
Konstantinos Βairaktaris provides a detailed commentary on the Larissa Court of Appeal Judgment No. 104/2026, which held a Greek bank liable for unauthorized transfers executed through a sophisticated phishing attack.
The article critically examines:
- The bank’s insufficient strong customer authentication (SCA) procedures, particularly the use of Viber for OTP delivery instead of more secure methods (hardware token or SMS).
- The allocation of risk between payment service providers and users under Law 4537/2018 (transposition of PSD II).
- The limits of the customer’s contributory negligence in cases of social engineering fraud.
- The possibility of concurrent tort liability under Greek law (Art. 8 of Law 2251/1994 and Art. 914 of the Civil Code).
A timely and well-reasoned contribution to the evolving case law on phishing and electronic banking fraud in Greece.
You can find the full analysis here.