Everything here is general guidance, not professional advice. We research carefully and can still be wrong or out of date, so treat it as suggestions to check rather than instructions to follow, and accept that you act on it at your own risk. Full terms.

PlaybooksScammed or fraudulent bank charge
Moneycritical20 minutes to prepare

Scammed or fraudulent bank charge

Money left your account that you did not authorise, or you were talked into sending it and have just realised.

01DetectConfirm the signal
02ContainStop more damage
03RecoverRestore control
04VerifyProve it works

Your preparation

0 of 0 safeguards ready
0%

What this means

There are two different situations here, and banks treat them very differently.

Unauthorised means someone used your card or account without you. A cloned card, a stolen number, a payment you never made. In most countries you are strongly protected, the bank usually refunds it, and the main thing you have to do is report it quickly.

Authorised means you made the payment yourself, because someone convinced you to. A fake bank call, a romance scam, an invoice that was not really from your builder. Legally this is much harder, because from the bank’s side you approved it. Protections have improved in some countries and are weak in others, and speed matters far more.

Either way the first hour is worth more than everything you do afterwards. Money moves through accounts fast and gets harder to trace at every step. If a transfer is very recent, the bank can sometimes stop it in flight.

One more thing, because it affects what happens next. If you were scammed, the shame is the scam’s most effective tool. It is what stops people calling the bank while there is still time. These operations are professional and they fool careful people every day. Make the call.

Warning signs

  • A payment on your statement you cannot place, even a small one. Testing with a small amount is standard before a large one.
  • Your card is declined unexpectedly, which can mean it is being used elsewhere.
  • A call, message, or email pressing you to move money urgently, especially to a “safe account”.
  • A supplier’s bank details change at the last moment, arriving by email.
  • Someone you only know online eventually asks for money, however gradually.
  • Notifications for a new payee you did not add.

Recover now

First 15 minutes

  1. Call your bank now, on the number on the back of your card. Do not use a number from the message or the caller. Most banks have a 24 hour fraud line, and this is the call that matters.
  2. Say clearly whether you authorised the payment. It changes how they handle it. If you were tricked into approving it, say so plainly rather than describing it as fraud on your account.
  3. Ask them to freeze the card or account and attempt a recall on any transfer. A recent transfer can sometimes be stopped or clawed back from the receiving bank.
  4. Do not contact whoever took the money. Warning them means the money moves on immediately.
  5. Write down the timeline while it is fresh. Times, amounts, account numbers, names used, what was said. You will be asked, and details fade fast.

Today

  1. Report it officially and keep the reference number. Where you report, and what the bank owes you, depends on your country.

Reporting fraud and getting money back

Almost everywhere: tell your bank immediately and in writing, ask for the transaction to be recalled, and check the deadline for disputing it. That deadline is usually short and starts from the transaction, not from when you noticed.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Austria yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Belgium yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Bulgaria yet, so only the rules that apply bloc-wide are shown above.

Your money comes back through the bank, not the police. Notifying the issuer without delay is what caps your liability, and federally regulated institutions must fully investigate any transaction you dispute.

  1. Tell your bank or card issuer immediately, then change passwords and PINs.
  2. Write down what happened, how you noticed, and who you spoke to and when.
  3. Report to the Canadian Anti-Fraud Centre at reportcyberandfraud.canada.ca or 1-888-495-8501, and to your local police, who are the ones who actually investigate.
  4. Ask Equifax and TransUnion to place a fraud alert and send you your report.
  5. Keep watching your statements, and use the institution's complaint process if the outcome is poor. Every federally regulated institution must have one.

Bring

  • Card and account numbers, and the dates, amounts, and merchants of the disputed transactions
  • Your written timeline and the names of the representatives you spoke to
  • Your card or account agreement, which is where your actual reporting deadline lives

Cost

  • Statutory maximum liability for unauthorised use of a bank credit card is $50, unless you were grossly negligent
  • Deposit accounts: usually 30 days from the statement date to dispute, though it varies by institution
  • Visa, Mastercard, Amex, and Interac all have zero-liability commitments on top of that

Easy to get wrong. Reporting to the Anti-Fraud Centre feels like the official decisive act, and it is not the one that gets your money back. It is an intelligence repository that supports law enforcement; only notifying your issuer stops the liability clock. People also lose otherwise valid claims through their own conduct rather than the fraudster's, since using your birthday as a PIN, sharing it with family, writing it near the card, or not cooperating with the investigation are all listed grounds for holding you liable. And note that zero-liability is a voluntary card-network promise rather than law, separate from the $50 statutory cap.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Croatia yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Cyprus yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Czechia yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Denmark yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Estonia yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Finland yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

In France

Block the card (faire opposition) and keep the registration number you are given, then dispute with the bank. France adds Perceval, a reporting channel that only fits one specific situation.

