European Union · PSD2 · SEPA and card disputes · 32 min read

How to Seek a Scam Payment Refund in the European Union

A scam payment can sometimes be refunded in the European Union, but there is no single EU recovery rule for every loss. The first legal question is whether the payment was unauthorised, authorised after deception, incorrectly executed, a card purchase for goods that never arrived, an investment transfer, or a fiat payment followed by a crypto transfer. Those labels control the route: PSD2 and its national implementation provide a strong framework for certain unauthorised payments; a SEPA Recall is a bank-to-bank recovery message rather than a guaranteed reversal; chargeback is usually a card-scheme or contract process; and consumer, investment, criminal and out-of-court remedies each have different scopes. This guide was checked against official material available on 28 July 2026. It is independent editorial information, not legal advice, not a promise of recovery and not a substitute for the rules and deadlines in the country, account contract and payment scheme that apply to your case.

01Current-law baseline checked against EUR-Lex, the Commission, EBA and EPC
02Unauthorised payments, authorised transfers and merchant disputes kept separate
03Every stated period is tied to its source, instrument and scope
13 monthsPSD2 outer notification periodfor an unauthorised or incorrectly executed debit; notify without undue delay
Next business dayPSD2 unauthorised-payment refund rulesubject to the Directive's fraud-suspicion exception and national implementation
10 banking daystwo SCT Recall reasonsduplicate sending or technical error; this is not a customer refund deadline
13 monthsfraudulent-origin SCT Recall windowa scheme message window, never a recovery guarantee
Sources for the introduction, figures and summary

The EU baseline is shared; the remedy is still country- and payment-specific

Direct answer: EU law creates a common payment-services baseline, but the practical refund route is determined by the payment type, the payer's consent, the provider's location, national transposition and any card or transfer scheme rules.

Start with the payment, not with the word “scam.” PSD2 deals with payment services and distinguishes consent, authorisation, authentication, execution and liability. Consumer contract law addresses a genuine trader's failure to deliver. Card schemes may offer chargeback. SEPA rules define messages that banks can exchange after a credit transfer. Criminal authorities investigate fraud. A financial ombudsman or alternative-dispute body reviews a complaint against a provider only where its mandate allows. These systems can overlap, but none should be presented as a universal recovery programme.

The distinction matters most when a bank says, “You approved it.” A transfer that the customer deliberately entered and confirmed after a fraudster lied about an investment is not automatically treated like a transfer secretly initiated from a compromised account. Conversely, use of the correct password, app or authentication factor does not by itself settle an unauthorised-payment dispute under Article 72 of PSD2. The complaint must describe what the customer did, what the fraudster did and which exact transaction the customer did or did not consent to.

National law remains central. PSD2 is a directive implemented through national legislation, and national courts, regulators and complaint bodies apply that law. Local rules may provide more favourable protection in some areas, and local procedures decide who can complain, in what language, through which form and within what further limitation period. A resident of one Member State using a payment institution authorised in another may also need to identify the provider's home and host regulators before choosing an out-of-court route.

Do not treat policy headlines as operative rights. The Commission recorded a political agreement on the review of the payment-services framework on 27 November 2025. Proposed or agreed reforms do not make every future PSD3 or Payment Services Regulation provision applicable to every payment made earlier. A sound claim states the transaction date and anchors the requested remedy in the law then applicable, while checking any later national change that is actually in force.

The EBA and ECB reported on 15 December 2025 that payment fraud totalled €4.2 billion in the EEA in 2024 and that users bore about 85% of credit-transfer fraud losses, mainly where scammers manipulated them into initiating payments. That aggregate finding explains why authorised-transfer cases need careful alternative arguments; it does not predict an individual outcome or prove that every manipulated transfer is irrecoverable.

ScamCompass EU Payment Route Map — classify before making a demand
What happenedPrimary route to testDo not confuse it with
A payment was initiated without the payer's consentPSD2 unauthorised-payment claim under national lawA voluntary SEPA Recall or merchant chargeback
The payer entered a transfer after deceptionImmediate bank recovery request plus national complaint and other legal routesAn automatic PSD2 unauthorised-payment refund
A real trader took a card payment but did not deliverTrader claim, consumer rights, and possible card chargebackAccount takeover or investment compensation
A bank transfer was executed to the wrong account or amountIncorrect-execution analysis and scheme recovery requestFraud merely because the result was unwanted
Fiat reached an exchange and crypto then left a walletAnalyse the fiat leg and the crypto leg separatelyA single reversible bank transfer

Source: EUR-Lex: Directive (EU) 2015/2366 on payment services (PSD2)Adopted 25 November 2015; Official Journal 23 December 2015

Source: European Commission: payment servicesUpdated 27 November 2025

Source: EBA and ECB: 2025 joint report on payment fraudPublished 15 December 2025

The first hour: stop further loss and create a transaction-grade record

Direct answer: Contact the payment provider through a verified channel immediately, secure compromised accounts, ask for the precise recovery action available for that rail, and preserve the evidence before chats, adverts or account pages disappear.

Use the number in the banking app, on the physical card or on the provider's independently typed official website. A message in the scam conversation is not a verified contact route. Tell the provider whether a card, credit transfer, direct debit, wallet, e-money account or exchange was involved. Ask for a fraud or complaint reference, the time of the report and written confirmation of any card block, account restriction, transfer Recall, request for recall or beneficiary-bank notification.

If credentials, a device, screen-sharing access or an authentication code may have been exposed, change the affected password from a clean device, revoke unknown sessions, remove remote-access software, call the mobile operator if a SIM swap is possible, and review email forwarding rules. Blocking a card does not necessarily secure online banking; changing online-banking access does not necessarily stop a direct-debit mandate. Ask the provider what it has actually disabled.

