Banking Law And Critical Financial Infrastructure Offenses Spain .
1. Constitutional and regulatory framework
Spain protects the financial system through a combination of criminal sanctions and administrative supervision.
Important institutions include:
- Banco de España — banking supervision and prudential functions;
- CNMV — securities and investment-market supervision;
- SEPBLAC — prevention and enforcement framework for money laundering/terrorist financing;
- Ministry of the Interior / CNPIC — protection of critical infrastructures;
- Spanish courts and Fiscalía — criminal enforcement.
The financial system is expressly recognised as a strategic sector for critical-infrastructure purposes. The consolidated Ley 8/2011 on Protection of Critical Infrastructures includes the financial and tax system among Spain's strategic sectors.
The important distinction is:
A violation of banking regulations is not automatically a criminal offence.
Many banking-law breaches are administrative offences. Criminal liability arises where the conduct satisfies the elements of a specific offence in the Código Penal.
2. Principal legislation
A. Spanish Criminal Code — Código Penal
The principal criminal statute is Organic Law 10/1995 (Ley Orgánica 10/1995). It contains the offences most relevant to banking, including:
- fraud (estafa);
- computer fraud;
- misappropriation (apropiación indebida);
- disloyal administration (administración desleal);
- falsification of documents;
- money laundering;
- corruption;
- market manipulation;
- insider dealing;
- damage to computer systems;
- interruption of computer systems;
- offences involving confidential information.
The current Criminal Code specifically criminalises serious attacks against computer data and systems.
B. Ley 10/2010 — Anti-Money Laundering
The Ley 10/2010, de 28 de abril, de prevención del blanqueo de capitales y de la financiación del terrorismo is fundamental to banking law.
Its objective is expressly to protect the integrity of the financial system by imposing preventive obligations against money laundering and terrorist financing.
Banks and credit institutions are expressly classified as obliged entities (sujetos obligados). Payment institutions and electronic-money institutions are also covered.
The obligations include, among other things:
- customer identification;
- beneficial-owner identification;
- due diligence;
- monitoring of transactions;
- reporting suspicious transactions;
- internal control;
- record keeping;
- enhanced due diligence in high-risk situations.
The important point is that Ley 10/2010 primarily establishes preventive/administrative obligations, while the actual criminal offence of money laundering is principally found in the Criminal Code.
3. Banking fraud — Estafa
One of the most important banking-related offences is estafa, generally translated as fraud or fraudulent deception.
The classic structure is:
deception → error → disposition of property → economic loss → unlawful benefit.
Banking examples include:
- obtaining a loan through fraudulent documentation;
- fraudulent transfers;
- manipulating banking instructions;
- using another person's credentials;
- fraudulent online banking transactions;
- false representations to obtain credit;
- fraudulent use of payment instruments.
Where computers or automated systems are used, the conduct may fall under computer fraud (estafa informática) rather than ordinary interpersonal deception.
4. Computer fraud and payment-card fraud
Spanish Supreme Court jurisprudence has treated manipulation of electronic/payment systems as capable of constituting computer fraud.
The Supreme Court's jurisprudential materials discuss cases involving fraudulent use of payment cards and POS/ATM systems, including STS 692/2006, 26 June, and STS 1476/2004, 21 February. The Court explained that unauthorised manipulation or use of an electronic system can satisfy the statutory concept of manipulation or a similar device for computer fraud.
This is particularly important for modern banking because the victim does not necessarily have to be deceived in the traditional sense.
Example
Suppose A obtains B's card information and uses it through a payment terminal to cause funds to be transferred without B's consent.
The legal analysis can focus on:
unauthorised manipulation of the information-processing/payment mechanism
rather than requiring the traditional model of a victim personally believing a false statement.
5. Misappropriation — Apropiación indebida
Another important banking offence is apropiación indebida.
It generally concerns property or money that was lawfully received but is subsequently appropriated or dealt with unlawfully.
Banking examples may involve:
- an employee entrusted with company funds;
- a financial intermediary holding client assets;
- a person entrusted with money who converts it for personal use;
- misuse of funds held on behalf of another person.
The distinction from fraud is important:
Fraud
The unlawful acquisition is produced through deception.
Misappropriation
The defendant may initially have obtained lawful possession or control, but later unlawfully appropriates the property.
6. Disloyal administration — Administración desleal
This offence is particularly important for bank directors, managers and senior officers.
It addresses abuse of entrusted management powers causing patrimonial damage.
