Criminal defence throughout Spain · offices in Madrid and Alicante
Criminal defence and claims against the bank in cases of phishing, smishing, vishing and spoofing of the bank’s own number: computer fraud under Article 248.2 of the Criminal Code and refund of the unauthorised amount under Royal Decree-Law 19/2018 on payment services.
In brief. Phishing is not the customer’s carelessness: it is a computer fraud offence and an unauthorised payment transaction. The criminal route identifies the perpetrators and blocks the funds; the payment-services route obliges the bank to refund the amount unless it proves fraud or gross negligence by the user. Both routes are compatible and should be opened in parallel.
Online bank fraud no longer resembles the badly translated e-mail of ten years ago. Today the message arrives inside the same SMS thread the bank uses, the call displays the bank’s real number on screen through caller-ID spoofing, and the person on the line knows the most recent movements on the account. The victim does not hand over money: they hand over a one-time code or validate a confirmation in the app in the belief that they are blocking a charge. In criminal law, that conduct is the computer fraud offence of Article 248.2 of the Criminal Code, punished under Article 249, because assets are transferred by means of computer manipulation or a similar artifice and without the holder’s valid consent.
On the contractual and administrative plane it opens a different and often faster route: the claim against the bank for an unauthorised payment transaction, in which the burden of proving authentication falls on the payment service provider, and the refund is excluded only where it proves fraud or gross negligence by the user. The two routes are compatible and should be opened in parallel, because they pursue different aims: the criminal route identifies the perpetrators, freezes the funds and sustains civil liability arising from the offence; the payment-services route obliges the bank to refund the amount unless it proves otherwise. Losing either through inactivity or a badly drafted notification is the costliest error a phishing victim can make.
| Offence | Article | Penalty framework | Key aggravating factor |
|---|---|---|---|
| Computer fraud (unauthorised transfer) | 248.2 a) · 249.1 | 6 months – 3 years | Total amount and continuing offence |
| Aggravated computer fraud (over €50,000 or many victims) | 250.1 | 1 – 6 years + fine 6 – 12 months | Scale of the campaign and proven loss |
| Unlawful access to systems (e-banking intrusion) | 197 bis.1 | 6 months – 2 years | Actual breach of security measures |
| Interception of data (capture of one-time codes) | 197 bis.2 | 3 months – 2 years or fine | Technical means and non-public transmission |
| Seizure and transfer of data (databases for targeted campaigns) | 197.1 · 197.3 | 1 – 4 years; dissemination 2 – 5 | Number of victims and later dissemination |
| Card forgery (cloning and virtual cards) | 399 bis | Forgery 4 – 8 years; use 2 – 5 | Manufacture versus mere knowing use |
| Intentional laundering (receiving account forwarding funds) | 301.1 | 6 months – 6 years + fine | Indications of knowledge of the criminal origin |
| Negligent laundering (gross failure of the duty to verify) | 301.3 | 6 months – 2 years + fine | Profile of the recruit and the bank’s warnings |
Penalty ranges are indicative and set out the ordinary framework; the sentence actually imposed depends on the degree of completion, aggravating and mitigating circumstances and the specific facts of each case.
A phishing case is defended on two simultaneous fronts, each with its own language. On the criminal front, the fraud infrastructure, the destination of the money and its recipients must be identified; on the payment-services front, the assertion that the customer authorised the transaction must be dismantled. Both rest on the same evidential material: a forensic extraction of the device with chain of custody, analysis of the message headers and of the spoofed caller ID, preservation of records through the judicial order of Article 588 octies of the Criminal Procedure Act, requests to providers under Article 588 ter j, traceability of the receiving accounts and applications for freezing and seizure under Articles 589 and 764 of the same Act. That material also compels the bank to produce its strong-authentication records and turns the claim into a defensible position before the Bank of Spain and, where necessary, the courts.
Individuals and self-employed persons with unrecognised charges, transfers or loans after receiving a message or call impersonating their bank.
Companies affected by CEO fraud or by the fraudulent alteration of payment accounts in invoices sent by e-mail.
People investigated for money laundering after receiving and forwarding funds from a bank fraud through their account.
Customers whose bank has refused the refund alleging gross negligence without producing the authentication records of the transaction.
Speak to a criminal lawyer
Criminal defence in English before the courts of Alicante and the rest of Spain, for residents and for visitors who have flown home.