{"id":2454,"date":"2022-11-24T11:28:39","date_gmt":"2022-11-24T10:28:39","guid":{"rendered":"https:\/\/odiceabogados.com\/?p=2454"},"modified":"2022-11-24T11:28:41","modified_gmt":"2022-11-24T10:28:41","slug":"estafas-digitales-reclamar-al-banco-por-phishing","status":"publish","type":"post","link":"https:\/\/odiceabogados.com\/en\/digital-scams-claim-bank-for-phishing\/","title":{"rendered":"Phishing: claiming against the bank for digital scams"},"content":{"rendered":"<h2 class=\"wp-block-heading\">What is phishing?<\/h2>\n\n\n\n<p>Phishing is one of the most well-known scams on the Internet because many people have suffered from it in recent years.&nbsp;<\/p>\n\n\n\n<p>To explain what this is about, we will refer to three characteristic factors:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>The attack is carried out by means of electronic communications, such as a <strong>email, a whatsApp message, an SMS, a phone call and even through platforms such as Wallapop or Vinted.<\/strong><\/li>\n\n\n\n<li>The attacker is impersonating a trusted person or entity (impersonation), such as your<strong> bank, your phone company or your insurer.<\/strong><\/li>\n\n\n\n<li><strong>Its objective<\/strong> is to obtain sensitive personal information to access your credit card. Usually through login credentials where your card is linked or directly by requesting your card numbers.<\/li>\n<\/ol>\n\n\n\n<p>When the attacker obtains this data, he normally performs three operations:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Payments with your card.<\/strong><\/li>\n\n\n\n<li><strong>Withdraw cash from the ATM.<\/strong><\/li>\n\n\n\n<li><strong>Make transfers to your card.<\/strong><\/li>\n<\/ul>\n\n\n\n<p>In most cases, it is very difficult to know the identity of the fraudster because these actions usually leave no trace.&nbsp;<\/p>\n\n\n\n<div style=\"height:22px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Phishing: legal framework<\/h2>\n\n\n\n<p>The <a href=\"https:\/\/www.boe.es\/buscar\/doc.php?id=BOE-A-2018-16036\" target=\"_blank\" rel=\"noreferrer noopener\">Royal Decree-Law 19\/2018 of 23 November 2018 on Payment Services<\/a>transposed into national law Directive (EU) 2015\/2366 of the European Parliament and of the Council of 25 November on <strong>Payment Services in the Internal Market.<\/strong><\/p>\n\n\n\n<p>The aim of this Decree-Law is to generate a safer and more reliable environment for users and to establish a <strong>quasi-objective liability framework of the Banking Entity<\/strong>.<\/p>\n\n\n\n<p>In this way, the<strong> Payment Services Act<\/strong> imposes the following rights and obligations on payment service users and payment service providers (the banks).<\/p>\n\n\n\n<figure class=\"wp-block-pullquote\"><blockquote><p><em><strong>\"Payment transactions are only authorised when the payer has given his consent (Art. 36). If the user denies having authorised a transaction, the bank must immediately refund the amount of the transaction (Art. 45)\".<\/strong>. <\/em><\/p><cite>Payment Services Act<\/cite><\/blockquote><\/figure>\n\n\n\n<div style=\"height:22px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Phishing: obligations of users:<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Use the payment instrument in accordance with the conditions agreed in the contract<\/li>\n\n\n\n<li>Take reasonable steps to protect your security credentials<\/li>\n\n\n\n<li>Report any loss, theft, misappropriation, misappropriation or unauthorised use without undue delay.