A classic scenario is:
A director has authority to manage the bank's assets but deliberately uses that authority contrary to the interests of the bank for personal or connected-party benefit.
Possible examples include:
- preferential loans to related companies;
- transactions with companies controlled by directors;
- deliberately disadvantageous asset transfers;
- diversion of corporate opportunities;
- manipulation of related-party transactions;
- use of bank resources for personal interests.
7. Important Supreme Court case: Eurobank
A particularly relevant Spanish banking case is the Eurobank case.
In 2018, the Spanish Supreme Court increased the defendants' sentences after finding both continued disloyal administration and misappropriation. The conduct involved the creation of a group of companies and transactions involving a banking entity, abuse of functions and appropriation of the bank's money, ultimately contributing to its dissolution and causing losses to shareholders.
The Supreme Court's reasoning is particularly useful because it illustrates that the same factual circumstances can involve different forms of patrimonial criminality.
The Court distinguished between:
- abuse of managerial powers/defective administration, and
- actual appropriation of money.
It therefore accepted the coexistence of administración desleal and apropiación indebida in the circumstances of the case.
Why Eurobank matters
It demonstrates that criminal liability of banking executives does not depend merely on whether a transaction was commercially unsuccessful.
The prosecution must establish the specific criminal elements, including the abuse/appropriation and the resulting patrimonial harm.
8. Falsification of banking documents
Banking activity relies heavily on documentary evidence.
Consequently, the following can generate criminal liability when the statutory requirements are satisfied:
- falsified loan applications;
- falsified financial statements;
- forged signatures;
- manipulated corporate documents;
- false accounting documentation;
- falsified electronic documents;
- fraudulent documentation used to obtain financing.
Falsification can also operate together with other crimes.
For example:
false document → fraudulent loan application → financial loss
could potentially involve:
falsification + fraud
depending on the facts and the applicable provisions.
9. Money laundering — Blanqueo de capitales
Money laundering is particularly important in banking law because banks are frequently used as channels through which illicit proceeds are transferred or concealed.
The preventive legislation defines money laundering broadly, including conversion or transfer of assets known to derive from criminal activity and concealment of their illicit origin.
Typical banking laundering structure
Predicate offence
↓
illegal proceeds
↓
deposit/transfer through financial institution
↓
conversion or concealment
↓
integration into apparently legitimate assets
The bank may therefore become:
- the instrument through which laundering occurs;
- an obliged entity with preventive duties;
- a victim of fraud;
- or, in appropriate circumstances, a potential participant whose employees/officers may incur liability.
10. Banks' AML obligations
Under Ley 10/2010, credit institutions are obliged entities.
This means that the bank must have systems for:
- identifying customers;
- identifying beneficial owners;
- understanding the purpose and nature of relationships;
- monitoring transactions;
- detecting suspicious activity;
- reporting appropriate cases;
- maintaining internal AML controls.
The legislation also applies to a much broader group of financial-sector entities, including investment firms, payment institutions and electronic-money institutions.
Criminal versus administrative liability
This distinction is essential for an examination:
Failure to comply with an AML control requirement ≠ automatically money laundering.
A regulatory breach can produce an administrative sanction.
Criminal money laundering requires satisfaction of the elements of the Criminal Code offence.
11. Attacks against banking computer systems
This is where Spanish banking law intersects with critical-infrastructure criminal law.
The Criminal Code contains specific offences concerning destruction, alteration, deletion or making inaccessible computer data.
Under Article 264, unauthorised and serious damage, deterioration, alteration, deletion or inaccessibility of another person's computer data can constitute an offence punishable by imprisonment. More serious circumstances increase the penalty.
Particularly important is Article 264.2.
The aggravated circumstances include conduct:
- committed by a criminal organisation;
- causing particularly serious damage;
- affecting a large number of systems;
- seriously affecting essential public services;
- affecting a computer system belonging to critical infrastructure; or
- creating serious danger to the security of Spain, the EU or an EU Member State.
This is directly relevant to banking infrastructure.
12. Article 264 bis — interruption of computer systems
Article 264 bis criminalises unauthorised and serious obstruction or interruption of another person's computer system.
It covers, among other things:
- introducing/transmitting data;
- destroying or damaging a system;
- making a system unusable;
- deleting or replacing systems or electronic storage.
The basic penalty is imprisonment of six months to three years, with enhanced consequences where the conduct seriously affects business or public administration.
Where circumstances equivalent to those in Article 264.2 occur, the penalty can rise to three to eight years' imprisonment plus a fine linked to the damage.
