Argentine Court Rules on Shared Responsibility in Remote Access Phishing Fraud Case
Argentina's Commercial Appeals Court ruled on shared responsibility in a phishing fraud case where a customer lost approximately 2.2 million pesos after fraudsters gained remote access to his phone. The court found both the bank's inadequate monitoring systems and the customer's negligence in downloading unauthorized remote access software contributed to the fraud, assigning 80% liability to the bank and 20% to the customer.
How the Fraud Occurred
In March 2023, a customer attempted to contact Visa regarding a credit card issue. After failing to reach support through official channels, he searched Google for an alternative Visa customer service number. Using the number from search results, he contacted what appeared to be technical support via WhatsApp. The fraudster posing as a support operator requested installation of TeamViewer, a remote access application.
Once installed, the fraudster gained remote control of the victim's smartphone and within 90 minutes added 11 new beneficiaries and executed 9 fund transfers totaling approximately 1.98 million pesos.
Bank's Defense Arguments
The bank maintained that:
- Its systems were not compromised
- Transfers were executed using the customer's legitimate credentials
- The bank never requests customers to download remote access applications
- It conducts ongoing fraud awareness campaigns
First Instance Judgment
The trial court determined that the bank failed to maintain adequate security standards required by central bank regulations. Digital and accounting expert analysis revealed the transactions on the fraud day were completely atypical—eleven new recipients added and nine consecutive transfers of nearly 2 million pesos in under two hours from an unusual device. The court concluded the bank's monitoring systems should have detected these anomalies before authorization. The bank was ordered to refund the full amount plus 800,000 pesos in damages.
Appeals Court Decision
While confirming the bank's consumer protection law violations, the appellate court conducted broader analysis:
Customer's Negligence: The court found the customer's actions—searching for phone numbers online, contacting unknown parties via WhatsApp, and downloading unauthorized remote access software—facilitated the fraud. TeamViewer requires explicit user authorization to enable remote control.
Bank's Failures: The court identified specific bank deficiencies:
- Security alerts were sent hours after transfers completed
- No alternative verification mechanisms were employed
- The system failed to flag eleven new payees and nine rapid transfers of nearly 2 million pesos in two hours as suspicious
- The customer's multiple attempts to contact the bank during the ongoing fraud received no immediate response
Liability Distribution
Applying the principle of concurrent negligence, the court determined both the customer's conduct and the bank's omissions were material to enabling the fraud. Responsibility was apportioned 80% to the bank and 20% to the customer, reducing the refund obligation to 1,584,032 pesos with adjusted interest rates.
Precedential Impact
This ruling may influence future online fraud cases. Traditionally, courts assigned full liability to banks; this decision emphasizes customer due diligence. However, the bank's obligations remain: implement effective monitoring systems, detect anomalous transactions, issue timely alerts, and provide rapid account blocking capabilities.
Protective Measures for Users
- Use only official contact numbers published on bank and card issuer websites
- Avoid searching for support numbers on search engines or social media
- Never download remote access applications like TeamViewer or AnyDesk when requested by unknown parties
- Do not share passwords, tokens, or verification codes
- Regularly review bank security alerts
- Contact your bank immediately if fraud is suspected to block accounts and file a police report
This judgment demonstrates that preventing modern social engineering fraud requires both informed customer vigilance and robust technological countermeasures from financial institutions.
Source: iProfesional