The Register Home Page

back to article EU legal eagle says banks should refund cybercrime victims first, argue later

One of the European Union's top legal advisors is trying to change how banks treat cybercrime victims – meaning they could enjoy greater financial protections sooner than expected. In a recently published legal opinion, Advocate General Athanasios Rantos urged lawmakers to alter their interpretation of the Second Payment …

  1. Guy de Loimbard Silver badge
    Meh

    Good intention perhaps

    But the devil will be in the detail for any legal implementation.

    It's a very strange area, we are dealing with multiple challenges and issues, not least the one being we've got scammers aplenty who are giving this the broadside approach and then clinging to any mark that seems to be drawn into the scam.

    It's an ever moving set of rules and goalposts.

    Whilst banks are very much loaded with cash, is it always the banks fault that a scammer has worked on their system to steal funds from a poor unsuspecting victim?

    As soon as you put a control in place to deal with something, then the miscreant n'er do well, will work out a method to get around it.

    Much like electricity and water, the thief will take the path of least resistance.

    1. Phil O'Sophical Silver badge

      Re: Good intention perhaps

      It's rarely the bank's fault, and people always seem to forget that high street banks get their money from their customers. The more the banks are forced to reimburse gullible customers who have been conned by scammers, the more the bank charges for all customers will go up.

      If someone follows a link they have been sent to a phishing site, instead of typing in the bank address as they have been repeatedly told to do, they must share the responsibility. The fact that the site pretends to be their bank isn't the bank's fault, nor the fault of the bank's more attentive customers, so why should they have to pay?

      1. Sorry that handle is already taken. Silver badge

        Re: Good intention perhaps

        A recent case in Australia

        It goes well beyond merely having accidentally been phished out of your access credentials. Scammers then have to engage in a lot of activity that would normally look very suspicious before they can exfiltrate the funds. That's where financial institutions should be doing a better job.

        Also, if legislation is introduced to increase the liability of the bank, that's a very strong incentive for them to improve their security (and customer education), which should reduce the frequency of successful scams in the long run.

    2. Cav

      Re: Good intention perhaps

      "is it always the banks fault that a scammer has worked on their system to steal funds from a poor unsuspecting victim"

      No, it isn't the bank's fault at all and said scammers don't "work on" the bank's system. If a scammer sets up something that looks like the bank's site then the bank has no responsibility at all. If a customer clicks a link and enters credentials, without checking, then it's their fault and I don't see why the bank should pay compensation at all.

      There is no control to work around. Anyone could set up a fake bank site now on a server anywhere in the world. If some idiot enters their actual bank credentials into it then there is nothing the bank can do to prevent it.

      1. Sorry that handle is already taken. Silver badge

        Re: Good intention perhaps

        The scammer still has to log into your bank account, change contact details, change MFA details, send money to accounts that have never been sent to before etc. etc. All things the bank could, and arguably should, be looking out for. There should be an expectation of a minimum duty of care. It's what that level is that's the question here. And it isn't zero.

        But anyway I hope you tell all of that to your friends, or family members, or yourself, if it happens to them one day...

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon