Imagine an international transaction between a supplier and a buyer from different countries. Through fraudulent interference by third parties — a BEC fraud — the buyer is induced to transfer the amount due to a bank account in Portugal held by a fraudster. The legitimate supplier never receives the payment, suffers significant loss, and then seeks to assess the possibility of holding the Portuguese bank that received and moved the diverted funds civilly liable. This is a complex situation, since the bank in question had no direct contractual relationship with the injured party, namely the supplier; the bank merely received a transfer order from the deceived customer and executed it.
The central legal question therefore arises: can the bank receiving the fraudulent funds be held civilly liable for the damage caused to the true creditor, even in the absence of any contractual relationship with that creditor?
1. Introduction
The fraud known as Business Email Compromise, or BEC, is a form of computer fraud in which a malicious third party intercepts or falsifies electronic communications between companies in order to induce improper payments. Typically, the fraudster impersonates a legitimate business partner — a supplier or customer — and provides a fraudulent IBAN to which the victim, acting under a mistake, transfers a significant sum. As a result, the funds are credited to a bank account controlled by the fraudster, frequently in the name of a “money mule”, instead of reaching the true legitimate beneficiary.
Imagine, for example, an international transaction between a supplier and a buyer from different countries. Through fraudulent interference by third parties — a BEC fraud — the buyer is induced to transfer the amount due to a bank account in Portugal held by a fraudster. The legitimate supplier never receives the payment, suffers significant loss, and then seeks to assess the possibility of holding the Portuguese bank that received and moved the diverted funds civilly liable. This is a complex situation, since the bank in question had no direct contractual relationship with the injured party, namely the supplier; the bank merely received a transfer order from the deceived customer and executed it.
The central legal question therefore arises: can the bank receiving the fraudulent funds be held civilly liable for the damage caused to the true creditor, even in the absence of any contractual relationship with that creditor?
The answer requires an analysis of the applicable legal framework — in particular in the field of non-contractual civil liability — and of the conduct required of financial institutions when processing electronic payments. It is therefore necessary to assess banks’ legal duties in the execution of transfers, such as the use of the IBAN as a unique identifier, as well as their compliance duties, namely KYC/AML obligations — Know Your Customer / anti-money laundering — in order to determine the extent to which a breach of those duties could ground an obligation to compensate. Additionally, it will be relevant to consider the approach taken by Portuguese case law in analogous cases involving BEC fraud or improper transfers, in order to assess whether the courts have admitted or rejected bank liability in these scenarios.
Finally, the article critically discusses whether the current legal framework effectively safeguards the victims of these frauds and what prospects exist for future developments, both at national and European level.
2. Applicable Legal Framework
Non-contractual civil liability: In the case under analysis, there is no contract between the injured party — the defrauded supplier — and the bank that received the funds. Accordingly, any duties allegedly breached by the bank do not arise from a contractual relationship, but rather from general normative sources. The issue therefore falls within the field of non-contractual civil liability, also known as tortious or delictual liability, as provided for in Article 483 of the Civil Code. This provision states that “anyone who, intentionally or by mere negligence, unlawfully violates another person’s right or any legal provision intended to protect the interests of others shall be obliged to compensate the injured party for the damage resulting from that violation”.
In summary, for tortious liability to arise, four requirements must be met: (i) an unlawful act, meaning an act or omission that violates a third party’s right or a legal provision intended to protect that party; (ii) fault on the part of the agent; (iii) damage; and (iv) a causal link between the act and the damage.
In the context at hand, since there is no contractual relationship between the bank and the injured party, any attempt to hold the Portuguese bank liable will have to satisfy these requirements of non-contractual liability. In particular, it will be necessary to demonstrate the existence of a culpable unlawful act attributable to the bank, that is, that the bank breached some legal duty or general duty of care intended to protect the interests of the injured party. The potentially relevant duties in this respect are the banking duties applicable to the processing of transfers and the duties of diligence in preventing money laundering — matters that will be analysed below.
The execution of electronic transfers; the IBAN as a unique identifier
One of the central aspects of this case is whether the receiving bank had a legal obligation to confirm that the name of the beneficiary indicated in the transfer corresponded to the actual holder of the destination account.
In Portugal, as in most EU countries, the answer is negative. The legal regime governing payment services provides that bank transfer orders are executed on the basis of a unique identifier, usually the IBAN, which is the binding data element for crediting the funds.
