The case, explained
Liability for bank fraud: proof of gross negligence
7 min read · Updated September 2026 · Editorial oversight: Avv. Federico Papa
Recent case law has outlined a complex framework regarding digital payments and cybersecurity. According to reports from Diritto e Giustizia and Quotidiano Giuridico, the focus has shifted from the mere technical execution of the transaction to the assessment of the professional diligence required of credit institutions, balanced with the user's conduct. This article examines how case law is divided between protecting the account holder and exonerating the intermediary in cases of gross negligence. Through the analysis of the regulations and our twin case, we will see how the boundary between simple distraction and gross negligence can determine the right to a refund or the loss of illegally stolen sums.

In brief
The Supreme Court, in ruling 25013/2024, established that banks are liable for phishing damages unless they prove the client's gross negligence. Demonstrating the correct registration of the transaction or the use of access codes is not enough. As professional operators, institutions must guarantee state-of-the-art security systems. This decision tips the scales in favor of consumers, making compensation a likely outcome whenever doubts remain regarding the dynamics of the cyber fraud, thus raising the required standard of technical diligence for credit institutions.
The facts
The case came to the attention of the Supreme Court of Cassation after an account holder suffered the unauthorized withdrawal of large sums from their account following a cyber attack. Unlike what happens in other proceedings, the claim for reimbursement had been upheld in the lower courts and the Supreme Court, with order 3780/2024, rejected the appeal by Poste Italiane S.p.A., confirming the order to refund. The plaintiff had challenged the vulnerability of the institution's IT system. The issue of fraudulent messages inserted into the same chain of official bank communications, capable of misleading even a moderately prudent user, constitutes instead a typical scenario highlighted by lower courts and the Banking and Financial Arbitrator (ABF) to exclude gross negligence. Other aspects of the case are covered in dedicated articles in this column.

The rules at play
The regulatory pillar is Legislative Decree 11/2010, which implements European directives on payment services.
- Article 10 establishes the burden of proof on the bank: if the user denies authorization, the institution must prove that the transaction was authenticated and did not suffer malfunctions.
- Article 12 limits the customer's liability only to cases of fraud or gross negligence in failing to comply with credential custody obligations.
- Article 1176 of the Civil Code imposes technical diligence on the banker, a professional parameter higher than that of the average person, requiring the adoption of the best available security technologies to prevent intrusions and spoofing phenomena.
What case law says
Supreme Court case law has clarified that the intermediary must provide proof of the proper functioning of the systems, framing the issue within contractual liability under Art. 1176, paragraph 2, of the Civil Code and Legislative Decree 11/2010. The thesis that qualifies online banking as a dangerous activity under Art. 2050 of the Civil Code currently represents a minority view. The jurisprudential framework is not unequivocally pro-customer, but is divided: while on one hand the mere recording of system logs is not enough to demonstrate the user's gross negligence, on the other hand the Supreme Court, with order 7214/2023, established that handing over credentials to third parties following a deceptive email constitutes gross negligence, exonerating Poste Italiane S.p.A. from all liability.
- Try edit.legal AI
Analysis drafted and verified with edit.legal
To verify the provisions cited in this article, we used edit.legal. Test our legal AI on official sources and apply it to your own matters.
What it teaches professionals
- For lawyers representing account holders, it is essential to produce screenshots and documentation demonstrating the plausibility of the fraudulent message to downgrade negligence from gross to ordinary.
- For institutional lawyers, the defense must focus on producing technical expert reports certifying system compliance with the highest PSD2 standards.
- It is always necessary to check whether the bank sent real-time alerts and whether it adopted automatic blocking systems for suspicious transactions to foreign accounts or beneficiaries never previously recorded.
Update and rectification note (17 September 2026)
The previous version of this article incorrectly reported that Supreme Court case law had a consolidated orientation in favor of the account holder and that it qualified online banking as a dangerous activity. Furthermore, it attributed arguments about fraudulent messages in the official chain to the Supreme Court, which instead belong to lower courts and the ABF, and reported an inaccurate procedural history for Poste Italiane. The text has been corrected based on official documents: the Supreme Court frames the issue within contractual liability and presents a divided orientation, having rejected Poste's appeal with order 3780/2024, but having exonerated it due to the customer's gross negligence with order 7214/2023.
Developments: the Supreme Court's final decision
With ruling no. 25013 published on 17 September 2024, the Supreme Court rejected the appeal by Poste Italiane, confirming the institution's liability for sums stolen through phishing. According to outlets such as Il Sole 24 Ore and Altalex, the decision solidifies the burden of proof: demonstrating the entry of codes is insufficient, as positive proof of the user's gross negligence is required. Diritto.it and Quotidiano Giuridico highlighted how the bank's professional diligence includes adopting updated biometric systems to prevent fraud, making reimbursement almost automatic in the absence of inexcusable negligence by the account holder.
References: D.Lgs. 11/2010Art. 1176 c.c.Art. 2050 c.c.Cass. 7214/2023Cass. 3780/2024
Related cases

Frequently asked questions
What exactly is meant by gross negligence of the account holder?
Gross negligence consists of conduct characterized by extraordinary imprudence, such as ignoring obvious security warnings or voluntarily handing over all credentials to strangers.
Must the bank always refund in case of phishing?
No, a refund is due only if the institution fails to prove the user's gross negligence or if its security systems were not up to the required professional standards.
How much time do I have to report an unauthorized transaction?
The user must communicate the unauthorized transaction to the bank without delay and in any case within 13 months from the debit date to retain the right to a refund.
Verified legal research and drafting with edit.legal
Legal research and drafting with citations checked against official databases. edit.legal is free to try, no credit card.
Try edit.legal for free