European Union · PSD2 · SEPA and card disputes · 32 min read
How to Seek a Scam Payment Refund in the European Union
A scam payment can sometimes be refunded in the European Union, but there is no single EU recovery rule for every loss. The first legal question is whether the payment was unauthorised, authorised after deception, incorrectly executed, a card purchase for goods that never arrived, an investment transfer, or a fiat payment followed by a crypto transfer. Those labels control the route: PSD2 and its national implementation provide a strong framework for certain unauthorised payments; a SEPA Recall is a bank-to-bank recovery message rather than a guaranteed reversal; chargeback is usually a card-scheme or contract process; and consumer, investment, criminal and out-of-court remedies each have different scopes. This guide was checked against official material available on 28 July 2026. It is independent editorial information, not legal advice, not a promise of recovery and not a substitute for the rules and deadlines in the country, account contract and payment scheme that apply to your case.
Sources for the introduction, figures and summary
- EUR-Lex: Directive (EU) 2015/2366 on payment services (PSD2)Adopted 25 November 2015; Official Journal 23 December 2015
- European Commission: payment servicesUpdated 27 November 2025
- EBA and ECB: 2025 joint report on payment fraudPublished 15 December 2025
- European Supervisory Authorities: tips for online financial frauds and scamsPublished 15 December 2025
- European Commission: protecting consumers when buying onlineUpdated 16 July 2026
- Your Europe: payments, transfers and cheques in the EULast checked 28 April 2026
- European Payments Council: current SEPA Credit Transfer rulebook and implementation guidelines2025 SCT Rulebook version 1.1 effective 5 October 2025; accessed 28 July 2026
- European Payments Council: 2025 SEPA Credit Transfer Rulebook version 1.0Issued 28 November 2024; entered into force 5 October 2025
- Your Europe: shipping and deliveryLast checked 29 April 2026
- Your Europe: consumer rights when shopping in the EULast checked 25 September 2025
- European Consumer Centres Network: services and complaint scopeAccessed 28 July 2026
- European Securities and Markets Authority: check whether an investment firm is regulatedAccessed 28 July 2026
- EUR-Lex: Regulation (EU) 2024/886, including verification of payeeOfficial Journal text; checked 29 July 2026
- European Payments Council: Verification of Payee scheme rulebookVersion 1.0 entered into force 5 October 2025
- European Consumer Centres Network: cross-border complaint processAccessed 28 July 2026
- European Banking Authority: how to complain about a financial institutionAccessed 28 July 2026
- European Commission: complain about a financial service provider in another EEA country through FIN-NETAccessed 28 July 2026
- European Supervisory Authorities: crypto-asset risks and consumer protection under MiCAPublished 6 October 2025
- European Banking Authority: registers of credit, payment and electronic-money institutionsAccessed 28 July 2026
- European Banking Authority: frauds and scams misusing the EBA nameAccessed 28 July 2026
The EU baseline is shared; the remedy is still country- and payment-specific
Direct answer: EU law creates a common payment-services baseline, but the practical refund route is determined by the payment type, the payer's consent, the provider's location, national transposition and any card or transfer scheme rules.
Start with the payment, not with the word “scam.” PSD2 deals with payment services and distinguishes consent, authorisation, authentication, execution and liability. Consumer contract law addresses a genuine trader's failure to deliver. Card schemes may offer chargeback. SEPA rules define messages that banks can exchange after a credit transfer. Criminal authorities investigate fraud. A financial ombudsman or alternative-dispute body reviews a complaint against a provider only where its mandate allows. These systems can overlap, but none should be presented as a universal recovery programme.
The distinction matters most when a bank says, “You approved it.” A transfer that the customer deliberately entered and confirmed after a fraudster lied about an investment is not automatically treated like a transfer secretly initiated from a compromised account. Conversely, use of the correct password, app or authentication factor does not by itself settle an unauthorised-payment dispute under Article 72 of PSD2. The complaint must describe what the customer did, what the fraudster did and which exact transaction the customer did or did not consent to.
National law remains central. PSD2 is a directive implemented through national legislation, and national courts, regulators and complaint bodies apply that law. Local rules may provide more favourable protection in some areas, and local procedures decide who can complain, in what language, through which form and within what further limitation period. A resident of one Member State using a payment institution authorised in another may also need to identify the provider's home and host regulators before choosing an out-of-court route.
Do not treat policy headlines as operative rights. The Commission recorded a political agreement on the review of the payment-services framework on 27 November 2025. Proposed or agreed reforms do not make every future PSD3 or Payment Services Regulation provision applicable to every payment made earlier. A sound claim states the transaction date and anchors the requested remedy in the law then applicable, while checking any later national change that is actually in force.
