info@societejuridique.com
Madrid: Paseo de la Castellana 216 8 ª Planta
Alicante: Av. Ansaldo Nº31, local 16
24h emergencies: 669 30 21 13

Social media:

Phishing · unauthorised payment transactions

Phishing and bank fraud: defence and recovery

Criminal defence throughout Spain · offices in Madrid and Alicante

Criminal defence and claims against the bank in cases of phishing, smishing, vishing and spoofing of the bank’s own number: computer fraud under Article 248.2 of the Criminal Code and refund of the unauthorised amount under Royal Decree-Law 19/2018 on payment services.

In brief. Phishing is not the customer’s carelessness: it is a computer fraud offence and an unauthorised payment transaction. The criminal route identifies the perpetrators and blocks the funds; the payment-services route obliges the bank to refund the amount unless it proves fraud or gross negligence by the user. Both routes are compatible and should be opened in parallel.

Why it is different

248.2
The paragraph of the Criminal Code that defines computer fraud and the unauthorised use of payment data.
13 months
The maximum period for notifying the bank of an unauthorised payment transaction.
D + 1
Refund of the amount no later than the business day following notification.

Phishing is not carelessness: it is computer fraud and an unauthorised payment

Online bank fraud no longer resembles the badly translated e-mail of ten years ago. Today the message arrives inside the same SMS thread the bank uses, the call displays the bank’s real number on screen through caller-ID spoofing, and the person on the line knows the most recent movements on the account. The victim does not hand over money: they hand over a one-time code or validate a confirmation in the app in the belief that they are blocking a charge. In criminal law, that conduct is the computer fraud offence of Article 248.2 of the Criminal Code, punished under Article 249, because assets are transferred by means of computer manipulation or a similar artifice and without the holder’s valid consent.

On the contractual and administrative plane it opens a different and often faster route: the claim against the bank for an unauthorised payment transaction, in which the burden of proving authentication falls on the payment service provider, and the refund is excluded only where it proves fraud or gross negligence by the user. The two routes are compatible and should be opened in parallel, because they pursue different aims: the criminal route identifies the perpetrators, freezes the funds and sustains civil liability arising from the offence; the payment-services route obliges the bank to refund the amount unless it proves otherwise. Losing either through inactivity or a badly drafted notification is the costliest error a phishing victim can make.

Types of offence

The criminal framework of online bank fraud

Art. 248.2 a) CP

Computer fraud

Punishes the unauthorised transfer of any asset obtained by computer manipulation or a similar artifice. It is the natural offence for bank phishing, in-app impersonation fraud and payment orders entered with captured credentials. Penalty determined under Article 249.
Art. 248.2 c) CP

Use of another’s card data

Covers transactions made to the detriment of the holder using credit or debit cards, travellers’ cheques or any other tangible or intangible payment instrument unlawfully obtained, including e-commerce purchases and recurring subscriptions. Penalty determined under Article 249.
Art. 249 CP

Penalty according to the amount

Imprisonment of six months to three years where the amount defrauded exceeds four hundred euros, and a fine of one to three months where it does not. In campaigns with multiple successive charges, a continuing offence is usually found over the total amount.
Art. 250.1 CP

Aggravated forms

Raises the range where the fraud exceeds fifty thousand euros, affects a large number of people, concerns basic necessities or the perpetrator abuses their business or professional credibility. Imprisonment of one to six years and a fine of six to twelve months.
Art. 197 bis CP

Unlawful access to information systems

Independently punishes access to all or part of a computer system in breach of its security measures, and the interception of non-public data transmissions, both prior and necessary steps in most e-banking fraud. Access: six months to two years; interception: three months to two years.
Art. 197 CP

Discovery and disclosure of secrets

Covers the seizure of credentials, messages and personal data, and their transfer or dissemination to third parties. The customer databases that feed targeted phishing campaigns fall squarely within this provision. Imprisonment of one to four years and a fine of twelve to twenty-four months.
Art. 399 bis CP

Forgery and use of cards

Punishes the forgery of credit and debit cards and travellers’ cheques, possession intended for distribution and use to another’s detriment with knowledge of the falsity, including cloned stripes and virtual cards created with captured data. Forgery: four to eight years; use: two to five years.
Art. 400 bis CP

Use by a person not entitled

Treats the use of genuine documents by a person not entitled to use them as equivalent to the use of a false document, a rule that is decisive where the perpetrator operates with the victim’s real documentation obtained in the data-capture phase. The penalty of the corresponding forgery offence.
Arts. 401 and 301 CP

Identity usurpation and money mules

Usurpation of civil status requires assuming another person’s full identity in legal transactions. In parallel, whoever receives and forwards the defrauded money is liable for money laundering, including its negligent form for gross failure to verify. Usurpation: six months to three years; laundering: six months to six years.
Penalties at a glance

Penalty framework by offence

OffenceArticlePenalty frameworkKey aggravating factor
Computer fraud (unauthorised transfer)248.2 a) · 249.16 months – 3 yearsTotal amount and continuing offence
Aggravated computer fraud (over €50,000 or many victims)250.11 – 6 years + fine 6 – 12 monthsScale of the campaign and proven loss
Unlawful access to systems (e-banking intrusion)197 bis.16 months – 2 yearsActual breach of security measures
Interception of data (capture of one-time codes)197 bis.23 months – 2 years or fineTechnical means and non-public transmission
Seizure and transfer of data (databases for targeted campaigns)197.1 · 197.31 – 4 years; dissemination 2 – 5Number of victims and later dissemination
Card forgery (cloning and virtual cards)399 bisForgery 4 – 8 years; use 2 – 5Manufacture versus mere knowing use
Intentional laundering (receiving account forwarding funds)301.16 months – 6 years + fineIndications of knowledge of the criminal origin
Negligent laundering (gross failure of the duty to verify)301.36 months – 2 years + fineProfile of the recruit and the bank’s warnings

Penalty ranges are indicative and set out the ordinary framework; the sentence actually imposed depends on the degree of completion, aggravating and mitigating circumstances and the specific facts of each case.