Preserve evidence in original form. Export account statements or transaction receipts; save complete chats with dates, usernames and message identifiers; record telephone numbers and email headers; capture the advert and landing-page URL; download invoices, supposed licences and contract terms; and retain the recipient IBAN, BIC, merchant descriptor, card authorisation code, crypto address and transaction hash where relevant. A screenshot is useful, but a statement or platform export is often easier to authenticate later.

Write a short chronology while memory is fresh. Separate statements made by the fraudster from actions taken by the payer and actions shown in the bank. Record the exact warning displayed before approval, the beneficiary name shown, whether the system returned a name match, and what the customer believed the payment was for. Avoid editing the original files; place working copies in a separate folder and keep an index.

Report the incident to the national police or designated online-fraud channel when deception or unauthorised access is involved. The 15 December 2025 joint European supervisory factsheet tells consumers to inform the bank or financial firm immediately and report the incident to police or the national financial authority. A police reference can support the chronology, but it does not force a bank or beneficiary to refund.

  1. 01
    Freeze

    Stop cards, sessions, mandates or exchange withdrawals that remain exposed; do not send a “release,” “tax” or “verification” payment.

  2. 02
    Notify

    Call the sending provider and request both the legally relevant claim route and the fastest scheme-level recovery message.

  3. 03
    Preserve

    Save statements, transaction identifiers, chats, warnings, recipient details and device events in their original form.

  4. 04
    Report

    Use the competent national criminal and financial channels; record every reference and response date.

  5. 05
    Review

    Map each payment separately. A series may contain card, transfer and crypto legs with different remedies.

PSD2 unauthorised payments: the core refund framework

Direct answer: If the payer did not consent to the specific transaction, PSD2 Articles 71–73 provide an EU baseline for prompt notification, proof and refund, subject to the Directive's exceptions and the national law implementing it.

Article 71 requires the payment service user to notify the provider without undue delay after becoming aware of an unauthorised or incorrectly executed transaction. The outer limit is 13 months after the debit date, unless the provider failed to provide or make the transaction information available as required. Thirteen months is therefore not a sensible waiting period and not a general deadline for every scam. Early notice preserves the best chance of stopping linked activity and avoids a separate argument over delay.

Article 73 says the payer's provider must refund an unauthorised transaction immediately and, in any event, no later than the end of the following business day after noting or being notified of it. The provider must also restore the debited account to the position it would have held without the transaction and ensure the credit value date is no later than the debit date. There is an exception where the provider has reasonable grounds to suspect fraud and communicates those grounds in writing to the relevant national authority. A complaint should quote the national implementing provision where possible, not only the Directive number.

The key factual issue is consent to the specific payment. An account takeover, cloned card or transfer created entirely by a fraudster can fit the unauthorised route. A customer who entered a beneficiary and amount and consciously approved that transfer after a lie faces a different analysis. Mixed cases exist: a fraudster may persuade a customer to add a payee but then change an amount, initiate later transfers or take over the session. Break the series into individual transactions instead of allowing one label to cover all of them.

Ask for a separate decision on each disputed transaction. The complaint table should include date and time, amount and currency, transaction reference, channel, device, authentication event, recipient, the customer's account of consent, the date of discovery and the date of notification. If the provider treats every payment as authorised, require it to identify the evidence for each one and the contractual or statutory basis for its conclusion.

Do not combine this rule with the eight-week refund process for certain transactions initiated by or through a payee. PSD2 Articles 76 and 77 create a distinct conditional refund route and include rules relevant to SEPA direct debits. They are not a general eight-week right to reverse a credit transfer that the payer initiated. A creditor-pulled direct debit, a card payment and a payer-pushed bank transfer must be classified separately.

  • Use “I did not consent to this specific transaction” only where it is accurate.
  • Give the provider the discovery date and notification date; do not rely on the 13-month outer limit.
  • Request account restoration, value-date correction and a reasoned written decision.
  • List disputed transactions one by one, including later payments that the fraudster may have initiated after access was obtained.
  • Keep the direct-debit refund route separate from a SEPA credit-transfer Recall.

Source: EUR-Lex: Directive (EU) 2015/2366 on payment services (PSD2)Adopted 25 November 2015; Official Journal 23 December 2015

Source: Your Europe: payments, transfers and cheques in the EULast checked 28 April 2026

Authentication is evidence, not the whole answer

Direct answer: Under PSD2 Article 72, recorded use of a payment instrument is not necessarily sufficient by itself to prove that the payer authorised the transaction or acted fraudulently or with gross negligence.

When a customer denies authorisation, the provider must prove that the transaction was authenticated, accurately recorded and entered in the accounts, and that it was not affected by a technical breakdown or other deficiency in the service. Article 72 then makes a separate point: use of the instrument recorded by the provider is not necessarily enough, on its own, to prove consent, fraud or intentional or grossly negligent failure by the payer. The provider must supply supporting evidence if it alleges fraud or gross negligence.

That distinction is practical. A log may show that an app on an enrolled phone completed strong customer authentication. It may not show who controlled the screen, what beneficiary and amount were displayed, whether malware altered the journey, whether the warning was visible, or whether the fraudster initiated a different payment after remote access. Ask the provider for a transaction-specific explanation that deals with those facts, subject to the disclosure rights and security limits under national procedure.

Strong customer authentication is valuable prevention, but it does not make manipulation disappear. The EBA and ECB's 2025 report found that authentication remained effective against the fraud types it was designed to mitigate, especially card fraud, while manipulation of payers was rising. For an intentionally approved transfer, this evidence can support the provider's classification as authorised; for a denied transaction, it is part of the proof analysis rather than an automatic conclusion.

