Find notable cyber news and cases, enriched with sources, timelines, and signals.

CJEU PSD2 refund opinion for phishing victims

Regulatory/Legal (General)
First reported
Last updated
Happening score
H score 12
1 unique sources, 1 articles

Summary

Hide ▲

The CJEU Advocate General issued a formal PSD2 opinion that could force banks to refund unauthorized transactions immediately, changing reimbursement handling for phishing victims across the EU. The dispute stems from a Polish preliminary-ruling case involving PKO BP S.A. and a customer who lost money after entering credentials on a fake bank login page. Rantos said a bank may withhold an immediate refund only when it has good reason to suspect fraud, and that suspicion must be reported in writing to the competent national authority. The opinion also keeps open a later recovery path if the bank proves gross negligence or intent by the customer.

Related Happenings

US District Court for the Eastern District of Texas complaint filed seeking damages against SonicWall on vendor-liability exposure over a cyber breach

Regulatory/Legal Action
First: 27.02.2026 00:02 Last: 27.02.2026 00:02 Sources 1

About this happening: Marquis filed a **federal complaint** in **US District Court for the Eastern District of Texas** against **SonicWall**, seeking **damages** over a **data breach** it says the vend...

Timeline

  1. 08.03.2026 02:00 2 articles · 2mo ago

    CJEU adviser issues PSD2 refund opinion

    Legal Policy Action Update

    Athanasios Rantos, Advocate General of the CJEU, issued a formal opinion in a Polish preliminary-ruling dispute between PKO BP S.A. and a customer who entered bank credentials on a fake login page after a malicious link on an auction platform; the opinion says banks must immediately refund unauthorized transactions under PSD2 unless they have reasonable grounds to suspect fraud, and they may later pursue recovery if gross negligence or intent is proven.

    Show sources