Phishing and Liability: Ignoring Public Warnings Amounts to Gross Negligence

This post is also available in: Français (French) Nederlands (Dutch)

Two phishing victims, aged 62 and 89, sought to hold their bank liable for a fraud exceeding EUR 50,000

They brought their bank before the Court of First Instance of Antwerp.

The customers of Bank X had received a very convincing email, purportedly sent by its “customer service”, asking them to complete an online procedure to replace their bank card.

The email came from the address “aanvraag@startprocedure.com”, which bore no connection to any official Bank X address. Its subject line contained only the word “message”, while the body referred to the “non-opening of your [Bank-X] mail” (the customers had no mailbox linked to Bank X). The signature purported to come from a “personal affairs department”. The web address to which the fraudulent email pointed was, for its part, insecure. One of the customers was later contacted on his private mobile number, something he stated during his hearing that he had found “suspicious”.

It was only when the customers discovered that more than EUR 50,000 had been siphoned from their account that they connected these events and contacted their bank.

The bank, for its part, had spontaneously detected the fraudulent transactions: it had blocked the customers’ accounts and warned them, but was able to recover only part of the diverted amount.

Realising they had fallen victim to phishing, the customers asked their bank to make good the unrecovered amounts, relying on the banking-law provisions set out in Book VII of the Belgian Code of Economic Law (CDE).

Phishing in brief

“Phishing” is a form of fraud, by email or text message, through which hackers seek to obtain internet users’ personal data with a view to using it fraudulently. The fraudsters pose as well-known companies, in messages that now look more genuine than ever. Banks and their customers are, of course, a prime target.

Despite repeated warnings from public authorities and from large companies, financial or otherwise, some customers still fall into the trap set for them.

What does banking law provide in the event of phishing? What liability for the bank?

The legal principles applicable to phishing are the same as those applicable to the loss or theft of a payment instrument.

In the event of loss, theft or forgery of a payment instrument, the instrument holder bears only limited liability: capped at EUR 50 for transactions occurring before the holder notifies the bank, and resting entirely on the bank for all subsequent transactions.

There is an exception to this principle: where the customer/holder has acted fraudulently or with gross negligence, that customer bears full liability for the disputed transactions.

What is meant by the gross negligence of a bank customer?

Negligence is a subjective notion left to the court’s assessment, but it goes without saying that the holder of a payment instrument is expected to use it in accordance with the terms governing its issuance, to take all reasonable steps to keep the instrument safe and its associated data confidential, and to notify the issuer (the bank) immediately of any loss, theft, or unlawful or unauthorised use of the instrument.

Article VII.44 §4 CDE characterises the following as gross negligence:

the fact, for the payer, of recording his personalised security credentials — such as his personal identification number or any other code — in an easily recognisable form, in particular on the payment instrument or on an object or document kept or carried with it, as well as the failure to notify the payment service provider of the loss or theft as soon as he became aware of it (Art. VII.44 §4 CDE).

The customers claimed to know nothing of phishing schemes. But one must always read one’s emails carefully.

The court found the customers of Bank X to have been grossly negligent. In the circumstances, their gross negligence was, in the court’s eyes, beyond doubt: their attention should have been drawn by the cluster of troubling elements encountered when reading and then acting on the fraudulent email.

The two customers invoked their advanced age and their ignorance of the existence of phishing schemes. The court rejected the argument, pointing to the regular communications of the Belgian authorities, the media and the bank itself regarding phishing risks and how to detect the fraudsters’ methods.

The court also recalled that a prudent and diligent payment services user is expected to read emails with particular care when asked to click on a link. If he clicks nonetheless and is then contacted by a stranger asking him to disclose personal security codes, that user is expected not to disclose them. If he does, he is deemed grossly negligent.

Note: this decision was upheld by the Court of Appeal in November 2020.

This article is a translation. Only the French version is authoritative. It is provided for information purposes and does not constitute legal advice.

Leave a Reply

Up ↑

Discover more from Banking and Finance law in Belgium

Subscribe now to keep reading and get access to the full archive.

Continue reading