• en
  • zh
  • ru
  • es
  • What we do
  • Who we work for
  • Experience
  • Awards
  • Team
  • Expert advice
  • Guidelines
  • Contact
  • en
  • zh
  • ru
  • es

Expert advice

Credit Card Fraud and Carding in Poland: Consequences

19.09.2026

Credit card fraud in Poland is the unauthorised use, acquisition, copying or manipulation of payment card data in order to obtain money, goods, services or another financial benefit. In legal practice, the term may cover physical card theft, unauthorised online transactions, ATM withdrawals, phishing, card skimming and the use of stolen card details.

Carding is a narrower term used mainly in cybercrime cases. It generally refers to the illegal trade, testing or use of payment card data, often obtained through data breaches, phishing campaigns, malware, compromised online shops or card skimming devices. The physical card does not need to be stolen for criminal liability to arise.


How payment fraud and carding are prosecuted in Poland

Polish law does not contain one separate offence called “credit card fraud” or “carding”. Prosecutors classify conduct on the basis of the method used, the intent of the suspect, the scale of the activity and the financial consequences. Several provisions of the Criminal Code may apply cumulatively or alternatively, depending on the facts of the case.

The most common legal bases include:

  • Fraud under Article 286 § 1 of the Criminal Code – where a person misleads another person in order to obtain an unlawful financial benefit. The penalty is imprisonment from 6 months to 8 years.[1]
  • Computer fraud under Article 287 § 1 of the Criminal Code – where a person interferes with automated data processing, alters data or affects an IT system in order to gain an unlawful financial benefit or cause damage. The penalty is imprisonment from 3 months to 5 years.[1]
  • Theft of a payment card under Article 278 § 5 of the Criminal Code – provisions on theft also apply to taking a payment card or another instrument authorising cash withdrawals from an ATM.[1]
  • Unauthorised access to IT systems under Article 267 of the Criminal Code – relevant, for example, where card data is obtained by breaking into an account, mailbox or payment system.[1]
  • Possession or distribution of tools and access data under Article 269b of the Criminal Code – potentially relevant to skimming equipment, malware, passwords, codes or other data enabling unauthorised access to protected information systems.[1]
  • Counterfeiting a payment instrument under Article 310 of the Criminal Code – applicable where payment cards or other payment instruments are forged or altered. This is a serious offence, punishable by imprisonment from 5 to 25 years.[1]

A payment card is generally treated as a payment instrument under the Act on Payment Services. Its unauthorised use may therefore have criminal, civil, banking and compliance consequences at the same time.[2]


Card skimming and carding: why the method matters

Card skimming usually involves copying card data through a device attached to an ATM, payment terminal or other compromised infrastructure. Offenders may also use concealed cameras or fake keypad overlays to capture PIN codes. In more advanced cases, skimming is combined with malware, remote access tools or the use of compromised merchant systems.

Carding often has a more distributed structure. One group may obtain card details, another may verify whether the cards remain active, and another may make online purchases, cash withdrawals or transfers. Financial proceeds may then be transferred through accounts held by intermediaries, virtual assets, prepaid instruments or apparently legitimate businesses.

This structure creates substantial evidentiary issues. Investigators commonly examine IP addresses, device identifiers, login histories, transaction patterns, communication records, bank-account flows, shipment addresses and data recovered from electronic devices. In cross-border cases, evidence may need to be obtained from foreign payment institutions, online platforms and service providers.

Three qualifications requiring separate assessment

  1. Possession of card data is not always sufficient to prove a completed payment fraud. Prosecutors must establish the origin of the data, the purpose of possession and the person’s knowledge and intent. Attempt may nevertheless be punishable under Articles 13 and 14 of the Criminal Code if conduct directly aims at committing an offence.[1]
  2. An unauthorised transaction does not automatically identify the perpetrator. A disputed payment may result from phishing, malware, account takeover, merchant-side compromise or misuse by a person close to the cardholder. Technical evidence and transaction context are essential.
  3. Not every disputed card payment creates criminal liability for the cardholder. The customer’s liability towards a payment service provider is assessed under the Act on Payment Services and depends on the circumstances, including whether the customer acted intentionally or with gross negligence.[2]


Consequences for suspects in carding prosecution

Carding prosecution can lead to detention, seizure of bank accounts, searches of homes and business premises, seizure of electronic devices and restrictions on contact with specified persons. In cases involving organised groups, large transaction volumes or international activity, the investigation may be conducted by specialised police units and prosecutors.

A conviction can result in imprisonment, a fine, forfeiture of proceeds and devices used to commit the offence, and an obligation to repair damage. Where funds are transferred through multiple accounts or disguised as legitimate revenue, prosecutors may also investigate money laundering under Article 299 of the Criminal Code.[1]

For business owners and managers, allegations may affect access to banking, payment processors, public procurement procedures and commercial relationships. A pending criminal case can also trigger internal investigations, contractual disputes, employment issues and reporting obligations.


Business response to suspected payment fraud

A company that discovers suspicious card transactions should act quickly but proportionately. The first priority is to stop further losses and preserve evidence. Deleting logs, resetting systems without documentation or informally questioning employees may make later proceedings more difficult.

Recommended initial steps include:

  • block compromised cards, accounts, payment links and user sessions;
  • secure transaction logs, server records, access histories, correspondence and CCTV recordings;
  • notify the bank, payment institution or payment processor under the applicable procedure;
  • assess whether customer data or personal data may have been compromised;
  • conduct a documented internal review of access rights, vendor relationships and approval processes;
  • consider a criminal notification where there is a justified suspicion of an offence.

