The case, explained
Liability for bank fraud: proof of gross negligence
7 min read · Updated September 2026 · Editorial oversight: Avv. Federico Papa
Recent case law has outlined a complex framework regarding digital payments and cybersecurity. According to reports from Diritto e Giustizia and Quotidiano Giuridico, the focus has shifted from the mere technical execution of the transaction to the assessment of the professional diligence required of credit institutions, balanced with the user's conduct. This article examines how case law is divided between protecting the account holder and exonerating the intermediary in cases of gross negligence. Through the analysis of the regulations and our twin case, we will see how the boundary between simple distraction and gross negligence can determine the right to a refund or the loss of illegally stolen sums.

In brief
The article analyzes the liability of intermediaries in cases of phishing and smishing, focusing on the distribution of the burden of proof. Case law is divided: while it is up to the institution to prove the user's gross negligence, rulings such as Cass. 7214/2023 exonerate the intermediary in the presence of the customer's severe negligence. The parameter of technical diligence under Art. 1176 of the Civil Code is examined, framing the issue within contractual liability.
The facts
The case came to the attention of the Supreme Court of Cassation after an account holder suffered the unauthorized withdrawal of large sums from their account following a cyber attack. Unlike what happens in other proceedings, the claim for reimbursement had been upheld in the lower courts and the Supreme Court, with order 3780/2024, rejected the appeal by Poste Italiane S.p.A., confirming the order to refund. The plaintiff had challenged the vulnerability of the institution's IT system. The issue of fraudulent messages inserted into the same chain of official bank communications, capable of misleading even a moderately prudent user, constitutes instead a typical scenario highlighted by lower courts and the Banking and Financial Arbitrator (ABF) to exclude gross negligence. Other aspects of the case are covered in dedicated articles in this column.

The rules at play
The regulatory pillar is Legislative Decree 11/2010, which implements European directives on payment services.
- Article 10 establishes the burden of proof on the bank: if the user denies authorization, the institution must prove that the transaction was authenticated and did not suffer malfunctions.
- Article 12 limits the customer's liability only to cases of fraud or gross negligence in failing to comply with credential custody obligations.
- Article 1176 of the Civil Code imposes technical diligence on the banker, a professional parameter higher than that of the average person, requiring the adoption of the best available security technologies to prevent intrusions and spoofing phenomena.
What case law says
Supreme Court case law has clarified that the intermediary must provide proof of the proper functioning of the systems, framing the issue within contractual liability under Art. 1176, paragraph 2, of the Civil Code and Legislative Decree 11/2010. The thesis that qualifies online banking as a dangerous activity under Art. 2050 of the Civil Code currently represents a minority view. The jurisprudential framework is not unequivocally pro-customer, but is divided: while on one hand the mere recording of system logs is not enough to demonstrate the user's gross negligence, on the other hand the Supreme Court, with order 7214/2023, established that handing over credentials to third parties following a deceptive email constitutes gross negligence, exonerating Poste Italiane S.p.A. from all liability.
- Try edit.legal AI
Analysis drafted and verified with edit.legal
To verify the provisions cited in this article, we used edit.legal. Test our legal AI on official sources and apply it to your own matters.
What it teaches professionals
- For lawyers representing account holders, it is essential to produce screenshots and documentation demonstrating the plausibility of the fraudulent message to downgrade negligence from gross to ordinary.
- For institutional lawyers, the defense must focus on producing technical expert reports certifying system compliance with the highest PSD2 standards.
- It is always necessary to check whether the bank sent real-time alerts and whether it adopted automatic blocking systems for suspicious transactions to foreign accounts or beneficiaries never previously recorded.
Update and rectification note (17 September 2026)
The previous version of this article incorrectly reported that Supreme Court case law had a consolidated orientation in favor of the account holder and that it qualified online banking as a dangerous activity. Furthermore, it attributed arguments about fraudulent messages in the official chain to the Supreme Court, which instead belong to lower courts and the ABF, and reported an inaccurate procedural history for Poste Italiane. The text has been corrected based on official documents: the Supreme Court frames the issue within contractual liability and presents a divided orientation, having rejected Poste's appeal with order 3780/2024, but having exonerated it due to the customer's gross negligence with order 7214/2023.
References: D.Lgs. 11/2010Art. 1176 c.c.Art. 2050 c.c.Cass. 7214/2023Cass. 3780/2024
Related cases

Frequently asked questions
What exactly is meant by gross negligence of the account holder?
Gross negligence consists of conduct characterized by extraordinary imprudence, such as ignoring obvious security warnings or voluntarily handing over all credentials to strangers.
Must the bank always refund in case of phishing?
No, a refund is due only if the institution fails to prove the user's gross negligence or if its security systems were not up to the required professional standards.
How much time do I have to report an unauthorized transaction?
The user must communicate the unauthorized transaction to the bank without delay and in any case within 13 months from the debit date to retain the right to a refund.
Verified legal research and drafting with edit.legal
Legal research and drafting with citations checked against official databases. edit.legal is free to try, no credit card.
Try edit.legal for free