Article 129 of the Legal Framework for Payment Services and Electronic Money, approved by Decree-Law No. 91/2018, which transposed Directive (EU) 2015/2366 — PSD2 — expressly provides that the payment service provider “may consider the payment order relating to the beneficiary indicated to have been correctly executed if it does so on the basis of the unique identifier supplied by the payer”.
Conversely, the bank has no legal duty to verify whether the name of the beneficiary associated with that IBAN does in fact correspond to the holder of the destination account. In other words, when receiving a transfer, the beneficiary’s bank fulfils its obligations if it credits the funds to the account whose IBAN was indicated; it is not required to verify other data, such as account ownership or the account holder’s name.
This rule — sometimes called the “IBAN rule” — aims to ensure the efficiency and speed of electronic payments, placing responsibility on the payer to correctly indicate the identifier of the intended account.
From a legal point of view, the practical consequence is that, if the payer provides an incorrect IBAN or an IBAN belonging to a third party, the banks — both the sending bank and the beneficiary bank — are, in principle, exempt from liability for defective execution of the transfer, since they have technically complied with the instructions received. The error lies with the payer who indicated the wrong data, even if that mistake was induced by a third party’s fraud.
This allocation of risk is aligned with the European regime under PSD2 and is confirmed by national case law, as will be seen below.
It should be emphasised that, in the BEC fraud case study presented, the IBAN provided in the transfer order was indeed the one indicated by the fraudster — the victim believed it to be the legitimate supplier’s IBAN, but it was not. Accordingly, in light of Article 129 of the Legal Framework for Payment Services and Electronic Money, the transaction was technically executed correctly in relation to the IBAN indicated, even though the money ultimately ended up in an account belonging to a fraudster. From a formal point of view, there was no “unlawful execution” of the transfer by the destination bank; on the contrary, the bank complied with the order in accordance with the elements provided.
Duties of diligence and compliance: KYC/AML obligations
Another possible source of liability for the banking institution would be the allegation that the Portuguese bank failed to comply with its duties of diligence in preventing fraud and money laundering.
Law No. 83/2017, the Law on the Prevention of Money Laundering and Terrorist Financing, which applies to financial institutions, imposes strict identification and due diligence obligations when accepting customers, as well as obligations to monitor and report suspicious transactions. In particular, the bank has a duty to properly identify account holders — the Know Your Customer principle — to refuse or close accounts used improperly, to monitor large or atypical transfers, and to immediately report to the authorities any indications of unlawful activities; see, for example, Articles 23, 32 and 43 of Law No. 83/2017.
In the hypothetical case, it could be argued that the bank breached these duties: it allowed the opening of an account in the name of malicious third parties — the “money mules” — and allowed the funds, shortly after being received, to be dissipated through withdrawals and successive transfers to other accounts, without raising suspicions or blocking the transaction. Such indicators — a recently opened account, a possibly fictitious account holder, a high-value international transfer followed by splitting of the amount and rapid outflow of funds — could be considered red flags for potential fraud and money laundering, requiring diligent action by the bank, such as blocking the account, freezing the funds and reporting the matter to the authorities.
It is, however, crucial to understand the legal framework of these compliance duties in the context of civil liability. The obligations aimed at preventing money laundering and terrorist financing are primarily intended to protect collective interests and public order — the integrity of the financial system and the repression of criminal activity. In terms of non-contractual liability, the question is whether the breach of such normative duties may be considered a “violation of a legal provision intended to protect the interests of others”, within the meaning of Article 483 of the Civil Code, in relation to a specific victim of fraud.
Portuguese case law has, to date, answered this question in the negative: it has held that compliance rules do not constitute “protective rules” of the type required by Article 483, aimed at safeguarding the private interests of the injured party, but rather diffuse interests of the community. Thus, even if a non-compliant bank may incur administrative or regulatory liability, such as fines imposed by the regulator, and possibly even criminal liability, such infringement does not automatically give rise to a duty to compensate the injured third party in civil law.
In summary, according to the dominant view, a mere failure to comply with money laundering prevention duties — however reprehensible from a regulatory point of view — does not, by itself, satisfy the specific unlawfulness requirement necessary for civil liability towards the victim of a fraud.
