The case: Payments and credit agreements after mobile phone theft
During a stay abroad, a consumer had his smartphone stolen. The device was secured using a unique device code and Face ID. The affected person immediately reported the theft to his bank and requested the blocking of his account and all associated payment instruments.
Nevertheless, within a short period of time several credit and installment payment contracts were concluded in the customer's name. At the same time, numerous large payments were made at various locations. Even after the blocking notice and the explicit withdrawal of the unsolicited financial products, further installments were debited from the account.
In addition to the question of whether the individual transactions were authorized, it raises another question in particular: wouldn't the bank's security system have long since had to sound the alarm in the face of this unusual transaction pattern?
Unauthorized payment transactions: The bank must refund the money in principle
A payment transaction is only authorized if the account holder or the account holder has given their consent. In the absence of such consent, an unauthorized payment transaction is present.
According to § 67 ZaDiG 2018, the bank must, in principle, immediately, and no later than by the end of the following business day after becoming aware of or being notified of the unauthorized payment transaction, refund the amount of the unauthorized payment transaction. The account must be set up in such a way that it would stand without the unauthorized charge.
The bank bears the burden of proof that the payment process was properly authenticated, recorded, and recorded. However, what is crucial is that the mere use of the payment instrument or a security check is not sufficient in itself to prove that the customer actually authorized the payment.
When is the account holder liable themselves?
A lien does not automatically exist just because a smartphone or a card has been stolen.
If the affected person has negligently violated their duty of care, a self-defense fee of up to EUR 50.00 may be considered in principle. Further liability generally requires that the person acted intentionally or with gross negligence.
Whether gross negligence exists always depends on the circumstances of the individual case. Relevant factors may include whether access data were openly available, whether warning notices were ignored, whether security codes were passed on to third parties, or whether the theft was not reported despite knowledge of it.
Conversely, an individual device code, biometric locks such as Face ID, and the immediate notification to the bank and mobile phone provider that the person concerned has fulfilled their essential protection and reporting obligations are all indicators that the person in question has done so.
Banks must detect suspicious transactions
Banks must not limit themselves to considering a technically successful registration or authorization as sufficient evidence of a legitimate transaction.
According to European regulations, payment service providers must implement transaction monitoring mechanisms that can detect fraudulent or unauthorized payment transactions. These systems must be based on the usual payment behavior of the respective customer and must detect any unusual deviations.
This does not mean that every unusual payment has to be automatically rejected. However, the more warning signals occur simultaneously, the more likely the bank will conduct additional checks, hold the transaction in abeyance, or block the account or individual payment instruments.
What warning signs should the bank sound the alarm about?
The assessment always depends on the individual case. The more unusual factors that occur simultaneously, the more likely the bank will have to question the transaction, implement additional security measures, or temporarily suspend the order.
Relevant warning signs may include, in particular:
- unusually high amounts that differ significantly from the previous payment behavior;
- a large number of payments within a very short time;
- several new recipients or dealers, in particular if no comparable payments have previously been made;
- unusual geographic patterns, such as a sudden use in another state or at several locations far apart;
- the opening of new financing, credit or installment payment products immediately before or during conspicuous payments;
- a new or unusually used end device, a changed IP address, or other deviations in access;
- already reported loss, theft, or fraud cases;
- known patterns of fraud or irregularities in the payment recipient.
In the case of a combination of such factors, a purely formal reference to successful registration is not sufficient. An effective fraud management system must detect conspicuous deviations from previous customer behavior and respond appropriately.
The case law has already clarified that the expectation of detecting numerous high and unusual transfers within a short period of time does not constitute an overreach of a bank’s duty of care.
What must the bank do if it detects a suspicious pattern in transactions?
A functioning fraud management system can trigger various responses – depending on the risk – including:
-
an additional authentication that goes beyond the usual login;
-
a delay or temporary withholding of the transaction;
-
a request from the customer for a secure, independent communication channel;
-
a restriction on further payments or the blocking of individual payment instruments;
-
a manual examination by the fraud prevention department; or
-
immediate full blocking if a theft or abuse has already been reported.
What is crucial is that the bank not only has a technical control system. This must also be capable of detecting significant anomalies. Therefore, in the case of several high payments, new credit products, and an unusual pattern of foreign use, a closer examination may be warranted.
Report of loss and ban: From this point onwards, further misuse must be prevented
Anyone who notices the loss or theft of a smartphone, card, or access data should immediately notify the bank and explicitly request the blocking of all affected payment instruments.
Following such a report, the bank has a particularly clear obligation: The continued use must be effectively prevented. If further transactions or debits are allowed despite a clear blocking notification, this is particularly problematic from a legal perspective.
This is especially true if, after a ban has been imposed, the bank continues to charge interest on contracts that the person concerned has explicitly denied and provisionally revoked.
Is the affected person responsible themselves?
A defect does not automatically exist just because a smartphone has been stolen. In the case of slight negligence in the performance of duty of care, a self-defense fee of up to EUR 50.00 may be considered.
Further liability generally requires that the affected person acted intentionally or with gross negligence. Whether this is the case depends heavily on the circumstances: Were access data publicly available? Were warning notices ignored? Was the theft not reported despite knowledge? Or was the device protected by a code and biometric locks, and the loss was immediately reported?
Especially in the latter case, there is much evidence that the person concerned has fulfilled their essential protection and reporting obligations. What affected persons should do in any case:
- Fully inform the bank: Request the blocking of accounts, cards, the banking app, digital wallets, and all associated payment instruments.
-
Documenting the blocking notice as evidence: Note the date, time, contact person, and content of the conversation. Additionally, confirm the lock-in by writing it down.
-
Controlling the account continuously: Not only do you need to check payments, but also newly established loans, installment payments, cards, and other banking products.
-
Claiming each transaction individually: Do not dispute unauthorized payments and contracts explicitly and demand a refund.
-
Submitting a police report: This serves to document and clarify the facts.
Conclusion: The bank must not turn a blind eye to serious irregularities
The theft of a mobile phone does not mean that the victim must automatically bear all subsequent losses. Under the ZaDiG 2018, the bank is not required to reimburse unauthorized payment transactions in principle. Furthermore, it may be liable if its control system fails to detect significant irregularities or if it allows further payments despite a loss and blocking notification.
Especially in the case of high amounts, a large number of transactions within a short period of time, unusual foreign payments, and at the same time newly concluded financing products, it must be examined whether the bank has sufficiently complied with its security and monitoring obligations. Affected parties should therefore have their claims for reimbursement, damages, and, if applicable, for establishing the invalidity of the contracts reviewed.
For individual advice, you are Anela Blöch and your team at the phone number 01 3912345 or by email bloech@atb.law happy to help.