EU court adviser says banks must immediately refund phishing victims
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。用户的要求很明确,不需要特定的开头,直接写描述即可。首先,我得通读整篇文章,抓住主要信息。 文章讲的是欧盟法院总顾问Athanasios Rantos发表的意见,建议银行必须立即退还账户持有人因未经授权交易而损失的资金,即使损失是客户自己的过错导致的。案例涉及波兰的一家银行和客户的钓鱼诈骗案。客户因为疏忽导致资金被盗,银行拒绝退款,客户起诉。 根据PSD2指令,除非有合理怀疑客户欺诈,否则银行必须立即退款。但银行之后可以向客户追偿,如果证明客户有重大过失或故意行为。 总结时要包含关键点:Rantos的意见、银行必须退款、PSD2的规定、例外情况以及后续追偿的可能性。同时要简洁明了,在100字以内。 可能的结构是:Rantos建议银行立即退款,除非怀疑欺诈;根据PSD2;银行可追偿;意见非最终裁决。这样就能涵盖主要信息。 </think> 欧盟法院总顾问建议银行在未经授权交易中立即向受害者退款,即使损失由客户过失引起。根据《支付服务指令》,除非有合理理由怀疑欺诈,否则银行必须退款。若客户存在重大过失或故意行为导致安全漏洞,银行可追偿损失。此意见为法律建议,并非最终裁决。 2026-3-8 15:30:21 Author: www.bleepingcomputer.com(查看原文) 阅读量:11 收藏

EU court adviser says banks must immediately refund phishing victims

Athanasios Rantos, the Advocate General of the Court of Justice of the EU (CJEU), has issued a formal opinion suggesting that banks must immediately refund account holders affected by unauthorized transactions, even when it's their fault.

The opinion was issued in response to a request for a preliminary ruling submitted by the District Court in Koszalin, Poland, in a dispute between the PKO BP S.A. bank and one of its customers.

The case involved phishing fraud, where the customer advertised an item for sale on an auction platform, and was approached by a fraudster who sent them a malicious link to a page resembling the bank’s login interface.

The customer entered their bank account credentials on that site, which the fraudster then used to execute an unauthorized payment.

The victim reported the transaction the next day to both the bank and the police, but the fraudsters were not identified, and the bank refused to refund the lost amount. In response, the customer sued the bank.

The dispute arose because the bank argued it could deny the refund if the customer’s negligence caused the loss.

Rantos states that under the EU Payment Services Directive (2015/2366 / PSD2), a bank cannot refuse to issue an immediate refund to victims unless it has reasonable grounds to suspect customer fraud.

“Advocate General Athanasios Rantos considers that EU law requires the bank, as a first step, to refund immediately the amount of the unauthorised transaction, unless it has good reason to suspect fraud, which it must communicate in writing to the competent national authority,” reads the CJEU press release.

However, it is clarified that the process doesn’t end there, as the banks are still allowed to seek recovery of the losses from the customer if they can prove gross negligence or intention, leading to the security breach.

“If the bank establishes that the customer has failed, intentionally or through gross negligence, to fulfil one of the obligations relating, in particular, to personalised security data, it may require the customer to bear the corresponding losses,” reads the AG’s opinion.

“If the customer refuses to reimburse the amount of the unauthorised transaction, it is up to the bank to take legal action against that person to obtain payment.”

It is important to clarify that this opinion is not a CJEU ruling, but rather an indication of the direction the court may take when the matter reaches that stage. The AG’s opinion (full text here) is a legal recommendation to the CJEU judges, but the CJEU's final ruling will be binding on all EU courts.

tines

Red Report 2026: Why Ransomware Encryption Dropped 38%

Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.


文章来源: https://www.bleepingcomputer.com/news/legal/eu-court-adviser-says-banks-must-immediately-refund-phishing-victims/
如有侵权请联系:admin#unsafe.sh