A bank was ordered by court judgment to pay €2,500 to a depositor who fell victim to online fraud through phishing, with the bank bearing co-liability. In the said judgment (Thessaloniki Magistrate’s Court 232/2023), it was established that the bank was liable through gross negligence for breach of its contractual obligations to “effectively shield its systems against the constantly mutating and evolving methods of deception that target them”. The case concerned transactions carried out through online banking from the depositor’s account to a third party’s account, after the depositor had been deceived using the phishing method.
What is the bank’s liability in online fraud?
According to the judgment, it is the bank’s duty and must be its daily concern to keep itself informed, to investigate and to fortify its systems with the best available methods, in order to protect the interests of its customers, who do not possess its strength, by their nature and position. Specifically: For the harvesting of the depositor’s personal data, both the bank is liable for the deficient shielding of its systems—which ought to have been excellent—and the depositor, who breached his obligation to safeguard his data and disregarded the security instructions of the defendant. Beyond that, it was established that the depositor, immediately after being notified of the transfer of his funds, contacted the bank by telephone and informed it that the remittance was the product of fraud.
Given this, if within those few minutes the transfer of the amount to the third party’s account had not yet been completed (a point which does not emerge clearly from the telephone conversation submitted in evidence), and that transfer was completed and not blocked by the bank despite the depositor having notified it, then the bank’s liability for breach of its contractual obligations to protect the depositor is full, irrespective of the conduct of either party at the time of the phishing.
That is to say, if, after notification was given to the bank that the remittance order was not genuine (which up to that point the bank had properly verified using the appropriate authentication methods, and which order it would therefore have been obliged to execute had it not been informed of its non-genuineness), the bank had the opportunity (in time and technically) to prevent the transfer but failed to do so, displaying gross negligence and completing the transaction, then its liability to compensate its customer is full.
What is the depositor’s liability in online fraud?
According to the said judgment, it emerges that, in parallel with the bank’s liability for the ineffective shielding of its systems against the constantly mutating and evolving methods of deception that target them—resulting in financial loss to the customers who entrusted it, which constitutes a breach of its contractual obligations and gives rise to its contractual liability—there also concurs the personal liability of the depositor, who failed to safeguard, as he was bound to, his sensitive banking data and disclosed them, when he ought not to have done so, even though the message which misled him originated within the SMS conversation environment with the defendant, even though he was led via the link to a website resembling that of the defendant, because he disregarded the relevant instructions and the strict warnings of the bank, breaching his duty to safeguard them.
What happens when there is co-liability between bank and depositor?
The lawsuit under examination is partially upheld on the merits, and with the plea of contributory fault of the depositor accepted at a rate of 1/6 of the loss he sustained, the bank’s obligation to pay him the sum of €2,500 is recognised, with statutory interest, as set out in the operative part. That is, the depositor was held responsible only for 1/6 of the amount lost in the online fraud.
What happens with moral damages when the depositor does not properly substantiate them?
As to the request for recognition of the bank’s obligation to pay him the sum of €1,000 as compensation for the moral damages he sustained from the fraud committed against him, this is held to be rejected as unfounded, because the bank’s liability is contractual and not tortious, while there are no special conditions that would justify treating the specific contractual breach as also tortious, so that moral damages of the depositor could be attributed to the bank.
Conclusion: had the depositor served an extra-judicial notice with specific questions (not general and vague accusations against the bank) before the service of the lawsuit, which extra-judicial notice the banks never answer in a determinate manner, he would have better substantiated his claim for moral damages and they would have been awarded to him.
- See also article Investigating Bank Liability in Online Fraud
- See also article Investment Fraud Lawyer
- See also article Legal Bases of Bank Liability in Online Fraud
- See also article New Law 2023 and Bank Liability in Online Fraud
- See also article Online Banking and the Phishing Phenomenon
- See also article Depositor Protection from Online Fraud
- See also article Lawyer for Investment Fraud
- See also article Defamation via Facebook
- See also article Child Pornography
- See also article Hacking
FREQUENTLY ASKED QUESTIONS ON BANK LIABILITY IN ONLINE FRAUD
1. I fell victim to phishing — is the bank also liable?
The bank bears a contractual obligation to effectively shield its systems against the constantly evolving methods of deception. When it breaches this obligation, its liability is established on the basis of gross negligence, as a recent court judgment characteristically held when it awarded compensation to a depositor-victim of phishing.
A critical element is also whether the depositor immediately notified the bank by telephone after becoming aware of the fraud. If there was time and technical scope to halt the remittance and the bank failed to do so, its liability is held to be full, irrespective of the depositor’s initial fault.
2. How much money can I claim from the bank?
The amount depends on the degree of contributory fault of the depositor. In the case decided judicially, the depositor was charged with only 1/6 of his loss, while 5/6 was awarded against the bank for breach of its contractual obligations to protect its customer.
As a rule, the apportionment of liability takes into account how quickly the bank was notified, whether it had the technical means to block the transaction, and whether the depositor breached strict security instructions. Moral damages are usually not awarded where liability is characterised as purely contractual rather than tortious.
3. What steps do I take immediately after losing money?
The first step is to notify the bank immediately by telephone, requesting cancellation or recall of the remittance, and asking that the call be recorded. There follow written notification of the fraud, the filing of a criminal complaint with the Public Prosecutor’s Office of the Court of First Instance (which is forwarded to the Cybercrime Division), and a report to the Hellenic Data Protection Authority (HDPA) where personal data have been compromised.
Subsequently, an extra-judicial notice is served on the bank with specific—not general—questions concerning the adequacy of its security measures. Failure to reply or a vague reply substantiates the contractual breach and strengthens a subsequent claim for moral damages in the lawsuit.
4. How long does it take for a judgment against the bank to be issued?
The lawsuit is filed before the Single-Member or Multi-Member Court of First Instance, depending on the amount in dispute. From filing to oral hearing typically takes between twelve and twenty-four months, with the judgment issued a few months after the hearing.
Before filing, an attempt at out-of-court settlement is mandatory. In the event of an adverse judgment, the bank may lodge an appeal, in which case final recovery of the sum is delayed. In the vast majority of cases, however, the declaratory judgment is complied with by the bank without recourse to enforcement measures.
5. What evidence do I need for the trial?
Essential items include account statements, the suspicious phishing SMS or email, screenshots of the fake website, a recording of the telephone notification call to the bank with the precise time, correspondence with the bank, and the criminal complaint filed with the authorities.
The chronological correlation between the remittance order, the notification to the bank, and the final debiting of the account is important. In addition, the bank’s strict security instructions are used to verify whether the obligation of strong customer authentication imposed by the European PSD2 Directive was complied with.
6. What role does the lawyer play in the claim?
The lawyer assesses the facts, identifies the points of negligence on the bank’s part (inadequate authentication, delayed response to notification, deficient suspicious-transaction detection systems) and drafts a targeted extra-judicial notice that founds both contractual and tortious liability, securing the basis for a claim that also includes moral damages.
The lawyer then files the lawsuit, represents the depositor at the hearing, and rebuts the plea of contributory fault that the bank will raise. Ziamparas D. & Associates Law Firm has handled phishing and bank fraud cases, with arguments grounded in recent case law favourable to depositors.