It should be noted that this interpretation is not universally uncontested. Part of the legal literature has discussed whether banking supervision and anti-fraud duties, although having a general purpose, should also protect those who legitimately place their trust in the banking system. For example, Miguel Pestana de Vasconcelos has suggested a broader view of banking liability in unauthorised payment transactions. Likewise, in more recent Spanish legal scholarship, the thesis has gained strength that a serious breach of compliance duties — such as allowing the opening of an account with a false identity or ignoring blatant discrepancies in a transfer — could be considered a breach of protective rules intended to safeguard potential victims, thereby satisfying the requirement of unlawfulness and opening the way to compensation claims against the bank. However, that understanding has not been adopted by Portuguese courts to date, which continue to require a more direct and specific link between the breached rule and the protection of the injured private interests.
5. National Case Law
Portuguese case law has addressed analogous cases — involving bank transfers credited to the wrong accounts or fraud schemes — and, almost unanimously, has not recognised civil liability on the part of banks in situations comparable to BEC fraud. Three judgments in particular should be highlighted:
Supreme Court of Justice — Judgment of 16 February 2023, Case No. 201/20.5T8MGL.S1: This case concerned a bank transfer that did not reach the correct beneficiary due to an error in the IBAN. The Supreme Court of Justice clearly established the principle that there is no legal obligation for the bank to confirm the correspondence between the beneficiary’s name and the IBAN provided. The Court held that, where the payer indicated a specific IBAN and the payment was made to the account corresponding to that IBAN — even if that account belonged to a person other than the intended nominal beneficiary — the bank could not be held liable for the incorrect allocation of the funds. The error is attributable to the payer who provided the wrong identifier, even if that error was induced by fraud committed by third parties. In short, the Supreme Court reaffirmed that the execution of the transfer on the basis of the IBAN satisfies the bank’s legal duties, and that there is no unlawfulness in its conduct when it complies with the instructions received.
Coimbra Court of Appeal — Judgment of 12 July 2022, Case No. 201/20.5T8MGL.C1: This judgment was delivered in the same chain of proceedings as the case referred to above, at the lower appellate level before the appeal decided by the Supreme Court in 2023. The Coimbra Court of Appeal adopted the same view, stressing that the IBAN functions as a unique and sufficient identifying element for the execution of transfer orders, and that no additional duties fall upon the bank to verify ownership of the destination account. This judgment confirmed the tendency of the Courts of Appeal to align with the rule laid down in Article 129 of the Legal Framework for Payment Services and Electronic Money, shielding banking institutions from liability where they act in accordance with the instructions provided by the payer customer.
Porto Court of Appeal — Judgment of 10 April 2025, Case No. 11955/21.1T8PRT: This recent judgment is of particular interest because it dealt precisely with a situation of international BEC fraud, with features similar to the hypothetical case under analysis. A foreign company that had suffered loss brought an action against the Portuguese bank where the fraudsters had opened the account to which the misdirected funds were transferred, alleging negligence by the bank in detecting the scheme. The Porto Court of Appeal, however, remained faithful to the existing line of case law: it held that neither the lack of confirmation between name and IBAN nor possible failures in banking compliance duties constitute, by themselves, a civil wrong capable of giving rise to a duty to compensate. The Court reaffirmed that there is no legal duty to check correspondence between the recipient’s name and the IBAN — even in cases of fraud — and that the breach of anti-money laundering obligations, such as customer identification or the reporting of suspicious transactions, does not create an immediate legal relationship with the victim of the fraud capable of grounding civil liability. In practical terms, the judgment concluded that the loss arising from this scheme falls on the parties involved in the transaction — the deceived payer and the unpaid supplier — and cannot be shifted to the bank, unless some intentional or extraordinarily negligent conduct by the bank were proven, which was not demonstrated.
In light of these precedents, it is clear that the national case law approach is consistent: in the absence of an express legal provision imposing duties of protection on the bank towards third parties who are not its customers in electronic transfers, there is no basis for civil liability of the bank in cases of BEC-type fraud. The courts emphasise the strict application of the unique identifier regime — the IBAN — and underline that banks, by complying with the technical rules for executing payments, do not act unlawfully, even if the result is a loss suffered by a third party outside the banking relationship. Additionally, they recognise the distinction between the regulatory/criminal sphere, where the bank may be liable for breaches of obligations towards the authorities, and the civil sphere, where a duty to compensate is admitted only if the breached rule was intended to directly protect the injured party — which, as interpreted, is not the case with AML rules. In short, the case law position has been that there is no duty to compensate on the part of the receiving bank in cases of fraudulent transfers where the bank acted in the ordinary manner.
