Banking Law And Identity Theft Crimes Spain .

Banking Law and Identity Theft Crimes in Spain

1. Introduction

Banking identity theft occurs when a person unlawfully obtains or uses another person’s identifying or banking information to:

  • Access a bank account;
  • Obtain a loan or credit card;
  • Make transfers or payments;
  • Open an account;
  • Change account-security details;
  • Take control of a mobile number;
  • Impersonate a customer before a bank;
  • Redirect payments; or
  • Conceal the identity of the real offender.

Spanish law does not treat every form of identity theft as one single offence. The applicable criminal charge depends on what the offender did with the stolen identity. The conduct may constitute computer fraud, unlawful access to data, disclosure of secrets, document forgery, unlawful use of identity documents, usurpation of civil status, money laundering, or membership in a criminal organisation.

The main legislation includes:

  • Organic Law 10/1995 containing the Spanish Criminal Code;
  • Royal Decree-Law 19/2018 on payment services;
  • The General Data Protection Regulation;
  • Organic Law 3/2018 on data protection and digital rights;
  • The EU Payment Services Directive;
  • DORA, concerning banks’ digital operational resilience; and
  • Consumer-protection legislation.

2. Meaning of Identity Theft in Spanish Banking Law

Banking identity theft normally contains three stages:

2.1 Obtaining the victim’s information

The offender may obtain:

  • Full name;
  • National identity number;
  • Passport details;
  • Bank-account number;
  • Debit or credit-card information;
  • Online-banking password;
  • Mobile number;
  • Electronic signature;
  • Authentication code;
  • Biometric information; or
  • Copies of identity documents.

The information may be obtained through phishing, smishing, vishing, malware, data breaches, social engineering, document theft, SIM swapping, or corrupt insiders.

2.2 Impersonating the victim

The offender then represents themselves as the victim before:

  • A bank;
  • A payment institution;
  • A mobile-network operator;
  • An online merchant;
  • A lending platform;
  • A cryptocurrency exchange; or
  • Another financial-service provider.

2.3 Obtaining a financial benefit

The stolen identity may be used to:

  • Transfer funds;
  • Obtain credit;
  • Purchase goods;
  • Withdraw cash;
  • Apply for payment cards;
  • Reset passwords;
  • Replace a SIM card;
  • Redirect a company’s payment;
  • Create accounts for laundering money; or
  • Receive fraud proceeds.

3. Relevant Criminal Offences

3.1 Computer Fraud

Article 249 of the Spanish Criminal Code covers various forms of computer fraud.

The offence may arise when a person, intending to obtain an unlawful financial benefit:

  • Manipulates a computer system;
  • Introduces, alters, deletes, transmits, or suppresses computer data;
  • Interferes with an information system;
  • Uses another person’s payment instrument;
  • Fraudulently uses payment-card information; or
  • Conducts an unauthorised banking transaction.

For example, if an offender obtains a customer’s credentials through phishing and transfers money from the customer’s account, this will normally constitute computer fraud.

The prosecution must generally prove:

  1. Intentional conduct;
  2. Use or manipulation of digital data, systems, or payment instruments;
  3. An unlawful economic benefit;
  4. Financial loss to another person; and
  5. A causal connection between the manipulation and the loss.

3.2 Traditional Fraud

Article 248 applies to ordinary fraud based on deception.

It may apply where an offender impersonates another person and deceives a bank employee into:

  • Opening an account;
  • Granting a loan;
  • Issuing a payment card;
  • Changing account details; or
  • Releasing funds.

The main elements are:

  • Sufficient deception;
  • Error caused by that deception;
  • Disposal of property or money;
  • Financial loss; and
  • Intention to obtain an unlawful benefit.

The distinction between ordinary and computer fraud depends on whether the immediate deception was directed at a human being or whether the offender manipulated an automated system.

3.3 Usurpation of Civil Status

Article 401 punishes a person who usurps another person’s civil status.

However, Spanish judicial doctrine generally requires more than an isolated use of someone’s name. The offender must assume the other person’s identity in a sufficiently complete and continuing manner and exercise rights or functions connected with that identity.

