Financial & Banking · European Union

Bank Spoofing Scams: Your Refund Rights Under PSD2 in the EU

Banks sometimes deny a refund by arguing you were "grossly negligent" simply because you entered a code sent by text. That's not automatically true — and the current law, PSD2, sets a real bar for what actually counts.

An Important Clarification Before Anything Else

The rules that govern your refund rights today come from the Second Payment Services Directive (PSD2), currently in force across the EU. A newer package — the Third Payment Services Directive (PSD3) and an accompanying Payment Services Regulation (PSR) — has been politically agreed and is moving toward formal adoption, but as of mid-2026 it has not yet been published in the EU Official Journal, and even once it is, the new rules generally won't apply for another 21 months after that. In practice, that means PSD3 protections are not yet operative, and won't be for some time — anyone dealing with a spoofing scam right now needs PSD2, not PSD3.

What PSD2 Actually Requires Today

Under PSD2, a payment service provider is generally liable to refund an unauthorized transaction, unless it can show the payer acted fraudulently or with gross negligence in failing to keep their security credentials safe. Gross negligence is a genuinely high legal standard — it means a serious, obvious failure to take reasonable care, not simply having been the victim of a convincing scam.

Why Entering a Code Doesn't Automatically Mean Gross Negligence

In a phone spoofing scam, the fraudster manipulates caller ID to display your bank's genuine, official support number, making the call appear indistinguishable from a legitimate one. If the bank's own systems, tone, and scripted language were successfully imitated to the point that a reasonable person couldn't have detected the fraud, that's a strong argument the customer wasn't grossly negligent — they were the target of a technically sophisticated deception, not someone who ignored an obvious warning sign. Courts and ombudsman bodies across the EU have increasingly scrutinized banks' blanket denials based simply on "the customer gave out a code," requiring a genuinely case-specific assessment instead.

What This Means for You

Related Kibbo Tools

Sources