It should be mentioned that, to date, no Portuguese judgments have been identified adopting a position contrary to this line of authority. Although injured parties frequently bring actions against banks in financial fraud cases, alleging security or monitoring failures, the courts have rejected such claims in light of the existing legal framework. This position is not exclusive to Portugal: a similar trend can also be observed in other European jurisdictions, with strict application of the unique identifier rule in accordance with EU directives. For example, recent French case law has reaffirmed that the execution of a transfer in accordance with the IBAN provided exonerates the bank from liability, and that a generic duty of supervision not provided for by law cannot be imposed ex post. In Spain and Italy as well, except in situations involving intentional conduct by the bank itself, the prevailing view has been that victims of scams such as BEC must bear the risk of the error, in the absence of gross fault by the financial institution.
6. Critical Analysis and Prospects
From the injured party’s point of view, the picture described is discouraging: despite having fallen victim to a sophisticated scheme, that party is left without civil compensation from the entity which, at first sight, appeared to have some capacity to avoid or minimise the damage — the bank that received the fraudulent funds. Portuguese courts place the emphasis on the self-responsibility of the user of the payment system, holding that it is for participants in transactions to ensure the accuracy of the data and to take precautions against fraud. The victim cannot shift the loss to the bank where the latter acted within the parameters of the law. This allocation of risk has a rationale from the perspective of the efficiency of the banking system: if every bank had a duty to manually confirm the correspondence of names and proactively monitor millions of transactions in real time, financial traffic would become more costly and slower. Moreover, it would create potentially unlimited liability for banks, which could become liable for virtually any fraud occurring between customers of other institutions. The current legal solution seeks to avoid that disincentive effect, assuring payment service providers that, provided they comply with the technical rules — for example, using the IBAN as the reference — and the prescribed diligence protocols, they will not be held liable for frauds committed by third parties outside their direct control. In return, injured parties are encouraged to adopt greater precautions, such as confirming by telephone any instructions to change bank account details received by email, or implementing internal verification systems.
Nevertheless, from the standpoint of substantive justice, this solution leaves victims of BEC fraud in a vulnerable position. In practice, the injured supplier will hardly obtain compensation: the true perpetrators of the fraud are unknown or insolvent — hackers, “mules” and criminal networks often based abroad — and the bank that could have acted as the “last barrier” to stop the fraud is not liable for the damage. The question therefore arises whether the legal system offers sufficient protection to these victims, or whether it would be desirable to strengthen banks’ duties and responsibilities in such contexts. One strand of legal scholarship argues that banks occupy a privileged position of control over financial movements and possess advanced means of detecting suspicious patterns, and should therefore bear a share of responsibility when they fail to prevent evident abuses. For example, if a particular transfer has manifestly atypical features or indicators of fraud — such as a newly onboarded beneficiary, a large amount followed by immediate withdrawals — it might be possible to require the bank, by law, to take minimal intervention measures, such as contacting the payer or delaying the credit for verification. Failure to take such care could then constitute negligence. However, as seen above, current legislation does not expressly impose such a reinforced duty of supervision in regular transfers, and the courts have been reluctant to construct it by interpretation.
There are signs, however, that the legal framework may evolve in order to mitigate exposure to frauds of this kind. At European level, Regulation (EU) 2024/886, known as the Instant Payments Regulation, was recently approved and introduces concrete measures to increase the security of bank transfers in euros. Among these measures is the obligation for payment service providers to offer a service verifying the name of the beneficiary immediately before the authorisation of an instant transfer, warning the payer if the name indicated does not correspond to the holder of the IBAN provided. Additionally, it provides that, if the payment service provider fails to carry out that verification or fails to properly warn the customer, and this results in an incorrect payment transaction — funds credited to an account different from the intended one — the bank must promptly reimburse the payer for the amount transferred. Conversely, if the bank carries out the verification and, despite being warned of the discrepancy, the customer chooses to proceed with the transfer, liability for the error remains with the customer. That situation is therefore treated in the same way as the provision of an incorrect IBAN, in accordance with the logic already present in PSD2.
