Phishing: when must a bank refund stolen money under German law?
Money missing after phishing or a fake bank call? Why a TAN does not prove everything, which deadlines apply and which documents support a refund claim.
Money missing: what to do first
A text message announces a security update. A caller knows your name and claims to work for your bank. Shortly afterwards, several thousand euros are missing. The legal assessment depends on the exact sequence: what did you see, enter and approve? This article addresses consumers’ claims against their bank under German payment-services law.
End contact with the suspected fraudsters and contact the bank using a reliable number you have obtained independently. Have affected access credentials and payment instruments blocked and immediately ask for a transfer recall. A recall is an attempt to recover the money, not a guarantee. Preserve messages and report the crime to the police. A police report does not replace notifying the bank.
Unauthorised payment or a transfer you made yourself?
Section 675u of the German Civil Code requires an unauthorised payment. The bank generally has no claim to reimbursement of its expenses and must restore the account to the position without the debit. The statutory refund deadline is the end of the business day following notification or knowledge. A specific exception concerns a substantiated suspicion of fraud by the payer reported in writing to the competent authority.
If you personally ordered a specific transfer to a recipient you believed to be legitimate, deception alone does not establish a claim under section 675u. Enrolling a device, approving a specific payment order and a payment initiated by fraudsters are distinct events. The actual sequence must be reconstructed, particularly in purported safe-account or device-change scenarios.
Why the bank cannot rely on the TAN alone
Where authorisation is disputed, section 675w requires the bank to prove authentication and proper recording and booking without a relevant malfunction. Technical use of a payment instrument and its security features does not necessarily, by itself, prove your consent. Acceptance of a TAN therefore does not answer every legal question.
A recorded approval is not irrelevant, however. The displayed amount, recipient, warnings and device matter, as does whether you approved device enrolment or an actual payment. Ask the bank to explain the specific events on which it bases its refusal.
Gross negligence: the key counterargument
Under section 675v(3), the bank may have a counterclaim for the entire loss if you caused it by intentionally or grossly negligently breaching the relevant duties. The label phishing does not decide this. Clear warnings, contradictory displays and disclosure of security credentials can matter. Section 675w requires supporting evidence of fraud, intent or gross negligence.
Exceptions to customer liability also need to be considered. Section 675v(4) addresses, in particular, cases where strong customer authentication was not required; subsection (5) includes losses from use after notification to block the instrument. The exceptions concerning fraud by the payer still apply. Blanket statements that customers always or never bear the loss overlook these distinctions.
Evidence to preserve now
Create a factual timeline while your memory is fresh. Separate what you observed from assumptions. If you cannot remember a warning, record that honestly. A retrospectively polished account makes the assessment harder.
- Account statements showing dates, amounts, recipients and payment references.
- Text messages, emails, call logs and any screenshots of approval screens.
- Times of bank contact, blocking and recall attempts, together with reference numbers.
- The bank’s complete refusal and its account of the technical process.
What is the deadline, and when is a review worthwhile?
Section 676b requires notification without undue delay after discovering an unauthorised payment. There is also generally a 13-month exclusion period following the debit; its commencement depends on the prescribed information having been provided. This outer limit is not permission to wait after discovery. Obtain and retain confirmation that your report was received.
An illustrative example: after a deceptive call, a customer approves registration of a new device. The fraudsters subsequently initiate transfers. Registration, later payment approvals and the information displayed at each stage must be examined separately. The initial click establishes neither an automatic full refund nor automatic liability for the entire loss.
The loss amount, evidence, the bank’s objections and possible costs cover determine whether legal assistance is economically sensible. Any legal-expenses insurance cover requires separate confirmation. A complete timeline helps identify early which legal and technical issues will decide the case.
Sources & further information
- Section 675u BGB: refund of unauthorised payments ↗
- Section 675v BGB: payer liability and exceptions ↗
- Section 675w BGB: authentication and evidence ↗
- Section 676b BGB: notification and exclusion period ↗
This article provides general guidance. The options available depend on your specific situation.