Athanasios Rantos, Advocate General at the Court of Justice of the European Union (CJEU), issued an opinion indicating that under the EU Payment Services Directive (PSD2, 2015/2366) banks should immediately refund customers for unauthorized transactions resulting from phishing, unless the bank has reasonable grounds to suspect customer fraud (which should be communicated in writing to the competent national authority). The opinion stems from a request for a preliminary ruling by a Polish court in a dispute involving PKO Bank Polski (PKO BP S.A.) and a customer who entered credentials into a spoofed login page after receiving a malicious link from a scammer posing as a buyer on an online auction platform.
In the underlying case, the victim reported the unauthorized payment the next day (including to police), the perpetrators were not identified, and the bank refused reimbursement—prompting the customer to sue. Rantos’ view supports a “refund now, sue later” approach: banks may still attempt to recover funds from the customer after refunding if they can prove the customer acted with gross negligence or intent. While the CJEU often follows Advocate General opinions, it is not guaranteed; if adopted, the position could materially change how phishing-loss reimbursement is handled in Poland and more broadly across Europe.

See the reporting duties and controls this puts on the clock.
8 events from the most recent confirmed update back to the earliest known activity.
On or before March 8, 2026, Advocate General Athanasios Rantos issued a formal opinion that banks must immediately refund unauthorized transactions caused by phishing unless they have reasonable grounds to suspect customer fraud. He said alleged gross negligence cannot justify delaying the initial refund, and banks must instead refund first and pursue recovery later if they can prove intentional misconduct or gross negligence.
In April 2025, Spain's Supreme Court held that banks must prove customer negligence or fraud to avoid covering phishing-related losses. The ruling was cited as a significant national development in the broader European debate over refund liability.
The European Banking Authority reported in 2025 that victims absorb about 85% of annual losses from fraudulent credit transfers, which totaled roughly €2.2 billion in 2024. The report linked this outcome in part to divergent national interpretations of authorization and gross negligence.
PSD2 entered into force in early 2018, establishing the EU framework governing payment service providers' obligations for unauthorized transactions. The later Polish dispute and Advocate General opinion center on how these PSD2 refund rules should be interpreted.
The District Court in Koszalin referred the Polish phishing-refund case to the Court of Justice of the European Union for clarification on interpreting PSD2 and its Polish transposition. The referral reflected broader uncertainty over whether banks can delay refunds by alleging gross negligence.
Following the bank's refusal to reimburse the stolen funds, the customer brought legal action against PKO Bank Polski. The case raised questions about whether banks may withhold immediate refunds based on alleged customer negligence.
After the unauthorized payment was reported, PKO Bank Polski declined to refund the customer, arguing negligence on her part. The refusal became the basis for subsequent litigation over PSD2 reimbursement obligations.
A customer in Poland was tricked through spoofed auction-platform and bank websites into disclosing banking credentials, enabling an unauthorized transfer of 3,000 Polish zlotys. She reported the incident to the bank and police the next day.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcego.theregister.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.