The EBA and ECB reported on 15 December 2025 that payment fraud totalled €4.2 billion in the EEA in 2024 and that users bore about 85% of credit-transfer fraud losses, mainly where scammers manipulated them into initiating payments. That aggregate finding explains why authorised-transfer cases need careful alternative arguments; it does not predict an individual outcome or prove that every manipulated transfer is irrecoverable.
| What happened | Primary route to test | Do not confuse it with |
|---|---|---|
| A payment was initiated without the payer's consent | PSD2 unauthorised-payment claim under national law | A voluntary SEPA Recall or merchant chargeback |
| The payer entered a transfer after deception | Immediate bank recovery request plus national complaint and other legal routes | An automatic PSD2 unauthorised-payment refund |
| A real trader took a card payment but did not deliver | Trader claim, consumer rights, and possible card chargeback | Account takeover or investment compensation |
| A bank transfer was executed to the wrong account or amount | Incorrect-execution analysis and scheme recovery request | Fraud merely because the result was unwanted |
| Fiat reached an exchange and crypto then left a wallet | Analyse the fiat leg and the crypto leg separately | A single reversible bank transfer |
Source: EUR-Lex: Directive (EU) 2015/2366 on payment services (PSD2)Adopted 25 November 2015; Official Journal 23 December 2015
Source: European Commission: payment servicesUpdated 27 November 2025
Source: EBA and ECB: 2025 joint report on payment fraudPublished 15 December 2025
The first hour: stop further loss and create a transaction-grade record
Direct answer: Contact the payment provider through a verified channel immediately, secure compromised accounts, ask for the precise recovery action available for that rail, and preserve the evidence before chats, adverts or account pages disappear.
Use the number in the banking app, on the physical card or on the provider's independently typed official website. A message in the scam conversation is not a verified contact route. Tell the provider whether a card, credit transfer, direct debit, wallet, e-money account or exchange was involved. Ask for a fraud or complaint reference, the time of the report and written confirmation of any card block, account restriction, transfer Recall, request for recall or beneficiary-bank notification.
If credentials, a device, screen-sharing access or an authentication code may have been exposed, change the affected password from a clean device, revoke unknown sessions, remove remote-access software, call the mobile operator if a SIM swap is possible, and review email forwarding rules. Blocking a card does not necessarily secure online banking; changing online-banking access does not necessarily stop a direct-debit mandate. Ask the provider what it has actually disabled.
Preserve evidence in original form. Export account statements or transaction receipts; save complete chats with dates, usernames and message identifiers; record telephone numbers and email headers; capture the advert and landing-page URL; download invoices, supposed licences and contract terms; and retain the recipient IBAN, BIC, merchant descriptor, card authorisation code, crypto address and transaction hash where relevant. A screenshot is useful, but a statement or platform export is often easier to authenticate later.
Write a short chronology while memory is fresh. Separate statements made by the fraudster from actions taken by the payer and actions shown in the bank. Record the exact warning displayed before approval, the beneficiary name shown, whether the system returned a name match, and what the customer believed the payment was for. Avoid editing the original files; place working copies in a separate folder and keep an index.
Report the incident to the national police or designated online-fraud channel when deception or unauthorised access is involved. The 15 December 2025 joint European supervisory factsheet tells consumers to inform the bank or financial firm immediately and report the incident to police or the national financial authority. A police reference can support the chronology, but it does not force a bank or beneficiary to refund.
- 01Freeze
Stop cards, sessions, mandates or exchange withdrawals that remain exposed; do not send a “release,” “tax” or “verification” payment.
- 02Notify
Call the sending provider and request both the legally relevant claim route and the fastest scheme-level recovery message.
- 03Preserve
Save statements, transaction identifiers, chats, warnings, recipient details and device events in their original form.
- 04Report
Use the competent national criminal and financial channels; record every reference and response date.
- 05Review
Map each payment separately. A series may contain card, transfer and crypto legs with different remedies.
Source: European Supervisory Authorities: tips for online financial frauds and scamsPublished 15 December 2025
Source: European Commission: protecting consumers when buying onlineUpdated 16 July 2026
Source: EUR-Lex: Directive (EU) 2015/2366 on payment services (PSD2)Adopted 25 November 2015; Official Journal 23 December 2015
Related steps:Investment Scam Recovery: Evidence and Complaint Routes · Crypto Scam Recovery: Trace the Payment Chain
Authentication is evidence, not the whole answer
Direct answer: Under PSD2 Article 72, recorded use of a payment instrument is not necessarily sufficient by itself to prove that the payer authorised the transaction or acted fraudulently or with gross negligence.
When a customer denies authorisation, the provider must prove that the transaction was authenticated, accurately recorded and entered in the accounts, and that it was not affected by a technical breakdown or other deficiency in the service. Article 72 then makes a separate point: use of the instrument recorded by the provider is not necessarily enough, on its own, to prove consent, fraud or intentional or grossly negligent failure by the payer. The provider must supply supporting evidence if it alleges fraud or gross negligence.
That distinction is practical. A log may show that an app on an enrolled phone completed strong customer authentication. It may not show who controlled the screen, what beneficiary and amount were displayed, whether malware altered the journey, whether the warning was visible, or whether the fraudster initiated a different payment after remote access. Ask the provider for a transaction-specific explanation that deals with those facts, subject to the disclosure rights and security limits under national procedure.
Strong customer authentication is valuable prevention, but it does not make manipulation disappear. The EBA and ECB's 2025 report found that authentication remained effective against the fraud types it was designed to mitigate, especially card fraud, while manipulation of payers was rising. For an intentionally approved transfer, this evidence can support the provider's classification as authorised; for a denied transaction, it is part of the proof analysis rather than an automatic conclusion.
Article 74's frequently quoted €50 amount is also narrower than many summaries suggest. It concerns specified losses from certain unauthorised transactions arising from a lost or stolen payment instrument or misappropriation before notification, with exceptions. Fraud or intentional or grossly negligent failure by the payer can change liability. There are also circumstances in which the payer bears no loss, including where loss, theft or misappropriation was not detectable before payment except for payer fraud. National implementation and the precise instrument therefore matter.