Accordingly:

  • Giving a false name on one occasion may not be enough;
  • Using another person’s complete identity over time may qualify;
  • Opening accounts, contracting services and presenting oneself consistently as the victim may support the offence; and
  • Temporary impersonation may instead be punished as fraud, forgery or unlawful use of documents.

Article 401 provides imprisonment of six months to three years.

3.4 Unlawful Access to Personal Data

Articles 197 and 197 bis protect privacy, personal data, communications and computer systems.

Criminal liability may arise where the offender:

  • Accesses a bank account without authorisation;
  • Intercepts electronic communications;
  • Obtains confidential customer information;
  • Accesses a bank’s database;
  • Takes control of an email account;
  • Installs spyware or keylogging software;
  • Circumvents security controls; or
  • Uses data obtained through unlawful system access.

The seriousness of the offence may increase where:

  • Sensitive personal information is involved;
  • Data are disclosed to third parties;
  • The offender acts for profit;
  • A large number of victims are affected;
  • The offender belongs to a criminal organisation; or
  • The offender abuses a professional or employment position.

3.5 Production or Possession of Hacking Tools

Article 197 ter can apply to the production, acquisition, importation, or provision of programs, passwords or access codes specifically intended to facilitate unlawful access or interception offences.

Examples include:

  • Phishing kits;
  • Banking malware;
  • Stolen credential databases;
  • Fake login-page software;
  • Password-stealing tools; and
  • Access codes supplied to criminal groups.

The prosecution must establish the criminal purpose connected to the possession or distribution of the tool.

3.6 Document Forgery

Identity theft frequently involves forged:

  • National identity cards;
  • Passports;
  • Bank statements;
  • Salary certificates;
  • Employment contracts;
  • Loan applications;
  • Direct-debit mandates;
  • Company invoices;
  • Powers of attorney; or
  • Electronic documents.

Articles 390 to 399 bis regulate various document-forgery offences.

An offender may be liable for:

  • Creating a false document;
  • Altering an authentic document;
  • Falsely representing another person’s participation;
  • Making false statements concerning essential facts; or
  • Knowingly using a forged document.

Electronic documents may also qualify as documents for criminal-law purposes.

3.7 Unlawful Use of Genuine Identity Documents

Article 400 bis extends criminal treatment to certain cases involving genuine identity documents used by someone who is not entitled to use them.

Therefore, an offender does not escape liability merely because the identity card or passport is authentic. Using another person’s genuine document to impersonate that person may still be criminal.

3.8 Payment-Card and Payment-Instrument Offences

Articles 399 bis and related provisions address the falsification, alteration, possession, trafficking and fraudulent use of credit cards, debit cards, traveller’s cheques and other payment instruments.

Liability may arise where a person:

  • Clones a payment card;
  • Manufactures a false card;
  • Uses stolen card information;
  • Possesses counterfeit cards for fraudulent use;
  • Sells payment-card credentials;
  • Uses a card belonging to another person; or
  • Participates in a card-fraud network.

3.9 SIM-Swapping Fraud

SIM swapping occurs when an offender impersonates the victim before a telecommunications provider and obtains control of the victim’s mobile number.

The offender can then intercept:

  • Authentication messages;
  • Password-reset codes;
  • Bank alerts;
  • Security calls; and
  • One-time passwords.

Depending on the circumstances, SIM swapping may involve:

  • Computer fraud;
  • Ordinary fraud;
  • Unlawful access;
  • Disclosure of secrets;
  • Document forgery;
  • Usurpation of civil status; and
  • Criminal-organisation offences.

If the offender uses the intercepted codes to transfer bank funds, each stage may form part of a connected criminal scheme.

3.10 Money Laundering and Money-Mule Liability

Fraud proceeds are often transferred through accounts belonging to “money mules.”

A money mule may:

  • Receive stolen funds;
  • Transfer them to another account;
  • Convert them into cryptocurrency;
  • Withdraw cash;
  • Retain a commission; or
  • Allow others to use their account.

