Papachatzis | Bairaktaris

Konstantinos Βairaktaris provides a detailed commentary on the Larissa Court of Appeal Judgment No. 104/2026, which held a Greek bank liable for unauthorized transfers executed through a sophisticated phishing attack.

The article critically examines:

  • The bank’s insufficient strong customer authentication (SCA) procedures, particularly the use of Viber for OTP delivery instead of more secure methods (hardware token or SMS).
  • The allocation of risk between payment service providers and users under Law 4537/2018 (transposition of PSD II).
  • The limits of the customer’s contributory negligence in cases of social engineering fraud.
  • The possibility of concurrent tort liability under Greek law (Art. 8 of Law 2251/1994 and Art. 914 of the Civil Code).

A timely and well-reasoned contribution to the evolving case law on phishing and electronic banking fraud in Greece.

You can find the full analysis here.