Online Fraud: Defence of the Accused & Recovering Your Money

Online fraud: two words, two entirely different nightmares — and in either case this page is for those who need legal representation and a defence against criminal prosecution. Whether the Cyber Crime Division (Greece’s cybercrime police unit) treats you as a suspect because fraud money passed through your account, or your own account was emptied within minutes by phishing — and you are asking “how do I get my money back?”.

We are a fighting criminal-law firm. As an online-fraud lawyer in Athens — a criminal-law specialist and qualified computer engineer — I read the technical evidence in every case myself: transaction logs, OTP timings, connection traces, the paths taken by the transfers. That is where both battles are won — the acquittal of the accused and the gross negligence of the bank, as in judgment 3764/2026 of the Athens Single-Member Court of First Instance, which our firm secured against a systemic bank.

🚨 How can we help you today?

I Am Accused / a Suspect

For those facing charges of phishing, ransomware, computer fraud or involvement as a “money mule” (a money courier). Legal representation and a defence against criminal prosecution.

See the Defence & Penalties ↓

I Fell Victim to Fraud (e-Banking)

For those who lost money from their account and want to pursue a court claim and compensation from the bank for its negligence.

See How to Get Your Money Back ↓

Part 1 — Accused of online fraud? Legal representation, penalties under Article 386Α of the Greek Criminal Code (GCC) and your defence

The Cyber Crime Division has knocked on your door. Your accounts have been frozen. You received a summons because money from a fraud victim was paid into your account — and you “were just helping out a friend” or “an employer you found online”. Responding to the prosecution starts at once: the case file will involve tracing through your IP address (IP tracking), a lifting of communications confidentiality and often seizure of your devices — and the defence is already won or lost at the preliminary inquiry.

“I lent my account or my card to a friend and now I’m charged with a felony. Where do I stand?”

The law does not see you as a “naïve friend” — it treats you as a direct accomplice or even a principal in the fraud (a money mule), often with an added charge of money laundering. The excuse “I didn’t know” does not on its own clear you. Our defence strategy is precise: we prove the absence of criminal intent and that you yourself were deceived by the real perpetrators — using the technical data in the case file (chats, timings, access traces) — so that the charge is downgraded or collapses.

When is online fraud a misdemeanour and when a felony? (Penalty table — Article 386Α GCC)

ScenarioLegal classificationPenalty faced
Basic form of computer fraud (Article 386Α in conjunction with 386 para. 1 GCC)MisdemeanourImprisonment of up to 5 years and a fine; if the loss is particularly large, imprisonment of at least 3 months
Committed on a professional basis with a total gain or total loss over 30.000 €FelonyIncarceration of up to 10 years and a fine
Loss over 120.000 €FelonyIncarceration of up to 10 years and a fine
Penalties for online fraud (computer fraud, Article 386Α GCC)

Be warned: with “lent” accounts, the fraud prosecution is often joined by money laundering — which turns a “favour for a friend” into a felony file. The sooner the defence is organised, the greater the room to manoeuvre: a defence memorandum, a technical rebuttal of the digital exhibits, an application to lift the asset freezes.

Part 2 — Why is the bank to blame when your money was stolen?

VICTIM OF ONLINE FRAUD? The bank is liable — reclaim your money 1 Immediate dispute and recall Block passwords and cards — recall the transfers 2 Complaint to the Cyber Crime Division Criminal track: tracing and freezing accounts 3 Formal notice to the bank Establishing negligence: logs, OTP, recordings 4 Damages claim — Law 4537/2018 (PSD2) The burden of proof lies with the bank Athens Court 3764/2026 139.865 € returned to victims + interest + costs • 21 transfers in 94 minutes • 8 accounts — 3 banks • GROSS NEGLIGENCE by the bank • Victim’s liability: only 50 € No phone alert at all — a single phone call would have prevented everything poiniko-cyber.gr — ZIAMPARAS D. & ASSOCIATES, Law Firm

Law 4537/2018, which transposed Directive (EU) 2015/2366 (PSD2), sets the rule: for unauthorised payment transactions the customer is liable up to a ceiling of 50 euros (Article 74) — unless the bank proves intent or gross negligence. Under Law 5019/2023, even where the consumer is grossly negligent their liability is capped at 1.000 euros, unless the bank proves that it applies additional, sophisticated control mechanisms (artificial intelligence, an extra code, biometrics or telephone confirmation) for transactions above 1.000 euros.