Article 74's frequently quoted €50 amount is also narrower than many summaries suggest. It concerns specified losses from certain unauthorised transactions arising from a lost or stolen payment instrument or misappropriation before notification, with exceptions. Fraud or intentional or grossly negligent failure by the payer can change liability. There are also circumstances in which the payer bears no loss, including where loss, theft or misappropriation was not detectable before payment except for payer fraud. National implementation and the precise instrument therefore matter.

A strong rebuttal avoids adjectives and tests the evidence. Instead of writing “the bank was careless,” identify the disputed inference: “The response relies on successful authentication but does not address my statement that I did not create or approve transaction X, the new-device event at 14:03, the beneficiary change at 14:07, or why the provider treats the app log alone as proof of consent.” This gives an ombudsman or adjudicator a reviewable issue.

Evidence questions for an unauthorised-payment complaint
Provider propositionFocused questionUseful record
The correct device was usedWas it a known device, a newly enrolled device or a remote session?Device enrolment and session timeline
Authentication succeededWhat transaction details were bound to the authentication step?Authentication method, time, amount and payee shown
The customer was grossly negligentWhich precise duty was breached and what supports the higher threshold?Contract term, warning shown and customer chronology
The customer benefitedWhere did the funds go and what evidence links the recipient to the customer?Recipient and account-ownership data available to the provider

Source: EUR-Lex: Directive (EU) 2015/2366 on payment services (PSD2)Adopted 25 November 2015; Official Journal 23 December 2015

Source: EBA and ECB: 2025 joint report on payment fraudPublished 15 December 2025

Authorised scam transfers: no automatic EU-wide refund rule

Direct answer: A transfer the customer deliberately instructed after being deceived does not automatically qualify for PSD2's unauthorised-payment refund, so recovery and complaint arguments must be built from the actual payment journey and applicable national law.

This category includes impersonation, romance, invoice-redirection and investment scams where the payer knowingly confirms the displayed beneficiary and amount but misunderstands the recipient's identity, purpose or honesty. The fraud is real; the payment-law classification can still be authorised. Calling every such transfer “unauthorised” may damage credibility and allow the provider to answer the wrong issue quickly.

The first task is operational: ask the sending provider to issue the appropriate SEPA or other scheme recovery message and notify the receiving provider's fraud team. The second task is evaluative: ask whether warnings, payee verification, transaction monitoring, account restrictions or staff interventions operated as they should under the law, contract and standards applicable at the time. The third is external: report the recipient and the deception to criminal and relevant financial authorities. None of these steps guarantees a refund.

A complaint should not assume that a bank owed a universal duty to detect any unusual transfer. It should identify concrete events. Was a new beneficiary added? Did the amount or frequency depart from account history? Did the payer call the bank while the transfer was pending? Did the system show a name mismatch? Did a staff member receive a clear statement that the payment was demanded by an alleged police officer or investment adviser? Was a subsequent payment processed after the first fraud report? Each point must be supported by a timestamp or document.

Mixed authorisation deserves special care. A payer may have authorised the first payment but not a later transfer initiated through a compromised device. A fraudster may have substituted beneficiary details in an invoice. A payment may have been sent to an account the customer owns at an exchange, after which the fraudster controlled the crypto withdrawal. Treating the whole chain as one “bank scam” hides potentially different defendants, evidence and remedies.

The 2025 EBA-ECB data provides context, not a rule: users bore approximately 85% of total credit-transfer fraud losses in 2024, mainly because scams tricked them into initiating payments. The figure is a strong reason to act fast and analyse other legal routes, not evidence that an individual complaint must fail. National courts or complaint bodies may consider facts and domestic duties that an aggregate report cannot decide.

  • Describe deception precisely: who claimed what, through which channel, and why the payer believed it.
  • Ask for scheme recovery and a formal complaint at the same time; do not wait for one before starting the other.
  • Identify any transaction after the first notification, because its liability analysis may differ.
  • Use national law and ombudsman decisions only after checking jurisdiction, date and precedential value.
  • Never promise an authorised-transfer reimbursement before the provider and country rules are known.

Source: EUR-Lex: Directive (EU) 2015/2366 on payment services (PSD2)Adopted 25 November 2015; Official Journal 23 December 2015

Source: EBA and ECB: 2025 joint report on payment fraudPublished 15 December 2025

Source: European Supervisory Authorities: tips for online financial frauds and scamsPublished 15 December 2025

SEPA Recall and Request for Recall are bank messages, not guaranteed reversals

Direct answer: For a SEPA Credit Transfer, the sending bank may use a Recall for defined scheme reasons or a different Request for Recall by the Originator, but the rulebook does not promise that the beneficiary's bank will return available funds.

The current EPC page identifies the 2025 SEPA Credit Transfer Rulebook version 1.1 as the operative rulebook from 5 October 2025. Its operational Recall provisions carry forward the rules published in the 2025 version 1.0. Ask the provider which scheme and version governed the transaction; instant credit transfers and non-SEPA rails should not be assumed to use the same message or timetable.

A formal SCT Recall is initiated by the Originator PSP — the sending payment service provider — which may act on behalf of the originator. The listed reasons are duplicate sending, a technical problem resulting in erroneous execution and a fraudulently originated SCT instruction. For duplicate sending and technical error, the Recall must be sent within ten Banking Business Days following execution. For the fraudulently originated reason, the rulebook allows the Originator PSP to send the Recall within thirteen months following the execution date.

Those periods are scheme message windows, not refund deadlines for a consumer. “Fraudulently originated” is also a scheme reason; it should not be read as converting every authorised scam transfer into an unauthorised payment claim. Ask the bank to identify the reason code it used, when it transmitted the message and whether the beneficiary bank acknowledged it.

The Beneficiary PSP must provide a positive or negative response within fifteen Banking Business Days after receiving the Recall. A negative response can result from insufficient funds, a closed account, a legal reason, beneficiary refusal, no response from the beneficiary, failure to receive the original transfer, or funds already returned. Where the funds have been credited, handling can depend on national law, the account contract and whether beneficiary authorisation is required. This is why a technically valid Recall can still end without recovery.