The response should also consider regulatory and contractual consequences. A business processing card payments may need to review its security controls, incident-response procedures and obligations towards customers and commercial partners. Broader fraud risks may require a forensic review and compliance measures, particularly where the incident indicates internal misconduct or weaknesses in financial controls. Related issues are discussed in KKZ materials on scams, cybercrime and anti-money laundering compliance.


Why early legal assessment matters

In payment fraud cases, the distinction between a victim, witness, employee with access to systems and suspected participant can change quickly. A careful assessment of the evidence, the role of each person and the applicable legal provisions is important before submitting explanations, internal reports or notifications to authorities.

Kopeć & Zaborowski (KKZ) supports businesses and individuals in criminal proceedings concerning economic crime, digital evidence, fraud risk and crisis management. The legal strategy should address both the criminal case and the operational consequences for the business.

This is informational material, not legal advice. Each case requires an assessment of its specific facts, available evidence and procedural stage.


Where a payment fraud or carding matter raises criminal-law concerns, it may be useful to consult the case with a lawyer and obtain an assessment of the situation. Early discussion can help identify possible procedural steps, evidence-preservation measures and business risks.


FAQ – Credit Card Fraud and Carding in Poland

Is carding illegal in Poland?

Yes. Carding may constitute computer fraud, fraud, unauthorised access to IT systems, possession of unlawful access data or other offences under the Criminal Code. The exact qualification depends on the conduct and evidence.

What is the penalty for credit card fraud in Poland?

It depends on the legal qualification. Fraud under Article 286 § 1 is punishable by 6 months to 8 years’ imprisonment, while computer fraud under Article 287 § 1 carries a penalty of 3 months to 5 years. Counterfeiting payment instruments may result in imprisonment from 5 to 25 years.[1]

Is card skimming prosecuted as a separate crime?

Card skimming is not a single separately named offence. It may be prosecuted under provisions concerning computer crime, unlawful access data, fraud, theft or counterfeiting payment instruments, depending on how the device and copied data were used.

Can an employee be liable for payment fraud committed through company systems?

Yes, if evidence shows intentional participation, unauthorised access, manipulation of transactions or assistance to perpetrators. Mere access to company systems is not sufficient to establish criminal liability.

What should a business do after discovering unauthorised card payments?

The business should block access, preserve relevant data, contact the payment provider, document the incident and assess whether a criminal notification, internal investigation or personal-data incident response is required.

Can a victim recover money lost through card fraud?

Recovery depends on the transaction circumstances, the payment-service-provider procedure, the speed of notification and the evidence available. Criminal proceedings may also include an order to repair damage, but this depends on the outcome of the case.


Bibliography

  • [1] Act of 6 June 1997 – Criminal Code, in particular Articles 13, 14, 267, 269b, 278 § 5, 286, 287, 299 and 310, ISAP: Dz.U. 1997 No. 88, item 553, as amended.
  • [2] Act of 19 August 2011 on Payment Services, ISAP: Dz.U. 2011 No. 199, item 1175, as amended.
  • [3] CERT Polska, Annual Report 2023, NASK National Research Institute.

Need help?

Maciej Zaborowski

Advocate, Managing Partner

contact@kkz.com.pl

+48 509 211 000

Expert advice

Surveillance and Wiretapping in Poland: Defense Strategies

Read more
Surveillance and Wiretapping in Poland: Defense Strategies

SIM Swapping and Phone Fraud in Poland: Criminal Threat

Read more
SIM Swapping and Phone Fraud in Poland: Criminal Threat

Digital Evidence in Polish Criminal Cases: Admissibility

Read more
Digital Evidence in Polish Criminal Cases: Admissibility
See all Expert advice

How can
we help you?

Contact
the experts
Maciej Zaborowski

Maciej Zaborowski

Advocate, Managing Partner

Paweł Gołębiewski

Paweł Gołębiewski

Attorney-at-law, Head of International Criminal Law Practice

Menu

  • What we do
  • Who we work for
  • Team
  • Experience
  • Awards
  • Expert advice
  • Glossary
  • Guidelines
  • RODO & terms of service
  • Contact
Kancelaria Kopeć Zaborowski Adwokaci i Radcowie Prawni

What we do

  • Expert’s Report on Conditions in the Polish Justice System (Expert Witness)
  • Driving under the influence in Poland
  • Asset recovery in Poland
  • Cybercrime in Poland
  • Extradition in Poland
  • Show more +
  • White-collar crime in Poland
  • Whistleblowers in Poland
  • Letter of safe conduct in Poland
  • Intellectual property protection in Poland
  • Insurance Fraud in Poland
  • European Arrest Warrant in Poland
  • Criminal defense in Poland
  • Red Notice in Poland
  • Interpol in Poland
  • Frauds in Poland
  • Investigative audits and internal investigations in Poland
  • Criminal compliance in Poland
  • Corporate crimes in Poland
  • Money Laundering in Poland
  • Scams in Poland
  • Corruption in Poland
  • VAT Refund Fraud in Poland
  • Organaized Crime in Poland
  • Insider trading and disclosure of inside information in Poland
  • Criminal liability of company officers in Poland
  • Capital Fraud in Poland

Our other services: + Kopeć & Zaborowski + Lawyers in Poland + Kontrola celno-skarbowa + Blokada Konta + ESG w Firmie + Kontrola PIP

Created by Tomczak | Stanisławski

© Copyrights to Kopeć & Zaborowski Law Firm