A strong rebuttal avoids adjectives and tests the evidence. Instead of writing “the bank was careless,” identify the disputed inference: “The response relies on successful authentication but does not address my statement that I did not create or approve transaction X, the new-device event at 14:03, the beneficiary change at 14:07, or why the provider treats the app log alone as proof of consent.” This gives an ombudsman or adjudicator a reviewable issue.
| Provider proposition | Focused question | Useful record |
|---|---|---|
| The correct device was used | Was it a known device, a newly enrolled device or a remote session? | Device enrolment and session timeline |
| Authentication succeeded | What transaction details were bound to the authentication step? | Authentication method, time, amount and payee shown |
| The customer was grossly negligent | Which precise duty was breached and what supports the higher threshold? | Contract term, warning shown and customer chronology |
| The customer benefited | Where did the funds go and what evidence links the recipient to the customer? | Recipient and account-ownership data available to the provider |
Source: EUR-Lex: Directive (EU) 2015/2366 on payment services (PSD2)Adopted 25 November 2015; Official Journal 23 December 2015
Source: EBA and ECB: 2025 joint report on payment fraudPublished 15 December 2025
SEPA Recall and Request for Recall are bank messages, not guaranteed reversals
Direct answer: For a SEPA Credit Transfer, the sending bank may use a Recall for defined scheme reasons or a different Request for Recall by the Originator, but the rulebook does not promise that the beneficiary's bank will return available funds.
The current EPC page identifies the 2025 SEPA Credit Transfer Rulebook version 1.1 as the operative rulebook from 5 October 2025. Its operational Recall provisions carry forward the rules published in the 2025 version 1.0. Ask the provider which scheme and version governed the transaction; instant credit transfers and non-SEPA rails should not be assumed to use the same message or timetable.
A formal SCT Recall is initiated by the Originator PSP — the sending payment service provider — which may act on behalf of the originator. The listed reasons are duplicate sending, a technical problem resulting in erroneous execution and a fraudulently originated SCT instruction. For duplicate sending and technical error, the Recall must be sent within ten Banking Business Days following execution. For the fraudulently originated reason, the rulebook allows the Originator PSP to send the Recall within thirteen months following the execution date.
Those periods are scheme message windows, not refund deadlines for a consumer. “Fraudulently originated” is also a scheme reason; it should not be read as converting every authorised scam transfer into an unauthorised payment claim. Ask the bank to identify the reason code it used, when it transmitted the message and whether the beneficiary bank acknowledged it.
The Beneficiary PSP must provide a positive or negative response within fifteen Banking Business Days after receiving the Recall. A negative response can result from insufficient funds, a closed account, a legal reason, beneficiary refusal, no response from the beneficiary, failure to receive the original transfer, or funds already returned. Where the funds have been credited, handling can depend on national law, the account contract and whether beneficiary authorisation is required. This is why a technically valid Recall can still end without recovery.
A Request for Recall by the Originator is a distinct procedure that can be considered where the narrow formal Recall reasons do not fit. It asks the beneficiary side to consider return and can depend on the beneficiary's response and applicable law. It is not a hidden chargeback and does not create a guaranteed entitlement. The complaint should state whether the bank sent a formal Recall or this request, because the names are often blurred in telephone notes.
Speed remains useful even when a longer scheme window exists. Funds may be moved from the recipient account within minutes, while later interbank processing cannot recreate a balance. Ask the sending bank to preserve the transaction reference, beneficiary IBAN, transmission and response timestamps, and every returned reason code. If the provider refuses to send any recovery message, request its reason in writing and check the account agreement and national complaint route.
| Procedure | When it may be used | Verified scheme timing | What it does not prove |
|---|---|---|---|
| Recall — duplicate or technical error | One of the two specified execution-error reasons | Send within 10 Banking Business Days after execution | That the customer has a fraud refund right |
| Recall — fraudulently originated SCT | The Originator PSP uses the scheme's fraud reason | Send within 13 months after execution | That funds remain or must be returned |
| Beneficiary PSP response | After receipt of a Recall | Positive or negative response within 15 Banking Business Days | That silence or refusal creates a refund |
| Request for Recall by the Originator | A different originator-request route under the rulebook | Check the applicable rulebook and bank handling | A compulsory debit from the beneficiary |
Source: European Payments Council: current SEPA Credit Transfer rulebook and implementation guidelines2025 SCT Rulebook version 1.1 effective 5 October 2025; accessed 28 July 2026
Source: European Payments Council: 2025 SEPA Credit Transfer Rulebook version 1.0Issued 28 November 2024; entered into force 5 October 2025
Source: EUR-Lex: Directive (EU) 2015/2366 on payment services (PSD2)Adopted 25 November 2015; Official Journal 23 December 2015
Related steps:UK APP Scam Reimbursement Rules
Card chargeback is different from PSD2 and consumer contract rights
Direct answer: A chargeback is generally a card-scheme or issuer process, while an unauthorised card payment can engage PSD2 and a genuine trader's non-delivery can create separate consumer-law rights.
Use three labels. First, an unauthorised card transaction is a payment the cardholder did not consent to; the PSD2 notification, proof and liability framework may apply through national law. Second, an authorised card purchase can be disputed through a scheme reason such as goods not received, service not provided, duplicate processing or a misdescribed transaction if the applicable scheme and issuer rules permit. Third, the consumer may have a direct contractual or statutory claim against a trader regardless of whether the issuer accepts a chargeback.