Article 301 on money laundering may apply where the account holder knew that the money came from criminal activity or deliberately ignored clear warning signs.

A person does not necessarily avoid liability by claiming not to know the precise details of the original fraud. Awareness of the unlawful origin, including through deliberate blindness, may be sufficient.

3.11 Criminal Organisations

Where several people cooperate in an organised and stable manner, Articles 570 bis and 570 ter may apply.

A banking identity-theft organisation may include:

  • A person who steals customer data;
  • A phishing-site operator;
  • A malware developer;
  • A person producing false documents;
  • A SIM-swap participant;
  • Account holders receiving stolen funds;
  • Cash withdrawers; and
  • Organisers who distribute the proceeds.

Each participant’s liability depends on their knowledge, intention, contribution and position within the organisation.

4. Bank Liability for Identity-Theft Transactions

Criminal responsibility of the offender is separate from the bank’s obligation to refund the customer.

Under the payment-services framework, a transaction is authorised only where the payer has given valid consent.

If a customer denies authorising a transaction, the payment-service provider must generally prove that:

  • The transaction was authenticated;
  • It was accurately recorded;
  • It was correctly entered in the accounts; and
  • It was not affected by a technical failure or other deficiency.

The mere fact that the correct password or authentication code was used does not automatically prove that the customer authorised the transaction or acted with gross negligence.

Refund obligation

For an unauthorised payment, the bank is generally required to:

  • Refund the transaction amount;
  • Restore the account to the position it would have occupied without the transaction; and
  • Do so within the legally prescribed period.

The bank may resist reimbursement where it proves that the customer:

  • Acted fraudulently; or
  • Intentionally or with gross negligence failed to protect personalised security credentials.

Ordinary carelessness is not necessarily gross negligence. Courts examine all circumstances, including:

  • How convincing the fraudulent message was;
  • Whether the message appeared in the bank’s genuine SMS chain;
  • Whether the bank detected unusual activity;
  • Whether a new device or destination account was used;
  • Whether transaction limits were suddenly changed;
  • Whether the bank gave effective warnings;
  • Whether several unusual transfers were made rapidly; and
  • Whether the bank’s authentication system was adequate.

5. Data-Protection Liability

Identity theft often begins with a personal-data breach.

Banks must implement appropriate technical and organisational security measures under the GDPR. These may include:

  • Encryption;
  • Access control;
  • Multifactor authentication;
  • Fraud monitoring;
  • Data minimisation;
  • Security testing;
  • Employee training;
  • Incident-response systems; and
  • Controls over outsourcing providers.

A serious personal-data breach may have to be reported to the Spanish Data Protection Agency. If the breach creates a high risk to individuals, the affected customers may also have to be informed.

A victim may claim compensation where there is:

  1. A violation of the GDPR;
  2. Material or non-material damage; and
  3. A causal relationship between the violation and the damage.

6. Important Case Laws

6.1 Spanish Supreme Court Judgment 571/2025

This Supreme Court judgment became an important reference in disputes concerning phishing and unauthorised banking transactions.

The Court treated payment-service liability as a special statutory regime. Where the customer denies authorisation, the bank must prove proper authentication and the relevant circumstances supporting customer fraud or gross negligence.

The use of valid credentials does not, by itself, conclusively establish customer authorisation.

Legal importance: Banks must provide positive technical and factual evidence. They cannot rely only on the fact that a password, SMS code or authentication factor was correctly entered.

6.2 Provincial Court of Badajoz, Phishing Judgment of 2025

The Provincial Court ordered a bank to compensate a customer affected by phishing. The court found that the bank had not maintained adequate mechanisms to detect and prevent the fraudulent operation.

Relevant circumstances included the nature of the transaction and the bank’s capacity to recognise unusual behaviour.

Legal importance: Banks are expected to operate active fraud-detection systems. Authentication is not the only relevant question; transaction monitoring is also important.

