Phishing and Fraudulent Use of Payment Instruments

This post is also available in: Français (French) Nederlands (Dutch)

Phishing and payment fraud are, unfortunately, thriving. Posing as trusted institutions in ever more convincing messages, fraudsters target banks and their customers in particular. Belgium’s financial ombudsman (Ombudsfin) has recorded a steep rise in payment-fraud complaints over recent years. This article sets out how Belgian law allocates the resulting losses between bank and customer.

The applicable Belgian framework

The rules sit in Book VII of the Belgian Code of Economic Law (CDE), which transposes the PSD2 Directive (EU) 2015/2366. Three provisions do most of the work.

Article VII.38 sets the payment-service user’s duties: use the instrument in line with its terms of issue, take all reasonable steps to keep it and its personalised security data secure, and notify the provider without delay of loss, theft or misuse.

Article VII.42 places the burden of proof on the payment service provider. Where the user denies having authorised a transaction, the provider must prove that the transaction was authenticated, accurately recorded and unaffected by any technical failure. Crucially, the mere record of an instrument’s use does not, in itself, prove that the user authorised the transaction or acted fraudulently or with gross negligence; the provider must adduce supporting evidence.

Article VII.43 requires the provider, in the event of an unauthorised transaction, to refund the payer immediately, and no later than the end of the next business day, unless it has reasonable grounds to suspect fraud and notifies those grounds in writing to the authorities.

Who bears the loss: the EUR 50 cap and its exceptions

Article VII.44 sets the allocation. As a rule, before notification the payer bears losses from a lost or stolen instrument only up to EUR 50; after notification, the payer bears nothing, unless the provider proves the payer acted fraudulently.

The decisive exception: the payer bears the entire loss, and the EUR 50 cap falls away, where the loss results from fraud on the payer’s part or from an intentional or grossly negligent breach of the Article VII.38 duties. This is where most phishing disputes are decided.

Gross negligence: an objective test

Article VII.44 §4 gives statutory examples of gross negligence, recording security codes in an easily recognisable form, or failing to report loss or theft promptly, and directs the court to weigh all the factual circumstances. Belgian courts have found gross negligence where a user disclosed confidential codes to a third party, entered the card and PIN at a stranger’s prompting, chose a PIN linked to their date of birth, or otherwise made the code easy to discover.

The key principle, confirmed by the Antwerp Court of Appeal (5 November 2020), is that gross negligence is assessed in abstracto: against the conduct of a normally prudent and diligent payment-services user in the same external circumstances, disregarding the user’s personal characteristics such as age. An 89-year-old who subscribed to and used the bank’s electronic payment services was therefore held to the same standard as any other user; the cluster of red flags (an email without the bank’s logo, a non-urgent follow-up call repeated on a Saturday, and repeated prior phishing warnings from the bank) should have prompted heightened vigilance.

How the case law applies in practice

A few contrasting decisions map the boundaries.

  • Liège, 9 January 2020, a “Windows”/remote-access scam validated through a card reader that never left the victim’s hands: the transaction was authorised and gross negligence retained, the “remote hacking” hypothesis being unsupported by any technical expertise.

  • Ghent, 15 January 2020, a stolen card (no chip, usable by swipe and signature) with statements diverted to another address: gross negligence rejected, as the holder could not reasonably have detected the theft sooner.

  • Brussels, 14 May 2020, fraudulent paper transfers submitted by an employee without a formal mandate: the bank was held liable, the company was not, even though it had not disputed the entries on its statements.

The pattern is clear: liability turns on whether the customer’s own conduct, disclosing codes, ignoring warning signs, enabled the fraud, assessed objectively and on a well-documented record.

Practical takeaway for banks

The strength of a bank’s position rests on evidence: proof of prior phishing warnings, of new-device or authentication notifications, and of the customer’s own involvement in validating the transaction. Where that record exists, Belgian courts consistently leave the loss with a grossly negligent customer. Where it is thin, or where the fraud was too sophisticated for a normal user to detect, the outcome shifts.

This article is a translation. Only the French version is authoritative. It is provided for information purposes and does not constitute legal advice.

Leave a Reply

Up ↑

Discover more from Banking and Finance law in Belgium

Subscribe now to keep reading and get access to the full archive.

Continue reading