Spoofing is a fraudulent technique that seeks to impersonate a person or entity in order to deceive and carry out malicious activities. This type of cyberattack can take different forms, from fake emails to telephone calls or even the impersonation of IP addresses. We explain what spoofing is, how it works and, most importantly, what measures you can take to protect yourself.
What is spoofing?
Spoofing is a cybersecurity term referring to digital impersonation. Attackers try to pass themselves off as a trusted person or entity, such as a well-known company, a bank or even a personal contact, to gain the victim’s trust and carry out the fraud. There are several types. Email spoofing: the criminal forges the sender field so that the message appears to come from a reliable source, such as a bank or a company you deal with. Caller ID spoofing: scammers alter the number shown on your screen so that it looks like a call from your bank or service provider. IP spoofing: the IP address of data packets is altered so that they appear to come from a legitimate source, in order to gain unauthorised access to networks or systems. Website spoofing (phishing): attackers create an identical copy of a legitimate website, for example an online bank, so that you enter your personal and banking details.
How spoofing works
Spoofing depends largely on the trust placed in the source or the communication channel. Attackers forge addresses, creating fake email addresses, telephone numbers or websites that imitate real ones. They sometimes use malware: clicking a link in a fake email or visiting a manipulated website may download software that gives the attacker access to confidential information. And they use social engineering, posing as friends, relatives or financial institutions to create a sense of urgency or trust that allows them to steal sensitive information such as passwords or card numbers.
How to protect yourself from spoofing
Verify the source: if you receive an email, text message or call that seems suspicious, do not reply immediately; check the email address, the telephone number or the URL and, if in doubt, contact the entity directly through its official channels. Do not click on unknown links or download attachments from messages whose authenticity you cannot confirm. Enable two-factor authentication, which adds an extra layer of security even if someone obtains your password. Keep your software up to date, since security updates prevent vulnerabilities from being exploited. Use security tools such as antivirus and anti-malware software and email filtering services. Be careful with telephone calls: never give sensitive information over the phone to a caller claiming to be your bank; call the institution back on its official number.
Conclusion
Spoofing is a constant threat in the digital world, but with caution and appropriate security measures you can considerably reduce the risks. Always verify sources, be careful with unknown links and keep your software up to date. Education and vigilance are your best allies. If you suspect you have been the victim of a spoofing attack, contact us as soon as possible: identity theft and the fraud that usually follows it can be prosecuted, and the first hours are decisive to preserve the evidence and block the charges.
The bank’s liability for unauthorised payments
Most spoofing attacks end with a transfer or a card payment that the victim did not authorise, or authorised while deceived. Royal Decree-Law 19/2018 on payment services, which transposes the second European Payment Services Directive, sets the rules. Under Article 45, when a payment transaction has not been authorised, the bank must refund its amount immediately and no later than the end of the following business day, unless it has reasonable grounds to suspect fraud by the customer and notifies them in writing. The burden of proof lies with the bank: it must show that the transaction was authenticated, accurately recorded and not affected by a technical failure, and the mere use of the customer’s credentials is not, by itself, sufficient proof that the customer authorised the payment or acted with gross negligence.
What the courts say about the customer’s negligence
Banks frequently refuse the refund alleging that the customer was grossly negligent for having provided their codes. The civil courts have repeatedly rejected this argument in cases where the deception was sophisticated: a call or message displaying the bank’s genuine number, a message inserted into the bank’s own conversation thread, or a caller who already knew personal data of the customer. In those circumstances the courts consider that an average consumer could not be expected to detect the fraud, and that the bank, which controls the security of its channels and has fraud-detection systems, must bear the loss. The customer’s conduct is examined in each case, and a refusal is more likely where the customer ignored explicit warnings or authorised several unusual operations in a row.
Steps to take and where to complain
The customer should notify the bank immediately, by a channel that leaves a record, block the cards and credentials and ask for the recall of the transfers; delay in notifying the bank may itself be treated as negligence. The criminal complaint with the National Police or the Guardia Civil documents the fraud and is often required by the bank. If the bank refuses the refund, a written complaint must be filed with its customer service department, and, if it is not resolved satisfactorily, the matter may be taken to the complaints service of the Bank of Spain and, ultimately, to the civil courts, where claims for these amounts are frequently upheld. Telecommunications authorities have also adopted measures in 2025 obliging operators to block certain calls and messages that present falsified Spanish numbering, which should reduce the most common form of the attack.
Frequently asked questions
Is spoofing a crime in Spain?
The impersonation itself and the fraud that usually follows are prosecuted under the Spanish Criminal Code, mainly as fraud (Article 248), together with offences of disclosure of secrets or computer damage depending on the conduct.
What should I do if I gave my details on a fake website?
Change your passwords immediately, contact your bank to block cards and charges, keep all the evidence and file a complaint with the police.
How can I tell a spoofed email from a real one?
Check the real sender address, not just the displayed name, distrust urgent requests for data or payments, and never follow links: type the official address yourself.
Does the bank have to refund a transfer made after a spoofing call?
If the transaction was not authorised, Royal Decree-Law 19/2018 obliges the bank to refund it immediately and no later than the end of the following business day, unless it proves fraud or gross negligence by the customer.
Is giving my codes to someone who called from the bank’s number gross negligence?
The civil courts have repeatedly held that it is not, when the deception was sophisticated and an average consumer could not detect it; each case is examined on its own facts.
Related guides
- Recovering money from an online scam in Spain
- Can they ask for a copy of your ID document in Spain?
- Cybercrime in Spain: types, penalties and defence
Do you need a criminal defence lawyer in Alicante or Madrid now? Société Juridique provides emergency assistance and 24-hour assistance to detained persons in Alicante, Madrid and throughout Spain.
This article is informative in nature and does not constitute legal advice. For a specific case, consult a lawyer.
Francisco Javier Martín Porras
Abogado penalista, socio de Société de Conseil Juridique et Expert y creador de la metodología LIWARD®. Dirige la defensa en procedimientos penales de alta complejidad, combinando estrategia procesal con análisis pericial y forense. Conozca al equipo →