Our differentiator

One case, two simultaneous fronts

A phishing case is defended on two simultaneous fronts, each with its own language. On the criminal front, the fraud infrastructure, the destination of the money and its recipients must be identified; on the payment-services front, the assertion that the customer authorised the transaction must be dismantled. Both rest on the same evidential material: a forensic extraction of the device with chain of custody, analysis of the message headers and of the spoofed caller ID, preservation of records through the judicial order of Article 588 octies of the Criminal Procedure Act, requests to providers under Article 588 ter j, traceability of the receiving accounts and applications for freezing and seizure under Articles 589 and 764 of the same Act. That material also compels the bank to produce its strong-authentication records and turns the claim into a defensible position before the Bank of Spain and, where necessary, the courts.

01

Legal intelligence

02

Financial and accounting analysis

03

Digital evidence · e-forensic

04

Procedural strategy

How we work

From the first notification to recovery

Phase 01

Arrest and investigation

Phase 02

Forensic analysis

Phase 03

Strategy and evidence

Phase 04

Trial and appeals

Who we represent

Each profile demands a distinct defence

P

Individuals and the self-employed

Individuals and self-employed persons with unrecognised charges, transfers or loans after receiving a message or call impersonating their bank.

C

Companies and directors

Companies affected by CEO fraud or by the fraudulent alteration of payment accounts in invoices sent by e-mail.

I

Persons under investigation

People investigated for money laundering after receiving and forwarding funds from a bank fraud through their account.

V

Victims · private prosecution

Customers whose bank has refused the refund alleging gross negligence without producing the authentication records of the transaction.

FAQ

Frequently asked questions

Is the bank obliged to refund my money?
Royal Decree-Law 19/2018 on payment services provides that, upon an unauthorised payment transaction notified by the user, the bank must refund the amount immediately and at the latest by the end of the following business day, unless it has reasonable grounds to suspect fraud by the user. It is released only if it proves that the customer acted fraudulently or with gross negligence.
Who must prove that I authorised the transaction?
The payment service provider. Where the user denies having authorised an executed transaction, it is the bank that must prove it was authenticated, accurately recorded and accounted for, and unaffected by any technical failure. The mere record that the credentials were used is not, by itself, sufficient to conclude that there was authorisation.
What is the deadline for claiming?
Notification must be made without undue delay upon becoming aware of the charge and, in any event, within a maximum of thirteen months from the debit date. On the criminal side, ordinary fraud becomes time-barred after five years, and the aggravated form of Article 250 after ten, under Article 131 of the Criminal Code.
I lent my account to receive a payment and I am now under investigation. What do I do?
Do not answer requests or attend to give a statement without technical defence. The strategy rests on establishing ignorance of the criminal origin of the funds and documenting the recruitment process, since the real risk is a finding of conditional intent or the negligent form of Article 301.3 of the Criminal Code.
Is it worth reporting if the money has already left the country?
Yes. The complaint makes it possible to request the freezing of intermediate accounts, the preservation of providers’ records and cooperation with other jurisdictions, and it is also the documentary support that reinforces the claim against the bank. The earlier it is filed, the greater the likelihood of reaching the funds before they are dispersed.
What is the LIWARD methodology?
It is our own methodology, Legal Intelligence Warfare for Defense, which integrates legal intelligence, financial and accounting analysis and digital forensic evidence into a single procedural strategy. It allows us to anticipate the weaknesses of the opposing case and to build on technical evidence, not on legal argument alone.

Speak to a criminal lawyer

In a fast-track case, the days you have are the case.

Criminal defence in English before the courts of Alicante and the rest of Spain, for residents and for visitors who have flown home.

Logotipos-abogacia-scje
Paseo De La Castellana 216 8º 28046 Madrid
Alicante – Playa de San Juan Av. Ansaldo 31, local 16, 03540 Alicante
Londres: 20 Wenlock Road, N1 7GU, Reino Unido
París: 72 Faubourg St Honoré, 75008, Francia
info@societejuridique.com

Société de Conseil Juridique et Expert es un despacho de abogados con sedes en Madrid, Alicante, Londres y París, especializado en defensa y acusación penal, delitos económicos y corporativos y derecho tecnológico. Trabajamos con orientación estratégica en procedimientos penales complejos, propiedad intelectual y análisis forense avanzado, y prestamos consultoría jurídica, compliance y escudos de protección a particulares y empresas. Atendemos desde Alicante y Madrid, con consulta online en toda España y asistencia al detenido 24 horas. Resuelva sus dudas en las preguntas frecuentes o solicite una primera consulta.

Copyright © 2026 Société de Conseil Juridique et Expert S.L.

EspanolEnglishFrancaisРусскийItalianoDeutsch
WhatsApp · Urgencias 24h