  1. Faire opposition at once, through your bank or the interbank server 0 892 705 705, open 24/7. You are given a numéro d'enregistrement, which is your dated proof. Opposition is irreversible even if the card turns up.
  2. Use Perceval only if you still physically hold the card and the details were used online. If the card itself was taken, Perceval is the wrong door and you need a plainte.
  3. Claim the refund from the bank, including any overdraft charges (agios) the fraud caused.
  4. If refused, escalate to the médiateur bancaire, then the courts.

Bring

  • Your opposition registration number and card number
  • Statements showing the fraudulent transactions
  • A FranceConnect account for Perceval

Cost

  • Perceval is free; the cost of opposition itself varies by bank
  • Deductible capped at €50 for a lost or stolen card, and not applicable at all where the card was copied or used without its security data

Easy to get wrong. Perceval is only for people still holding their card. If it was physically stolen you need a theft report instead, and filing on Perceval wastes the trip. Visitors hit a harder wall: Perceval works only through FranceConnect, which needs a French tax, health, or La Poste digital identity, so a foreigner generally cannot use it and must go to a commissariat. Note too that the deadline runs from the debit date, and drops from 13 months to 70 days where the payment was made outside the EEA.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Germany yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Greece yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Hungary yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Iceland yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Ireland yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Italy yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Latvia yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Liechtenstein yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Lithuania yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Luxembourg yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Malta yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Netherlands yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Norway yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Poland yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Portugal yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Romania yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Slovakia yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Slovenia yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Spain yet, so only the rules that apply bloc-wide are shown above.

Everywhere in the EU and EEA

PSD2 gives you the same rights in every EEA country. The headline one surprises most people: your bank has to put the money back first and investigate afterwards, not the other way round.

  1. Report it the moment you notice, through any channel the bank offers, and write down the date, time, and reference number. That timestamp is what drops your liability to zero.
  2. Ask for a refund under Article 73(1) by name, and say you expect it by the end of the next business day. Do not accept being told the refund follows the investigation.
  3. If you are told that a correct PIN or password proves you authorised it, push back. Article 72 puts the burden of proof on the bank, and says use of the instrument is not in itself enough to prove you authorised the payment or were grossly negligent.
  4. Ask whether strong customer authentication was applied. If it was not, Article 74(2) removes your liability entirely unless you acted fraudulently.
  5. If they refuse, get the refusal in writing and take it to your national regulator or ombudsman.
  • Refund: by the end of the following business day after you report it (Article 73(1)). A bank may hold back only if it suspects fraud and has said so in writing to the national authority.
  • Your maximum loss: €50 (Article 74(1)), and zero once you have reported the card or credentials lost or stolen (Article 74(3)). Some countries set a lower figure.
  • Outer limit to claim: 13 months from the debit date (Article 71(1)). This is a longstop, not a grace period.

Easy to get wrong. Accepting "we will refund you once our investigation is complete" reverses the law. The refund comes first, by the end of the next business day, and the investigation happens after. The only lawful exception is suspected fraud that the bank has reported in writing to the national authority — an internal review does not count. Separately, if the account is a business rather than a consumer one, Article 61(1) lets the bank contract out of nearly all of this, so check the terms.

We have not checked the local mechanics for Sweden yet, so only the rules that apply bloc-wide are shown above.

Two legally different situations. If you did not consent to the payment, the bank must refund you by the end of the next business day. If you were tricked into sending it yourself, that is APP fraud, and since October 2024 reimbursement is mandatory rather than discretionary.

  1. Contact your bank first, before the police. The bank is the body that owes you money.
  2. Work out which regime applies. Unauthorised, meaning you did not consent, falls under regulation 76 of the Payment Services Regulations 2017. If you were deceived into making a UK transfer over Faster Payments or CHAPS, that is APP fraud.
  3. Report to the police, or give the bank consent to do it for you, which the reimbursement rules list as a claimant obligation.
  4. Answer the bank's information requests promptly, after checking the request is genuine. Firms can pause the clock while gathering information but must reach an outcome within 35 business days.
  5. If refused, escalate free to the Financial Ombudsman Service.