6.3 Murcia Banking-Fraud Judgment of 2025

A Murcia court ordered BBVA to reimburse €5,977 to a customer affected by banking fraud. The decision referred to Supreme Court Judgment 571/2025 and the statutory liability regime for unauthorised transactions.

Legal importance: A financial institution must show more than formal authentication. It must establish customer authorisation or circumstances legally sufficient to transfer the loss to the customer.

6.4 Moncada Court Judgment of 2023

A court in Moncada ordered a bank to reimburse approximately €5,800 to a customer who suffered online fraud.

The court considered phishing a foreseeable risk connected with online-banking services. Banks providing digital services must employ security systems capable of addressing risks inherent in those services.

Legal importance: Banking fraud committed by a third party does not automatically release the bank from civil liability toward its customer.

6.5 Las Palmas Cyber-Fraud Judgment of 2024

A court in Las Palmas held a bank responsible for failing to prevent a cyber-fraud incident and ordered reimbursement of the fraudulently obtained amount.

The reasoning focused on the bank’s responsibility to operate effective security and fraud-prevention mechanisms.

Legal importance: A bank may be responsible even though the immediate criminal act was committed by an unknown third party.

6.6 Provincial Court of Zaragoza Phishing Case

The Provincial Court of Zaragoza imposed prison sentences on members of an organised group that obtained personal and banking data through phishing.

The case involved coordinated conduct, including collecting credentials and using them to commit financial fraud.

Legal importance: Participants may be convicted according to their respective roles even if they did not personally send the phishing message or withdraw the stolen money.

6.7 Spanish Constitutional Court Judgment 61/2019

The defendant argued that another person had impersonated her and used her identity in transactions that led to a fraud conviction.

The Constitutional Court examined the procedural treatment of evidence supporting identity theft and the defendant’s right to effective judicial protection. The available material included other judgments in which she had been acquitted of similar allegations because of evidence that a third party had used her identity.

Legal importance: A person whose identity has been stolen must not be convicted merely because records or online accounts contain their name. Courts must examine evidence connecting that person to the actual criminal conduct.

6.8 Natsionalna agentsia za prihodite, Case C-340/21

A cyberattack resulted in the disclosure of personal data. The Court of Justice held that a successful cyberattack does not automatically prove that the data controller’s security measures were inadequate.

However, the controller bears responsibility for demonstrating that its technical and organisational measures were appropriate.

Legal importance for Spanish banks: A bank must be able to prove how its controls were selected, implemented, monitored and tested. Written security policies alone may be insufficient.

6.9 Österreichische Post, Case C-300/21

The Court of Justice ruled that a GDPR infringement alone does not automatically create a right to compensation. The claimant must establish infringement, actual damage and causation.

However, there is no requirement that non-material damage reach a particular minimum level of seriousness.

Legal importance: Victims of banking identity theft may recover compensation for proven financial or non-financial damage caused by unlawful personal-data processing.

6.10 Scalable Capital, Joined Cases C-182/22 and C-189/22

Personal data belonging to customers of a financial trading platform were unlawfully obtained.

The Court explained that GDPR compensation is compensatory rather than punitive. Fear of future misuse may constitute damage where it is genuine and properly established.

Legal importance: A victim does not necessarily have to wait until stolen data are used for a second fraud. A well-founded fear of identity misuse may itself be relevant to compensation.

7. Criminal Liability of Different Participants

ParticipantPossible liability
Person sending phishing messagesFraud, attempted fraud, unlawful data collection
Person operating a fake bank websiteComputer fraud, unlawful access, possession of hacking tools
Person using stolen credentialsComputer fraud, unlawful access
Person producing false identity documentsDocument forgery
Person using another person’s genuine IDUnlawful use of identity documents
Person obtaining a replacement SIMFraud, identity usurpation, unlawful access
Money-mule account holderFraud participation or money laundering
Bank employee supplying customer dataDisclosure of secrets, fraud participation
Criminal-group organiserFraud, money laundering, criminal-organisation offences
Business negligently losing customer dataRegulatory and civil liability; criminal liability only where the legal requirements are met

8. Evidence in Banking Identity-Theft Cases

Important evidence may include:

  • Bank-access logs;
  • IP addresses;
  • Device identifiers;
  • Mobile-phone records;
  • SIM-replacement records;
  • Authentication logs;
  • One-time password records;
  • Transaction timestamps;
  • CCTV recordings;
  • ATM records;
  • Email headers;
  • Fraudulent websites;
  • WhatsApp or messaging communications;
  • Money-mule account statements;
  • Cryptocurrency records;
  • Copies of forged documents; and
  • Expert computer-forensic reports.

