Phishing judgements in Germany: Banks liable, chat fraud mostly uninsured
Recent court rulings show: banks must pay for direct banking attacks, but those who disclose data in chats often receive nothing.

Phishing in court: Who pays – and who does not
Victims of phishing attacks may be able to recover their money from their bank – but the outcome depends heavily on the individual case. Recent rulings demonstrate this, as reported by boerse-express.com.
Chat fraud: Vinted user's lawsuit fails
The District Court Bernau dismissed the lawsuit of a Vinted user (ref. 10 C 212/25). The woman had disclosed her IBAN and credit card data in a chat and subsequently approved a payment in her banking app – losing nearly 2,000 euros in the process.
The court made clear: IBAN and credit card data do not constitute confidential access credentials under insurance terms and conditions. The loss did not result from unauthorised access, but from the claimant's own deliberate authorisation of the payment.
The German Bar Association (DAV) additionally points out that phishing clauses in contents insurance policies are often formulated very restrictively – some cover exclusively fraud cases initiated via emails.
Banks liable for direct attacks
The situation is different when customers become victims without their own involvement. The Koblenz Higher Regional Court ordered a credit institution to reimburse 56,099.91 euros plus lawyer's fees (ref. 8 U 682/24). In summer 2022, unauthorised instant transfers were made from the claimant's account.
The bank could not demonstrate gross negligence on the customer's part. An expert report supported his statement that an activation code did not necessarily have to be displayed on his device.
In April 2026, the Berlin Regional Court II (ref. 38 O 293/25) decided similarly: apoBank must reimburse over 218,000 euros after customers fell victim to a phishing attack.
The Federal Court of Justice had already clarified in 2025 (ref. XI ZR 107/24): gross negligence always requires a case-by-case examination. The Frankfurt Higher Regional Court also enabled damages claims in autumn 2025 directly against the holders of money-laundering accounts.
Economic damage in the billions
The economic dimension of the phishing and cyber fraud problem is substantial. According to a Bitkom study from 2025, 87 per cent of German companies were affected by theft, espionage or sabotage. Total damage amounted to 289.2 billion euros.
Extortion demands increased by 47 per cent in 2025, with 86 per cent of affected companies refusing to pay ransom. Average damage fell by 19 per cent to approximately 116,000 US dollars. Particularly prevalent: Business Email Compromise (BEC) and fraudulent payment instructions accounted for 58 per cent of incidents.
Data breaches and AI gaps worsen the situation
At the end of May 2026, AOK Niedersachsen mistakenly sent letters to fewer than 0.21 per cent of its members with the incorrect statement that the electronic health record (ePA) would be deleted. The cause was an error during a system adjustment. As early as February 2026, AOK Bayern had temporarily closed several thousand records.
At Meta, an AI support chatbot caused a stir in spring 2026: a security gap enabled the takeover of Instagram accounts. Attackers deceived the AI and had verification codes redirected to new email addresses. The gap has since been closed.
Source: Google News AT — Crime (de)