Logo ECIJA

    Man-in-the-middle fraud and the limits of banks' liability

    Instant transfers will bring new security requirements for financial institutions in the face of the rise of sophisticated frauds such as Man-in-the-Middle.

    In an increasingly digitalised environment, banking scams have evolved significantly in terms of complexity and sophistication. One of the scams that has gained prominence in recent years is the so-called "Man-in-the-Middle" attack.

    This type of fraud involves the unauthorised interception of communications between two devices connected to a network, allowing the attacker to alter and divert messages exchanged between users.

    One of the most frequent scenarios involves the interception of a communication requesting a payment, whereby the fraudster modifies the IBAN of the bank account to which the transfer is to be made in order to get the money. The process generally unfolds as follows:

    • A company receives an e-mail from a supplier, requesting payment of an invoice for the provision of services.
    • Unbeknownst to the company, an attacker intercepts and manipulates the email, changing the IBAN number of the account to which the payment is to be made.
    • The cybercriminal impersonates the provider, sending the message from an email address almost identical to the original, but with a slight alteration that is almost unnoticeable.
    • The receiving company, trusting the authenticity of the message, makes the transfer to the fraudulent account.

    In this way, a computer alteration is carried out with the aim of achieving a financial transfer to the detriment of the originator of the transfer, as provided for in Article 249.1 (a) of the Criminal Code.

    When the originator notices the error, its first reaction is to try to contact the receiving bank in the hope that the funds can be blocked in time. However, in most cases, the cybercriminal has been quicker: the money has already been transferred to another account or withdrawn, leaving little room for manoeuvre, so the only alternative is to file a complaint.

    However, identifying the perpetrator is not a simple task. Cybercriminals operate complex mechanisms to hide their identity and make it difficult to trace the money, making the possibility of recovering the money directly from the offender increasingly remote.

    Faced with this situation, many people affected are looking for another way forward: claiming the subsidiary civil liability of the bank that executed the transfer. But can the bank be held liable for processing the transaction?

    The answer to this question is to be found in Article 59 of the Payment Services Act, which regulates the liability of banks in situations where incorrect identifiers have been used. According to this regulation, when a payment order is executed in accordance with the unique identifier (IBAN) it is considered to be validly processed with respect to the payee associated with that identifier. Moreover, the third paragraph of this Article states that, if the payer provides additional information to the IBAN, such as the name of the payee, the bank is not obliged to check its correspondence.

    This criterion has been endorsed by different Courts in the civil sphere, as stated, for example, in the Judgment of the Provincial Court of Zaragoza no. 87/2019 of 25 March 2019, which confirms that the bank's responsibility is limited to executing the order in accordance with the unique identifier, without having to consider other additional data.

    In the same vein, the 2018 Complaints Report of the Market Conduct and Complaints Department of the Banco de España reinforces this interpretation, recalling that transfers are automatically processed according to the IBAN indicated, without banks carrying out additional checks. In other words, any other information included in the payment order, such as the concept of the transfer, is merely informative for the beneficiary and does not represent a binding instruction for the institution.

    Therefore, the rules seem clear: if there is an error in the unique identifier (IBAN) when ordering a transfer, the receiving bank should not be liable. Its only obligation should be to credit the funds to the indicated account, without carrying out additional checks on the ownership of the recipient account.

    However, the scenario becomes more complicated for banks with the entry into force of Regulation (EU) 2024/886 of the European Parliament and of the Council of 13 March 2024 on immediate credit transfers in euro. In the specific case of immediate credit transfers, banks will be obliged to implement a system of verification of the beneficiary before executing the transaction. This new requirement sets a higher standard of diligence for financial institutions and will imply a significant change in the way in which responsibilities are distributed in cases of fraud or error.

    This new regulatory framework responds to the need to reinforce security in a context where instant payments have become increasingly common with the aim of providing greater user protection against unintentional errors and fraud. Thus, as of 9 October 2025, payment service providers will be legally obliged to check that the name of the beneficiary matches the IBAN provided and to alert the payer in case of discrepancies.

    Notwithstanding the above, taking into account that the new provisions are still in the implementation period and will not be mandatory for banks until October 2025, it is essential that, during this transition period, both banks and users take the utmost precautions. On the one hand, financial institutions must continue to improve their systems for detecting suspicious transactions and reinforce security mechanisms to prevent fraud. On the other hand, users should be especially careful when making transfers, verifying the authenticity of the recipients and paying attention to warning signs that could indicate a possible scam, such as urgent requests for payment, unexpected changes in bank account details or e-mails attempting to impersonate identities.

    Article written by Marta Coro, Economic Criminal Law and Compliance lawyer at ECIJA Madrid.

    LATEST FROM #ECIJA

    Articles
    29 June 2026
    Laura Fernández proposes freezing properties with clandestine airstrips; experts see both advantages and limitations

    A bill that would allow for the registration of properties where clandestine or unauthorised airstrips are in operation – used for illicit activities such as drug trafficking and money laundering – to be frozen.

    Read more
    Articles
    23 June 2026
    Public corruption and criminal liability: reflections on the judgment 418/2026 of the Supreme Court

    Judgment 418/2026 of the Criminal Division of the Supreme Court has consolidated as a historic resolution in exhaustively analyzing various criminal offenses linked to corruption in the exercise of public functions.

    Read more
    News
    19 June 2026
    Christian Molina, a partner at ECIJA in the Dominican Republic, featured in an interview with IFLR

    Christian Molina has been featured in a recent interview published by IFLR, in which he discusses his career and his views on the development of trust law in the Dominican Republic.

    Read more
    Reports
    8 June 2026
    Update of the SEPBLAC digital certificate and report on the penalties imposed in 2025

    The renewal of the SEPBLAC digital certificate requires all entities subject to these regulations to review and update their digital certificates before 30 June 2026, in order to have the latest version of the online procedure and to submit the relevant notifications to this body.

    Read more
    Articles
    26 May 2026
    Artificial intelligence and criminal liability of legal entities

    The rise of artificial intelligence is reshaping the landscape of criminal risks for companies and putting pressure on traditional compliance models.

    Read more
    Reports
    20 May 2026
    DPD and RSII: are they compatible?

    The implementation of the Internal Information System has raised practical questions in many organizations regarding the allocation of internal responsibilities and, in particular, how this fits with the role of the Data Protection Officer.

    Read more
    Articles
    15 May 2026
    The limits of access to personal data in the digital age

    Rosario Alonso, analyses the debate currently facing the US Supreme Court regarding the limits of access to personal data and how this discussion also connects with the current challenges in Chile.

    Read more
    Articles
    13 May 2026
    ECIJA Barcelona joins Barcelona Health Hub to promote legal innovation in digital health

    ECIJA Barcelona is positioned as a strategic ally of the digital health ecosystem thanks to its transversal approach that connects law, technology and business.

    Read more
    Articles
    12 May 2026
    Uruguay to implement digital wallet as part of Digital Strategy

    The Uruguayan government presented an electronic wallet that will bring together documents and transactions on a single platform, with the aim of streamlining processes and enhancing security.

    Read more