There is no single published EU chargeback deadline that safely applies to every card, reason code and country. The European Commission's current online-safety page tells consumers they can ask their bank to freeze cards or seek a chargeback, and Commission guidance in merchant-cancellation contexts advises checking whether the card company's chargeback policy applies. That is materially different from an EU statute promising chargeback in all cases. Ask the issuer for the exact scheme, reason code, evidence list and deadline governing your transaction.
For a merchant dispute, contact the trader in writing unless doing so creates a security risk or the trader is plainly fictitious. State the order, contractual delivery date, what was received, the remedy requested and a reasonable response date. Your Europe says that, unless another time was agreed, a trader should deliver within thirty days; after an additional reasonable period without delivery, the consumer may terminate and seek reimbursement, with exceptions where delivery was refused or timing was essential. These contract steps can also create the evidence an issuer requests.
For a fake storefront that has disappeared, preserve the checkout page, merchant descriptor, order confirmation, domain and any delivery tracking. The party named on the card statement may be a payment facilitator rather than the website brand. Give the issuer both names and explain why the transaction is a scam or non-delivery dispute. Do not mark it unauthorised merely because the merchant was dishonest if the cardholder knowingly approved the purchase.
Investment deposits require extra precision. A card payment to a genuine, regulated platform may have purchased the service described even if the customer then made a losing or fraudulent transfer elsewhere. A card payment directly to a sham broker may raise different scheme issues. The card network's classification, merchant evidence and chain of funds matter. Chargeback should not be advertised as an investment-loss insurance policy.
| Card event | Primary question | Evidence to attach |
|---|---|---|
| Card details were stolen | Did the cardholder consent to this transaction? | Statement, possession timeline, device/account alerts |
| Goods never arrived | What did the trader promise and what remedy was requested? | Order, delivery terms, complaint and tracking |
| Service differed materially | What representation and performance can be proved? | Advertisement, contract, delivered service and correspondence |
| Card funded an exchange or wallet | What did the merchant itself provide, and what happened next? | Card receipt, exchange ledger, wallet withdrawal and transaction hash |
Source: European Commission: protecting consumers when buying onlineUpdated 16 July 2026
Source: Your Europe: payments, transfers and cheques in the EULast checked 28 April 2026
Source: Your Europe: shipping and deliveryLast checked 29 April 2026
Source: EUR-Lex: Directive (EU) 2015/2366 on payment services (PSD2)Adopted 25 November 2015; Official Journal 23 December 2015
Fake merchant, non-delivery and investment scams need different proof
Direct answer: A missing parcel from an identifiable trader is a consumer dispute; a fabricated shop may be criminal fraud; and a sham investment platform belongs primarily in the financial-regulatory and criminal track, even when all three began with an online advert.
For an identifiable professional trader, establish the legal entity, country, order terms and delivery commitment. EU consumer rights generally distinguish a trader from a private seller. Your Europe states that professional-trader purchases can carry delivery, conformity and withdrawal rights, while private-to-private transactions do not receive the same EU consumer framework. A marketplace logo does not prove that the marketplace itself was the seller.
A website can imitate a trader without any real entity behind it. Search the trade register and check whether the stated address, VAT number, telephone number and domain correspond. A copied registration number can identify an innocent company rather than the scammer. If the supposed trader cannot be identified or is carrying out fraud, ECC-Net says the case may fall outside its complaint-assistance remit. Bank action and a criminal report become more important than a conventional trader negotiation.
For non-delivery, pin down the promised date. If the contract set no different period, Your Europe describes the thirty-day delivery baseline and the normal additional reasonable period before termination. Do not use that rule mechanically where the goods, service, seller or agreed timing falls outside its scope. Attach the order confirmation and the notice giving additional time, or explain why no further time was required because the trader refused delivery or the agreed date was essential.
For investments, identify the legal firm before discussing performance. ESMA says firms may provide investment services in the EU only when authorised and directs investors to national and ESMA registers. A matching brand is not enough: compare the legal name, domain, address, licence status and authorised activities. Clone firms deliberately borrow the name and number of a real entity. Record the payment recipient as well as the platform name shown on screen.
A real investment loss is not automatically a scam, and an investor compensation scheme is not a guarantee against market loss or fraud by an unauthorised firm. If the platform fabricated balances, blocked withdrawals unless a further “tax” was paid, impersonated an authorised firm or directed funds to unrelated personal accounts, state each fact and source. Report the case to police and the relevant national financial authority; ask the payment provider about available recovery without overstating the regulator's power to obtain funds.
| Pattern | First demand | Best factual anchors | Likely escalation |
|---|---|---|---|
| Real EU trader, no delivery | Deliver by a reasonable final date or reimburse after termination | Legal entity, order, agreed date, tracking, written notice | ECC-Net for eligible cross-border trader complaint; ADR or court where appropriate |
| Unidentifiable fake shop | Bank/card recovery action and fraud registration | Domain, merchant descriptor, copied identity, advert, payment record | Police and relevant national reporting channel |
| Regulated firm service dispute | Formal complaint identifying rule or contract failure | Licence, client agreement, advice records, account ledger | Financial ombudsman/ADR or regulator within its remit |
| Clone or sham investment site | Stop payments, issue recovery request, preserve recipient trail | False domain, payment destination, licence mismatch, withdrawal demands | Police and national financial authority |
Source: Your Europe: consumer rights when shopping in the EULast checked 25 September 2025
Source: Your Europe: shipping and deliveryLast checked 29 April 2026
Source: European Consumer Centres Network: services and complaint scopeAccessed 28 July 2026
Source: European Securities and Markets Authority: check whether an investment firm is regulatedAccessed 28 July 2026
Build evidence for both the sending and receiving sides
Direct answer: The sending provider needs a precise claim and recovery instruction, while information about the receiving account, payee check and movement of funds should be preserved through provider and authority channels rather than guessed from public data.