At the same time, Article 8 of Law 2251/1994 establishes a quasi-strict liability of the bank with a reversal of the burden of proof: you do not have to prove its negligence — it must prove that it met its duties of care and security in commercial dealings (fraud detection, strong customer authentication (SCA), timely notification, immediate recall). And the “force majeure defence” (Article 92 of Law 4537/2018) is rejected where the loss could have been avoided — where a simple phone call would have sufficed.

The “modern” victims: Revolut, digital wallets and cryptocurrencies

The classic SMS-phishing scam is now well known — but the perpetrators have moved on. The provider’s liability and your right to compensation apply just as much to the new forms:

  • Scams through Revolut, N26 and other digital banks: many people think that “because it’s a foreign/online bank, nothing can be done”. Wrong — as licensed payment institutions in the EU they are bound by the same European framework (PSD2), with the same obligations of strong authentication and liability for unauthorised transactions.
  • Apple Pay / Google Pay scams (wallet tokens): here the perpetrators do not steal your e-banking passwords — they “trap” you into approving the addition (tokenisation) of your card to their own digital wallet. If the bank activated the token without strong authentication, the liability rests with it.
  • Cryptocurrency scams (crypto scams): victims persuaded to “invest” in fake platforms. Here a lawyer is needed to trace the flow towards the exchanges and to seek the freezing of the receiving accounts before the funds vanish.

“Gross negligence”: the bank’s weapon — and how we demolish it in court

Strong authentication is a two-stage process. If you disclosed the credentials of only one stage (username and password), or an OTP that did not relate to a money transfer, your negligence is as a rule judged slight — so your liability stops at 50 euros and the bank owes the rest.

In court, the allegation is demolished using the bank’s own data: transaction timings showing record-breaking back-to-back transfers with no alert whatsoever, logs showing e-banking activated from an unknown device, the absence of any telephone confirmation despite an obviously suspicious pattern. So the “customer’s gross negligence” boomerangs back: gross negligence of the bank — exactly as held in judgment 3764/2026.

Judgment 3764/2026 of the Athens Court of First Instance: a systemic bank held liable for gross negligence

Telephone phishing by a bogus “employer” of a relative, over a 150-euro allowance. The perpetrator extracted card details and the PIN, personally activated e-banking that the victims had never held, and within 94 minutes carried out 21 transfers totalling 147.340 euros to 8 accounts across 3 banks — without a single confirmation call.

“The defendant […] displayed gross negligence as regards the security it provided for its electronic-transaction services, thereby undermining the trust of its customers […], since it had not adopted complete and improved measures aimed at more fully protecting its customers from malicious attacks and online fraud.”

— Athens Court of First Instance, judgment 3764/2026

The outcome: the victim’s contributory fault was just 50 euros — the bank was ordered to pay 139.865,30 euros with interest, plus 3.600 euros in legal costs.

Download judgment 3764/2026 (PDF, anonymised) Download judgment 6950/2025 (PDF, anonymised)

The judgment is genuine and published; the case was handled by our firm. It is published in anonymised form to protect the parties — without the parties’ names or company names. Every case is decided on its own facts — this outcome is not a guarantee of results in future cases.

What to do RIGHT NOW if your account has been emptied

  1. Block everything — immediately. The bank’s 24/7 line: lock e-banking, cancel cards and immediately request a recall of the transfers.
  2. File a complaint with the Cyber Crime Division. This triggers the tracing and freezing of the “mule” accounts before the sums disappear.
  3. Do not accept any “liability” over the phone. Calls with the bank are recorded and will be used against you.
  4. Gather evidence. Account statements, SMS/Viber messages, call times, staff names — request everything in writing.
  5. Formal notice and lawsuit. A written dispute, a formal extrajudicial notice documenting the negligence and, if it refuses, a damages claim.

Panic & first moves — the first 5 questions every victim asks

1. “My bank account was emptied a short while ago. What do I do now?”

Every minute counts. Call your bank’s customer service straight away (there is a 24/7 fraud line) to lock your e-banking and your cards. Immediately request a recall of the transfers, if you are in time before they are executed. Then come to our office so we can file a complaint with the Cyber Crime Division and begin the process of disputing the transactions.

