A quarter of a million incidents of computer fraud in a year – that is how many CERT Polska registered in 2025 (an increase of 158%), adding a quarter of a million domains to the warning list and blocking nearly 1.9 million malicious SMS messages with operators during that time. If you have a Polish bank account (or help family in Poland), you need to know today’s fraud schemes – and, more importantly, your hard rights: the bank has a legal obligation to refund unauthorized transactions by the end of the next business day, and the burden of proof lies with it. This guide describes current scams, free defensive infrastructure (number 8080, CERT warning list, blocking), and a step-by-step path to recovering money – even remotely, from abroad.
What They Are Fishing for in 2025/2026 (CERT Polska Data)
- Fake investment websites – according to CERT, “the most financially damaging” scams: platforms impersonating Orlen or Baltic Pipe with images of well-known individuals (more in the guide on bonds and saving).
- Brand phishing: 78,000 incidents of login data theft in 2025 – most often impersonating OLX (28,000) and Allegro (22,000): “buyers” send a link to “collect money,” which steals card data.
- Fake payment requests: “e-TOLL” sites with overdue road fees, “refund from NFZ,” “overpayment for electricity” – two-step forms first extracting personal data, then the card with CVV code.
- SMS without a link (new trend): after successfully blocking SMS with links, criminals write “Mom, my phone broke, text me on WhatsApp…” – bait to contact outside SMS.
- BLIK: a hijacked friend’s account on Facebook asks for a BLIK code “because they urgently need it”; in 2025, CERT also warned about a campaign impersonating the BLIK service itself.
- Fake applications: 119 applications impersonating well-known Polish companies were removed from Google Play after CERT reports – only install official bank applications and check the publisher.
- Phone spoofing “from the bank”: still active despite the law – since 2023, impersonating a number is a crime (up to 5 years), operators block fake calls and registered SMS overlays, but approach every incoming call “from the bank” with the assumption that it may be fake. Scenarios targeting seniors (“for the grandchild,” “safe account”) are described separately in the guide on protecting parents from scammers.
Free defensive arsenal – save these three things: forward suspicious SMS (without editing) to number 8080 (CERT Polska – contributes to the warning list and blocking patterns with operators); report incidents or suspicious sites at incydent.cert.pl; you can block cards with one phone call to all banks: +48 828 828 828 (available 24/7; from February 2026, you can also block documents in the mObywatel app). Before you pay someone, check the public warning list of KNF and the CERT warning list.
Your Hard Rights: Payment Services Act
| Principle | Basis |
|---|---|
| The bank refunds unauthorized transactions no later than by the end of the next business day after reporting – unless it has documented suspicions of fraud on the part of the client and has notified law enforcement | art. 46 of the Payment Services Act |
| The burden of proof lies with the bank: the bank must prove that the transaction was authorized – merely stating “your card/login was used” is insufficient to demonstrate authorization or “gross negligence” | art. 45 |
| Your liability for a stolen card/instrument: a maximum of 50 euros; full liability only in cases of intent or gross negligence; zero after reporting loss | art. 46 in conjunction with art. 42/44 |
| You have a maximum of 13 months to report an unauthorized transaction from the charge – but report immediately | art. 44 |
| The bank responds to complaints within 15 business days (in particularly complicated cases up to 35, with written justification) | art. 15a |
Context worth knowing: UOKiK has been pursuing banks for the practice of “we reject because the client was negligent” – it charged several banks in 2022 and 2024 for not returning funds from unauthorized transactions on time D+1. A fair note: there is a difference between an unauthorized transaction (someone stole the data) and a transfer that you authorized yourself under manipulation – in the latter case, banks defend themselves more effectively and the chances of a refund are lower.
Step-by-Step Money Recovery
Immediately: bank + blocks
Call the bank’s official hotline: report the transaction, block the card/access, request an attempt to stop/cancel the transfer (every minute counts before settlement). Block your PESEL (mObywatel/gov.pl – from 1.06.2024, banks must check the register before granting credit) and consider BIK Alerts (48 PLN/year) to catch attempts to defraud your data.
Written complaint
Describe the incident, cite art. 46 (refund D+1) and art. 45 (burden of proof on the bank). When paying by card to a fraudulent seller, ask the bank for a chargeback (payment organization procedure; deadlines depend on the scheme – report as soon as possible, typically counted in weeks–months).
Report of a crime
You can submit it at any police station (there is no dedicated online form from CBZC). Prepare according to the CBZC list: website addresses, correspondence, account and crypto wallet numbers, payment confirmations. Living in the USA: you can send the report by mail to the prosecutor's office or submit it through an attorney in Poland.
Bank refused? Financial Ombudsman – for free
After exhausting the complaint, submit a request for a free intervention procedure from the Financial Ombudsman (email biuro@rf.gov.pl, e-Doręczenia, ePUAP – operates fully remotely). The Ombudsman does not issue binding decisions, but their intervention often changes the bank's position, and the final opinion is valuable in court. Note: the application to the Ombudsman does not interrupt the statute of limitations – do not postpone the matter for years.
Banking from Abroad: Digital Hygiene
- Log in only through the bank's official app with mobile authorization on a trusted phone – authorization apps work anywhere in the world. Before a longer trip, update your phone number and contact details with the bank.
- Some banks apply additional verifications when logging in from foreign IP addresses – this is normal; avoid logging in through public Wi-Fi and random VPNs.
- Never install software “at the bank's request” (AnyDesk and similar remote desktops are classic account takeover methods) and remember: the bank never asks for a transfer to a “technical account.”
- A cautionary tale: criminals even exploit bank rebranding – after the ownership change, Santander Bank Polska redirects addresses to the new brand, and every such confusion is a harvest for phishing. You can verify the authenticity of any financial site using methods from the guide on recognizing true sources.
Five reflexes that protect your money: (1) phone “from the bank”? Hang up and call the number on your card; (2) SMS with a link for “payment of 2.50 PLN”? Forward to 8080 and delete; (3) a friend asks for a BLIK code in chat? Call them vocally; (4) “investment opportunity” from an ad? Check the KNF warning list; (5) something already happened? Bank → complaint (art. 46!) → police → Financial Ombudsman. Don’t be ashamed to report – with a quarter of a million incidents annually, it’s not “naivety,” just statistics.
Sources
| Source | Type | Status / Credibility |
|---|---|---|
| CERT Polska: annual report 2025 | Official report | Primary source (incident statistics) |
| CERT Polska: warning list and number 8080 | Official site | CERT Polska / NASK |
| incydent.cert.pl – reporting incidents | Official service | CERT Polska |
| Payment Services Act – art. 46 (refund D+1) | Legal act | Text of the act (also art. 44, 45, 15a) |
| UOKiK: unauthorized transactions – client rights and proceedings | Official site | UOKiK |
| Financial Ombudsman: free intervention procedure | Official site | rf.gov.pl |
| CBZC: how to report cyber fraud | Official site | Police |
| KNF: public warning list | Official register | KNF |
| gov.pl: block your PESEL number | Official service | gov.pl |
| Restricted Documents System (ZBP) | Official service | ZBP (from 02.2026 also in mObywatel) |
| zastrzegam.pl – blocking cards (828 828 828) | Official service | ZBP / NBP |
| BIK: BIK Alerts | Official institution | Credit Information Bureau |
| Act on Combating Abuses in Electronic Communication | Legal act | Text of the act (spoofing = crime) |
Comments (0)
No comments yet. Be the first!