In an era of widespread digitisation and a growing number of cyber-threats, the financial security of bank customers should be a priority. Banks have advanced fraud-detection systems, user-behaviour analysis, and obligations arising from national and EU law (including PSD2 and the Polish Financial Supervision Authority's Recommendation D). But do these safeguards actually work? Can customers feel safe? One of the most recent cases we have assessed shows that the answer to these questions is not clear-cut.
An OLX phishing case – how easily you can lose your life savings
A client came to our practice who had fallen victim to a classic phishing attack. The fraudsters posed as a buyer on OLX and sent him a fake link supposedly allowing him to collect a payment. The page imitated the bank's login panel. The client – unfortunately – entered his login credentials and then confirmed the login authorisation using an SMS code.
Within a few minutes:
- The fraudsters added a new authorisation device – a Xiaomi Redmi smartphone located in Russia,
- They made a series of internal transfers and transfers from the credit account, including a transfer of funds to a Revolut account,
- They stole several thousand zlotys.
Did the bank react?
Despite obvious signs of fraud – such as:
- a new login location (a foreign IP),
- a change of the authorised device,
- transfers to external e-wallets (e.g. Revolut),
- a non-standard pattern of customer behaviour,
the banking system did not react in any way. The transactions were approved and executed, and the customer only found out about everything after the fact.
What is more, after the complaint was filed, the bank carried out its own "internal analysis" and then... refused to refund the funds. In doing so, it provided no technical logs – neither IP data, nor details of the device being added, nor the transaction parameters.
Banks' obligations vs reality
Under the laws and regulations:
- The PSD2 directive and the Payment Services Act: "The bank is obliged to provide strong customer authentication and systems detecting unauthorised, fraudulent or unusual activity."
- The DORA Regulation: "REGULATION (EU) 2022/2554 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011"
- GDPR – Article 15: "The customer has the right of access to their personal data, including logs and information about activities on their account."
Conclusions from the analysis carried out by our team: do banks really protect their customers?
Unfortunately, in practice we increasingly observe that:
- banks shift responsibility onto the customer, citing an alleged "authorisation" of the actions, even if these were the result of social-engineering manipulation (phishing),
- they do not apply effective anomaly-detection procedures, even when the transactions bear the hallmarks of a crime,
- they refuse to provide key data, which makes it impossible for the customer to genuinely defend their rights.
Meanwhile, part of the case law and the positions of supervisory institutions argue that an authorisation made under the influence of fraud may not constitute the customer's conscious consent. The assessment depends, however, on the circumstances of the case — including the user's possible gross negligence (Articles 42–46 of the Payment Services Act) — and is not uniform in the case law. Banks have not only the technical means but also a legal obligation to act in the customer's interest and to counter cybercrime.
In an age of the rapid development of artificial intelligence and behavioural analytics, banks have tools that allow the almost instant detection of anomalies – such as a login from an unusual place, a device change, or transactions going beyond the customer's typical profile. In a world where algorithms can recognise a face, predict a fall in share prices or suggest an advertisement based on a single click – the failure to detect an obvious phishing attack is a serious oversight. So if a bank has such tools and yet fails to detect an obvious phishing scheme, it is reasonable to question the adequacy of its safeguards. The assessment in a specific case, however, rests with the court — based on an expert opinion and the totality of the circumstances of the event.
What next?
If you have fallen victim to cybercrime, do not be fobbed off with a terse response from the bank. You have the right to:
✅ demand full access to the login and transaction data,
✅ a refund of the funds if the transactions were unauthorised,
✅ file a report with the prosecutor's office and obtain legal assistance,
✅ file a lawsuit with the court in civil proceedings.
Modern banking is not only digital convenience but also a battlefield for security. And the customer should not be alone in that war.