2. “I made the transfer myself, because I was tricked. Can I get my money back?”

If you made the transfer yourself (for example, to a fraudster posing as your accountant or as a buyer on Car.gr), the bank will throw up its hands, because the instruction was yours. Your only hope is to have the fraudster’s account frozen (usually a “mule” — a money mule) before he can withdraw the cash from an ATM or send it abroad. We need an immediate prosecutor’s order to freeze the receiving account.

3. “How did they get my passwords? Was I hacked?”

In 95% of cases you were not hacked; you were lured into handing them over yourself (phishing). They sent you an SMS or Viber message (appearing to come from the postal service (ELTA), the tax office, or the bank itself) claiming your account had been locked, you clicked the link, landed on an identical fake page and typed in your username, password and the SMS confirmation code.

4. “Will the police find the fraudster and get my money back for me?”

The Cyber Crime Division will find out whose name the account that received the money is in, but that person is almost never the real mastermind. They are usually vulnerable individuals or foreign nationals paid a few euros to open an account. Even if they are caught, they have no assets to compensate you. The only route to getting your money back is to turn against the bank.

5. “How much does it cost to pursue the fraudster through the courts?”

A criminal complaint against persons unknown or against the holder of the receiving account has costs (court fees, lawyer’s fees) and will take 2-3 years to reach trial. If the fraudster is “penniless”, you will have spent yet more money with nothing to show for it. That is why our strategy focuses on the bank’s civil liability, where the chances of actually recovering the money are 100% if we win.

The bank’s liability & negligence — the 5 questions behind a claim

6. “I gave my passwords to a fake link (phishing). The bank tells me it’s my fault. Do I have the right to claim my money?”

Yes, you do. The bank will try to pin sole responsibility on you to escape paying compensation. But under the payment-services law (PSD2), the bank bears strict liability. Even if you made a mistake and were taken in by the phishing, the bank is required to have systems that recognise fraud. If we prove that the bank failed to observe the security measures, it is obliged to refund your money.

7. “15.000 euros left my account in 5 minutes through back-to-back transfers and the bank never called me. Is that negligence?”

It is clear-cut negligence on the bank’s part. Banks are required to have systems for detecting unusual transactions (fraud detection systems). When an account that used to make transfers of 50 euros suddenly sends thousands of euros to unknown accounts (often abroad) in the middle of the night, the system should have flagged it “red” and automatically blocked the transaction until telephone confirmation was obtained. That failure establishes the bank’s liability.

8. “What is the ‘gross negligence’ the bank blames me for so it doesn’t have to pay?”

Gross negligence means you showed utter indifference to your own security (for example, you had the PIN written on the card, or you gave your passwords to someone while the SMS clearly read “WARNING: FRAUD”). The bank uses “gross negligence” as its stock excuse to reject every compensation claim. In court, however, the burden of proof lies with the bank. The courts now accept that phishing is so sophisticated that the average person can be misled without this amounting to gross negligence.

9. “The fraudsters changed the notification phone number (OTP) or bypassed the approval through the bank’s app. Who is at fault?”

The fault lies solely with the bank’s security gap. If the bank’s system allowed the fraudsters to link your e-banking to a new device of their own (device registration), or to change the mobile number that receives the SMS confirmations, without any additional, strong safeguard, then the bank failed to apply Strong Customer Authentication (SCA). In that case, the bank is 100% exposed.

10. “How can I force the bank to return the stolen money to me?”

Wishful thinking and complaints at the branch get you nowhere. The procedure is specific:

  1. Filing a formal written dispute of the transactions with the bank.
  2. If the bank refuses (which is most likely), we move straight to a damages claim before the civil courts.

Case law has shifted in favour of consumers, and the courts now increasingly compel banks to return the money, with interest.

poiniko-cyber.gr is the specialist digital criminal-law platform of the law firm Ziamparas D. & Associates (ziamparas.gr).

Related articles on cybercrime

Whether you are accused of online fraud or have fallen victim to it, time and proper documentation decide the outcome — the case must be built correctly from the very first moment, with the criminal and the civil track moving in parallel.
Read more about the cybercrime lawyer →

ELEN