When is a phishing victim considered grossly negligent and held personally liable for their loss?

A phishing victim is only fully liable for his or her losses if the bank proves that the victim was grossly negligent, and not merely careless. In a ruling dated June 29, 2026, the Court of Cassation ruled for the first time on the interpretation of that concept in Article VII.44 Code of Economic Law (CEL). It overturned a ruling that had ordered a smishing victim to pay 24,852.15 euros, and clarified two points: what constitutes gross negligence, and that a judge may not base that determination on intermediate steps that have not been proven.

The facts

On January 23, 2020, a KBC customer received a text message about an alleged outstanding tax debt of 89 euros, along with a payment link. The message was fake (smishing). After clicking on the link, the victim did not pay the 89 euros, but—without realizing it—consented to the installation and activation of KBC Mobile on a new device belonging to the fraudster. From that device, the fraudster stole a total of 24,852.15 euros.

In 2025, the Brussels Court of Appeal ruled that the victim had been grossly negligent and was therefore liable for the loss. It based this ruling on a series of findings: that the payer had logged in to unsecured web pages without using the usual login method via Itsme or e-ID, that he must have validated the context message “Subscription request OK?” on his card reader, and that he had ignored automatic warning text messages regarding the recent installation. The victim filed a petition for cassation against that ruling.

The decision

The Court first rejects the bank’s argument that the ground for cassation is inadmissible. The interpretation of the concept of gross negligence under Article VII.44, § 1, paragraph 4 of the CEL is a legal question, not merely a question of fact. The Court may therefore examine whether the appeal court correctly applied the statutory standard to the established facts.

The Court then defines that standard itself. Relying on recital 72 of the preamble to PSD2 , gross negligence entails more than ordinary negligence and implies conduct involving a significant degree of carelessness. Gross negligence is a qualified breach of the duty of care: it exists when the payer does or fails to do something that a reasonably and normally careful payer would never do or fail to do. The Court also confirms that the mere registration of the use of the payment instrument with a code known only to the user does not constitute sufficient grounds for presuming negligence (Art. VII.44, § 4, third paragraph, CEL).

As applied to this case: the bank bears the burden of proof regarding gross negligence (Article VII.44, § 4 CEL). Although the victim stated that he had not conducted any verification whatsoever and had blindly trusted the message, there was no conclusive evidence for the intermediate steps on which the Court of Appeal based its finding of gross negligence: exactly which web pages the payer viewed, whether the context message was actually displayed and validated, or whether the warning text messages were received. Based on these findings, the court of appeal could not legally conclude that the victim had failed to fulfill one of his obligations under Article VII.38 of the CEL due to gross negligence. The Court of Cassation overturns theruling and remands the case to the Court of Appeal in Antwerp.

Legal analysis and interpretation

The Court of Cassation takes a hard line on the theory, but does not rule on the case itself

The significance of this ruling lies in its confirmation that the classification of gross negligence is subject to review in cassation. This allows for intervention when the trial court confuses carelessness with gross negligence. Now that the Court has ruled that the interpretation is a legal question, an overly hasty equating of “he could have seen it” with “he was grossly negligent” can be challenged.

At the same time, the implications for legal practice are more limited than the media suggests. The Court formulates an abstract standard and applies it to the reasoning behind a single contested decision. What the ruling does make clear is that the standard exists and that the Brussels Court of Appeal had insufficiently substantiated its decision in this case. The Court of Cassation does not explicitly state why there was no gross negligence. This restraint is consistent with the role of the Court of Cassation, but it also means that the next Court of Appeal (in Antwerp) must still weigh the facts itself and could very well conclude that gross negligence did occur if it provides a better justification for its decision.

The real issue is one of evidence, not substance

The substantive standard (“conduct that a normally prudent payer would never engage in”) does not represent a break with the past. Case law has applied this threshold for years, using phrases such as “an inexcusable negligence that is virtually equivalent to intent.” What the Court adds lies elsewhere: a judge may not infer gross negligence from a chain of steps that have not been proven. If the bank bases its claim on logging in on unsecured pages, validating a message on the card reader, and ignoring warnings, it must prove each link in the chain separately. If evidence for a link is missing, it cannot simply be assumed to be the victim’s fault.

This is consistent with general rules of evidence: the bank must prove its allegation in concrete terms and with a reasonable degree of certainty (Art. 8.5 Civil Code), and in case of doubt, she comes up short (Art. 8.4 of the Civil Code). The Dutch-speaking Business Court in Brussels considered that in March and May 2025: It remains unclear how the banking app ended up on the fraudster’s device, but that alone is not enough to reverse the burden of proof. The Court of Cassation is now taking that line of reasoning to the highest level.

Note the relationship to the European two-step logic

This ruling concerns the second phase of the liability system: who ultimately bears the loss. It should not be confused with the first phase, which is the bank’s immediate obligation to reimburse (Art. VII.43 CEL). Advocate General Rantos emphasized in his opinion of March 5, 2026, in the case C-70/25 (Tukowiecka) that PSD2 strictly separates these two steps: Article 73 requires the bank to refund the amount first, and only a presumption of fraud—not of gross negligence—allows the bank to refuse that refund. Only in the second step (Article 74) may the bank attempt to recover the refunded amount by demonstrating gross negligence. The Court of Cassation ruling of June 29, 2026, pertains entirely to that second step.

Specifically, what does this mean?

For victims of phishing. The ruling strengthens your negotiating and litigation position. Insist that the bank substantiate every factual element of its allegation, and challenge any arguments that infer gross negligence from the mere observation that the fraud was technically possible only with the customer’s cooperation. First, argue that the fraud could not have been detected in advance (Art. VII.44, § 1, second paragraph, 1°) and that there was no valid strong client authentication; address the gross negligence only as a last resort. Disputed or unproven warning text messages do not count.

For banks and payment service providers. An allegation of gross negligence based on assumptions about what the customer “must” have seen or validated does not hold up. Anyone seeking to establish the customer’s full liability must document and prove specific actions: the context message that was actually displayed and validated, the warning that was demonstrably delivered and ignored, and the actual transmission of an activation code. A voluminous but largely non-case-specific collection of documents is insufficient.

Frequently asked questions (FAQ)

Is my bank required to reimburse me for the money stolen in a phishing scam?
In principle, yes. In the case of an unauthorized payment transaction, the bank is liable for the loss, subject to a deductible of up to 50 euros, unless it can prove fraud or gross negligence on your part. Furthermore, there is an immediate obligation to refund the amount, which is separate from any subsequent discussion of liability.

What is the difference between ordinary carelessness and gross negligence?
Ordinary negligence is failing to act as a reasonably prudent person would. Gross negligence requires more: conduct involving a significant degree of carelessness that a reasonably careful payer would never engage in. Only in cases of gross negligence (or fraud) will you be liable for the entire loss yourself.

Who has to prove that I was grossly negligent?
The bank. It bears the burden of proof and must demonstrate every factual element of its allegation. The mere fact that you used codes or that the fraud technically required your cooperation is not sufficient evidence.

Conclusion

The Court of Cassation confirms that gross negligence is a high, verifiable threshold and that a judge may not base that determination on unproven intermediate steps. The substantive standard is not new, but the strict evidentiary requirements imposed by the Court give phishing victims a stronger weapon.


Joris Deene

Attorney-partner at Everest Attorneys

Contact

Questions? Need advice?
Contact Attorney Joris Deene.

Phone: 09/280.20.68
E-mail: joris.deene@everest-law.be

Topics