Computer fraud and unauthorized transactions: the intermediary is not safe if technical proof is missing
Summary
The Banking and Financial Arbitrator has established that the intermediary must reimburse unauthorized transactions if it does not provide complete technical evidence.
Key Points
- The burden of proof of the regularity of digital transactions always lies with the financial intermediary.
- Simple two-factor authentication does not exempt the bank without the production of complete IT logs.
- According to Legislative Decree 11/2010, the intermediary is liable unless there is proof of willful misconduct (dolo) or gross negligence (colpa grave) on the part of the user.
- The Bari Panel ordered Poste Italiane to provide a full refund due to a lack of adequate technical documentation.
A recent decision by the Banking and Financial Arbitrator – Bari Panel (no. 1599570/2022) confirms a fundamental principle in digital payments: the burden of proof of the regularity of the transaction always lies with the intermediary.
In the case in question, the applicant had disputed five unauthorized transactions, for a total amount of 8,393.50 euros, carried out via mobile application. The intermediary (Poste Italiane) had claimed “correct authentication” through a two-factor system, but did not provide complete IT logs, limiting itself to partial screenshots without indications of the authentication factors.
The Panel recalled that:
"Proof of the formal regularity of the transaction is not sufficient to demonstrate the absence of fraud, willful misconduct (dolo) or gross negligence (colpa grave) on the part of the user" (cf. ABF Coordination Panel, no. 22745/2019).
Based on articles 10 and 12 of Legislative Decree 11/2010, and the most recent ABF jurisprudence, liability falls on the intermediary, unless there is rigorous and complete contrary proof. In the absence of adequate technical documentation (e.g., complete logs, traceability of authentication factors), the intermediary is required to reimburse.
The appeal was upheld with an order for full reimbursement and costs to be borne by the intermediary.
OPERATIONAL CONSIDERATIONS
This decision once again highlights the importance for banks and fintech operators to:
- equip themselves with advanced anti-fraud systems;
- store IT logs in a structured and verifiable manner;
- train customers on the risks associated with phishing, spoofing, and vishing;
- intervene promptly in the event of complaints for anomalous transactions.
At the same time, it represents a warning for consumers: disputes must be timely and detailed, even in the absence of immediate technical evidence.
To assess the compliance of your IT security systems with legal requirements and the most recent ABF practices, contact us.
Content drafted with the support of artificial intelligence tools and reviewed by the firm’s lawyers. More information
Attached Documents
Avv. Roberto Antonio Catanzariti
Legal Aid Italia
Ha letto l'articolo e ha bisogno di assistenza?
Lo Studio Legal Aid è a disposizione per una consulenza riservata. Risposta garantita entro 24 ore.
Legal Insight
Altri articoli dello Studio
Mandato di arresto europeo (MAE): radicamento in Italia e rifiuto della consegna
La Cassazione ribadisce che il termine dei cinque anni non è un dato orientativo ma una soglia legale, e che la sua verifica documentale resta terreno del giudice di merito.
LeggiConfisca a metà: la Cassazione boccia la doppia motivazione su profitto e sproporzione
Cass. pen., Sez. IV, 9 giugno 2026 (dep. 8 settembre 2026), n. 33026. La contraddizione tra confisca diretta e confisca per sproporzione è vizio autonomo, anche quando l'importo in gioco è modesto.
LeggiSequestro su rogatoria estera: l'art. 724 c.p.p. alla prova della Corte costituzionale
L'ordinanza del dott. Roberto Crepaldi, giudice per le indagini preliminari presso il Tribunale di Milano, apre la questione di legittimità costituzionale: manca un rimedio per contestare i.
Leggi