The sending bank or payment institution is normally the first operational contact because it authenticated or executed the payment and can send the relevant scheme message. Give it the transaction ID, amount, currency, time, beneficiary name and account, payment purpose shown at authorisation, scam report time and police reference when available. Ask whether it contacted the beneficiary PSP and for the timestamp and response, but do not assume the sender can disclose protected information about the recipient.
The receiving provider may hold the account that first received the funds, but that does not mean it owes the payer an automatic refund. Its ability to restrict or return funds depends on the facts, applicable law, account contract, scheme and instructions from competent authorities. Direct emails to a generic address may not be treated as an authenticated interbank claim. Ask the sending provider and police to use the correct operational channel.
Regulation (EU) 2024/886 requires a payer’s payment service provider to offer a free verification-of-payee service before a credit transfer is authorised. It compares the supplied payee name with the account identifier and requires a warning where they do not match or almost match. The compliance dates are phased: providers in Member States whose currency is the euro were due to comply with this part by 9 October 2025, while providers in non-euro Member States have until 9 July 2027. In July 2026, availability therefore still depends on the provider and jurisdiction.
The European Payments Council’s Verification of Payee scheme entered into force on 5 October 2025 to standardise checks for relevant SEPA payments. Record the result displayed — match, close match, no match or unavailable — and the name proposed, if any. A match does not establish that the recipient is honest, and a mismatch does not by itself create a refund. The result is one part of the authorisation journey.
Ask what happened after a warning. Did the payer override a clear mismatch, did the app show an unavailable result, or did the bank supply a different name? Was the payment made before the service applied to that provider or instrument? Because rollout and legal obligations have date and geographic scope, do not import a current payee-check expectation into an older payment without checking the applicable rules.
For account takeover, request preservation of device enrolment, IP and session events, payee creation, limit changes, authentication method, alerts and communications. For an authorised scam, preserve the warning screen, transfer purpose, payee-check result, branch or call-centre interaction and any attempt to cancel. For a merchant payment, preserve the merchant category and descriptor. For a crypto on-ramp, obtain both the bank record and the exchange ledger.
Evidence should be proportionate and lawful. A victim does not need to publish an alleged recipient's personal data or contact family members. Put identifiers in the bank and police file, redact them in public posts, and let competent bodies obtain protected records. Public accusations can create privacy, defamation and investigation risks while doing little to preserve funds.
- Sending side: transaction reference, authentication, warning, cancellation request and interbank message.
- Receiving side: beneficiary account identifier, PSP, Recall response and any authority reference.
- Payee check: exact displayed result, proposed name and timestamp — not a paraphrase from memory.
- Sequence: show when the provider learned of fraud and whether later transactions still left the account.
- Disclosure: request relevant records through the complaint or authority process; do not demand unlawful personal-data release.
Source: EUR-Lex: Regulation (EU) 2024/886, including verification of payeeOfficial Journal text; checked 29 July 2026
Source: European Payments Council: Verification of Payee scheme rulebookVersion 1.0 entered into force 5 October 2025
Source: European Payments Council: 2025 SEPA Credit Transfer Rulebook version 1.0Issued 28 November 2024; entered into force 5 October 2025
Source: EUR-Lex: Directive (EU) 2015/2366 on payment services (PSD2)Adopted 25 November 2015; Official Journal 23 December 2015
Source: EBA and ECB: 2025 joint report on payment fraudPublished 15 December 2025
ECC-Net, police and regulators do different jobs
Direct answer: Use ECC-Net for an eligible cross-border consumer complaint against a registered trader; use police for suspected crime; and use the national financial authority for provider or investment-regulation issues within its mandate.
ECC-Net offers free information and assistance for consumers resident in an EU Member State, Norway or Iceland who have a cross-border complaint against a trader in those territories. Its process begins with a complaint to the trader and, if unresolved, a request to the European Consumer Centre in the consumer's country of residence. That makes it useful for a genuine cross-border purchase, travel or service dispute.
Its published scope also sets limits. ECC-Net says it cannot assist with consumer-to-consumer or business-to-business transactions, businesses outside the covered area, cases already in legal action, unidentified businesses, fraudulent operators and transactions involving financial or investment products such as cryptocurrencies, shares and investment funds. It may still provide information or signposting, but it is not a criminal investigator and cannot force a scammer or bank to return money.
Police or the designated national fraud-reporting service receives the criminal allegation. Give it the chronology, payment identifiers, recipient details, platform accounts, domains and evidence of impersonation or false representations. Ask for a report reference and add later information under that reference. A police report is not a chargeback and a case closure does not decide a separate PSD2 complaint.
A national financial authority supervises activities within its legal remit. For a suspected sham investment firm, ESMA directs victims to police and the national competent authority. For a payment-provider complaint, the EBA's consumer page directs the customer to complain to the institution first, then make an official written complaint, then approach the appropriate national authority or ombudsman. The EBA itself does not decide individual complaints against banks.