A Request for Recall by the Originator is a distinct procedure that can be considered where the narrow formal Recall reasons do not fit. It asks the beneficiary side to consider return and can depend on the beneficiary's response and applicable law. It is not a hidden chargeback and does not create a guaranteed entitlement. The complaint should state whether the bank sent a formal Recall or this request, because the names are often blurred in telephone notes.

Speed remains useful even when a longer scheme window exists. Funds may be moved from the recipient account within minutes, while later interbank processing cannot recreate a balance. Ask the sending bank to preserve the transaction reference, beneficiary IBAN, transmission and response timestamps, and every returned reason code. If the provider refuses to send any recovery message, request its reason in writing and check the account agreement and national complaint route.

SEPA Credit Transfer recovery messages under the current EPC framework
ProcedureWhen it may be usedVerified scheme timingWhat it does not prove
Recall — duplicate or technical errorOne of the two specified execution-error reasonsSend within 10 Banking Business Days after executionThat the customer has a fraud refund right
Recall — fraudulently originated SCTThe Originator PSP uses the scheme's fraud reasonSend within 13 months after executionThat funds remain or must be returned
Beneficiary PSP responseAfter receipt of a RecallPositive or negative response within 15 Banking Business DaysThat silence or refusal creates a refund
Request for Recall by the OriginatorA different originator-request route under the rulebookCheck the applicable rulebook and bank handlingA compulsory debit from the beneficiary

Source: European Payments Council: current SEPA Credit Transfer rulebook and implementation guidelines2025 SCT Rulebook version 1.1 effective 5 October 2025; accessed 28 July 2026

Source: European Payments Council: 2025 SEPA Credit Transfer Rulebook version 1.0Issued 28 November 2024; entered into force 5 October 2025

Source: EUR-Lex: Directive (EU) 2015/2366 on payment services (PSD2)Adopted 25 November 2015; Official Journal 23 December 2015

Card chargeback is different from PSD2 and consumer contract rights

Direct answer: A chargeback is generally a card-scheme or issuer process, while an unauthorised card payment can engage PSD2 and a genuine trader's non-delivery can create separate consumer-law rights.

Use three labels. First, an unauthorised card transaction is a payment the cardholder did not consent to; the PSD2 notification, proof and liability framework may apply through national law. Second, an authorised card purchase can be disputed through a scheme reason such as goods not received, service not provided, duplicate processing or a misdescribed transaction if the applicable scheme and issuer rules permit. Third, the consumer may have a direct contractual or statutory claim against a trader regardless of whether the issuer accepts a chargeback.

There is no single published EU chargeback deadline that safely applies to every card, reason code and country. The European Commission's current online-safety page tells consumers they can ask their bank to freeze cards or seek a chargeback, and Commission guidance in merchant-cancellation contexts advises checking whether the card company's chargeback policy applies. That is materially different from an EU statute promising chargeback in all cases. Ask the issuer for the exact scheme, reason code, evidence list and deadline governing your transaction.

For a merchant dispute, contact the trader in writing unless doing so creates a security risk or the trader is plainly fictitious. State the order, contractual delivery date, what was received, the remedy requested and a reasonable response date. Your Europe says that, unless another time was agreed, a trader should deliver within thirty days; after an additional reasonable period without delivery, the consumer may terminate and seek reimbursement, with exceptions where delivery was refused or timing was essential. These contract steps can also create the evidence an issuer requests.

For a fake storefront that has disappeared, preserve the checkout page, merchant descriptor, order confirmation, domain and any delivery tracking. The party named on the card statement may be a payment facilitator rather than the website brand. Give the issuer both names and explain why the transaction is a scam or non-delivery dispute. Do not mark it unauthorised merely because the merchant was dishonest if the cardholder knowingly approved the purchase.

Investment deposits require extra precision. A card payment to a genuine, regulated platform may have purchased the service described even if the customer then made a losing or fraudulent transfer elsewhere. A card payment directly to a sham broker may raise different scheme issues. The card network's classification, merchant evidence and chain of funds matter. Chargeback should not be advertised as an investment-loss insurance policy.

Choose the card argument that matches the facts
Card eventPrimary questionEvidence to attach
Card details were stolenDid the cardholder consent to this transaction?Statement, possession timeline, device/account alerts
Goods never arrivedWhat did the trader promise and what remedy was requested?Order, delivery terms, complaint and tracking
Service differed materiallyWhat representation and performance can be proved?Advertisement, contract, delivered service and correspondence
Card funded an exchange or walletWhat did the merchant itself provide, and what happened next?Card receipt, exchange ledger, wallet withdrawal and transaction hash

Source: European Commission: protecting consumers when buying onlineUpdated 16 July 2026

Source: Your Europe: payments, transfers and cheques in the EULast checked 28 April 2026

Source: Your Europe: shipping and deliveryLast checked 29 April 2026

Source: EUR-Lex: Directive (EU) 2015/2366 on payment services (PSD2)Adopted 25 November 2015; Official Journal 23 December 2015

Fake merchant, non-delivery and investment scams need different proof

Direct answer: A missing parcel from an identifiable trader is a consumer dispute; a fabricated shop may be criminal fraud; and a sham investment platform belongs primarily in the financial-regulatory and criminal track, even when all three began with an online advert.

For an identifiable professional trader, establish the legal entity, country, order terms and delivery commitment. EU consumer rights generally distinguish a trader from a private seller. Your Europe states that professional-trader purchases can carry delivery, conformity and withdrawal rights, while private-to-private transactions do not receive the same EU consumer framework. A marketplace logo does not prove that the marketplace itself was the seller.

