This post is also available in:
The Court of Cassation tightens the notion of gross negligence, without turning the bank into an automatic insurer against phishing.
By a judgment of 29 June 2026, the Belgian Court of Cassation clarified the notion of gross negligence in phishing fraud. The decision undeniably raises the bar for banks that intend to leave the loss definitively with their client. It does not mean, however, that every phishing victim must be compensated, nor that every imprudence becomes legally irrelevant.
To grasp the judgment’s scope, two questions must be distinguished, which public debate regularly conflates. The first is the immediate, provisional refund of a disputed transaction. The second is final liability: who, client or bank, will ultimately bear the loss? These questions obey distinct rules and are not necessarily decided at the same time.
A fraud triggered by a fake tax message
The case concerned a client who, on 23 January 2020, received an SMS about a supposed tax debt of 89 euros, with a payment link. By following the proposed procedure, the client did not simply pay that amount. The manipulations enabled the installation and activation of the KBC Mobile application on a new device controlled by the fraudster. Transactions totalling EUR 24,852.15 were then executed from that application.
The Brussels Court of Appeal had found gross negligence: the client had not checked the existence of the tax debt, had followed a link in a generic message, had used his security data on unsecured pages, and had necessarily validated a message about the activation of a new mobile subscription. The Court of Cassation quashed that decision.
Gross negligence is qualified negligence
The Court first recalls that gross negligence is a question of law: the trial court assesses the facts, but their legal characterisation is reviewable. Gross negligence is a qualified breach of the duty of prudence. It requires conduct that a reasonable and normally prudent payer would never have adopted, or an omission such a payer would never have made. The formula is demanding: a simple fault, an error of judgment or ordinary imprudence does not necessarily suffice, and all concrete circumstances must be weighed.
The negligence must also relate to one of the client’s obligations under Article VII.38 of the Code of Economic Law: using the payment instrument in accordance with its terms, taking all reasonable steps to protect it and its personalised security data, and notifying the bank without delay of loss, misappropriation or unauthorised use. It is not enough to find that the client was generally careless: the precise obligation breached must be identified, and the breach must reach the required degree of seriousness.
What the Court did not decide
The judgment has sometimes been presented as requiring banks to refund phishing victims even when they were careless. That reading is excessive. The Court did not itself hold that the client was free of gross negligence, nor did it order the bank to refund definitively. It held that the appellate court’s reasoning did not legally support the conclusion of gross negligence, and referred the case to the Antwerp Court of Appeal for a fresh assessment. The judgment creates no general immunity for phishing victims. It raises the standard of proof and reasoning for gross negligence.
An authenticated transaction is not necessarily an authorised one
A transaction is authenticated when executed with the payment instrument and its security data: PIN, card reader, banking app, strong authentication. But the correct use of these tools does not necessarily prove that the client consented to the transaction as finally executed. In many phishing scenarios, the client believes he is validating one operation, paying a small debt or confirming his identity, while the generated data is used to activate a new device or execute other transactions. Proof of authentication alone establishes neither authorisation nor gross negligence. The analysis remains factual: what did the client see, what did he understand, what operation did he believe he was confirming?
First question: must the bank refund immediately?
Article VII.43 of the Code of Economic Law organises the immediate refund of an unauthorised payment transaction: in principle, immediately and at the latest by the end of the next business day after notification. This refund precedes any finding on final liability and is not an admission of liability. The bank may defer it only where it has reasonable grounds to suspect fraud by the payer himself, notified in writing to the FPS Economy. A suspicion of negligence, even gross, is not a suspicion of fraud: fraud requires intentional or disloyal participation by the payer.
Second question: who ultimately bears the loss?
Final liability is governed mainly by Article VII.44. The payer’s liability is in principle limited, up to EUR 50 for certain pre-notification transactions. In some cases the client bears no loss at all, notably where the fraud could not reasonably be detected or where strong authentication requirements were not met. Conversely, the client bears the entire loss where he acted fraudulently or breached his security obligations intentionally or with gross negligence. The 29 June 2026 judgment concerns this second question. Refund first does not necessarily mean pay definitively: the bank may refund provisionally, then claim restitution if it proves fraud or gross negligence.
The role of the summary proceedings judge
Where the bank refuses the immediate refund, some clients apply for interim relief. An Antwerp order thus provisionally ordered a bank to refund nearly EUR 50,000 to an elderly couple before final liability was decided. But summary proceedings are not automatic. Two Brussels orders of 9 and 10 June 2026 recalled that urgency must be concretely demonstrated. In one case, a company claiming over EUR 238,000 failed: the judge weighed its investments, cash and credit facilities. The legal obligation of immediate refund exists independently of urgency, but interim relief requires procedural urgency to be established.
The particular position of businesses
Businesses are not necessarily in the same position as consumers. Part of the payment services rules is mandatory for consumers, while certain protections may be contractually adapted for professional clients within the limits of the Code. Before invoking the refund mechanism, a business must review its account terms, user powers, internal validation procedures and any derogating clauses. Payment fraud is at once an IT incident, a contractual question, an evidentiary problem, a governance issue and sometimes an immediate liquidity risk. Phishing leading to an unauthorised transaction must also be distinguished from fraud where the victim knowingly executes a payment to the wrong beneficiary: invoice fraud or CEO fraud do not necessarily fall under the same regime, since consent existed, even if obtained through lies.
Consequences for banks
The judgment does not abolish the gross negligence defence. It requires it to be better substantiated. A bank cannot merely note that the client clicked a link, entered a code or used his card reader. It must reconstruct the fraud path and explain which legal or contractual obligation was breached, what message or information the client received, why it should have aroused suspicion, what a reasonable payer would have done, and why the client’s actual conduct goes beyond mere imprudence. Preserving technical data, authentication screens, contextual messages, notifications and internal alerts becomes central. The reasoning of refusal decisions also gains importance: a standard formula referring to validation with personal codes risks being insufficient.
Stronger protection, not automatic insurance
The case law clearly moves towards stricter scrutiny of how gross negligence is invoked and proven. Parliament follows the same trend: an amendment tabled in June 2026 would give the payment service provider thirteen months to inform the consumer of its intention to recover the provisional refund, failing which the right to recovery would lapse. But neither the Cassation judgment nor the immediate-refund mechanism turns the bank into an automatic insurer of all digital fraud. The right question is not whether the bank must always or never pay. One must successively determine whether the transaction was authorised, whether it was merely authenticated or genuinely consented to, whether a provisional refund was due, what obligations the client had to respect, whether their breach amounts to true gross negligence, and who must ultimately bear the loss. The judgment of 29 June 2026 does not end that debate. Above all, it obliges banks and courts to conduct it with greater precision.
This article is a translation. Only the French version is authoritative. It is provided for information purposes and does not constitute legal advice.
Leave a Reply