Run these tracks in parallel where appropriate. A non-delivered card purchase from a real trader in another Member State may justify a trader complaint, card dispute and ECC-Net request. An impersonation transfer may justify immediate bank recovery, a formal bank complaint and a police report. A clone investment site may require the bank, police and financial regulator but fall outside ECC-Net. A route map prevents a valid referral from being treated as a rejection of the whole case.
| Body | Useful for | Cannot be assumed to do |
|---|---|---|
| ECC-Net | Eligible cross-border consumer-to-trader disputes | Investigate crime, cover every non-EU trader or compel reimbursement |
| Police / national fraud channel | Criminal report and evidence for investigation | Decide a card-scheme or PSD2 complaint |
| National financial authority | Supervisory report and provider or firm issues within mandate | Act as the victim's recovery agent in every case |
| Financial ombudsman / ADR body | Out-of-court complaint where jurisdiction and admissibility rules are met | Freeze recipient funds or prosecute a fraudster |
| Sending payment provider | Register claim, secure account and issue available recovery messages | Guarantee that the beneficiary still has the money |
Source: European Consumer Centres Network: services and complaint scopeAccessed 28 July 2026
Source: European Consumer Centres Network: cross-border complaint processAccessed 28 July 2026
Source: European Banking Authority: how to complain about a financial institutionAccessed 28 July 2026
Source: European Securities and Markets Authority: check whether an investment firm is regulatedAccessed 28 July 2026
A complete complaint file beats a long accusation
Direct answer: Submit a dated, transaction-by-transaction complaint with the remedy requested, supporting documents and a response deadline tied to verified payment rules or the named national complaint scheme.
Open with four lines: the disputed transaction; its classification; the legal or contractual issue; and the remedy. Then add a chronology and numbered exhibits. A reviewer should be able to locate every factual statement without reading an unstructured chat archive. If the case has several payments, include a table stating for each whether it was authorised, unauthorised, a card purchase, a transfer or a later crypto movement.
For payment-service complaints, Your Europe states that the bank or card provider must have a formal consumer complaint procedure and give a written response within fifteen business days, extendable to thirty-five business days in certain exceptional circumstances. That reflects PSD2 Article 101's complaint-handling framework. State the date the provider received the formal complaint and preserve its acknowledgement. Do not convert those periods into a promise of reimbursement; they concern the complaint response.
For an unauthorised or incorrectly executed payment, PSD2 Article 71 requires notice without undue delay and sets the thirteen-month outer period described earlier. Card chargeback time limits are scheme- and reason-specific. National ombudsman, ADR, court and criminal periods vary. Therefore, the file should list every known clock separately and use the earliest safe date, rather than assuming that the PSD2 period saves another claim.
If the provider's final response is unsatisfactory, use the EBA's country list to find the appropriate national competent authority or ombudsman. The EBA recommends contacting the institution, submitting an official complaint in writing with documents, and then approaching the competent national body. Check that body's current eligibility rules, filing period, language, monetary scope, required final response and whether its decision is binding before filing.
FIN-NET can assist with certain cross-border complaints about a financial service provider in another EEA country. The Commission says to write to the provider first, then use the FIN-NET form or contact a member in the consumer's or provider's country. It says members usually reach an outcome within ninety days and that providers are usually not obliged to follow members' decisions, although many do voluntarily. Ninety days is an indicative network outcome period, not a limitation period or refund promise.
Ask the provider to answer the actual issues: classification and consent; evidence of authentication; fraud or gross-negligence allegation; recovery message and response; complaint timing; and the legal and contractual basis for refusal. If it relies on a generic warning, request the version and screen displayed on the transaction date. If it says no funds remain, ask when the receiving response was obtained. A precise unanswered question is useful on escalation.
- Cover page: name, account identifier, contact details, complaint date and provider reference.
- Transaction schedule: date, time, amount, currency, recipient, reference, channel and disputed classification.
- Chronology: first contact, deception, each payment, discovery, notification, account security and reports.
- Evidence index: statements, app receipts, chats, calls, warnings, payee-check result, adverts, contracts and police reference.
- Remedy: refund or restoration basis, recovery request, interest or fees where supported, and a reasoned final response.
- Deadline sheet: PSD2 notice, provider response, card scheme, ombudsman/ADR and court dates — each with a source.
Source: EUR-Lex: Directive (EU) 2015/2366 on payment services (PSD2)Adopted 25 November 2015; Official Journal 23 December 2015
Source: Your Europe: payments, transfers and cheques in the EULast checked 28 April 2026
Source: European Banking Authority: how to complain about a financial institutionAccessed 28 July 2026
Source: European Commission: complain about a financial service provider in another EEA country through FIN-NETAccessed 28 July 2026
Crypto cases: separate the fiat on-ramp from the blockchain transfer
Direct answer: A bank or card payment into an exchange and a later crypto transfer are legally and operationally different legs, so each needs its own consent analysis, records, provider notice and regulatory check.
Draw the chain. The first leg may be a card payment or SEPA transfer from the victim's bank to a crypto-asset service provider. The second may be a purchase of a crypto-asset inside the platform. The third may be a withdrawal to an external wallet. In some scams the fraudster controls the bank session; in others the victim authorises the fiat funding but is manipulated into sending crypto. Do not describe all legs as one unauthorised bank debit unless that is what happened.
For the fiat leg, apply the ordinary classification. Was the card or transfer unauthorised? Did the bank execute it incorrectly? Did the genuine exchange provide the funding service described? Was the recipient account held in the victim's name? A bank may have correctly transferred funds to a regulated exchange even though the later wallet transfer was fraudulent. A chargeback against the exchange cannot be assumed merely because assets later left its platform.
