphasizes the need for financial institutions to implement robust cybersecurity policies and rapid anomaly detection mechanisms, as required by the DORA regulation.

Statistics:

  • EUR2,122.99: The amount of unauthorized transactions made through the credit card.
  • 4 devices: The number of devices linked in a short period of time, facilitating the unauthorized transactions.
  • 24 transactions: The number of purchase transactions, including prepaid card registration requests, purchases, transfers, and cash payments at ATMs, deemed unauthorized.
  • January 2025: The deadline for financial institutions to implement robust cybersecurity policies and rapid anomaly detection mechanisms, as required by the DORA regulation.

Sources:

  • General Council of the Judiciary (CGPJ) news release.
  • Regulation (EU) 2022/2554 (DORA)
  • Royal Decree-Law 19/2018 on payment services
  • NIS2 Directive