Two recent Belgian court decisions have significantly clarified the right of refund for service users who fall victim to phishing and banking fraud. The Belgian Supreme Court provided in its judgment of 29 June 2026 a long-awaited legal definition of “gross negligence” within the meaning of article VII.44, §1, paragraph 4 of the Belgian Economic Law Code (BEC). Short before this, the President of the Antwerp Enterprise Court, presiding in summary proceedings, ordered on 26 May 2026 the immediate refund to two elderly victims of banking fraud. Together, these rulings deliver an important message to payment service providers and users: consumer protection is paramount, gross negligence must be assessed in context and the obligation to refund is the rule, not the exception.
Liability for unauthorised payment transactions is governed by articles VII.43 and VII.44 BEC.
In case of an unauthorized payment transaction, a payment service provider (“PSP”) must refund the payer by the end of the next business day after notification, unless it has reasonable grounds to suspect fraud by the payer.
However, the final liability is allocated as follows:
The burden of proving fraud, intent or gross negligence rests on the PSP. Transaction logs and proof of use of a personal security code alone are generally considered insufficient to establish negligence on the part of the payer. When a court assesses negligence, it must consider all circumstances of the case.
In the case-at-hand, the applicant was the victim of a smishing attack in January 2020. The applicant received a text message seemingly coming from a government tax authority, claiming an outstanding tax debt and containing a payment link. By following the steps on the fraudulent webpage behind the link, the victim unknowingly consented to the installation and activation of the KBC Mobile banking application on a device belonging to a fraudster. The fraudster debited a total of almost EUR 25,000 from the victim’s account. The Brussels Court of Appeal ruled that the victim had acted with gross negligence, thereby releasing KBC Bank from any refund obligation.
The Belgian Supreme Court, however, annulled this decision, ruling that the facts alone were insufficient to establish gross negligence. For the first time, the Supreme Court explicitly defines “gross negligence” as stated in article VII.44, §1, paragraph 4 BEC:
“Gross negligence constitutes a qualified breach of the duty of care. There is gross negligence within the meaning of Article VII.44, §1, paragraph 4 BEC, when the payer engages in, or fails to engage in, conduct that a reasonably and normally careful payer would never engage in or fail to engage in.”
The Supreme Court further confirmed the following principles:
The judgment of the Supreme Court is a landmark ruling and is to be welcomed as it provides much-needed guidance to lower courts, even though the factual assessment of negligence ultimately remains with the lower courts. The Court’s definition provides a clear two-pronged test:
From now on, this is a demanding standard for PSPs to meet. That said, the judgment does not mean that gross negligence can never be established in phishing cases. The Court confirmed that the factual assessment remains with the judge on the merits. PSPs will continue to argue gross negligence in these cases, but the burden of proof is heavier because of this new and more strict definition.
The key takeaway is that gross negligence cannot be presumed: it must be proven by the PSP, considering all the circumstances measured against this objective standard. It must be noted that the standard remains broadly formulated, leaving considerable room for interpretation in practice.
This case dates from January 2026. The applicants, a married elderly couple, were customers of Argenta Spaarbank. On 23 January 2026, while one of the victims was in the process of making a transfer, he was called by a person pretending to be an Argenta employee. Later that day, he discovered that two transfers totalling almost EUR 50,000 had been made from the couple’s accounts to an unknown account in Portugal. His son contacted the fraud helpline and Card Stop. A police complaint was also filed. The parties dispute what information was shared during the phone call and whether the transactions were authorized. Argenta refused to refund the amounts, reason why the applicants initiated summary proceedings seeking immediate refund.
The presiding judge of the Antwerp Enterprise Court rejected Argenta’s arguments, based on the following:
By confirming that the refund obligation under article VII.43 BEC is immediate and cannot be subordinated to the PSPs defenses, including authorised transaction or gross negligence, the court underlined that the goal of the law is ‘refund first and litigate later’. The risk of litigation lies with the PSPs and not with the payers. However, it must be emphasized that each case needs to be assessed individually.
It is to be expected that PSPs will build in more security systems (e.g. amount limitations, payment delays, etc.), which may not benefit customer experience.
The legal landscape surrounding phishing liability is rapidly evolving, both at national and European level. At the EU level, an important preliminary ruling is pending before the Court of Justice. In his opinion of 5 March 2026, Advocate General Rantos also advised that EU law requires PSPs to immediately refund the amount of an unauthorised transaction. Gross negligence on the part of the customer cannot suspend that obligation. Only after making that refund PSP’s may seek to recover the amount from the consumer in separate proceedings.
The forthcoming CJEU Ruling in case C-70/25 will be closely watched by our team, as it is expected to bring much-needed clarity on how the immediate refund obligation must be applied across Member States.
These two decisions together provide a clearer picture of the legal landscape governing phishing-related fraud.