For the exchange and blockchain legs, preserve the customer identifier, deposit and withdrawal ledgers, asset, network, destination address, transaction hash, wallet labels, device history and every support ticket. Contact the provider immediately through its official channel and ask it to flag the destination, preserve account and KYC records, and consider any restriction available under law and policy. Do not publish private keys or seed phrases; no legitimate investigator needs them to view a public transaction.
The three European supervisory authorities warned on 6 October 2025 that crypto-assets can be risky and legal protection may be limited depending on the asset and provider. They advised consumers to check whether the provider is authorised in the EU and to secure wallets. The warning explained that MiCA applies to certain crypto-assets and services and that some national transitional arrangements could run until 1 July 2026. Because that stated date has passed, verify present status in the current EU and national registers rather than accepting an old claim that a licence is “pending.”
Authorisation is not proof that a contact or website is genuine. Compare the exact legal entity, domain and authorised service. Clone sites borrow a regulated firm's details. The EBA maintains registers of credit, payment and electronic-money institutions, while crypto and investment authorisations may be found through ESMA and national authority registers. Use the register appropriate to the service; an entry for a payment institution does not automatically authorise investment advice or every crypto activity.
A blockchain record can show addresses, times and amounts but not necessarily the natural person controlling an address. Recovery may depend on tracing funds to a custodial provider that can act on a valid legal request, or on criminal and civil measures available in relevant countries. Anyone who promises a guaranteed on-chain reversal or demands a wallet “synchronisation” fee is misrepresenting the problem.
| Leg | Core question | Records |
|---|---|---|
| Bank or card to on-ramp | Who authorised it and what service did the recipient provide? | Bank receipt, merchant descriptor, authentication and exchange deposit |
| Fiat-to-crypto trade | Which asset was bought, at what time and in whose account? | Order history, fees and account owner |
| Crypto withdrawal | Who instructed it and where did it go? | Withdrawal approval, device data, address, network and transaction hash |
| Later movement | Did funds reach an identifiable custodial service? | Public chain data plus provider identification suitable for authorities |
Source: European Supervisory Authorities: crypto-asset risks and consumer protection under MiCAPublished 6 October 2025
Source: European Banking Authority: registers of credit, payment and electronic-money institutionsAccessed 28 July 2026
Source: European Securities and Markets Authority: check whether an investment firm is regulatedAccessed 28 July 2026
Source: European Supervisory Authorities: tips for online financial frauds and scamsPublished 15 December 2025
Recovery-room scams target people who have already lost money
Direct answer: Treat unsolicited recovery offers, regulator impersonation, guaranteed outcomes and demands for upfront release, tax or verification payments as high-risk signals and verify every identity independently.
A recovery-room operator often knows the victim's name, loss amount, platform and telephone number. That information may come from the original scam, a sold contact list or a public complaint. Knowledge of the case is not proof of authority. The operator may claim that a regulator, bank, court, blockchain node or “central recovery department” has already found the money and needs one final payment to release it.
Official bodies publish unusually clear warnings. The EBA says it does not approve private financial transfers, does not require payments from private citizens and will never contact a private citizen to request personal details or money. The European Commission's FIN-NET page says FIN-NET is a network of national complaint bodies, does not contact citizens or ask for complaint information, and that anyone purporting to act for FIN-NET while offering a refund or recovery help is attempting a scam.
Verify outside the conversation. Type the regulator or firm's official domain yourself, use the number in its public register, and ask whether the named person and reference are real. A copied logo, case number, signature, government crest or video call can be fabricated. Do not use a telephone number or link supplied in the recovery message to verify that same message.
A legitimate paid professional should identify the contracting legal entity, country, regulator or professional register where applicable, scope of work, fee basis, conflicts, data handling and what happens if no funds are recovered. Even then, no responsible provider can guarantee that a recipient account holds money, that a bank will accept liability, that a court will grant relief or that a crypto transfer will be reversed.
Stop if anyone asks for a seed phrase, private key, one-time bank code, remote screen access, a payment to a personal account, a crypto deposit to “connect” a wallet, or a percentage tax before viewing a supposed recovered balance. Save the approach, report the impersonation to the named body and police, and tell the original provider if account details were disclosed.
For a genuine assessment, send a redacted transaction schedule and the provider's final response before sending full identity material. The review should first identify the payment route and jurisdiction, then explain evidence gaps and realistic escalation. A referral to an independent legal or recovery partner should be disclosed as a referral; the reviewer should never present a lead form as a government or bank process.
- No regulator logo proves that funds exist.
- No public blockchain viewer requires a private key or seed phrase.
- No guaranteed refund percentage can be known before evidence and jurisdiction are reviewed.
- No extra “tax” should be paid to an unsolicited contact without independent professional verification.
- No referral relationship should be hidden from the person submitting the case.
Source: European Banking Authority: frauds and scams misusing the EBA nameAccessed 28 July 2026
Source: European Commission: complain about a financial service provider in another EEA country through FIN-NETAccessed 28 July 2026
Source: European Supervisory Authorities: tips for online financial frauds and scamsPublished 15 December 2025
Concise answers
Frequently asked questions
Can an EU bank transfer to a scammer be refunded?
Sometimes, but not under one universal rule. If the payer did not consent to the transaction, PSD2's unauthorised-payment framework may require prompt refund subject to its exceptions and national law. If the payer deliberately sent the transfer after deception, the bank can attempt scheme recovery and the customer can test national complaint and legal routes, but there is no automatic EU-wide refund for every authorised scam transfer.
Is every payment made after a scammer's lie unauthorised?
