Phishing and Computer Fraud: A Legal Guide to Deception, Digital Evidence, and Bank Liability
Summary
Phishing and computer fraud require a complex distinction between fraud and computer fraud, influencing criminal liability.
Key Points
- Distinction between fraud (Art. 640 c.p.), based on human error, and computer fraud (Art. 640-ter c.p.), based on direct intervention on the system.
- Importance of the victim in phishing: if the transfer of funds is mediated by a conscious act of the individual, it constitutes fraud.
- Rigor of Digital Forensics: digital evidence must be acquired through forensic copy and validated with a Hash value to be admissible.
- Responsibility of intermediaries: the bank is liable for damages unless it proves the client's gross negligence, according to the parameters of professional diligence.
1. Systematic Framework: The Evolution of Property Criminal Law in the Era of Digital Crime
The impact of the digital revolution has created a deep rift in the traditional structure of property criminal law. The evolution of fraud – and in particular the phenomenon of phishing – represents the paradigmatic example of the dematerialization of crime.
Fraud (Art. 640 c.p.) is historically based on interpersonal deception, while modern technological aggressions materialize in the creation of "simulated digital environments." This evolution has made it necessary to distinguish between:
- Fraud (Art. 640 c.p.): punishes the inducement of a person into error and the vitiation of their will.
- Computer Fraud (Art. 640-ter c.p.): punishes the alteration of a system's operation or unauthorized intervention on data and programs.
2. Anatomy of Phishing: The Structural Distinction Between Fraud and Computer Fraud
The core of the debate lies in identifying the object of the aggression: the victim's psyche or the algorithm?
2.1. The Enduring Vitality of Fraud under Art. 640 c.p. in "Classic" Phishing
In traditional phishing, the hacker manipulates the victim's perception of reality through spoofing techniques. The essence of the offense remains psychological: it is the user who, deceived, voluntarily enters their credentials. The Court of Cassation has established that if the harmful event results from a conscious act of the passive subject induced into error, the case constitutes fraud.
2.2. Computer Fraud under Art. 640-ter c.p.: Human Disintermediation
Art. 640-ter c.p. punishes intervention on data or the system that procures an unjust profit. Here, the deception is directed "to the machine." The transfer of funds occurs without the cooperation (albeit vitiated) of the victim, often through malware or Man-in-the-Browser attacks.
According to the Joint Sections (judgment no. 41210/2017), the distinction lies in the role of will: if the transfer is the direct effect of computer intrusion that bypasses human action, it constitutes computer fraud.
2.3. The "Gray Areas": Hybrid Models and Concurrence of Crimes
Often, cascade attacks occur (e.g., Vishing combined with SIM Swapping). In these cases, formal concurrence of crimes (Art. 81 c.p.) is frequent, with offenses such as:
- Impersonation (Art. 494 c.p.)
- Unauthorized access to a computer system (Art. 615-ter c.p.)
- Unlawful possession of access codes (Art. 615-quater c.p.)
3. Evidentiary Criticalities: Digital Evidence
The ascertainment of computer fraud requires Digital Forensics expertise.
3.1. Identification of the Perpetrator and Money Mules
Anonymity is guaranteed by VPNs, TOR, and the use of Money Mules (individuals who lend their accounts to fragment financial traceability). Investigations are based on the analysis of Log files and telematic traffic data made available by ISPs.
3.2. Volatility of Evidence and ISO/IEC 27037 Standard
Digital evidence is fragile. To ensure its integrity, acquisition must follow precise standards:
- Execution of a Forensic Copy (Bit-stream image).
- Calculation of the Hash value (algorithmic digital fingerprint).
The absence of such procedures can lead to the inadmissibility of the evidence.
3.3. Territorial Jurisdiction: The Locus Damni
The Court of Cassation (judgment no. 17325/2020) has clarified that jurisdiction is established in the place where the patrimonial impoverishment occurs (locus damni), which usually coincides with the branch where the damaged party's current account is located.
4. Civil Law: The Responsibility of Banking Intermediaries
The battle for the recovery of sums shifts to the bank.
4.1. Diligence of the Bonus Argentarius
The bank, as a professional operator, is bound by qualified technical diligence (Art. 1176, paragraph 2, c.c.). In the case of unauthorized operations, it is up to the bank to provide exculpatory evidence (fortuitous event or gross negligence of the client).
4.2. The PSD2 Revolution
Legislative Decree 218/2017 (PSD2) introduced:
- Strong Customer Authentication (SCA): two-factor or multi-factor authentication (knowledge, possession, inherence).
- Reversal of the burden of proof: the bank must immediately reimburse the client, unless there is proof of fraud or gross negligence on the part of the latter.
4.3. The Limits of "Gross Negligence"
The concept of gross negligence is interpreted restrictively. It is not gross negligence to fall for Sms Spoofing or Caller ID Spoofing if the deception is particularly sophisticated. Gross negligence can be configured, however, if the client ignores explicit security warnings or neglects the safekeeping of codes.
4.4. The Banking and Financial Arbitrator (ABF)
The ABF represents the primary tool for recovering sums. Although the decisions are not judgments, compliance by banks is very high to avoid reputational damage.
5. Future Perspectives
The use of Generative Artificial Intelligence and vocal Deepfakes will make phishing increasingly insidious. Defense will shift to technical regulation, such as the DORA regulation and the future PSD3, which aim to strengthen cyber resilience and protection against impersonation fraud.
Content drafted with the support of artificial intelligence tools and reviewed by the firm’s lawyers. More information
Avv. Roberto Antonio Catanzariti
Legal Aid Italia
Ha letto l'articolo e ha bisogno di assistenza?
Lo Studio Legal Aid è a disposizione per una consulenza riservata. Risposta garantita entro 24 ore.
Legal Insight
Altri articoli dello Studio
Mandato di arresto europeo (MAE): radicamento in Italia e rifiuto della consegna
La Cassazione ribadisce che il termine dei cinque anni non è un dato orientativo ma una soglia legale, e che la sua verifica documentale resta terreno del giudice di merito.
LeggiConfisca a metà: la Cassazione boccia la doppia motivazione su profitto e sproporzione
Cass. pen., Sez. IV, 9 giugno 2026 (dep. 8 settembre 2026), n. 33026. La contraddizione tra confisca diretta e confisca per sproporzione è vizio autonomo, anche quando l'importo in gioco è modesto.
LeggiSequestro su rogatoria estera: l'art. 724 c.p.p. alla prova della Corte costituzionale
L'ordinanza del dott. Roberto Crepaldi, giudice per le indagini preliminari presso il Tribunale di Milano, apre la questione di legittimità costituzionale: manca un rimedio per contestare i.
Leggi