Opening your bank’s app and discovering that tens of thousands of euros have disappeared from your account is one of the worst scenarios imaginable for those who use home banking. But after the shock almost always comes a second question, much less immediate than it seems: Who has to prove that the transfer was not authorized? Must the customer be able to reconstruct how the fraudsters entered the account, or is it up to the bank to prove that it was the account holder himself, with grossly negligent behavior, who made the fraud possible?
A particularly significant response comes from Court of Appeal of Palermowhich with sentence no. 1929/2026 confirmed the conviction of a credit institution for a fraudulent transfer from 23,500 euroscarried out via home banking to a beneficiary unknown to the company holding the account. The central point of the decision is not only the amount of the sum returned, but the rule on which most of the controversies related to online banking fraud are based: the customer’s gross negligence cannot simply be presumed because the operation was carried out using his credentials correctly.
The 23,500 euro transfer and the discovery of the fraud
The story starts from an operation that the account holder company claims to have never arranged. When he notices the 23,500 euro transfer, he ignores it and files a complaint. The Court of Palermo ruled in favor of her at first instance and condemned the bank to pay a total sum close to 30 thousand euros, also considering legal costs and costs of technical consultancy. However, the credit institution appeals, arguing among other things that the transaction had been duly authenticated and that what happened was attributable to the user’s gross negligence.
The Third Civil Section of the Court of Appeal rejects the appeal. And this is where the story of the single transfer becomes interesting for millions of people who use current accounts, banking apps and home banking every day.
Why authenticating a payment does not necessarily mean having authorized it.
If passwords and credentials were used, it doesn’t mean it’s your fault
This is probably the most important step to understand.
When a fraudulent transfer is made using the real account holder’s username, password, codes or other authentication tools, the bank’s first objection might appear almost obvious: the system has correctly recognized the credentials, so the order must have come from the customer or the customer must have handed them over to the fraudsters.
However, the regulation on payment services says something more complex.
Article 10 of Legislative Decree 11/2010 establishes that, when the user denies having authorized a transaction, it is up to the payment service provider to prove that it has been authenticated and correctly recorded and that it has not been affected by malfunctions. But above all he specifies that the simple use of the payment instrument registered by the bank is not in itself sufficient to demonstrate either that the customer authorized the operation or that he acted with fraud or gross negligence. Proof of fraud, willful misconduct or gross negligence on the part of the user is the responsibility of the payment service provider.
The Palermo ruling, therefore, does not invent a new rule, but applies it in a very concrete way to sophisticated computer fraud. And it is precisely this that makes it particularly relevant: it is not the customer who has to perfectly reconstruct the cyber attack to prove his innocence; if the bank wants to deny him the refund by invoking his gross negligence, it must provide elements capable of proving it.
What had become suspicious in the transfer
In the Sicilian case, the technical consultancy highlighted several important elements. The operation was linked to an unregistered IP address and, on the same day, the system had already blocked previous access attempts considered suspicious. The company would also have fallen victim to the malicious campaign called BRATAthrough a link apparently attributable to the bank that had induced the user to download a fraudulent application; from there the criminals would have managed to steal the credentials and arrange the transfer remotely.
And it is precisely this reconstruction that undermines the apparently simplest equation: correct credentials equal authorized operation.
According to what emerges from the ruling, a theft of credentials obtained through sophisticated techniques smishing and malware does not allow us to automatically conclude that the victim acted with grave negligence. Naturally, the evaluation of behavior in which it is demonstrated that the user has voluntarily communicated his credentials to third parties or has violated security obligations with serious negligence could be different.
When the bank must refund the unauthorized transfer
The Italian regulation is, at least on paper, rather strong in protecting the user. In the presence of an actually unauthorized payment transaction, Article 11 of Legislative Decree 11/2010 provides that the payment service provider refunds the amount immediately and in any case by the end of the following business day to the one in which he becomes aware of the transaction or receives the report, bringing the account back to the situation it would have been in if the payment had never occurred. The refund may be suspended in the presence of a justified suspicion of fraud on the part of the customer, a circumstance which must be communicated to the Bank of Italy.
