• en
  • zh
  • ru
  • es
  • What we do
  • Who we work for
  • Experience
  • Awards
  • Team
  • Expert advice
  • Guidelines
  • Contact
  • en
  • zh
  • ru
  • es

Expert advice

Banking Fraud in Poland: Unauthorized Transactions and Charges

27.07.2026

Banking fraud in Poland is conduct aimed at unlawfully obtaining money, access to a bank account, payment instrument, credentials or payment data, usually through deception, technical interference, identity abuse or manipulation of the victim or bank systems.

In practice, banking fraud includes phishing, fake bank websites, BLIK scams, SIM swap attacks, malware, business e-mail compromise, card fraud, unauthorized transfers and the use of “money mules” to move stolen funds. For companies, the issue is not limited to the lost amount. It may also involve interrupted payments, accounting exposure, AML alerts, liability of managers, employment consequences and reputational damage.

Polish law treats such cases on two parallel tracks. The first is the civil and regulatory relationship with the payment service provider, including the bank’s duty to assess whether a transaction was authorized. The second is criminal liability of the perpetrators, and sometimes of persons who assisted in receiving or transferring stolen funds.


Unauthorized transaction under Polish payment services law

An unauthorized transaction is a payment transaction executed without the payer’s consent. Under the Polish Payment Services Act, consent is a key condition for authorization of a payment transaction [1]. If there was no consent, the payer may request a refund and restoration of the account balance.

The Payment Services Act places the burden of proof on the payment service provider. The provider must prove that the transaction was authenticated, accurately recorded, entered in the accounts and not affected by a technical failure or other deficiency [1]. Importantly, authentication alone does not automatically prove that the payer authorized the transaction or acted fraudulently or with gross negligence.

As a rule, after notification of an unauthorized transaction, the provider should refund the amount no later than by the end of the business day following the day on which the provider noticed or was notified of the transaction. The law allows refusal of immediate refund where the provider has reasonable and duly documented grounds to suspect fraud and notifies the competent law enforcement authority in writing [1].


Three exceptions: when bank fraud charges may shift risk to the customer

In disputes concerning unauthorized transfers, banks often examine whether the customer’s conduct falls within statutory exceptions. The three exceptions should be separated from ordinary carelessness or the mere fact that criminals obtained access to credentials.

  • payer acted fraudulently
  • payer intentionally failed to fulfil one or more obligations
  • payer failed to fulfil obligations as a result of gross negligence

Outside these exceptions, the payer may still bear limited liability up to the equivalent of EUR 50 in certain cases involving a lost, stolen or misappropriated payment instrument before notification, subject to statutory exclusions [1].

These exceptions are fact-sensitive. They require analysis of how the credentials were obtained, what warnings were displayed, whether strong customer authentication was applied, how the customer reacted to alerts, whether the device was compromised, and how quickly the unauthorized transfer was reported.

The payer must also notify the provider without undue delay after becoming aware of the unauthorized transaction. The Payment Services Act sets a maximum notification period of 13 months from the debit date, unless the provider failed to provide or make available the required information on the transaction [1]. Delay may materially affect the legal position.


Bank fraud charges in Poland: criminal classification

Banking fraud may lead to several criminal charges under the Polish Criminal Code. The classification depends on the method used and the evidence collected. A phishing case may be assessed differently from a malware case, a fake invoice scheme or a transfer made by an employee using unlawfully obtained access.

  • Fraud – Article 286 of the Criminal Code applies where the perpetrator, in order to gain a financial benefit, causes another person to dispose of property unfavourably by deception, exploitation of error or inability to properly understand the action [2].
  • Computer fraud – Article 287 of the Criminal Code may apply to an unauthorized transfer crime involving unauthorized influence on automatic processing, collection or transmission of data, or alteration, deletion or introduction of a new record of computer data to gain a financial benefit or cause damage [2].
  • Unlawful access – Article 267 of the Criminal Code may apply where the perpetrator obtains access to information not intended for them, including by bypassing electronic security [2].
  • Damage to data or interference with IT systems – Articles 268a and 269a of the Criminal Code may be relevant where data or systems are altered, blocked, disrupted or destroyed [2].
  • Money laundering – Article 299 of the Criminal Code may apply where funds derived from crime are received, transferred or concealed, including through bank accounts used by money mules [2].