A website can imitate a trader without any real entity behind it. Search the trade register and check whether the stated address, VAT number, telephone number and domain correspond. A copied registration number can identify an innocent company rather than the scammer. If the supposed trader cannot be identified or is carrying out fraud, ECC-Net says the case may fall outside its complaint-assistance remit. Bank action and a criminal report become more important than a conventional trader negotiation.

For non-delivery, pin down the promised date. If the contract set no different period, Your Europe describes the thirty-day delivery baseline and the normal additional reasonable period before termination. Do not use that rule mechanically where the goods, service, seller or agreed timing falls outside its scope. Attach the order confirmation and the notice giving additional time, or explain why no further time was required because the trader refused delivery or the agreed date was essential.

For investments, identify the legal firm before discussing performance. ESMA says firms may provide investment services in the EU only when authorised and directs investors to national and ESMA registers. A matching brand is not enough: compare the legal name, domain, address, licence status and authorised activities. Clone firms deliberately borrow the name and number of a real entity. Record the payment recipient as well as the platform name shown on screen.

A real investment loss is not automatically a scam, and an investor compensation scheme is not a guarantee against market loss or fraud by an unauthorised firm. If the platform fabricated balances, blocked withdrawals unless a further “tax” was paid, impersonated an authorised firm or directed funds to unrelated personal accounts, state each fact and source. Report the case to police and the relevant national financial authority; ask the payment provider about available recovery without overstating the regulator's power to obtain funds.

ScamCompass dispute classifier
PatternFirst demandBest factual anchorsLikely escalation
Real EU trader, no deliveryDeliver by a reasonable final date or reimburse after terminationLegal entity, order, agreed date, tracking, written noticeECC-Net for eligible cross-border trader complaint; ADR or court where appropriate
Unidentifiable fake shopBank/card recovery action and fraud registrationDomain, merchant descriptor, copied identity, advert, payment recordPolice and relevant national reporting channel
Regulated firm service disputeFormal complaint identifying rule or contract failureLicence, client agreement, advice records, account ledgerFinancial ombudsman/ADR or regulator within its remit
Clone or sham investment siteStop payments, issue recovery request, preserve recipient trailFalse domain, payment destination, licence mismatch, withdrawal demandsPolice and national financial authority

Build evidence for both the sending and receiving sides

Direct answer: The sending provider needs a precise claim and recovery instruction, while information about the receiving account, payee check and movement of funds should be preserved through provider and authority channels rather than guessed from public data.

The sending bank or payment institution is normally the first operational contact because it authenticated or executed the payment and can send the relevant scheme message. Give it the transaction ID, amount, currency, time, beneficiary name and account, payment purpose shown at authorisation, scam report time and police reference when available. Ask whether it contacted the beneficiary PSP and for the timestamp and response, but do not assume the sender can disclose protected information about the recipient.

The receiving provider may hold the account that first received the funds, but that does not mean it owes the payer an automatic refund. Its ability to restrict or return funds depends on the facts, applicable law, account contract, scheme and instructions from competent authorities. Direct emails to a generic address may not be treated as an authenticated interbank claim. Ask the sending provider and police to use the correct operational channel.

Regulation (EU) 2024/886 requires a payer’s payment service provider to offer a free verification-of-payee service before a credit transfer is authorised. It compares the supplied payee name with the account identifier and requires a warning where they do not match or almost match. The compliance dates are phased: providers in Member States whose currency is the euro were due to comply with this part by 9 October 2025, while providers in non-euro Member States have until 9 July 2027. In July 2026, availability therefore still depends on the provider and jurisdiction.

The European Payments Council’s Verification of Payee scheme entered into force on 5 October 2025 to standardise checks for relevant SEPA payments. Record the result displayed — match, close match, no match or unavailable — and the name proposed, if any. A match does not establish that the recipient is honest, and a mismatch does not by itself create a refund. The result is one part of the authorisation journey.

Ask what happened after a warning. Did the payer override a clear mismatch, did the app show an unavailable result, or did the bank supply a different name? Was the payment made before the service applied to that provider or instrument? Because rollout and legal obligations have date and geographic scope, do not import a current payee-check expectation into an older payment without checking the applicable rules.

For account takeover, request preservation of device enrolment, IP and session events, payee creation, limit changes, authentication method, alerts and communications. For an authorised scam, preserve the warning screen, transfer purpose, payee-check result, branch or call-centre interaction and any attempt to cancel. For a merchant payment, preserve the merchant category and descriptor. For a crypto on-ramp, obtain both the bank record and the exchange ledger.

Evidence should be proportionate and lawful. A victim does not need to publish an alleged recipient's personal data or contact family members. Put identifiers in the bank and police file, redact them in public posts, and let competent bodies obtain protected records. Public accusations can create privacy, defamation and investigation risks while doing little to preserve funds.

  • Sending side: transaction reference, authentication, warning, cancellation request and interbank message.
  • Receiving side: beneficiary account identifier, PSP, Recall response and any authority reference.
  • Payee check: exact displayed result, proposed name and timestamp — not a paraphrase from memory.
  • Sequence: show when the provider learned of fraud and whether later transactions still left the account.
  • Disclosure: request relevant records through the complaint or authority process; do not demand unlawful personal-data release.

Source: EUR-Lex: Regulation (EU) 2024/886, including verification of payeeOfficial Journal text; checked 29 July 2026

Source: European Payments Council: Verification of Payee scheme rulebookVersion 1.0 entered into force 5 October 2025

Source: European Payments Council: 2025 SEPA Credit Transfer Rulebook version 1.0Issued 28 November 2024; entered into force 5 October 2025

Source: EUR-Lex: Directive (EU) 2015/2366 on payment services (PSD2)Adopted 25 November 2015; Official Journal 23 December 2015

Source: EBA and ECB: 2025 joint report on payment fraudPublished 15 December 2025

ECC-Net, police and regulators do different jobs

Direct answer: Use ECC-Net for an eligible cross-border consumer complaint against a registered trader; use police for suspected crime; and use the national financial authority for provider or investment-regulation issues within its mandate.

