You do not have to be gullible to fall for it. Modern scams no longer look like badly written 'Nigerian prince' emails. They are SMS messages that appear in the same thread as genuine messages from your bank. They are calls from a 'security officer' who knows your full name. They are pages identical to your online banking site. And when you enter the one-time password - because 'the bank asked you for it' - you think the game is over.
It is not. This is where a legal story begins that most people do not know - and one that, in recent years, has been moving step by step in the consumer's favour.
The big misconception: 'I gave them the code, so it is my fault'
Entering credentials or an OTP does not by itself settle whether a transaction was authorised. An unauthorised transaction carried out without the payer's consent is legally distinct from a transfer the payer initiated or approved while being deceived, often called an authorised push payment (APP) scam. The latter is not automatically an unauthorised payment transaction. Classification depends on the actual payment flow, the scope of consent, the authentication evidence and the circumstances of the deception; an OTP alone proves neither authorisation nor gross negligence.
Greek Law 4537/2018, which transposed PSD2, assigns different roles to evidence, reimbursement and allocation of loss:
- Article 72: the payment service provider must prove that the transaction was authenticated, accurately recorded and not affected by a technical failure. Use of the payment instrument alone does not prove authorisation, fraud or gross negligence.
- Article 73: if the transaction is unauthorised, the provider must make the prescribed immediate reimbursement, subject to the statutory conditions and exceptions.
- Article 74: determines when, and up to what amount, the payer bears the loss.
If the transaction is legally classified as unauthorised, Article 73 makes reimbursement the starting point, subject to the statutory exceptions. A transfer approved by the customer while deceived follows a different legal analysis and does not automatically trigger the same refund regime. The actual payment flow and evidence therefore matter.
Classify the transaction first: unauthorised, or approved under deception. Only then assess reimbursement, gross negligence and allocation of the loss.
When are you actually at fault?
The exception has a name: gross negligence. Courts, however, have approached it more carefully than banks might prefer. Saying 'but the customer gave away the OTP' is not enough to make you bear the entire loss. Gross negligence is not presumed merely because a code was entered; it is assessed as a whole, in light of all the facts.
The Court of Justice judgment of 1 August 2025 in Case C-665/23 (Veracash) has a narrower scope. It concerned delayed notification of successive unauthorised transactions under the former Directive 2007/64/EC. The Court held that reimbursement may be lost for transactions where the delay in reporting was fraudulent or grossly negligent, even within the 13-month long-stop period; for successive transactions, that assessment must be limited to the transactions affected by the delay. The judgment does not establish a general rule that entering an OTP or another code either rules out or automatically proves gross negligence.
So where is the line drawn? Greek case law offers the following examples:
- In the consumer's favour: where the fraud was sophisticated, the setting convincing and the bank lacked adequate systems for detecting suspicious transfers. In such cases, courts have placed the loss on the bank.
- Against the consumer: where the warning signs were blatant - for example, where someone entered an OTP despite not having initiated any transaction and had received a message with obviously suspicious features (see Chalkida Magistrates' Court judgment 394/2022, EirChalk 394/2022). The court found gross negligence in that case.
When greater bank responsibility may be examined
Liability turns on the specific facts, technical evidence and causal link to the loss. There is no general rule that a bank is liable for every fake website, or that use of an OTP automatically clears or condemns either party. The following are specific first-instance outcomes as described in public reports; they are not binding rules for every case:
- According to a published legal summary, Athens Single-Member Court of First Instance judgment 11632/2025 attributed the unrecovered EUR 10,150 loss in that case exclusively to the bank, also examining prevention of websites that imitated web banking. That fact-specific outcome does not create a universal duty to block every fraudulent website.
- According to public reporting, the Lasithi Single-Member Court of First Instance held on 15 May 2026 that EUR 5,674 should be repaid to a 71-year-old and did not find gross negligence. It was a first-instance ruling, and the bank was reported to retain a right of appeal.
A reliable assessment requires the full reasons for judgment, transaction logs, any device or beneficiary change, the bank's alerts, the timeline and the conduct of everyone involved.
The specific rule is in Article 22 of Law 5019/2023, which amended Article 74(1) of Law 4537/2018. In cases involving a lost, stolen or misappropriated payment instrument, the payer's basic exposure may be up to EUR 50, subject to the statutory exceptions. A payer who acts fraudulently, or intentionally fails to comply with security obligations, bears all losses. Where the payer is a consumer and the loss results from gross negligence, the law sets a EUR 1,000 ceiling, taking account of the nature of the personalised security credentials and the circumstances. That ceiling does not apply if the provider proves that it had and applied the additional effective transaction-control mechanisms described in the same provision for transactions above EUR 1,000. This is a consumer rule, not a universal cap for every business or corporate transaction.