For suspects, the key issue is not only the statutory name of the offence, but also intent, role in the scheme, knowledge of the illegal origin of funds and the flow of money. For victims, the priority is preserving evidence and securing possible recovery.


What companies should do after an unauthorized transfer crime

Time is critical. The first hours after discovering an unauthorized transfer can determine whether funds are frozen before they leave the banking system. Internal chaos also increases the risk of contradictory statements, incomplete evidence and mistakes in communication with the bank or authorities.

A company should usually take the following steps:

  1. immediately notify the bank and request blocking, recall or freezing of the transfer, depending on the available banking procedure;
  2. secure logs, e-mails, payment approvals, screenshots, device data and internal correspondence;
  3. change credentials and isolate potentially compromised devices;
  4. verify whether the event triggers notification duties under data protection, AML, contractual or sectoral rules;
  5. file a criminal notification with evidence supporting the request for urgent action;
  6. conduct an internal review of approval paths, employee conduct and technical controls.

Where the fraud involved employees, suppliers or management approvals, an internal forensic audit may be necessary. It should distinguish facts from assumptions and identify whether the transaction resulted from external cybercrime, internal abuse, negligence, conflict of interest or a weakness in payment procedures.


Business exposure beyond the stolen funds

Unauthorized transactions may affect financial statements, insurance claims, supplier relations and board reporting. If the company is a regulated entity or an obliged institution under AML rules, the incident may also require assessment under the Act on Counteracting Money Laundering and Terrorist Financing [3].

Management should also consider whether internal procedures were adequate. Lack of dual approval, weak payment limits, poor vendor verification, untrained staff or failure to monitor legal and regulatory changes may increase the company’s exposure. In some cases, the incident may become part of a broader compliance review.

Kopeć & Zaborowski (KKZ) advises on criminal, compliance and litigation aspects of financial crime, including scams, cybercrime and AML-related risks. Related materials are available in the law firm’s sections on scams, cybercrime and Poland’s AML framework.


Evidence in disputes with banks and in criminal proceedings

Evidence should be collected in a way that is useful both in a complaint against the bank and in criminal proceedings. This includes banking confirmations, transaction identifiers, IP logs if available, SMS or push notifications, call recordings, e-mail headers, malware scan results and internal approval records.

In bank disputes, the central questions are authorization, authentication, customer conduct and the provider’s security obligations. In criminal proceedings, the focus shifts to identifying perpetrators, tracing funds and proving the elements of the offence. These tracks are connected, but they are not identical.

This is informational material, not legal advice. The correct assessment of bank fraud charges, civil liability and reporting obligations depends on the factual situation, documents and technical evidence.


Legal support in banking fraud cases


In matters involving unauthorized transfers, phishing, cybercrime or suspected financial fraud, it is often useful to obtain an early legal assessment before sending final statements to the bank or authorities. A criminal lawyer can help organize evidence, assess possible charges and discuss the next procedural steps. Contact details are available at https://criminallawpoland.com/contact/.


FAQ: Banking Fraud in Poland: Unauthorized Transactions and Charges

What is banking fraud in Poland?

Banking fraud in Poland is conduct aimed at unlawfully obtaining money, bank access, payment credentials or payment data. It may involve deception, cyber intrusion, identity abuse, manipulation of payment approvals or laundering of stolen funds.

Is every unauthorized transfer a crime?

Not automatically. An unauthorized transfer may result from crime, technical error, internal mistake or a disputed authorization. Criminal liability requires proof of statutory elements, such as deception, unlawful access, computer manipulation or intent to gain a financial benefit.