ECC-Net offers free information and assistance for consumers resident in an EU Member State, Norway or Iceland who have a cross-border complaint against a trader in those territories. Its process begins with a complaint to the trader and, if unresolved, a request to the European Consumer Centre in the consumer's country of residence. That makes it useful for a genuine cross-border purchase, travel or service dispute.

Its published scope also sets limits. ECC-Net says it cannot assist with consumer-to-consumer or business-to-business transactions, businesses outside the covered area, cases already in legal action, unidentified businesses, fraudulent operators and transactions involving financial or investment products such as cryptocurrencies, shares and investment funds. It may still provide information or signposting, but it is not a criminal investigator and cannot force a scammer or bank to return money.

Police or the designated national fraud-reporting service receives the criminal allegation. Give it the chronology, payment identifiers, recipient details, platform accounts, domains and evidence of impersonation or false representations. Ask for a report reference and add later information under that reference. A police report is not a chargeback and a case closure does not decide a separate PSD2 complaint.

A national financial authority supervises activities within its legal remit. For a suspected sham investment firm, ESMA directs victims to police and the national competent authority. For a payment-provider complaint, the EBA's consumer page directs the customer to complain to the institution first, then make an official written complaint, then approach the appropriate national authority or ombudsman. The EBA itself does not decide individual complaints against banks.

Run these tracks in parallel where appropriate. A non-delivered card purchase from a real trader in another Member State may justify a trader complaint, card dispute and ECC-Net request. An impersonation transfer may justify immediate bank recovery, a formal bank complaint and a police report. A clone investment site may require the bank, police and financial regulator but fall outside ECC-Net. A route map prevents a valid referral from being treated as a rejection of the whole case.

Who handles which part of an EU scam-payment case?
BodyUseful forCannot be assumed to do
ECC-NetEligible cross-border consumer-to-trader disputesInvestigate crime, cover every non-EU trader or compel reimbursement
Police / national fraud channelCriminal report and evidence for investigationDecide a card-scheme or PSD2 complaint
National financial authoritySupervisory report and provider or firm issues within mandateAct as the victim's recovery agent in every case
Financial ombudsman / ADR bodyOut-of-court complaint where jurisdiction and admissibility rules are metFreeze recipient funds or prosecute a fraudster
Sending payment providerRegister claim, secure account and issue available recovery messagesGuarantee that the beneficiary still has the money

A complete complaint file beats a long accusation

Direct answer: Submit a dated, transaction-by-transaction complaint with the remedy requested, supporting documents and a response deadline tied to verified payment rules or the named national complaint scheme.

Open with four lines: the disputed transaction; its classification; the legal or contractual issue; and the remedy. Then add a chronology and numbered exhibits. A reviewer should be able to locate every factual statement without reading an unstructured chat archive. If the case has several payments, include a table stating for each whether it was authorised, unauthorised, a card purchase, a transfer or a later crypto movement.

For payment-service complaints, Your Europe states that the bank or card provider must have a formal consumer complaint procedure and give a written response within fifteen business days, extendable to thirty-five business days in certain exceptional circumstances. That reflects PSD2 Article 101's complaint-handling framework. State the date the provider received the formal complaint and preserve its acknowledgement. Do not convert those periods into a promise of reimbursement; they concern the complaint response.

For an unauthorised or incorrectly executed payment, PSD2 Article 71 requires notice without undue delay and sets the thirteen-month outer period described earlier. Card chargeback time limits are scheme- and reason-specific. National ombudsman, ADR, court and criminal periods vary. Therefore, the file should list every known clock separately and use the earliest safe date, rather than assuming that the PSD2 period saves another claim.

If the provider's final response is unsatisfactory, use the EBA's country list to find the appropriate national competent authority or ombudsman. The EBA recommends contacting the institution, submitting an official complaint in writing with documents, and then approaching the competent national body. Check that body's current eligibility rules, filing period, language, monetary scope, required final response and whether its decision is binding before filing.

FIN-NET can assist with certain cross-border complaints about a financial service provider in another EEA country. The Commission says to write to the provider first, then use the FIN-NET form or contact a member in the consumer's or provider's country. It says members usually reach an outcome within ninety days and that providers are usually not obliged to follow members' decisions, although many do voluntarily. Ninety days is an indicative network outcome period, not a limitation period or refund promise.

Ask the provider to answer the actual issues: classification and consent; evidence of authentication; fraud or gross-negligence allegation; recovery message and response; complaint timing; and the legal and contractual basis for refusal. If it relies on a generic warning, request the version and screen displayed on the transaction date. If it says no funds remain, ask when the receiving response was obtained. A precise unanswered question is useful on escalation.

  • Cover page: name, account identifier, contact details, complaint date and provider reference.
  • Transaction schedule: date, time, amount, currency, recipient, reference, channel and disputed classification.
  • Chronology: first contact, deception, each payment, discovery, notification, account security and reports.
  • Evidence index: statements, app receipts, chats, calls, warnings, payee-check result, adverts, contracts and police reference.
  • Remedy: refund or restoration basis, recovery request, interest or fees where supported, and a reasoned final response.
  • Deadline sheet: PSD2 notice, provider response, card scheme, ombudsman/ADR and court dates — each with a source.

Crypto cases: separate the fiat on-ramp from the blockchain transfer

Direct answer: A bank or card payment into an exchange and a later crypto transfer are legally and operationally different legs, so each needs its own consent analysis, records, provider notice and regulatory check.

