Unauthorized Payment Transactions: What Are the Implications for Banks According to the Italian Law?

Who is required to bear the loss when a bank transfer is fraudulently ordered through the home banking system? The answer is not straightforward and highlights an important factor: the correct use of access credentials is not what matters, but it is necessary to assess all the circumstances of the case, including both the conduct of the intermediary (the banking institution) and that of the user. Two recent decisions of Italian courts provide opposite answers to the question, however showing a certain balance that is useful in the assessment. On the one hand, judgment no. 1929/2026 of the Court of Appeal of Palermo confirmed the liability of the banking institution in relation to an unauthorized bank transfer of 23,500 euros, carried out through home banking. On the other hand, the Court of Taranto, with judgment 410/2025, instead excluded the bank’s liability in a phishing case, finding the customer responsible for negligence.

In the first case mentioned, the fraud had been carried out through the BRATA malware and, according to the reconstruction of the facts, the transaction came from an IP address never used by the customer and, on the same day, the bank’s system had already detected previous suspicious access attempts. According to the Court, these anomalies should have required further checks and a higher level of attention from the intermediary and therefore, the correct authentication of the transaction would not, by itself, be sufficient to exclude the intermediary’s liability. This point is particularly significant for banking operators: the formal regularity of a transaction must be accompanied by systems capable of detecting specific anomalies in the customer’s behavior and access activity.

In the second case mentioned, on the contrary, the customer, victim of phishing, had received a link via SMS and entered their credentials and security codes into the system. Despite a message from the home banking system clearly warning them that through the link they would authorize a bank transfer, the user nevertheless decided to proceed. This behavior was considered by the judges of Taranto to be seriously negligent conduct, excluding in this case the liability of the banking institution.

It therefore clearly emerges that the assessment of liability depends on the specific circumstances, the conduct of the parties and the possibility of recognizing any signs of fraud.

The decisions are part of the approach already expressed by the Italian Supreme Court with judgment no. 3780/2024 and are supported by the rules of PSD2.

When the customer disputes a transaction, the intermediary must be able to prove the correct authentication, recording and accounting of the transaction and the absence of technical problems. At the same time, the bank’s liability may be excluded when fraudulent or seriously negligent conduct by the customer is specifically demonstrated. In the cases mentioned, therefore it is clear that in the first case, the bank had information which, according to the judges, should have led to further checks on the transaction, while in the second case the conduct was considered sufficiently serious to exclude the intermediary’s liability.

The two decisions draw attention to the need to support authentication systems with effective procedures for detecting and managing anomalies, but also to how necessary it is to assess problems on a case-by-case basis. The increasing sophistication of digital fraud implies greater attention in assessing the conduct of banking institutions and customers.

For both parties, therefore, it becomes particularly important to keep track of the actions taken in order to be able to identify the responsible party in the event of improper violations.

In the event of a violation, it is always useful to act promptly by blocking the home banking system and informing the banking institution, including through a written complaint.

Alongside the prompt management of fraud, its prevention is also particularly important. The recent cybersecurity incident involving TeamSystem, an Italian company active in the development of digital solutions and services for businesses and professionals, highlighted how the theft of accounting data can be used to create particularly credible fraud schemes, for example through false communications relating to changes in bank account details or payment requests apparently coming from parties known to the company. For companies, it therefore becomes important to adopt internal procedures that make it possible to verify payment requests or changes to IBAN details through independent channels and, for more significant transactions, to provide double authorization systems, as well as to raise awareness among staff involved in payment management.

Veronica Gianola Veronica Gianola

Veronica Gianola

Veronica Gianola, an accomplished Italian lawyer, is a member of the Milan Bar Association.
Jun Jie Yang Jun Jie Yang

Jun Jie Yang

Jun Jie Yang, has developed strong expertise in the areas of TMT, Data Protection, and commercial contracts.

Contact us for a
first consultation

CONTACT US FOR A FREE CONSULTATION

This field is for validation purposes and should be left unchanged.