/** Translation for 'read more' button in blog**/

Liability for Phishing and Disclosure of TANs in Online Banking: German Federal Court of Justice Draws Clear Limits on Reimbursement Claims in Cases of Gross Negligence

14. August 2026

Liability for Phishing and Disclosure of TANs in Online Banking: German Federal Court of Justice Draws Clear Limits on Reimbursement Claims in Cases of Gross Negligence

Read out the article

In another landmark ruling, the German Federal Court of Justice (Bundesgerichtshof – BGH) addressed the question of whether a payment service provider is required to reimburse an unauthorised payment transaction under Section 675u of the German Civil Code (Bürgerliches Gesetzbuch – BGB) where the account holder disclosed several transaction authentication numbers (TANs) to third parties over the telephone as part of a phishing attack. The practical implications of the ruling are significant for bank customers and should therefore be taken seriously. Attorney Sascha C. Fürstenow explains the reasons behind the decision in this article.

 

What is the case about?

The claimant is a customer of a German savings bank (Sparkasse). Since 2014, she has held a joint current account with the defendant savings bank and has used its online banking services.

To access online banking, the claimant required a personal login name and a PIN. Payment orders were authorised using the chipTAN procedure with a TAN generator. Until then, she had exclusively used the optical chipTAN procedure, involving a flickering graphic displayed on the computer screen.

In July 2022, she unsuccessfully attempted several times to change her login credentials because the TAN generator repeatedly aborted the process. During these attempts, a pop-up appeared asking her to re-enter her login details and install new “security software”. According to the claimant, she closed the pop-up.

Shortly afterwards, she received a telephone call from a person claiming to be an employee of the bank. Caller ID spoofing was used so that a false bank telephone number appeared on the claimant’s display. The caller was able to provide personal account information and instructed the claimant to enter numbers into her TAN generator and disclose a TAN over the telephone, supposedly for the purpose of installing a new security program.

In reality, the purpose of these steps was to increase the transfer limit and prepare a bank transfer. The claimant was unaware of this because she had no experience with the manual chipTAN procedure.

The following day – a Sunday – the process was repeated. Ultimately, an instant bank transfer of EUR 35,555 was made to an unknown account.

 

Halle Regional Court, judgment of 4 January 2024

The bank customer subsequently brought an action against her savings bank, seeking reimbursement of the amount transferred. She relied on Section 675u BGB, which governs the liability of payment service providers for unauthorised payment transactions.

The Halle Regional Court largely upheld her claim for reimbursement. According to the court, the claimant could not be accused of gross negligence. It accepted the savings bank’s counterclaim for damages under Section 675v BGB only in the amount of EUR 50.

 

Naumburg Higher Regional Court, judgment of 22 May 2024: Customer acted with gross negligence

Following an appeal by the savings bank, the Naumburg Higher Regional Court dismissed the claim in its entirety. It held that the claimant’s reimbursement claim under Section 675u BGB was offset by a claim for damages of the same amount in favour of the defendant savings bank under Section 675v BGB.

The Higher Regional Court found that the customer’s conduct amounted to gross negligence. In its view, she should have been more suspicious and should have questioned the fact that, immediately after the earlier incident – and for the first time after several years of using online banking – she was contacted by a supposed employee of the bank and asked to identify herself in connection with a new security program, particularly as the call took place on a Sunday.

In addition, given her many years of experience with online banking, she should have been able to see from the information displayed on the TAN generator that she was confirming a recipient IBAN and a payment instruction.

 

Federal Court of Justice confirms gross negligence

The BGH confirmed that the transfer was in fact an unauthorised payment transaction. Under Section 675u BGB, the savings bank would therefore generally have been required to reimburse the transferred amount without undue delay.

However, this does not apply where the bank itself has a claim for damages in the same amount under Section 675v BGB because the customer caused the loss by intentionally or grossly negligently breaching one or more obligations under Section 675l BGB or contractual conditions governing the issuance and use of a payment instrument, such as a TAN.

The BGH held that disclosing several TANs during two separate telephone calls – particularly where one of those calls took place on a Sunday – constituted a grossly negligent breach of the customer’s obligations under Section 675l BGB.

The customer’s conduct could also not be regarded as a mere “momentary lapse” (“Augenblicksversagen”). A momentary lapse refers to a situation in which a person fails, for a brief period, to exercise the level of care required in the circumstances.

According to the BGH, this was not a short-lived error of judgment. The TANs were disclosed over a period of two days, meaning that the customer had an entire day in which to reconsider and reflect on the circumstances.

The BGH also based its finding of gross negligence on the fact that the customer had been familiar with the chipTAN procedure for several years. In addition, warnings about fraudulent telephone calls were regularly displayed on the bank’s website and within its online banking service, while phishing attacks involving online banking had also been widely reported in the media in recent years.

 

Did the savings bank fail to use strong customer authentication?

Under Section 675v BGB, the bank’s claim for damages may be excluded if the payment service provider failed to require strong customer authentication.

The BGH therefore also considered whether the bank’s claim for damages should be excluded because the savings bank required strong customer authentication for the execution of the bank transfer, but not for logging into online banking. This lack of authentication at the login stage had enabled the fraudster to obtain access to the customer’s information.

Both the Higher Regional Court and the BGH considered this circumstance to have contributed to the loss. However, they held that it was not decisive in this particular case because the customer’s degree of fault outweighed the shortcomings in the bank’s system security.

Accordingly, the requirement for strong customer authentication relates to the specific payment transaction rather than to the entire sequence of events within online banking.

Nevertheless, Attorney Fürstenow points out that, depending on the circumstances of an individual case, a failure to require strong customer authentication for the online banking login may constitute contributory negligence on the part of the bank under Section 254 BGB. This may result in a reduction of the bank’s claim for damages under Section 675v BGB.

 

What does the ruling mean for bank customers?

Importantly, disclosing a TAN does not automatically amount to gross negligence in every case. The BGH emphasised that the circumstances of each individual case must be examined.

The key question may be whether the customer merely suffered a “momentary lapse” – for example because of time pressure or a particularly manipulative situation, which may in some circumstances be excusable – or whether the conduct went beyond what can reasonably be excused. This may be the case where the fraudulent process extends over a longer period and gives the customer an opportunity to reconsider and reflect on what is happening, explains Attorney Fürstenow.

For bank customers, the following precautions are particularly important:

  • Never disclose a TAN over the telephone – even to someone claiming to be a “bank employee”.
  • Banks will not call customers to ask them to disclose a TAN.
  • Do not install unfamiliar software at the request of an unexpected caller.
  • If in doubt, end the call and contact the bank yourself using its official telephone number.
  • Record the date and time of any suspicious call and make a note of any TANs that were disclosed.

As a general rule, customers continue to have a right to reimbursement under Section 675u BGB in the event of unauthorised payment transactions. Whether the customer acted with gross negligence, however, always depends on the specific circumstances of the individual case.

Bank customers affected by phishing should therefore not hesitate to seek legal advice so that the particular circumstances of their case can be assessed individually.

 

 

Attorney Sascha C Fürstenow will be happy to advise you on this topic and offers a free and non-binding initial assessment of your case in advance.

The legal advice in German was prepared by Ms. Dastan, an employee of the FÜRSTENOW law firm, and reviewed and finalized by attorney Fürstenow.