Draw the chain. The first leg may be a card payment or SEPA transfer from the victim's bank to a crypto-asset service provider. The second may be a purchase of a crypto-asset inside the platform. The third may be a withdrawal to an external wallet. In some scams the fraudster controls the bank session; in others the victim authorises the fiat funding but is manipulated into sending crypto. Do not describe all legs as one unauthorised bank debit unless that is what happened.

For the fiat leg, apply the ordinary classification. Was the card or transfer unauthorised? Did the bank execute it incorrectly? Did the genuine exchange provide the funding service described? Was the recipient account held in the victim's name? A bank may have correctly transferred funds to a regulated exchange even though the later wallet transfer was fraudulent. A chargeback against the exchange cannot be assumed merely because assets later left its platform.

For the exchange and blockchain legs, preserve the customer identifier, deposit and withdrawal ledgers, asset, network, destination address, transaction hash, wallet labels, device history and every support ticket. Contact the provider immediately through its official channel and ask it to flag the destination, preserve account and KYC records, and consider any restriction available under law and policy. Do not publish private keys or seed phrases; no legitimate investigator needs them to view a public transaction.

The three European supervisory authorities warned on 6 October 2025 that crypto-assets can be risky and legal protection may be limited depending on the asset and provider. They advised consumers to check whether the provider is authorised in the EU and to secure wallets. The warning explained that MiCA applies to certain crypto-assets and services and that some national transitional arrangements could run until 1 July 2026. Because that stated date has passed, verify present status in the current EU and national registers rather than accepting an old claim that a licence is “pending.”

Authorisation is not proof that a contact or website is genuine. Compare the exact legal entity, domain and authorised service. Clone sites borrow a regulated firm's details. The EBA maintains registers of credit, payment and electronic-money institutions, while crypto and investment authorisations may be found through ESMA and national authority registers. Use the register appropriate to the service; an entry for a payment institution does not automatically authorise investment advice or every crypto activity.

A blockchain record can show addresses, times and amounts but not necessarily the natural person controlling an address. Recovery may depend on tracing funds to a custodial provider that can act on a valid legal request, or on criminal and civil measures available in relevant countries. Anyone who promises a guaranteed on-chain reversal or demands a wallet “synchronisation” fee is misrepresenting the problem.

Crypto scam evidence by transaction leg
LegCore questionRecords
Bank or card to on-rampWho authorised it and what service did the recipient provide?Bank receipt, merchant descriptor, authentication and exchange deposit
Fiat-to-crypto tradeWhich asset was bought, at what time and in whose account?Order history, fees and account owner
Crypto withdrawalWho instructed it and where did it go?Withdrawal approval, device data, address, network and transaction hash
Later movementDid funds reach an identifiable custodial service?Public chain data plus provider identification suitable for authorities

Recovery-room scams target people who have already lost money

Direct answer: Treat unsolicited recovery offers, regulator impersonation, guaranteed outcomes and demands for upfront release, tax or verification payments as high-risk signals and verify every identity independently.

A recovery-room operator often knows the victim's name, loss amount, platform and telephone number. That information may come from the original scam, a sold contact list or a public complaint. Knowledge of the case is not proof of authority. The operator may claim that a regulator, bank, court, blockchain node or “central recovery department” has already found the money and needs one final payment to release it.

Official bodies publish unusually clear warnings. The EBA says it does not approve private financial transfers, does not require payments from private citizens and will never contact a private citizen to request personal details or money. The European Commission's FIN-NET page says FIN-NET is a network of national complaint bodies, does not contact citizens or ask for complaint information, and that anyone purporting to act for FIN-NET while offering a refund or recovery help is attempting a scam.

Verify outside the conversation. Type the regulator or firm's official domain yourself, use the number in its public register, and ask whether the named person and reference are real. A copied logo, case number, signature, government crest or video call can be fabricated. Do not use a telephone number or link supplied in the recovery message to verify that same message.

A legitimate paid professional should identify the contracting legal entity, country, regulator or professional register where applicable, scope of work, fee basis, conflicts, data handling and what happens if no funds are recovered. Even then, no responsible provider can guarantee that a recipient account holds money, that a bank will accept liability, that a court will grant relief or that a crypto transfer will be reversed.

Stop if anyone asks for a seed phrase, private key, one-time bank code, remote screen access, a payment to a personal account, a crypto deposit to “connect” a wallet, or a percentage tax before viewing a supposed recovered balance. Save the approach, report the impersonation to the named body and police, and tell the original provider if account details were disclosed.

For a genuine assessment, send a redacted transaction schedule and the provider's final response before sending full identity material. The review should first identify the payment route and jurisdiction, then explain evidence gaps and realistic escalation. A referral to an independent legal or recovery partner should be disclosed as a referral; the reviewer should never present a lead form as a government or bank process.

  • No regulator logo proves that funds exist.
  • No public blockchain viewer requires a private key or seed phrase.
  • No guaranteed refund percentage can be known before evidence and jurisdiction are reviewed.
  • No extra “tax” should be paid to an unsolicited contact without independent professional verification.
  • No referral relationship should be hidden from the person submitting the case.

Concise answers

Frequently asked questions

Can an EU bank transfer to a scammer be refunded?

Sometimes, but not under one universal rule. If the payer did not consent to the transaction, PSD2's unauthorised-payment framework may require prompt refund subject to its exceptions and national law. If the payer deliberately sent the transfer after deception, the bank can attempt scheme recovery and the customer can test national complaint and legal routes, but there is no automatic EU-wide refund for every authorised scam transfer.

Is every payment made after a scammer's lie unauthorised?

No. Payment authorisation concerns consent to the specific payment. A customer who entered and confirmed the beneficiary and amount may have authorised the transfer even though consent was induced by deception. If a fraudster created, changed or initiated a transaction the customer did not approve, that transaction needs a separate unauthorised-payment analysis.

How long do I have to report an unauthorised transaction under PSD2?