13. Why a bank cyberattack can become a critical-infrastructure offence
This is one of the most important points.
Imagine a cyberattack against a bank's:
- core banking system;
- payment-processing infrastructure;
- ATM network;
- clearing infrastructure;
- electronic-payment platform.
If the attack merely compromises an individual account, ordinary offences such as fraud may be appropriate.
But if the attack:
seriously compromises the operation of a system forming part of critical infrastructure
the Criminal Code provides aggravated treatment.
Article 264 expressly refers to computer systems of critical infrastructure.
Therefore:
ordinary cybercrime
can become
aggravated critical-infrastructure cybercrime
when the statutory requirements are satisfied.
14. What is “critical infrastructure” in Spain?
The principal statute is Ley 8/2011, de 28 de abril, por la que se establecen medidas para la protección de las infraestructuras críticas.
Its purpose is to coordinate the protection of critical infrastructure and protect essential services from deliberate attacks, including cyberattacks.
The law creates the Sistema de Protección de Infraestructuras Críticas and provides for:
- identification of critical infrastructures;
- identification of critical operators;
- security planning;
- specific protection plans;
- security officers;
- inspections;
- coordination with government authorities.
The financial and tax system is expressly included among the strategic sectors.
15. Critical operator obligations
An operator designated as critical has enhanced security responsibilities.
Among other obligations, the law provides for:
- a Plan de Protección Específico for each critical infrastructure;
- designation of a Responsable de Seguridad y Enlace;
- designation of a security delegate for relevant infrastructures;
- cooperation with inspections;
- implementation of required security measures.
This is primarily a protective/regulatory regime, not a separate general criminal offence called "critical infrastructure offence."
That distinction is important.
16. Cybersecurity of essential financial services
Spain also has the Real Decreto-ley 12/2018, de seguridad de las redes y sistemas de información.
It establishes rules concerning:
- security of networks and information systems;
- essential services;
- incident notification;
- supervision;
- cybersecurity measures.
The financial system was specifically included within the strategic sectors covered by the regime for essential services.
Operators of essential services must adopt appropriate security measures and notify incidents having significant disruptive effects.
The legislation also provides administrative sanctions for serious and very serious non-compliance.
Thus there are two different legal consequences:
Cyberattack by an offender
Potential criminal liability under the Criminal Code.
Failure of an operator to satisfy cybersecurity obligations
Potential administrative/regulatory liability.
Both can arise from the same incident.
17. Market-abuse offences
Banking law also intersects with securities-market criminal law.
Important conduct includes:
- insider dealing;
- unlawful disclosure of inside information;
- market manipulation;
- fraudulent market practices.
The principal regulatory framework includes Ley 6/2023, de los Mercados de Valores y de los Servicios de Inversión, together with EU market-abuse legislation and the Criminal Code.
The 2023 law also establishes the national framework for investment services and incorporates the European prudential architecture applicable to financial firms.
A bank may therefore be involved in criminal proceedings both as:
a credit institution
and, where authorised activities are involved,
an investment-services provider.
18. Corporate criminal liability
A major issue in financial criminal law is whether liability falls only on the individual or can extend to the company.
Spanish criminal law recognises criminal liability of legal persons in specified circumstances.
This is particularly relevant to:
- banks;
- financial companies;
- payment institutions;
- investment firms;
- corporate groups.
However, corporate criminal liability does not mean that every offence committed by an employee automatically makes the bank criminally liable.
The statutory requirements concerning:
- who committed the offence;
- position of the individual;
- benefit to the company;
- organisational failures;
- compliance/control measures;
must be examined.
19. Relationship between banking regulation and criminal law
A useful examination framework is:
| Conduct | Possible legal consequence |
|---|---|
| Failure to perform AML due diligence | Administrative/regulatory sanction |
| Concealing criminal proceeds | Money laundering |
| Fraudulent loan application | Fraud |
| Taking entrusted client funds | Misappropriation |
| Abuse of managerial powers | Disloyal administration |
| Forging banking documents | Document falsification |
| Manipulating payment systems | Computer fraud |
| Destroying bank data | Computer damage offence |
| Disrupting banking infrastructure | Article 264 bis |
| Attack on critical financial infrastructure | Aggravated cyber offence where statutory conditions are met |
| Insider trading | Market-abuse offence/regulatory liability |
| Manipulating securities market | Market-abuse offence/regulatory liability |
20. Important Spanish case-law principles
1. Eurobank — administration + appropriation
The Supreme Court's Eurobank decision demonstrates that abusive management of a bank and subsequent appropriation of bank funds can support both administración desleal and apropiación indebida.
