the art of being legal

Specialist Cybersecurity Lawyers

Cyberseguridad Compliance Canal Denuncia

Cybersecurity at Conesa Legal

When you contact Conesa Legal by email, we will apply the Turing Test to your first message, via the legal platform Mail in Black:

This is to verify that you are a person and not an automated system, and your email will be held temporarily: please do not worry, we can still retrieve it, but if you want to make sure we receive it, you will need to follow the steps we indicate and provide a single word for security purposes.

Protecting against viruses and hackers

This may seem like a minor initial inconvenience, but it is in everyone's interest, yours and ours, as it helps us guard against viruses and hackers. Online fraud is growing every day: 85% of the emails we receive are spam, and 95% of the malware used by hackers is delivered via email, with the aim of introducing viruses, stealing identities, or capturing passwords (phishing).

Implementing protective measures in your software means adopting a cybersecurity policy.

Who is liable in a phishing case?

Article written by

Conesa Legal

At Conesa Legal, a legal advisory firm based in Barcelona, we have a team of lawyers specialized in all areas of law. We also provide comprehensive advisory and management services covering payroll, tax and accounting, and corporate compliance for both companies and self-employed professionals. We stand out for our expertise in labor law and social security, offering a highly specialized and personalized service since 1976. Our services include both preventive and reactive legal advice and representation, tailored to the needs of businesses and workers alike. Our multilingual team provides legal assistance in English, French, and Spanish, and is well prepared to support a broad range of local and international clients, whether they are companies seeking comprehensive legal solutions or individuals in need of personalized legal advice.

View professional profile

At Conesa Legal we provide the best advice because we know how to defend our clients every step of the way. It is our view that case law will increasingly tend to hold those without adequate cybersecurity measures liable for any resulting damages.

Let me illustrate with a real example:

"Some years ago, a client came to us who was the managing director of a chemical company that purchased containers of high-value mineral materials from Asia for the Spanish chemical industry (each container was worth €1 million).

This gentleman came to our office with a dismissal letter because, after several years with the company and having completed a great many purchases with the same supplier, he placed a final order for three containers as he had always done. He received the invoice by email and transferred payment to the bank account indicated.

Days went by without the goods arriving, and when he contacted the supplier, the supplier told him, as was supposedly standard practice, that payment was required before the shipment could be dispatched. Our client examined every email in detail and discovered that the address he had been corresponding with was virtually identical to the real one, but with a single letter changed, and that the bank account quoted in the invoice was completely unknown to the supplier. It was clear that their communications had been compromised: someone had intercepted the email exchange.

The money transferred was never traced, the containers never arrived, and the manager lost his job."

This kind of story happens every day.

At Conesa Legal, we had little hesitation in implementing the Mail in Black cybersecurity tool, which is designed to prevent exactly this from happening. We need to guarantee our clients that our communications are secure, for two reasons:

  1. We protect the money and information that clients share with us, because beyond the financial loss, a security breach can derail a transaction that is critical to our clients' interests.
  2. We protect clients from a court finding them negligent for having shared their details in response to a fraudulent request. In other words, failing to implement adequate cybersecurity measures can itself give rise to legal liability.

Recent court decisions have already begun ruling on cases of this kind, attributing responsibility not only to the hacker (when caught) but also to one of the parties involved, for failing to ensure secure communications. The ruling of the Court of First Instance and Instruction of Moncada, dated 31/05/2023, appeal: 848/2021 concerns a phishing case in which fraudulent charges were made against the bank account of a customer of a banking institution. The charges followed the claimant receiving an email that appeared to come from her bank, requesting her personal details and access credentials. After the claimant provided that information, two fraudulent purchases were made using her debit card at an Apple Store in Barcelona.

The Court, drawing on case law and legislation, reasoned as follows:

"In phishing cases such as these, we are dealing with highly sophisticated criminal conduct, often carried out by professional fraudsters who replicate the authentic formats of banking institutions with great precision and deceive victims with relative ease. The difficulty users face in detecting this type of fraud is evident from the sheer volume of criminal proceedings brought before our courts in connection with such scams."

Can I bring a claim against my bank following a phishing attack?

The same Court reasoned that "consequently, the law has opted for a system of quasi-strict liability, which places on banking institutions the duty to reimburse unauthorised transactions, except where the conduct of the user has been fraudulent or grossly negligent."

This position is shared by the ruling of the Provincial Court of Madrid of 13 January 2023, which held that "we cannot in any circumstances characterise the claimant's possible negligence in safeguarding her credentials as gross negligence. We are dealing with a very specific type of fraud of which it is easy to become a victim, and this does not in itself imply negligent conduct on the part of the customer, given how well-structured this form of fraud is in its execution."

Whilst it is true that the Court and the Provincial Court impose on the bank a duty of vigilance with regard to unusual movements in a customer's account, it is equally true that we are seeing a growing judicial trend towards requiring a minimum standard of cybersecurity diligence, since it is now well established that ........% of hacker attacks enter through email inboxes. This is reflected in the aforementioned ruling, which states that "it has not been alleged, let alone proven, that the defendant company provided the claimant with personalised, enhanced anti-phishing monitoring mechanisms sufficient to detect and prevent this type of fraud, and the generic warnings on the bank's website cannot be considered adequate for this purpose."

Who is liable for an erroneous bank transfer made as a result of phishing?

On 16 January 2023, the South Johannesburg High Court ruled that ENSAfrica must pay damages and costs to Judith Hawarden and ordered the firm to transfer the property, because Judith Hawarden, the buyer, had transferred 5.5 million rand to the account of a fraudster who had impersonated ENSAfrica.

The ruling reasoned that:

"Further, the defendant (ENSAAfrica) had control over the way in which it conveyed its bank account details to the plaintiff - in an unprotected pdf attachment to an email it transmitted to the plaintiff – whilst technically safe measures, amongst others, multi-channel verification (in-person or telephonic confirmation of bank details) were available to be employed by it to avert cyber fraud. Held that, a duty of care exists between a purchaser in a conveyancing transaction and the conveyancing attorneys handling the transaction to prevent harm resulting from the conveyancer's failure to warn the depositor of the dangers of cyber hacking and spoofing of emails or of the fact that pdf attachments to emails containing sensitive information such as bank account details are not invulnerable to BEC"

In other words, the party who communicated how and in what manner the transfer was to be made should have employed basic security measures to enable the client to transfer the funds to the correct bank account.

Contact our phishing specialist lawyer

abogado penalista barcelona

Date published: 16 April 2024

Last updated: 22 August 2026

Published on Updated on