In online fraud, time is quite literally money. The sooner you act, the greater the chance that the transfer can be frozen or recalled:
- Call the bank immediately using its official telephone number and request that it block the card/account and recall the transfer. Record the time and the employee's name.
- Submit a written report/objection identifying the transaction as unauthorised - do not rely on a telephone call alone. Ask for a reference or protocol number.
- Report the incident to the Hellenic Police Cyber Crime Division (Dieythynsi Dioxis Ilektronikoy Egklimatos) and file a criminal complaint against unknown offenders.
- Collect evidence: take screenshots of the message, link and time. Every trace may be valuable evidence.
- Do not delete anything or 'clean' your phone before the data have been copied.
If the bank refuses
A bank's first response is very often: 'We reject your claim because the transaction was completed using your personal credentials.' Do not treat this as a final verdict. It is a position, not a court judgment. At this stage:
- Request the refusal in writing, with reasons. You need to know exactly what the bank alleges against you.
- Request the transaction records (logs, timestamps, IP address and authentication data). You have a right of access to personal data concerning you.
- Contact the Consumer Ombudsman (Synigoros toy Katanaloti) and the Hellenic Financial Ombudsman (Ellinikos Chrimatooikonomikos Mesolavitis). Both offer out-of-court procedures free of charge.
- If necessary, bring a civil claim: as the cases above show, the courts no longer side automatically with the bank.
And, of course, the best defence: do not take the bait
No legal protection is as painless as avoiding the fraud in the first place. Keep these three rules in mind:
- Your bank will never ask for your password, PIN or OTP - not by SMS, telephone or email. Anyone who asks for them is a fraudster.
- Do not click links in messages. Access online banking only by typing the address yourself or using the official app.
- If something pressures or frightens you ('your account will be closed in 10 minutes'), it is almost certainly a scam. Hang up and call the official number yourself.
Frequently asked questions
I entered the OTP myself. Do I really have a chance?
Yes - a genuine one. Entering an OTP does not automatically establish that you were at fault. The question is whether, considering all the circumstances, your conduct amounted to gross negligence. If the scam was sophisticated and the bank failed to detect the suspicious transaction, your prospects improve.
How quickly must I report it?
Immediately - ideally within minutes. Acting quickly can help freeze the money and strengthen your legal position by showing that you did not authorise the transaction. An unexplained delay may be used against you.
The bank says it has no liability. Is that correct?
That is the bank's position, not the rule laid down by law. Law 4537/2018 makes reimbursement the rule and customer liability for fraud or gross negligence the exception - which must be proved. Request a reasoned written response and consult a lawyer.
Does this apply only to individuals, or also to professionals and businesses?
PSD2 protections are stronger for consumers, but professionals also have rights and have succeeded in court. The details differ, so a specialist legal assessment is essential.
This article is for information only and refers to legislation and case law as they stood when it was written. Every fraud case is assessed on its own facts. If you have fallen victim, act immediately and consult a lawyer.
What the official card data show
The Bank of Greece Financial Stability Review (May 2026) records 363,101 fraudulent card transactions in 2025, equal to 0.013% of transaction volume, or about one in every 7,600 transactions. Their value was EUR 22,601,632, equal to 0.019% of transaction value, or about EUR 1 in every EUR 5,300. The number of incidents fell by 9% from 2024, while their value remained broadly stable at EUR 22.6 million.
Read these figures carefully: they cover fraud in payment-card transactions, not every phishing incident or every form of bank fraud. They also do not automatically represent consumers' final net loss after refunds or compensation.
Sources and verification
This article was checked against official or primary sources. Figures and thresholds may change through later legislation or circulars.
- Law 4537/2018 - payment services
- Law 5019/2023, Article 22 - liability for unauthorised transactions
- Bank of Greece - Financial Stability Review, May 2026
- CJEU, C-665/23 (Veracash), judgment of 1 August 2025
- Nomiki Bibliothiki Daily - public legal summary of judgment 11632/2025
- eKriti - public report on the Lasithi first-instance ruling
Comments
Share your thoughts about this article.
No comments yet. Be the first to comment.
Submit a comment