{"id":9300,"date":"2023-01-16T09:10:14","date_gmt":"2023-01-16T08:10:14","guid":{"rendered":"https:\/\/droitbancaire.be\/?p=9300"},"modified":"2026-07-27T21:12:19","modified_gmt":"2026-07-27T19:12:19","slug":"phishing-recent-case-law-belgium","status":"publish","type":"post","link":"https:\/\/droitbancaire.be\/en\/phishing-recent-case-law-belgium\/","title":{"rendered":"Phishing: Where Recent Belgian Case Law Now Stands"},"content":{"rendered":"<p>Our earlier articles set out the principles applicable to <a class=\"ml-ctx\" href=\"https:\/\/droitbancaire.be\/en\/phishing-gross-negligence-public-warnings\/\">phishing<\/a>. A consistent line of recent Belgian case law now applies those principles and has curbed the assumption \u2014 long held by many fraud victims \u2014 that a bank must automatically reimburse sums stolen through phishing.<\/p>\n<p>The picture that emerges from the last few years is clear. Where a customer has disclosed personalised security data, or validated transactions using a card reader or step-up SMS codes, Belgian courts overwhelmingly find gross negligence and leave the loss with the customer.<\/p>\n<p><strong>The governing standard<\/strong><\/p>\n<p>The starting point is Article VII.38 CDE: the payment-instrument user must use the instrument in accordance with its terms of issue, notify the bank without delay of any loss, theft, misappropriation or unauthorised use, and take all reasonable steps to protect the instrument and its personalised security data.<\/p>\n<p>Crucially, gross negligence is assessed against the conduct of a normally prudent and diligent payment services user placed in the same external circumstances. The user\u2019s personal characteristics \u2014 age in particular \u2014 are not taken into account. In its judgment of 5 November 2020, the Antwerp Court of Appeal held that an 89-year-old customer who used the bank\u2019s electronic payment services was to be measured against any other &#8220;normal&#8221; user; a cluster of red flags (an email without the bank\u2019s logo, a follow-up call repeated on a Saturday for a non-urgent matter) should have drawn his attention.<\/p>\n<p><strong>A consistent line of decisions<\/strong><\/p>\n<p>Across the recent rulings, the same reasoning recurs: the disputed transaction could only have been carried out with the customer\u2019s own participation \u2014 by disclosing codes to the fraudsters or by entering them on their instructions \u2014 and the many public warnings about phishing mean that ignoring the warning signs is itself gross negligence.<\/p>\n<p><strong>Illustrative rulings<\/strong><\/p>\n<ul>\n<li>\n<p>Li\u00e8ge, 9 January 2020: a &#8220;Windows&#8221; support scam; the debit was validated through a card reader that never left the victim\u2019s possession, and no technical evidence supported the &#8220;remote hacking&#8221; hypothesis. Transaction deemed authorised; gross negligence retained.<\/p>\n<\/li>\n<li>\n<p>Antwerp, 16 March 2022: the customer admitted having found the facts suspicious yet proceeded, despite an explicit new-device notification from the bank. Gross negligence.<\/p>\n<\/li>\n<li>\n<p>Antwerp, 4 April 2022: EUR 22,428.61 stolen during an online purchase; the payment page bore no reference to the bank. Gross negligence.<\/p>\n<\/li>\n<li>\n<p>Brussels (French-speaking), 9 May 2022: card and phone left in a gym locker; the PIN was the last digits of the customer\u2019s phone number. Gross negligence.<\/p>\n<\/li>\n<li>\n<p>Antwerp, 20 May 2022: codes disclosed by phone around midnight following a fake digipass request; EUR 50,000 stolen. Gross negligence.<\/p>\n<\/li>\n<li>\n<p>Antwerp, 29 June 2022: by relaying step-up SMS codes by phone, the customer was found to have consented; the transactions were authorised payment transactions.<\/p>\n<\/li>\n<\/ul>\n<p><strong>Practical takeaway<\/strong><\/p>\n<p>For banks, this body of case law confirms that a well-documented file \u2014 evidence of public warnings, of new-device notifications, and of the customer\u2019s own involvement in validating the transaction \u2014 will, as a rule, defeat a claim for reimbursement. The debate now turns far more on the factual record than on the legal principle.