Although this new regime currently applies only to instant transfers in euros, its relevance should not be underestimated. It signals a regulatory trend towards strengthening banks’ duties of diligence in order to prevent fraudulent transfers, moving closer to mechanisms already adopted in some countries, such as the Confirmation of Payee system in the United Kingdom. It is expected that the widespread adoption of name/IBAN matching verification will drastically reduce the effectiveness of BEC frauds within the European area, by making it more difficult for fraudsters to go unnoticed. In any event, it should be noted that Regulation 2024/886 did not apply at the time of the cases analysed here, nor does it yet cover traditional, non-instant transfers. It is a prospective change. Nevertheless, its mention illustrates the legislator’s response to the need for greater protection of users and may, in the future, influence the interpretation of banking duties even outside the strict scope of instant payments.
Finally, from a practical and preventive perspective, victims of BEC fraud currently have few recovery mechanisms beyond criminal proceedings and international cooperation for the freezing of assets. It is crucial to act quickly as soon as the fraud is discovered: notify the bank involved and the competent authorities in an attempt to block the funds before they are dissipated. Unfortunately, as the hypothetical case demonstrates, by the time the bank is alerted, the funds have often already been moved successively, making recovery unfeasible. Injured parties should also file criminal complaints both in their own country and in the country of the destination bank — in this case, Portugal — so that any criminal liability for fraud, forgery and money laundering may be investigated. Although criminal proceedings do not guarantee compensation, they may lead to the punishment of those responsible and, if seized assets are identified, may allow for some recovery. In addition, it is advisable to file a complaint with the banking regulator — Banco de Portugal — setting out the facts, not in order to obtain compensation, but so that any regulatory breaches by the bank may be investigated, such as failures in AML protocols. Such scrutiny may result in sanctions against the financial institution or in orders to improve procedures, indirectly contributing to higher standards of diligence. In short, under the current circumstances, the legal response available to a BEC victim lies more in the criminal and regulatory spheres than in the civil sphere.
7. Conclusions
In conclusion, in light of the current state of the applicable law and case law, the situation may be summarised in the following key points:
Absence of a duty to verify name/IBAN correspondence: Banks are not legally required to confirm whether the name of the beneficiary indicated matches the holder of the destination account. The execution of a transfer solely on the basis of the IBAN provided by the payer is considered valid and sufficient, releasing the bank from that additional verification.
Risk allocated to the payer/victim: If the IBAN indicated does not correspond to the intended beneficiary — whether due to error or fraud suffered by the payer — the risk of the undue payment falls on the payer who provided the data, even if that payer was himself deceived. As a rule, there is no automatic reimbursement by the bank. The law currently treats this situation as a customer error, not as a failure by the payment service provider.
Compliance duties do not, by themselves, generate civil liability towards third parties: Breach of anti-money laundering prevention obligations or of duties of diligence in monitoring transactions may expose the bank to administrative and reputational penalties, but it does not automatically establish a civil liability link in relation to the victims of a fraud such as BEC. Such rules are interpreted as protecting general interests — legality and the stability of the financial system — rather than specific individual interests. Therefore, their breach does not satisfy the specific unlawfulness requirement under Article 483 of the Civil Code in the context of a compensation action brought by the injured party.
Settled case law denying bank liability: Portuguese higher courts have repeatedly held that there is no civil liability on the part of banks in cases of fraudulent transfers of the BEC type. Judgments of the Supreme Court of Justice in 2023 and of the Courts of Appeal — Coimbra in 2022 and Porto in 2025 — confirm that, where the bank acts in accordance with the data in the transfer order, namely the IBAN, and there are no indications of collusion or intentional wrongdoing by the bank itself, there is no culpable breach of duty justifying compensation to the injured party.
In short, the current Portuguese legal regime does not impose civil liability on banks for losses caused by BEC frauds, except in exceptional circumstances that have not yet been recognised in judicial practice.
The scenario may change with legislative and case law developments — notably through new payment verification obligations imposed by European law — but until then, participants in commercial transactions should strengthen their own confirmation and alert procedures in order to avoid falling into the traps of this type of fraud. Trust in the banking system remains a value to be preserved, but without a specific legal basis supporting it in these cases, the principle of user self-responsibility and strict compliance with transfer procedures prevails, leaving injured parties to pursue alternative avenues in their search for justice.