Nadezhda T. orders a payment by entering her bank card number on a link sent to her on behalf of the bank of which she is a client, after selecting an item for purchase on the platform for selling second-hand goods at olx.bg. for a value of 12 BGN.
A few days later, she checks her account balance and learns that an unauthorized transaction worth 4360 BGN was made from her card.
She files a complaint with Bank I. B., where she waits for a response for 2 weeks, in which she is informed that her request for a refund will not be satisfied.
Nadezhda T. sends an application to initiate a reconciliation procedure to the e-mail address of the CARS "Consensus", together with the letters and responses from and to the bank, with a detailed description of the case and all bank statements before and after the unauthorized transaction.
CARS "Consensus" prepares a letter to Bank I.B., requesting an opinion, mentioning applicable legal texts from the Payment Services and Payment Systems Act and the EU Directive (Payment Service Directive (PSDII). The case was reviewed again by the bank's team of lawyers and representatives of its management and an assessment was made that it was a phishing attack*.
The case was analyzed in its entirety. It is assumed that in this case there was no gross negligence on the part of the bank's client, but that the principle of double identification was not applied when approving a series of transactions.
Bank X. sends a letter that the consumer's claim will be satisfied. The amount was subsequently refunded to the cardholder Nadezhda T.
*Phishing is a type of fraud in which fraudsters try to steal your personal data by posing as institutions you trust. They send emails or messages through random selections or popular platforms in which involve victims of fraud in conversations, online or by phone, aimed at voluntarily providing sensitive information, such as passwords, codes or bank card numbers. Therefore, remember:
You can provide your bank account, but not your bank card numbers!
Keep your PINs, codes and passwords safe, especially those that can be used to authorize bank payments.
Avoid opening suspicious emails or links that resemble those from your bank or other service providers, such emails and links should not be opened.