The Bank of Italy has also expressly reminded intermediaries on this point. In a communication dedicated to denials of unauthorized operations, it reported the existence of practices that can lead to unfounded refusals or delayed refunds, recalling that the simple presence of thestrong authentication, the so-called SCAdoes not automatically allow the bank to conclude that the customer acted with intent or gross negligence. An effective evaluation of user behavior is needed.
In other words, receiving a code on your phone, using the app or seeing a technically correct authentication in the bank’s logs does not automatically close the refund discussion.
Gross negligence is the decisive point
This is where the real watershed lies.
If the bank can demonstrate that the customer acted fraudulently or breached his obligations with willful misconduct or gross negligencethe right to reimbursement may cease. But it must, in fact, be a demonstrated responsibility and not automatically derived from the simple fact that the fraudsters managed to take possession of the credentials.
It’s an especially important distinction today, because fraud has become much harder to recognize than the old poorly written email that asked you to type in your password and card number. Fake SMS apparently coming from the same sender as the bank, cloned sites, malware, phone calls constructed with spoofing techniques and procedures that imitate official ones can make it much more difficult to establish where the deception ends and where negligence so serious as to lead to the loss of the protections provided by law begins.
And precisely for this reason the evaluation must take place on a case-by-case basis.
Please note: Not all wire transfer scams are the same
However, there is a fundamental distinction to be made to avoid transforming the Palermo ruling into a promise of automatic reimbursement for any fraud.
One thing is unauthorized transferi.e. a transfer ordered by a criminal after having obtained the victim’s credentials. Another case is where the account holder, deceived by the fraudster, arrange the transfer personallyfor example, believing they are transferring the money to the secure account suggested by a fake bank operator.
The Bank of Italy reports precisely the so-called payer manipulation as the prevalent form of wire transfer fraud: the fraudster does not necessarily enter the account in place of the victim, but convinces the victim himself to make the payment. It is a different case, in which the question of authorizing the operation becomes much more complex.
For this reason, sentence no. 1929/2026 does not mean that every transfer made following a scam must be automatically returned by the bank. Instead, it means something very precise and important: when the operation is disavowed as unauthorized, the bank cannot simply show that the correct credentials were used and transfer the entire weight of the proof to the customer.
What to do when a bank transfer appears that you never arranged
The first rule is don’t wait. The legislation allows up to 13 months to request reimbursement for unauthorized transactions, but the Bank of Italy recommends communicating the incident as soon as it becomes known. It is therefore necessary to promptly deny the operation to your intermediary, block or secure any compromised instruments and keep all the documentation useful for reconstructing what happened.
If the bank rejects the request, the customer can file a formal complaint. In case of an unsatisfactory answer, you can then contact theFinancial Banking Arbitratorin addition of course to the possibility of appealing to the ordinary judge; for payment services the intermediary must normally respond to the complaint within 15 working days and the appeal to the ABF costs 20 euros, returned in the event of a favorable outcome.
It’s not a marginal problem. In 2025 the Financial Banking Arbitrator received more 13,500 appeals and those relating to fraudulent uses have now represented more than a third of the total. Overall, 56% of the decided proceedings ended with a result substantially favorable to the client, considering total or partial acceptances and agreements reached before the decision.
The stolen password is no longer enough to blame the customer
The Palermo sentence therefore tells something that goes beyond those 23,500 euros.
For years, the weak point of victims of bank fraud was precisely the one apparently most difficult to dispute: if the criminal had managed to gain entry using authentic credentials, it seemed almost inevitable to wonder what the account owner had done wrong.
The legal logic, however, is different. The bank is the professional operator, it manages the system through which the money passes and has the technical tools necessary to reconstruct authentications, IPs, anomalies, accesses and operation methods. If you want to attribute serious fault to the customer such as to exclude the refund, you must prove that fault.
And this is probably the most important message of the new ruling: in home banking in 2026, a correct password can prove that someone gained access to the account. It does not prove, by itself, that that someone was its owner.




