You do not have to be gullible to fall for it. Modern scams no longer look like badly written 'Nigerian prince' emails. They are SMS messages that appear in the same thread as genuine messages from your bank. They are calls from a 'security officer' who knows your full name. They are pages identical to your online banking site. And when you enter the one-time password - because 'the bank asked you for it' - you think the game is over.
It is not. This is where a legal story begins that most people do not know - and one that, in recent years, has been moving step by step in the consumer's favour.
The big misconception: 'I gave them the code, so it is my fault'
Let us clear up the most widespread misconception - and the one most convenient for banks. The fact that you entered your credentials or the OTP yourself does not automatically mean that you authorised the transaction. In legal terms, a payment made while you were being deceived is generally an unauthorised payment transaction.
The framework is set by Greek Law 4537/2018, which transposed the EU's revised Payment Services Directive (PSD2) into Greek law. It provides two rules worth knowing precisely:
- Article 73: where a transaction is unauthorised, the bank must refund the amount immediately - unless it has reasonable grounds to suspect fraud by the customer.
- Article 72: the customer bears the loss only where there is fraud or gross negligence.
Put simply, reimbursement is the rule. Refusal to reimburse is the exception - and, as a rule, the bank bears the burden of proving that the exception applies. That reversal changes everything.
The rule is not 'if you gave away the code, you lose'. The rule is 'the bank refunds you' - and the exception must be proved.
When are you actually at fault?
The exception has a name: gross negligence. Courts, however, have approached it more carefully than banks might prefer. Saying 'but the customer gave away the OTP' is not enough to make you bear the entire loss. Gross negligence is not presumed merely because a code was entered; it is assessed as a whole, in light of all the facts.
This is exactly what the Court of Justice of the European Union (CJEU) confirmed in its 2025 judgment in Case C-665/23 (Veracash): assessing 'gross negligence' requires an overall appraisal by the national court - it does not follow mechanically from the user's having used their security credentials.
So where is the line drawn? Greek case law offers the following examples:
- In the consumer's favour: where the fraud was sophisticated, the setting convincing and the bank lacked adequate systems for detecting suspicious transfers. In such cases, courts have placed the loss on the bank.
- Against the consumer: where the warning signs were blatant - for example, where someone entered an OTP despite not having initiated any transaction and had received a message with obviously suspicious features (see Chalkida Magistrates' Court judgment 394/2022, EirChalk 394/2022). The court found gross negligence in that case.
Banks are being held to greater responsibility
The most notable development of the past two years is that courts have stopped treating the bank as a passive victim and have begun requiring it to provide active protection. Two examples make this clear:
- The Athens Single-Member Court of First Instance, judgment 11632/2025 (MPrAth 11632/2025), held that a bank must detect and block fraudulent websites that imitate its web-banking environment. It attributed the loss to the bank's exclusive fault and ordered it to pay EUR 10,150.
- The Lasithi Single-Member Court of First Instance ruled in favour of a 71-year-old pensioner who lost EUR 5,674 from his retirement lump sum, finding that the loss resulted from a deficiency in the bank's security systems, rather than from gross negligence on his part.
At the same time, the legislature intervened through Law 5019/2023, which includes a specific provision on a payer's liability for unauthorised payment transactions involving phishing. The legal landscape is therefore not static: it is moving towards greater protection for payment-service users.
In online fraud, time is quite literally money. The sooner you act, the greater the chance that the transfer can be frozen or recalled:
- Call the bank immediately using its official telephone number and request that it block the card/account and recall the transfer. Record the time and the employee's name.
- Submit a written report/objection identifying the transaction as unauthorised - do not rely on a telephone call alone. Ask for a reference or protocol number.
- Report the incident to the Hellenic Police Cyber Crime Division (Dieythynsi Dioxis Ilektronikoy Egklimatos) and file a criminal complaint against unknown offenders.
- Collect evidence: take screenshots of the message, link and time. Every trace may be valuable evidence.
- Do not delete anything or 'clean' your phone before the data have been copied.
If the bank refuses
A bank's first response is very often: 'We reject your claim because the transaction was completed using your personal credentials.' Do not treat this as a final verdict. It is a position, not a court judgment. At this stage:
- Request the refusal in writing, with reasons. You need to know exactly what the bank alleges against you.
- Request the transaction records (logs, timestamps, IP address and authentication data). You have a right of access to personal data concerning you.
- Contact the Consumer Ombudsman (Synigoros toy Katanaloti) and the Hellenic Financial Ombudsman (Ellinikos Chrimatooikonomikos Mesolavitis). Both offer out-of-court procedures free of charge.
- If necessary, bring a civil claim: as the cases above show, the courts no longer side automatically with the bank.
And, of course, the best defence: do not take the bait
No legal protection is as painless as avoiding the fraud in the first place. Keep these three rules in mind:
- Your bank will never ask for your password, PIN or OTP - not by SMS, telephone or email. Anyone who asks for them is a fraudster.
- Do not click links in messages. Access online banking only by typing the address yourself or using the official app.
- If something pressures or frightens you ('your account will be closed in 10 minutes'), it is almost certainly a scam. Hang up and call the official number yourself.
Frequently asked questions
I entered the OTP myself. Do I really have a chance?
Yes - a genuine one. Entering an OTP does not automatically establish that you were at fault. The question is whether, considering all the circumstances, your conduct amounted to gross negligence. If the scam was sophisticated and the bank failed to detect the suspicious transaction, your prospects improve.
How quickly must I report it?
Immediately - ideally within minutes. Acting quickly can help freeze the money and strengthen your legal position by showing that you did not authorise the transaction. An unexplained delay may be used against you.
The bank says it has no liability. Is that correct?
That is the bank's position, not the rule laid down by law. Law 4537/2018 makes reimbursement the rule and customer liability for fraud or gross negligence the exception - which must be proved. Request a reasoned written response and consult a lawyer.
Does this apply only to individuals, or also to professionals and businesses?
PSD2 protections are stronger for consumers, but professionals also have rights and have succeeded in court. The details differ, so a specialist legal assessment is essential.
This article is for information only and refers to legislation and case law as they stood when it was written. Every fraud case is assessed on its own facts. If you have fallen victim, act immediately and consult a lawyer.
Sources and verification
Before publication, this article was checked against official or primary sources. Figures and thresholds may change through later legislation or circulars.
Comments
Share your thoughts about this article.
No comments yet. Be the first to comment.
Submit a comment