Article 71 requires notice without undue delay after awareness and sets an outer period of thirteen months after the debit, subject to an information exception. Report immediately. The thirteen months does not govern card chargebacks, authorised transfers, ombudsman filings or court claims.

Does successful two-factor authentication prove that I authorised the payment?

Not necessarily. PSD2 Article 72 says recorded use of a payment instrument is not necessarily enough by itself to prove authorisation, fraud or intentional or gross negligence. Authentication evidence remains important, and in a deliberately confirmed transfer it may strongly support an authorised classification, but the provider should address the transaction-specific facts.

Can a SEPA Recall force the receiving bank to reverse a transfer?

No. A Recall is a bank-to-bank procedure under the EPC rulebook. Defined reasons and time windows govern the message, and the receiving bank can return a negative response for several reasons, including insufficient funds, legal restriction or beneficiary refusal. A valid Recall request is not a recovery guarantee.

What is the difference between a SEPA Recall and a Request for Recall by the Originator?

A formal Recall uses specified rulebook reasons, including duplicate sending, technical error and a fraudulently originated SCT. A Request for Recall by the Originator is a distinct request route. Both operate through payment providers and neither gives the payer an automatic right to debit the beneficiary's account.

Is chargeback an EU legal right?

Chargeback is generally provided through card-scheme and issuer rules, not one universal EU statute. It is separate from the PSD2 remedy for an unauthorised card payment and from consumer-law claims against a trader. Ask the issuer for the applicable scheme, reason code, evidence and deadline.

Can ECC-Net recover money from a fake investment platform?

ECC-Net's published complaint scope excludes fraudulent operators and transactions involving financial and investment products, including cryptocurrencies and investment funds. It is designed mainly for eligible cross-border consumer disputes with registered traders. Investment fraud should be reported to the payment provider, police and relevant national financial authority.

Where do I complain if the bank rejects my case?

Use the bank or payment institution's formal written complaint process first. Then use the EBA's country list to identify the competent authority or ombudsman and check its current filing rules. FIN-NET can help with some cross-border EEA financial-service complaints after the provider has been approached.

Does Verification of Payee guarantee that the recipient is legitimate?

No. Regulation (EU) 2024/886 requires a free name-and-account check before authorisation, subject to phased compliance dates, but the result does not verify the honesty, purpose or beneficial owner behind a payment request. A mismatch or unavailable result can be evidence; it is not automatically a refund entitlement.

Can I charge back a card payment used to buy crypto?

It depends on what the card merchant provided and the applicable scheme rules. If a genuine exchange credited the customer's account and the customer later sent crypto to a scammer, the merchant may have delivered its service. Analyse the card funding, exchange trade and wallet withdrawal separately rather than assuming the later fraud invalidates the first payment.

What should I send for a first case review?

Start with a redacted transaction schedule, short chronology, payment-provider complaint and response, relevant chats or contract, and police or regulator references. Never send passwords, one-time codes, private keys or seed phrases. A review can identify possible routes and evidence gaps, but cannot promise recovery.

Evidence register

Sources and relevant dates

We link to primary sources whenever available. Sources are grouped under the section they support; the displayed date may be a publication, effective or editorial-review date. A public outcome does not promise the same result in another case.

  1. EUR-Lex: Directive (EU) 2015/2366 on payment services (PSD2)Adopted 25 November 2015; Official Journal 23 December 2015
  2. European Commission: payment servicesUpdated 27 November 2025
  3. EBA and ECB: 2025 joint report on payment fraudPublished 15 December 2025
  4. European Supervisory Authorities: tips for online financial frauds and scamsPublished 15 December 2025
  5. European Commission: protecting consumers when buying onlineUpdated 16 July 2026
  6. Your Europe: payments, transfers and cheques in the EULast checked 28 April 2026
  7. European Payments Council: current SEPA Credit Transfer rulebook and implementation guidelines2025 SCT Rulebook version 1.1 effective 5 October 2025; accessed 28 July 2026
  8. European Payments Council: 2025 SEPA Credit Transfer Rulebook version 1.0Issued 28 November 2024; entered into force 5 October 2025
  9. Your Europe: shipping and deliveryLast checked 29 April 2026
  10. Your Europe: consumer rights when shopping in the EULast checked 25 September 2025
  11. European Consumer Centres Network: services and complaint scopeAccessed 28 July 2026
  12. European Securities and Markets Authority: check whether an investment firm is regulatedAccessed 28 July 2026
  13. EUR-Lex: Regulation (EU) 2024/886, including verification of payeeOfficial Journal text; checked 29 July 2026
  14. European Payments Council: Verification of Payee scheme rulebookVersion 1.0 entered into force 5 October 2025
  15. European Consumer Centres Network: cross-border complaint processAccessed 28 July 2026
  16. European Banking Authority: how to complain about a financial institutionAccessed 28 July 2026
  17. European Commission: complain about a financial service provider in another EEA country through FIN-NETAccessed 28 July 2026
  18. European Supervisory Authorities: crypto-asset risks and consumer protection under MiCAPublished 6 October 2025
  19. European Banking Authority: registers of credit, payment and electronic-money institutionsAccessed 28 July 2026
  20. European Banking Authority: frauds and scams misusing the EBA nameAccessed 28 July 2026

Continue the review

Guides for adjacent questions

A final step without pressure

Check which actions may still be available

ScamCompass is an information hub, not a law firm. With your separate consent, an enquiry may be shared with an independent legal or recovery partner. Recovery is never guaranteed.

We never request an unlocking fee, seed phrase, password or remote access.

How ScamCompass earns revenue: with the separate optional consent below, we may receive payment from an independent legal or recovery partner for a qualified referral. This does not guarantee that a partner will accept the matter or that funds will be recovered. About our model.

Never include passwords, seed phrases, one-time codes or full card details.