<\/p>\n<p>[Link to pillar: Phishing and fraudulent use of payment instruments]<\/p>\n<p><em>This article is a translation. Only the French version is authoritative. It is provided for information purposes and does not constitute legal advice.<\/em><\/p>\n<p><!-- SM --><\/p>\n<div class=\"maillage-sm\">\n<h3>On the same topic<\/h3>\n<ul>\n<li><a href=\"https:\/\/droitbancaire.be\/en\/phishing-bank-liability-client-age-perception\/\">Phishing, Internet Fraud and Bank Liability: Do the Client&#8217;s Age and Perception Matter?<\/a><\/li>\n<li><a href=\"https:\/\/droitbancaire.be\/en\/bank-not-automatic-insurer-phishing-cassation\/\">The Bank Is Not an Automatic Insurer Against Phishing<\/a><\/li>\n<li><a href=\"https:\/\/droitbancaire.be\/en\/phishing-fraudulent-use-payment-instruments-belgium\/\">Phishing and Fraudulent Use of Payment Instruments<\/a><\/li>\n<li><a href=\"https:\/\/droitbancaire.be\/en\/banking-phishing-is-the-bank-the-temporary-financier-of-uncertainty\/\">Banking Phishing: Is the Bank the Temporary Financier of Uncertainty?<\/a><\/li>\n<li><a href=\"https:\/\/droitbancaire.be\/en\/phishing-gross-negligence-public-warnings\/\">Phishing and Liability: Ignoring Public Warnings Amounts to Gross Negligence<\/a><\/li>\n<\/ul>\n<\/div>\n<p><!-- \/SM --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Our earlier articles set out the principles applicable to phishing. A consistent line of recent Belgian case law now applies those principles and has curbed the assumption \u2014 long held by many fraud victims \u2014 that a bank must automatically reimburse sums stolen through phishing. The picture that emerges from the last few years is&#8230; <a class=\"more-link\" href=\"https:\/\/droitbancaire.be\/en\/phishing-recent-case-law-belgium\/#more-9300\">Continue Reading &rarr;<\/a><\/p>\n","protected":false},"author":185562167,"featured_media":5134,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","advanced_seo_description":"Belgian courts have curbed the assumption that phishing victims are automatically reimbursed. A synthesis of the recent case law on gross negligence.","jetpack_seo_html_title":"Phishing: Where Belgian Case Law Now Stands","jetpack_seo_noindex":false,"jetpack_seo_schema_type":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":true,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_wpcom_ai_launchpad_first_post":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[6325],"tags":[],"class_list":["post-9300","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-non-classe","clear","fallback-thumbnail"],"jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pbYDZD-2q0","jetpack-related-posts":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/droitbancaire.be\/wp-content\/uploads\/2023\/01\/hacking-gc21851df5_1920.jpg?fit=1920%2C1280&ssl=1","_links":{"self":[{"href":"https:\/\/droitbancaire.be\/en\/wp-json\/wp\/v2\/posts\/9300","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/droitbancaire.be\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/droitbancaire.be\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/droitbancaire.be\/en\/wp-json\/wp\/v2\/users\/185562167"}],"replies":[{"embeddable":true,"href":"https:\/\/droitbancaire.be\/en\/wp-json\/wp\/v2\/comments?post=9300"}],"version-history":[{"count":2,"href":"https:\/\/droitbancaire.be\/en\/wp-json\/wp\/v2\/posts\/9300\/revisions"}],"predecessor-version":[{"id":9728,"href":"https:\/\/droitbancaire.be\/en\/wp-json\/wp\/v2\/posts\/9300\/revisions\/9728"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/droitbancaire.be\/en\/wp-json\/wp\/v2\/media\/5134"}],"wp:attachment":[{"href":"https:\/\/droitbancaire.be\/en\/wp-json\/wp\/v2\/media?parent=9300"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/droitbancaire.be\/en\/wp-json\/wp\/v2\/categories?post=9300"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/droitbancaire.be\/en\/wp-json\/wp\/v2\/tags?post=9300"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}