Phishing: Where Recent Belgian Case Law Now Stands

This post is also available in: Français (French) Nederlands (Dutch)

Our earlier articles set out the principles applicable to phishing. A consistent line of recent Belgian case law now applies those principles and has curbed the assumption — long held by many fraud victims — that a bank must automatically reimburse sums stolen through phishing.

The picture that emerges from the last few years is clear. Where a customer has disclosed personalised security data, or validated transactions using a card reader or step-up SMS codes, Belgian courts overwhelmingly find gross negligence and leave the loss with the customer.

The governing standard

The starting point is Article VII.38 CDE: the payment-instrument user must use the instrument in accordance with its terms of issue, notify the bank without delay of any loss, theft, misappropriation or unauthorised use, and take all reasonable steps to protect the instrument and its personalised security data.

Crucially, gross negligence is assessed against the conduct of a normally prudent and diligent payment services user placed in the same external circumstances. The user’s personal characteristics — age in particular — are not taken into account. In its judgment of 5 November 2020, the Antwerp Court of Appeal held that an 89-year-old customer who used the bank’s electronic payment services was to be measured against any other “normal” user; a cluster of red flags (an email without the bank’s logo, a follow-up call repeated on a Saturday for a non-urgent matter) should have drawn his attention.

A consistent line of decisions

Across the recent rulings, the same reasoning recurs: the disputed transaction could only have been carried out with the customer’s own participation — by disclosing codes to the fraudsters or by entering them on their instructions — and the many public warnings about phishing mean that ignoring the warning signs is itself gross negligence.

Illustrative rulings

  • Liège, 9 January 2020: a “Windows” support scam; the debit was validated through a card reader that never left the victim’s possession, and no technical evidence supported the “remote hacking” hypothesis. Transaction deemed authorised; gross negligence retained.

  • Antwerp, 16 March 2022: the customer admitted having found the facts suspicious yet proceeded, despite an explicit new-device notification from the bank. Gross negligence.

  • Antwerp, 4 April 2022: EUR 22,428.61 stolen during an online purchase; the payment page bore no reference to the bank. Gross negligence.

  • Brussels (French-speaking), 9 May 2022: card and phone left in a gym locker; the PIN was the last digits of the customer’s phone number. Gross negligence.

  • Antwerp, 20 May 2022: codes disclosed by phone around midnight following a fake digipass request; EUR 50,000 stolen. Gross negligence.

  • Antwerp, 29 June 2022: by relaying step-up SMS codes by phone, the customer was found to have consented; the transactions were authorised payment transactions.

Practical takeaway

For banks, this body of case law confirms that a well-documented file — evidence of public warnings, of new-device notifications, and of the customer’s own involvement in validating the transaction — will, as a rule, defeat a claim for reimbursement. The debate now turns far more on the factual record than on the legal principle.

[Link to pillar: Phishing and fraudulent use of payment instruments]

This article is a translation. Only the French version is authoritative. It is provided for information purposes and does not constitute legal advice.

Leave a Reply

Up ↑

Discover more from Banking and Finance law in Belgium

Subscribe now to keep reading and get access to the full archive.

Continue reading