Bring

  • Transaction dates and amounts, and all correspondence with the scammer
  • Your police or Report Fraud reference
  • The bank's final response letter and its date, which starts the Ombudsman clock

Cost

  • APP fraud: reimbursement within 5 business days, capped at £85,000, with an optional excess of up to £100 that cannot be applied to vulnerable consumers
  • Unauthorised transactions: your maximum liability is £35 under regulation 77, and nil once you have notified the bank or where the bank failed to apply strong customer authentication
  • The Financial Ombudsman is free to consumers

Easy to get wrong. Filing with Report Fraud feels decisive and recovers nothing. It gathers intelligence, the police do not investigate every report, and the regulator cannot look at individual cases either. Only your bank can reimburse you and only the Ombudsman can overrule your bank. Two deadlines quietly kill claims: the right to redress for an unauthorised transaction expires 13 months after the debit date, which is how an unnoticed small recurring charge becomes unrecoverable, and the six-month window to escalate runs from the date on the bank's final response letter. Note also that APP protection covers UK bank transfers only, not card, cash, or cheque payments.

Debit and credit are governed by two different federal regimes with different caps and different clocks. On a debit card your liability escalates purely with how fast you report. On a credit card it is capped low, but the dispute has to be in writing.

  1. Tell the bank immediately, by phone or app. Notice counts once you have taken reasonable steps to convey it, even through a different number than the one specified.
  2. For a debit card, report within two business days of learning it is gone to cap your liability at $50.
  3. For a credit card, follow up in writing. A phone call protects your liability cap but does not preserve the dispute right.
  4. If the bank asks you to confirm an oral debit-card notice in writing, send it within 10 business days or you lose the right to provisional credit.
  5. Report to ReportFraud.ftc.gov, file a CFPB complaint, and add IC3 if the fraud was internet-enabled.

Bring

  • Account number and statements showing the disputed charges
  • The date you noticed the card was gone and the date you reported it
  • Notes of your calls and copies of correspondence

Cost

  • Debit: $50 if reported within 2 business days, $500 within 60 days of the statement, unlimited after that
  • Credit: $50 maximum for unauthorised use under Regulation Z
  • No filing fee for FTC, CFPB, or IC3 reports

Easy to get wrong. Two clocks catch people out. The debit-card two-day clock starts when you learn the card is gone, not when a fraudulent charge posts and not when you spot it on a statement, so a card stolen Monday and missed Wednesday must be reported by Friday even if nothing has been charged. And on the credit side, the billing error notice must be written and received within 60 days of the statement — people who call, are told it is handled, and never write are the ones who lose. An issuer may not deny an unauthorised-use claim just because you declined to file a police report.

  1. Change the passwords on your online banking and the email address attached to it, especially if any part of this involved a link you clicked.
  2. Check for other payments you missed. Fraud rarely stops at one transaction, and small ones are easy to overlook.
  3. Check whether any new payee, standing order, or direct debit was set up on the account.
  4. If you gave away identity details rather than just money, consider a credit freeze so nobody can open accounts in your name.
  5. Ask the bank for their decision in writing, along with the timescale they are working to.

Verify recovery

  • The compromised card is cancelled and a replacement is on the way.
  • Every payee, standing order, and direct debit on the account is one you recognise.
  • The bank has given you a case reference and a date for their decision.
  • Your banking password and email password are both changed, and neither is used anywhere else.
  • Your statements for the last few months contain nothing else unexplained.

Prepare now

Making fraud harder

  • Transaction alerts are on for every payment, so you see money leave in real time.
  • Online banking has two-factor authentication that is not just SMS.
  • The email address attached to your bank has its own two-factor authentication.
  • Daily transfer limits are set to something you actually need, rather than the maximum.
  • Any card you rarely use is frozen in the app until you need it.

Making a scam harder to fall for

  • You know your bank will never ask you to move money to a “safe account”. No bank does this, ever.
  • You have a habit of hanging up and calling back on the number from your card, for any unexpected call about money.
  • Anyone in the household who might be targeted knows the same, particularly older relatives.
  • New bank details from a supplier get confirmed by phone, on a number you already had.

Making recovery easier

  • You know your bank’s fraud number, or it is saved in your phone.
  • Statements are checked at least monthly, so a small test charge gets noticed.
  • You know which national fraud service you would report to.

Common mistakes

  • Waiting until morning. Fraud lines run all night for a reason. Overnight is when the money moves.
  • Being vague about whether you approved it. The bank needs to know which process applies, and getting this wrong slows the claim.
  • Contacting the scammer to ask for the money back. It confirms you have noticed, and the money leaves immediately.
  • Calling the number in the message. In a bank impersonation scam, that number is part of the scam. Use the card.
  • Not reporting it because the amount was small. Small charges are tests, and reporting builds the case that stops the next one.
  • Staying quiet out of embarrassment. Delay is the only thing that reliably makes this unrecoverable.

Sources

Last reviewed July 27, 2026Guidance changes. Confirm provider-specific actions in the linked official sources.