When must a bank refund an unauthorized transaction?

As a rule, the provider should refund the amount by the end of the next business day after noticing or being notified of the unauthorized transaction. This rule is subject to statutory conditions, including documented suspicion of fraud reported to law enforcement [1].

Can the bank refuse a refund if the customer clicked a phishing link?

Clicking a phishing link does not automatically prove gross negligence or fraud. The assessment depends on the whole factual situation, including warnings, authentication method, customer behaviour, speed of notification and the security measures applied by the bank.

What criminal charges may apply to an unauthorized transfer crime?

Depending on the method, charges may include fraud under Article 286, computer fraud under Article 287, unlawful access under Article 267, interference with data or systems under Articles 268a or 269a, and money laundering under Article 299 of the Polish Criminal Code [2].

What should a company do first after detecting bank fraud?

The company should immediately notify the bank, request urgent blocking or recall of the transfer, secure evidence, isolate compromised devices and consider filing a criminal notification. Internal communication should be controlled and based on verified facts.


Bibliography

  1. Act of 19 August 2011 on Payment Services, in particular Articles 40, 42, 44, 45 and 46.
  2. Act of 6 June 1997 – Criminal Code, in particular Articles 267, 268a, 269a, 286, 287 and 299.
  3. Act of 1 March 2018 on Counteracting Money Laundering and Terrorist Financing.
  4. Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market (PSD2).
  5. Polish Financial Supervision Authority (KNF), public warnings and communications concerning cyber threats and financial market security.

Need help?

Maciej Zaborowski

Advocate, Managing Partner

contact@kkz.com.pl

+48 509 211 000

Expert advice

Insurance Fraud in Poland: Criminal Consequences Explained

Read more
Insurance Fraud in Poland: Criminal Consequences Explained

Interpol Wanted List: How to Check If You Are Wanted and What It Means in Poland

Read more
Interpol Wanted List: How to Check If You Are Wanted and What It Means in Poland

Organized Crime Prosecutions in Poland: RICO-Style Proceedings

Read more
Organized Crime Prosecutions in Poland: RICO-Style Proceedings
See all Expert advice

How can
we help you?

Contact
the experts
Maciej Zaborowski

Maciej Zaborowski

Advocate, Managing Partner

Paweł Gołębiewski

Paweł Gołębiewski

Attorney-at-law, Head of International Criminal Law Practice

Menu

  • What we do
  • Who we work for
  • Team
  • Experience
  • Awards
  • Expert advice
  • Glossary
  • Guidelines
  • RODO & terms of service
  • Contact
Kancelaria Kopeć Zaborowski Adwokaci i Radcowie Prawni

What we do

  • Expert’s Report on Conditions in the Polish Justice System (Expert Witness)
  • Driving under the influence in Poland
  • Asset recovery in Poland
  • Cybercrime in Poland
  • Extradition in Poland
  • Show more +
  • White-collar crime in Poland
  • Whistleblowers in Poland
  • Letter of safe conduct in Poland
  • Intellectual property protection in Poland
  • Insurance Fraud in Poland
  • European Arrest Warrant in Poland
  • Criminal defense in Poland
  • Red Notice in Poland
  • Interpol in Poland
  • Frauds in Poland
  • Investigative audits and internal investigations in Poland
  • Criminal compliance in Poland
  • Corporate crimes in Poland
  • Money Laundering in Poland
  • Scams in Poland
  • Corruption in Poland
  • VAT Refund Fraud in Poland
  • Organaized Crime in Poland
  • Insider trading and disclosure of inside information in Poland
  • Criminal liability of company officers in Poland
  • Capital Fraud in Poland

Our other services: + Kopeć & Zaborowski + Lawyers in Poland + Kontrola celno-skarbowa + Blokada Konta + ESG w Firmie + Kontrola PIP

Created by Tomczak | Stanisławski

© Copyrights to Kopeć & Zaborowski Law Firm