No. Payment authorisation concerns consent to the specific payment. A customer who entered and confirmed the beneficiary and amount may have authorised the transfer even though consent was induced by deception. If a fraudster created, changed or initiated a transaction the customer did not approve, that transaction needs a separate unauthorised-payment analysis.
How long do I have to report an unauthorised transaction under PSD2?
Article 71 requires notice without undue delay after awareness and sets an outer period of thirteen months after the debit, subject to an information exception. Report immediately. The thirteen months does not govern card chargebacks, authorised transfers, ombudsman filings or court claims.
Does successful two-factor authentication prove that I authorised the payment?
Not necessarily. PSD2 Article 72 says recorded use of a payment instrument is not necessarily enough by itself to prove authorisation, fraud or intentional or gross negligence. Authentication evidence remains important, and in a deliberately confirmed transfer it may strongly support an authorised classification, but the provider should address the transaction-specific facts.
Can a SEPA Recall force the receiving bank to reverse a transfer?
No. A Recall is a bank-to-bank procedure under the EPC rulebook. Defined reasons and time windows govern the message, and the receiving bank can return a negative response for several reasons, including insufficient funds, legal restriction or beneficiary refusal. A valid Recall request is not a recovery guarantee.
What is the difference between a SEPA Recall and a Request for Recall by the Originator?
A formal Recall uses specified rulebook reasons, including duplicate sending, technical error and a fraudulently originated SCT. A Request for Recall by the Originator is a distinct request route. Both operate through payment providers and neither gives the payer an automatic right to debit the beneficiary's account.
Is chargeback an EU legal right?
Chargeback is generally provided through card-scheme and issuer rules, not one universal EU statute. It is separate from the PSD2 remedy for an unauthorised card payment and from consumer-law claims against a trader. Ask the issuer for the applicable scheme, reason code, evidence and deadline.
Can ECC-Net recover money from a fake investment platform?
ECC-Net's published complaint scope excludes fraudulent operators and transactions involving financial and investment products, including cryptocurrencies and investment funds. It is designed mainly for eligible cross-border consumer disputes with registered traders. Investment fraud should be reported to the payment provider, police and relevant national financial authority.
Where do I complain if the bank rejects my case?
Use the bank or payment institution's formal written complaint process first. Then use the EBA's country list to identify the competent authority or ombudsman and check its current filing rules. FIN-NET can help with some cross-border EEA financial-service complaints after the provider has been approached.
Does Verification of Payee guarantee that the recipient is legitimate?
No. Regulation (EU) 2024/886 requires a free name-and-account check before authorisation, subject to phased compliance dates, but the result does not verify the honesty, purpose or beneficial owner behind a payment request. A mismatch or unavailable result can be evidence; it is not automatically a refund entitlement.
Can I charge back a card payment used to buy crypto?
It depends on what the card merchant provided and the applicable scheme rules. If a genuine exchange credited the customer's account and the customer later sent crypto to a scammer, the merchant may have delivered its service. Analyse the card funding, exchange trade and wallet withdrawal separately rather than assuming the later fraud invalidates the first payment.
What should I send for a first case review?
Start with a redacted transaction schedule, short chronology, payment-provider complaint and response, relevant chats or contract, and police or regulator references. Never send passwords, one-time codes, private keys or seed phrases. A review can identify possible routes and evidence gaps, but cannot promise recovery.
Evidence register
Sources and relevant dates
We link to primary sources whenever available. Sources are grouped under the section they support; the displayed date may be a publication, effective or editorial-review date. A public outcome does not promise the same result in another case.
- EUR-Lex: Directive (EU) 2015/2366 on payment services (PSD2)Adopted 25 November 2015; Official Journal 23 December 2015
- European Commission: payment servicesUpdated 27 November 2025
- EBA and ECB: 2025 joint report on payment fraudPublished 15 December 2025
- European Supervisory Authorities: tips for online financial frauds and scamsPublished 15 December 2025
- European Commission: protecting consumers when buying onlineUpdated 16 July 2026
- Your Europe: payments, transfers and cheques in the EULast checked 28 April 2026
- European Payments Council: current SEPA Credit Transfer rulebook and implementation guidelines2025 SCT Rulebook version 1.1 effective 5 October 2025; accessed 28 July 2026
- European Payments Council: 2025 SEPA Credit Transfer Rulebook version 1.0Issued 28 November 2024; entered into force 5 October 2025
- Your Europe: shipping and deliveryLast checked 29 April 2026
- Your Europe: consumer rights when shopping in the EULast checked 25 September 2025
- European Consumer Centres Network: services and complaint scopeAccessed 28 July 2026
- European Securities and Markets Authority: check whether an investment firm is regulatedAccessed 28 July 2026
- EUR-Lex: Regulation (EU) 2024/886, including verification of payeeOfficial Journal text; checked 29 July 2026
- European Payments Council: Verification of Payee scheme rulebookVersion 1.0 entered into force 5 October 2025
- European Consumer Centres Network: cross-border complaint processAccessed 28 July 2026
- European Banking Authority: how to complain about a financial institutionAccessed 28 July 2026
- European Commission: complain about a financial service provider in another EEA country through FIN-NETAccessed 28 July 2026
- European Supervisory Authorities: crypto-asset risks and consumer protection under MiCAPublished 6 October 2025
- European Banking Authority: registers of credit, payment and electronic-money institutionsAccessed 28 July 2026
- European Banking Authority: frauds and scams misusing the EBA nameAccessed 28 July 2026