2. Payment-card/electronic manipulation
Supreme Court jurisprudence has recognised that unauthorised manipulation/use of payment systems can fall within computer fraud, including cases involving POS terminals and payment cards. The Court's jurisprudential compilation refers, among others, to STS 692/2006 and STS 1476/2004.
3. Critical-infrastructure cyberattacks
The significance of critical infrastructure is now expressly incorporated into the Criminal Code's aggravated computer-damage provisions. Article 264.2 specifically identifies attacks affecting a computer system of critical infrastructure as an aggravating circumstance.
21. Hypothetical case study
Facts
A criminal group obtains privileged credentials of employees of a major Spanish bank.
They:
- enter the bank's internal network;
- modify payment databases;
- transfer €50 million;
- disable parts of the payment-processing system;
- prevent customers from accessing accounts;
- use shell companies to receive the stolen funds.
Possible offences
The investigation could potentially involve:
(1) Computer intrusion/access offences
depending on the precise method of access.
(2) Computer fraud
because the electronic system was manipulated to produce unlawful transfers.
(3) Computer damage/interference
if databases or systems were damaged or made inaccessible.
(4) Article 264/264 bis aggravated provisions
if the statutory conditions concerning serious disruption or critical infrastructure are satisfied.
(5) Fraud
for the resulting patrimonial deception where the elements are established.
(6) Money laundering
for transferring/concealing the €50 million proceeds.
(7) Criminal-organisation liability
if the evidence establishes the required organisational structure.
This demonstrates why a single banking cyberattack can produce a multi-offence prosecution.
22. Critical distinction: “financial infrastructure offence”
Spanish law does not create one universal offence called:
“offence against critical financial infrastructure.”
Instead, the legal analysis is constructed from different provisions.
For example:
Attack
→ unauthorised computer interference
→ Article 264/264 bis
→ aggravating circumstance: critical infrastructure
→ potentially much higher punishment.
At the same time:
same conduct
→ fraudulent transfer
→ computer fraud/fraud
and potentially:
proceeds
→ money laundering.
This is the most accurate way to conceptualise Spanish critical-financial-infrastructure criminal law.
23. European dimension
Spanish banking criminal law cannot be studied in isolation from EU law.
Particularly important are:
- CRR/CRD — prudential banking regulation;
- PSD2/payment-services framework;
- MiFID II/MiFIR;
- Market Abuse Regulation;
- AML directives/regulations;
- NIS cybersecurity framework;
- DORA — Digital Operational Resilience Act.
DORA is especially important for financial-sector ICT risk because it creates a specialised EU framework for digital operational resilience of financial entities.
Consequently, modern Spanish financial-infrastructure law increasingly operates through a three-layer structure:
EU financial regulation + Spanish regulatory law + Spanish criminal law
24. Overall legal framework
A concise way to remember the system is:
SPANISH FINANCIAL CRIMINAL LAW │ ┌─────────────────┼─────────────────┐ │ │ │ BANKING CRIMES FINANCIAL CRIMES CYBERCRIMES │ │ │ Fraud Insider dealing Data damage Misappropriation Manipulation System attacks Disloyal admin. Market offences Computer fraud Falsification AML offences Infrastructure attacks │ │ │ └─────────────────┼─────────────────┘ │ CRITICAL INFRASTRUCTURE │ Ley 8/2011 + cybersecurity │ FINANCIAL SYSTEM / BANKS │ Aggravated Criminal Code rules
Key authorities to cite in an academic answer
- Código Penal — Organic Law 10/1995, particularly the provisions on fraud, misappropriation, disloyal administration, money laundering and computer offences.
- Ley 10/2010, Anti-Money Laundering and Terrorist Financing Act.
- Ley 8/2011, Critical Infrastructure Protection Act.
- Real Decreto-ley 12/2018, security of networks and information systems.
- Ley 6/2023, Securities Markets and Investment Services Act.
- STS / Supreme Court Eurobank case, concerning the concurrence of disloyal administration and misappropriation.
- STS 692/2006 and STS 1476/2004, relevant to computer fraud/payment-card manipulation.
Bottom line: Spanish law protects banks and the financial system through a combination of ordinary financial crimes, AML offences, corporate/managerial offences, computer crimes, and special critical-infrastructure aggravations. The most important modern development is that a cyberattack against a banking system is not treated merely as property crime: where the statutory conditions are met, its impact on critical infrastructure and essential financial services can substantially alter the criminal classification and penalty.

comments