<\/li>\n<\/ol>\n\n\n\n<div style=\"height:48px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"512\" src=\"https:\/\/odiceabogados.com\/wp-content\/uploads\/2022\/11\/Estafas-digitales_-Phishing-1024x512.png\" alt=\"Digital scams_ Phishing\" class=\"wp-image-2457\" srcset=\"https:\/\/odiceabogados.com\/wp-content\/uploads\/2022\/11\/Estafas-digitales_-Phishing-1024x512.png 1024w, https:\/\/odiceabogados.com\/wp-content\/uploads\/2022\/11\/Estafas-digitales_-Phishing-300x150.png 300w, https:\/\/odiceabogados.com\/wp-content\/uploads\/2022\/11\/Estafas-digitales_-Phishing-768x384.png 768w, https:\/\/odiceabogados.com\/wp-content\/uploads\/2022\/11\/Estafas-digitales_-Phishing-1536x768.png 1536w, https:\/\/odiceabogados.com\/wp-content\/uploads\/2022\/11\/Estafas-digitales_-Phishing-2048x1024.png 2048w, https:\/\/odiceabogados.com\/wp-content\/uploads\/2022\/11\/Estafas-digitales_-Phishing-18x9.png 18w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<div style=\"height:48px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Phishing: obligations of the provider of the means of payment:<\/h3>\n\n\n\n<p>In addition to those stipulated in the contract, it must implement <strong>the security measures necessary to ensure the identity of the payer and the authentication of the transaction <\/strong>with the aim of detecting unauthorised or fraudulent payment transactions in time.<\/p>\n\n\n\n<div style=\"height:22px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h4 class=\"wp-block-heading\">Strong authentication<\/h4>\n\n\n\n<p>The Payment Services Directive (PSD2) obliges banks to ensure that payment orders are made by means of a <strong>strong authentication<\/strong> (Arts. 97 and 98).<\/p>\n\n\n\n<p>This means that <strong>the transaction must be validated with the personal password<\/strong> -or with a biometric factor such as fingerprint or facial recognition, <strong>or with a random key generated for each operation<\/strong> which must be sent to the user to revalidate the operation (two-factor authentication\/security).<\/p>\n\n\n\n<p>Fraudulent operations<\/p>\n\n\n\n<p>Similarly, the entity must be able to detect when authentication elements (personal keys) have been compromised or stolen, <strong>block the operation<\/strong> and contact the user to verify whether he or she is doing it.<\/p>\n\n\n\n<p>For the purpose of verifying the transaction, the bank shall make use of, among other factors, the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Analysis of user consumption patterns or habits<\/li>\n\n\n\n<li>Coordinate cards.<\/li>\n\n\n\n<li>The authorisation code for certain transactions.<\/li>\n\n\n\n<li>Notices on the website of operations.<\/li>\n\n\n\n<li>The concept, the amount and the type of operation.<\/li>\n\n\n\n<li>Detect which shops are safe.<\/li>\n\n\n\n<li>The person to whom the operation is addressed.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:48px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"512\" src=\"https:\/\/odiceabogados.com\/wp-content\/uploads\/2022\/11\/Estafas-digitales_-reclamar-al-banco-por-Phishing-1024x512.png\" alt=\"Digital scams_ claiming against the bank for phishing\" class=\"wp-image-2458\" srcset=\"https:\/\/odiceabogados.com\/wp-content\/uploads\/2022\/11\/Estafas-digitales_-reclamar-al-banco-por-Phishing-1024x512.png 1024w, https:\/\/odiceabogados.com\/wp-content\/uploads\/2022\/11\/Estafas-digitales_-reclamar-al-banco-por-Phishing-300x150.png 300w, https:\/\/odiceabogados.com\/wp-content\/uploads\/2022\/11\/Estafas-digitales_-reclamar-al-banco-por-Phishing-768x384.png 768w, https:\/\/odiceabogados.com\/wp-content\/uploads\/2022\/11\/Estafas-digitales_-reclamar-al-banco-por-Phishing-1536x768.png 1536w, https:\/\/odiceabogados.com\/wp-content\/uploads\/2022\/11\/Estafas-digitales_-reclamar-al-banco-por-Phishing-2048x1024.png 2048w, https:\/\/odiceabogados.com\/wp-content\/uploads\/2022\/11\/Estafas-digitales_-reclamar-al-banco-por-Phishing-18x9.png 18w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<div style=\"height:48px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Can I get my money back if I have been phished?