Possession of the receiving account does not automatically prove authorship of the entire fraud. The prosecution must establish the accused person’s knowledge and intentional participation.

Similarly, use of the victim’s name does not prove that the victim carried out the transaction.

9. Rights and Steps Available to a Victim

A victim should act quickly by:

  1. Informing the bank and requesting immediate blocking of accounts and payment instruments;
  2. Contesting every unauthorised transaction in writing;
  3. Requesting reimbursement under the payment-services rules;
  4. Changing online-banking and email credentials;
  5. Contacting the mobile provider where SIM swapping is suspected;
  6. Reporting the incident to the National Police or Guardia Civil;
  7. Preserving messages, emails, screenshots and transaction records;
  8. Requesting information about accounts or loans opened in the victim’s name;
  9. Reviewing credit and financial records for additional fraud;
  10. Filing a complaint with the bank’s customer-service department;
  11. Referring an unresolved banking complaint to the Banco de España; and
  12. Considering civil proceedings for reimbursement and damages.

A complaint to the Banco de España does not replace criminal proceedings or a civil action, and its reports normally do not have the same binding effect as a court judgment.

10. Defences Commonly Raised by Banks

Banks frequently argue that:

  • Correct credentials were used;
  • Strong customer authentication was completed;
  • The customer revealed a password or code;
  • The customer ignored security warnings;
  • The transaction came from a recognised device;
  • The bank’s system was not technically compromised; or
  • The customer acted with gross negligence.

These arguments must be evaluated carefully. Successful authentication establishes that the system accepted the credentials, but it does not necessarily prove that the genuine customer gave consent.

The essential questions are:

  • Who actually initiated the transaction?
  • How were the credentials obtained?
  • Was the operation objectively unusual?
  • Could the bank have detected the anomaly?
  • Did the bank apply all required authentication controls?
  • Did the customer act fraudulently or with gross negligence?
  • Was there a technical or monitoring failure?

11. Penalties and Additional Consequences

The exact penalty depends on the offences, amounts, victims and aggravating circumstances.

Consequences may include:

  • Imprisonment;
  • Criminal fines;
  • Confiscation of fraud proceeds;
  • Restitution of stolen money;
  • Compensation for economic and emotional harm;
  • Closure of websites or systems used for fraud;
  • Disqualification in appropriate cases;
  • Corporate criminal liability;
  • Increased penalties for organised crime; and
  • Liability for money laundering.

Continuing offences, multiple victims, high losses, abuse of trust, vulnerable victims and criminal-organisation involvement may significantly increase the sentence.

12. Conclusion

Banking identity theft in Spain can produce several overlapping offences. The legal classification depends on whether the accused:

  • Stole personal data;
  • Accessed a computer system;
  • Impersonated the victim;
  • Manipulated an automated banking system;
  • Deceived a bank employee;
  • Forged or used documents;
  • Made unauthorised payments;
  • Received stolen money; or
  • Participated in an organised criminal group.

The offender’s criminal liability is separate from the bank’s obligation to reimburse the customer. In unauthorised-payment disputes, the bank generally bears the burden of proving authentication and the circumstances that justify refusing reimbursement. Correct credentials alone do not necessarily prove genuine consent.

Spanish and European case law therefore establishes two complementary principles: offenders may be punished for fraudulent identity use, while banks must maintain effective authentication, monitoring, data-security and fraud-prevention systems to protect their customers.

 

 

LEAVE A COMMENT