CASE COMMENTARY · HIGH COURT OF JUSTICEImpersonating the account holder at the counter: fraud is not undone by the bank’s control failures
DECISION
Judgment of the High Court of Justice of Asturias (2026)
COURT
High Court of Justice of Asturias, Civil and Criminal Chamber
IDENTIFICATION
Fraud by impersonation at a bank branch
OUTCOME
Conviction upheld; the judgment is not final
At a bank branch in Lugones, the defendant verbally identified herself as the holder of another person’s account, supplied details from the real holder’s identity document and email address, and succeeded in withdrawing 1,500 euros in cash. The High Court of Justice of Asturias has upheld the sentence of three years and six months of imprisonment, a fine of 1,890 euros and compensation of 1,500 euros plus interest.
The interest of the ruling lies in the defence argument rejected: that the weakness of the bank’s internal controls should exclude or mitigate the criminal liability of the person who carried out the fraud.
The facts and the procedural route
- A bank branch located in Lugones
- Verbal identification by the defendant as the account holder
- Supply of details from the real holder’s identity document and email address
- Withdrawal of 1,500 euros in cash
- Previous convictions for similar fraud offences
- Sentence of three years and six months, a fine of 1,890 euros and compensation of 1,500 euros plus interest
- The judgment is not final: an appeal in cassation remains available
The legal keys
- Sufficient deception: objective capacity to cause error
- Error on the part of the bank employee as intermediary
- Act of disposal of assets causing loss to the bank
- Intent to profit established by the cash withdrawal
- Weak internal controls do not exonerate the offender
- Victim self-endangerment has very limited scope in fraud
THE DOCTRINEWhat the court holds
The structure of fraud in impersonation cases
The offence of fraud requires deception sufficient to cause error in another, an act of disposal of assets carried out as a result of that error, loss, and intent to profit. In cases of impersonation before a bank these elements are clearly present: the deception consists in asserting another person’s identity backed by genuine personal data, the error is suffered by the employee handling the transaction, and the disposal materialises in handing over the cash.
Sufficient deception and the supply of genuine data
A nuance deserves attention. What gives the deception its capacity is not the bare lie about identity, which anyone could tell, but its support with verifiable personal information: the identity document number and the real holder’s email address. That combination conveys to the employee an appearance of legitimacy that crosses the threshold of what case law calls sufficient deception, that is, apt to overcome the ordinary precautions required in everyday dealings.
Rejection of the defence based on internal controls
The defence argued that the bank’s identification protocols were deficient and that this should bear on the characterisation of the offence. The court rejects that approach with reasoning worth retaining. Any negligence by the victim or its employees does not erase the deception, nor does it render lawful the conduct of the person who deploys it with intent to profit. The doctrine of victim self-endangerment operates in fraud with very restricted scope, reserved for cases of a total absence of elementary diligence, and not for the mere imperfection of a protocol.
The relevance of previous convictions
The ruling notes that the defendant had previous convictions for similar fraud offences. That fact does not alter the characterisation of the offence, but it does bear on sentencing and potentially on the aggravating circumstance of recidivism under Article 22(8) of the Criminal Code, as well as on the prognosis required for any suspension of the sentence.
THE FIRM’S READINGWhat it means in practice
For the defence. A challenge based on the bank’s control failures rarely succeeds on its own. It is more productive to contest the identification of the offender, especially where it rests on an employee’s recognition or on limited-quality CCTV images, and to examine the chain of custody of those recordings and the correctness of the identification procedures.
For the injured bank. Claiming civil liability within the criminal proceedings avoids duplicating actions. It is advisable to produce from the outset the applicable identification protocol, the system audit trail and the recordings, both to establish the loss and to neutralise any allegation of its own negligence.
On the boundary with usurpation of civil status. Where the impersonation is isolated and aimed at obtaining a specific financial benefit, the natural characterisation is fraud. Usurpation of civil status under Article 401 requires a substitution of personality intended to be lasting, not an isolated act.
FREQUENTLY ASKED QUESTIONSFrequently asked questions
Is impersonating another person at a bank an offence?
Yes. Where impersonation is used to obtain a disposal of assets, it amounts to fraud under Article 248 of the Spanish Criminal Code, with the elements of sufficient deception, error, act of disposal, loss and intent to profit.
Does the bank’s failure to verify identity exonerate the offender?
No. The court expressly rejects that argument: any deficiency in internal controls does not relieve of criminal liability the person who carried out the fraud with intent to profit.
What sentence was imposed?
Three years and six months of imprisonment, a fine of 1,890 euros and compensation to the bank of 1,500 euros plus statutory interest. The judgment is not final and may be appealed in cassation.
What is the difference from usurpation of civil status?
Fraud punishes deception aimed at obtaining a specific transfer of assets. Usurpation of civil status requires a substitution of personality intended to be lasting, exercising the rights and obligations of the person impersonated.
YOU MAY ALSO LIKERelated content
Article 248: fraudArticle 250: aggravated fraudPractice areasPractical defence guides
Commentary prepared by the SCJE team from public sources on the decision. Its content is summarised for informational purposes, without full reproduction. It does not constitute individual legal advice. Source consulted: Tirant lo Blanch, actualidad jurídica.
SCJE · ALICANTE AND MADRIDAre you under investigation for bank fraud?
Francisco Javier Martín Porras
Abogado penalista, socio de Société de Conseil Juridique et Expert y creador de la metodología LIWARD®. Dirige la defensa en procedimientos penales de alta complejidad, combinando estrategia procesal con análisis pericial y forense. Conozca al equipo →