<\/h2>\n\n\n\n<p>Having explained the legal framework of <strong>Payment Services Act<\/strong>If the user denies having authorised a transaction, we can conclude that payment transactions are only considered authorised when the payer has given his consent (Art. 36). If the user denies having authorised a transaction, <strong>the bank must immediately repay the amount of the transaction to you<\/strong> (Art. 45)<strong>unless he proves that the holder has acted fraudulently or with gross negligence <\/strong>when it comes to keeping their security keys.<\/p>\n\n\n\n<p>In this sense, <strong>banks argue that voluntarily providing passwords to a phishing scammer constitutes gross negligence<\/strong>for non-compliance by the holder with his obligation to keep the security keys.<\/p>\n\n\n\n<p>However, <strong>according to the Supreme Court, phishing is a scam, which conceptually is a \"<\/strong><a href=\"https:\/\/dpej.rae.es\/lema\/enga%C3%B1o-bastante#:~:text=Pen.,en%20el%20delito%20de%20estafa.\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>quite misleading<\/strong><\/a><strong>\"<\/strong> and therefore \"gross negligence\" is annulled.<\/p>\n\n\n\n<div style=\"height:22px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">What to do if I have been phished?<\/h2>\n\n\n\n<p>The <a href=\"https:\/\/www.incibe.es\/\" target=\"_blank\" rel=\"noreferrer noopener\">National Cyber Security Institute <\/a>(INCIBE), indicates that it is important that the moment you become aware that it is a scam, you contact your bank immediately \"to cancel any unauthorised payments or our card if necessary\".<\/p>\n\n\n\n<p>In this way, the bank will have no objection to refunding you for any transaction after you have reported the phishing attack.<\/p>\n\n\n\n<p>In addition, INCIBE stresses the importance of gathering all possible evidence in order to file a complaint with the State Security Forces and Corps.<\/p>\n\n\n\n<p>However, if you have suffered from this or any other cyber fraud or your bank is not responsible for the attack, do not hesitate to <a href=\"https:\/\/odiceabogados.com\/en\/#contacto#contacto\" target=\"_blank\" rel=\"noreferrer noopener\">contact us<\/a> y <strong>We will handle your request in the best possible way.<\/strong><\/p>","protected":false},"excerpt":{"rendered":"<p>\u00bfQu\u00e9 es el phishing? El phishing es una de las estafas m\u00e1s conocidas de Internet porque muchas personas lo han sufrido en los \u00faltimos a\u00f1os.&nbsp; Para explicar de qu\u00e9 se trata haremos referencia a tres factores caracter\u00edsticos: Cuando el atacante consigue estos datos, normalmente hace tres operaciones: En la mayor\u00eda de casos, resulta muy dif\u00edcil [&hellip;]<\/p>","protected":false},"author":3,"featured_media":2456,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[87],"tags":[133,132,131],"class_list":["post-2454","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-penal","tag-derecho-penal","tag-estafas-digitales","tag-phishing"],"_links":{"self":[{"href":"https:\/\/odiceabogados.com\/en\/wp-json\/wp\/v2\/posts\/2454","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/odiceabogados.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/odiceabogados.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/odiceabogados.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/odiceabogados.com\/en\/wp-json\/wp\/v2\/comments?post=2454"}],"version-history":[{"count":2,"href":"https:\/\/odiceabogados.com\/en\/wp-json\/wp\/v2\/posts\/2454\/revisions"}],"predecessor-version":[{"id":2460,"href":"https:\/\/odiceabogados.com\/en\/wp-json\/wp\/v2\/posts\/2454\/revisions\/2460"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/odiceabogados.com\/en\/wp-json\/wp\/v2\/media\/2456"}],"wp:attachment":[{"href":"https:\/\/odiceabogados.com\/en\/wp-json\/wp\/v2\/media?parent=2454"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/odiceabogados.com\/en\/wp-json\/wp\/v2\/categories?post=2454"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/odiceabogados.com\/en\/wp-json\/wp\/v2\/tags?post=2454"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}