Perspective:

Courts impose enhanced accountability on payment service providers for phishing-related fraud

Commercial Law | Legal Newsflash

Two recent Belgian court decisions have significantly clarified the right of refund for service users who fall victim to phishing and banking fraud. The Belgian Supreme Court provided in its judgment of 29 June 2026 a long-awaited legal definition of “gross negligence” within the meaning of article VII.44, §1, paragraph 4 of the Belgian Economic Law Code (BEC). Short before this, the President of the Antwerp Enterprise Court, presiding in summary proceedings, ordered on 26 May 2026 the immediate refund to two elderly victims of banking fraud. Together, these rulings deliver an important message to payment service providers and users: consumer protection is paramount, gross negligence must be assessed in context and the obligation to refund is the rule, not the exception.

Background: the regulatory framework

Liability for unauthorised payment transactions is governed by articles VII.43 and VII.44 BEC.

In case of an unauthorized payment transaction, a payment service provider (“PSP”) must refund the payer by the end of the next business day after notification, unless it has reasonable grounds to suspect fraud by the payer.

However, the final liability is allocated as follows:

  • the payer bears losses up to EUR 50,00 prior to notification;
  • the payer bears no loss where the incident could not have been detected beforehand or was caused by the provider’s staff;
  • the payer bears unlimited liability where they acted fraudulently or with intent or gross negligence, to comply with the following obligations:
    • to use the payment instrument in accordance with objective, non-discriminatory and proportionate terms;
    • to notify the provider without undue delay after becoming aware of any loss, theft, misappropriation or unauthorised use.

The burden of proving fraud, intent or gross negligence rests on the PSP. Transaction logs and proof of use of a personal security code alone are generally considered insufficient to establish negligence on the part of the payer. When a court assesses negligence, it must consider all circumstances of the case.

The judgment of the Supreme Court: a brand new definition of gross negligence

In the case-at-hand, the applicant was the victim of a smishing attack in January 2020. The applicant received a text message seemingly coming from a government tax authority, claiming an outstanding tax debt and containing a payment link. By following the steps on the fraudulent webpage behind the link, the victim unknowingly consented to the installation and activation of the KBC Mobile banking application on a device belonging to a fraudster. The fraudster debited a total of almost EUR 25,000 from the victim’s account. The Brussels Court of Appeal ruled that the victim had acted with gross negligence, thereby releasing KBC Bank from any refund obligation.

The Belgian Supreme Court, however, annulled this decision, ruling that the facts alone were insufficient to establish gross negligence. For the first time, the Supreme Court explicitly defines “gross negligence” as stated in article VII.44, §1, paragraph 4 BEC:

“Gross negligence constitutes a qualified breach of the duty of care. There is gross negligence within the meaning of Article VII.44, §1, paragraph 4 BEC, when the payer engages in, or fails to engage in, conduct that a reasonably and normally careful payer would never engage in or fail to engage in.”

The Supreme Court further confirmed the following principles:

  • gross negligence is more than mere negligence;
  • gross negligence implies conduct displaying a considerable degree of carelessness, it is not equivalent to ordinary carelessness;
  • the judge must consider all factual circumstances of the case when assessing the negligence.
First observations

The judgment of the Supreme Court is a landmark ruling and is to be welcomed as it provides much-needed guidance to lower courts, even though the factual assessment of negligence ultimately remains with the lower courts. The Court’s definition provides a clear two-pronged test:

  • a qualified breach of the duty of care;
  • measured against the conduct of a reasonably and normally careful payer. 

From now on, this is a demanding standard for PSPs to meet. That said, the judgment does not mean that gross negligence can never be established in phishing cases. The Court confirmed that the factual assessment remains with the judge on the merits. PSPs will continue to argue gross negligence in these cases, but the burden of proof is heavier because of this new and more strict definition.

The key takeaway is that gross negligence cannot be presumed: it must be proven by the PSP, considering all the circumstances measured against this objective standard. It must be noted that the standard remains broadly formulated, leaving considerable room for interpretation in practice.

The Antwerp summary proceedings decision: even more strict for PSPs

This case dates from January 2026. The applicants, a married elderly couple, were customers of Argenta Spaarbank. On 23 January 2026, while one of the victims was in the process of making a transfer, he was called by a person pretending to be an Argenta employee. Later that day, he discovered that two transfers totalling almost EUR 50,000 had been made from the couple’s accounts to an unknown account in Portugal. His son contacted the fraud helpline and Card Stop. A police complaint was also filed. The parties dispute what information was shared during the phone call and whether the transactions were authorized. Argenta refused to refund the amounts, reason why the applicants initiated summary proceedings seeking immediate refund.

The presiding judge of the Antwerp Enterprise Court rejected Argenta’s arguments, based on the following:

  • PSPs must refund first, and may then seek recovery from the payer in separate proceedings on the merits if gross negligence can be demonstrated;
  • the only valid exception to the immediate refund obligation is a reasonable suspicion of fraud by the payer itself. This must be communicated in writing to the FPS Economy withing the day.
First observations

By confirming that the refund obligation under article VII.43 BEC is immediate and cannot be subordinated to the PSPs defenses, including authorised transaction or gross negligence, the court underlined that the goal of the law is ‘refund first and litigate later’. The risk of litigation lies with the PSPs and not with the payers. However, it must be emphasized that each case needs to be assessed individually.

It is to be expected that PSPs will build in more security systems (e.g. amount limitations, payment delays, etc.), which may not benefit customer experience.

The forthcoming CJEU ruling 

The legal landscape surrounding phishing liability is rapidly evolving, both at national and European level. At the EU level, an important preliminary ruling is pending before the Court of Justice. In his opinion of 5 March 2026, Advocate General Rantos also advised that EU law requires PSPs to immediately refund the amount of an unauthorised transaction. Gross negligence on the part of the customer cannot suspend that obligation. Only after making that refund PSP’s may seek to recover the amount from the consumer in separate proceedings. 

The forthcoming CJEU Ruling in case C-70/25 will be closely watched by our team, as it is expected to bring much-needed clarity on how the immediate refund obligation must be applied across Member States. 

What's Changed in Phishing Protection?

These two decisions together provide a clearer picture of the legal landscape governing phishing-related fraud. 

  • For PSPs: more lawsuits are to be expected. The Supreme Court’s ruling increases the burden of proof for PSPs. However, this does not imply that PSPs will automatically have to refund all phishing losses. PSPs will need to demonstrate more rigorously why a customer acted with gross negligence. The assessment remains fact-based and case by case.
  • For payment service consumers: a PSP is required to refund a victim of an unauthorised payment transaction immediately. Only a formal suspicion of fraud, which must be communicated in writing to the relevant authorities, can delay this obligation.