A text message from a supposed courier asking for extra payment for a package, a call from a "bank employee" warning of an attempted account hack, or a fake login page that looks deceptively like an online banking system – the methods used by cybercriminals are increasingly sophisticated and increasingly difficult to recognize, even for a cautious customer. When life savings disappear from an account, victims usually hear one response from the bank: "It's your fault. You provided authorization details, so we can't refund the funds." Does the bank really have the right to do this? In the vast majority of cases, the answer is no, and this is directly dictated by law.

Unauthorized payment transaction

Liability for unauthorized payment transactions is regulated by the Payment Services Act of 19 August 2011, which implements the EU PSD2 directive. These regulations protect consumers and, to a significant extent, shift the burden of liability onto the payment service provider, i.e., the bank.

Pursuant to Article 40, Section 1 of the Act, a payment transaction is deemed authorized only if the payer has consented to it in the manner specified in the agreement concluded with the payment service provider. If a criminal impersonates a customer, takes over their login details, or fraudulently obtains an SMS authorization code, this is not authorization within the meaning of the Act, but a crime as a result of which the customer becomes a victim of fraud, rather than a party knowingly accepting the transaction.

Importantly, Article 45(1) of the Act places the burden of proof on the payment service provider to demonstrate that a given transaction was authorized, correctly recorded in the payment processing systems, and was not affected by a technical failure or other service-related defect. In other words, the customer does not have to prove that they did not make the transfer – the bank must demonstrate that the transaction was fully authorized, and simply citing the fact that the operation was confirmed by an SMS code or logging into a mobile application is not sufficient to satisfy this evidentiary burden.

D+1 rule and refund amount range

The Act provides for a very short statutory deadline for the return of stolen funds. Pursuant to Article 46, Section 1 of the Act, in the event of an unauthorized payment transaction, the payer's payment service provider is obligated to immediately, but no later than the end of the business day following the day on which it discovered the transaction or received the appropriate notification from the customer, refund the full amount of the unauthorized transaction to the payer. This provision obliges the bank not only to formally return the funds but also to restore the debited payment account to the state it would have been in had the unauthorized transaction not occurred. This means that the bank must refund not only the amount of the stolen transaction itself but also compensate the customer for any subsequent financial consequences incurred as a result, including any interest or fees accrued in the meantime, which the customer would not have incurred had the funds remained in the account.

It is important to distinguish between the obligation to refund the full amount of an unauthorized transaction, arising from Article 46, and the limited financial liability of the payer himself, regulated in Article 45, paragraph 2 of the Act. According to this provision, in cases where an unauthorized transaction occurred as a result of the perpetrator using a lost or stolen payment instrument, or as a result of misappropriation and unauthorized use of a payment instrument, the payer is liable only up to the equivalent of €50, converted at the average exchange rate announced by the National Bank of Poland on the date of the transaction. The bank must return the remaining amount of the stolen amount without fail. However, this limit does not apply and is waived in its entirety if the unauthorized transaction resulted from the payer's intentional act or gross negligence. In such a situation, the customer's liability may cover the full amount lost, making the legal qualification of the customer's behavior a key element of any dispute with the bank.

When can a bank refuse to refund funds immediately?

A bank may waive its obligation to immediately return funds only in strictly defined situations stipulated by law. The first is when the bank has reasonable and duly documented grounds to suspect fraud on the part of the client, of which it is obligated to notify the relevant supervisory authority, i.e., the Polish Financial Supervision Authority, in writing. The second is when the unauthorized transaction occurred as a result of the client's intentional actions or gross negligence. Furthermore, under Article 44, Section 2 of the Act, the bank is exempt from the obligation to return funds if the client failed to report the unauthorized transaction within 13 months of its occurrence. However, this deadline should be treated as final and not as an excuse for refusing a refund in situations where the report was made relatively soon after the irregularity was discovered.

It is around the concept of gross negligence that the vast majority of court disputes between injured customers and banks revolve.

The concept of gross negligence in judicial practice

Banks readily classify as gross negligence simply clicking a link sent via text message or providing a BLIK code to a consultant posing as a bank employee. However, common courts and the Financial Ombudsman assess such situations significantly differently and define the concept of gross negligence much more restrictively.

Gross negligence, as defined by civil law, is conduct bordering on willful misconduct—it signifies a complete disregard for basic, obvious precautions for the average person, rather than a simple oversight justified by the circumstances. Modern criminals possess technology that allows them to display a real, authentic bank hotline number on a victim's phone screen, known as number spoofing. They also create websites that are deceptively similar to real online banking systems, complete with identical graphical elements, domains similar to the originals, and security certificates that create a false sense of authenticity. In such situations, the customer acts under the influence of a deliberate, sophisticated psychological manipulation, known as social engineering, rather than as a result of their own negligence.

The case law of the Supreme Court and common courts is clear on this matter: falling victim to deliberate fraud and professional manipulation by criminals does not equate to gross negligence on the part of the customer. As indicated above, the burden of proof in this regard rests with the bank, not the customer. The bank must demonstrate in court specific circumstances demonstrating the customer's gross negligence, and cannot limit itself to merely demonstrating that the disputed transaction was properly confirmed via SMS code or mobile app, as correct technical confirmation alone does not determine the customer's fault.

What to do if funds disappear from your account

A victim of bank account theft should immediately contact the bank via the official hotline to block their payment cards and access to online banking, which will prevent further unauthorized transactions. The next step is to report the matter to the police and obtain confirmation of filing a criminal complaint, which serves as important evidence in any subsequent proceedings against the bank. A formal complaint should then be filed with the bank, demanding an immediate refund of the funds under Article 46, Section 1 of the Payment Services Act. It's worth emphasizing that the bank's initial negative response is often simply standard operating procedure for the financial institution, intended to discourage the injured party from pursuing further claims, rather than a substantive resolution of the case based on a thorough analysis of the circumstances of the incident. Therefore, this should not discourage them and lead to further action.

This article is for informational purposes only and does not constitute legal advice. The law is current as of August 12 , 2026.

Author / Editor of the series:

    Have any questions? Contact us – we'll respond as quickly as possible.