Skip to main content

Bank and Internet Fraud in Poland: Phishing, Spoofing, Fake BLIK, and How to Recover Money (2026)

A quarter of a million incidents in 2025 (CERT Polska report) – current schemes and hard laws: refund of unauthorized transactions by the end of the next business day (art. 46), burden of proof on the bank (art. 45), free Financial Ombudsman, number 8080, blocking PESEL and cards, and secure banking from abroad.

A quarter of a million incidents of computer fraud in a year – that is how many CERT Polska registered in 2025 (an increase of 158%), adding a quarter of a million domains to the warning list and blocking nearly 1.9 million malicious SMS messages with operators during that time. If you have a Polish bank account (or help family in Poland), you need to know today’s fraud schemes – and, more importantly, your hard rights: the bank has a legal obligation to refund unauthorized transactions by the end of the next business day, and the burden of proof lies with it. This guide describes current scams, free defensive infrastructure (number 8080, CERT warning list, blocking), and a step-by-step path to recovering money – even remotely, from abroad.

What They Are Fishing for in 2025/2026 (CERT Polska Data)

  • Fake investment websites – according to CERT, “the most financially damaging” scams: platforms impersonating Orlen or Baltic Pipe with images of well-known individuals (more in the guide on bonds and saving).
  • Brand phishing: 78,000 incidents of login data theft in 2025 – most often impersonating OLX (28,000) and Allegro (22,000): “buyers” send a link to “collect money,” which steals card data.
  • Fake payment requests: “e-TOLL” sites with overdue road fees, “refund from NFZ,” “overpayment for electricity” – two-step forms first extracting personal data, then the card with CVV code.
  • SMS without a link (new trend): after successfully blocking SMS with links, criminals write “Mom, my phone broke, text me on WhatsApp…” – bait to contact outside SMS.
  • BLIK: a hijacked friend’s account on Facebook asks for a BLIK code “because they urgently need it”; in 2025, CERT also warned about a campaign impersonating the BLIK service itself.
  • Fake applications: 119 applications impersonating well-known Polish companies were removed from Google Play after CERT reports – only install official bank applications and check the publisher.
  • Phone spoofing “from the bank”: still active despite the law – since 2023, impersonating a number is a crime (up to 5 years), operators block fake calls and registered SMS overlays, but approach every incoming call “from the bank” with the assumption that it may be fake. Scenarios targeting seniors (“for the grandchild,” “safe account”) are described separately in the guide on protecting parents from scammers.

Free defensive arsenal – save these three things: forward suspicious SMS (without editing) to number 8080 (CERT Polska – contributes to the warning list and blocking patterns with operators); report incidents or suspicious sites at incydent.cert.pl; you can block cards with one phone call to all banks: +48 828 828 828 (available 24/7; from February 2026, you can also block documents in the mObywatel app). Before you pay someone, check the public warning list of KNF and the CERT warning list.

Your Hard Rights: Payment Services Act

PrincipleBasis
The bank refunds unauthorized transactions no later than by the end of the next business day after reporting – unless it has documented suspicions of fraud on the part of the client and has notified law enforcementart. 46 of the Payment Services Act
The burden of proof lies with the bank: the bank must prove that the transaction was authorized – merely stating “your card/login was used” is insufficient to demonstrate authorization or “gross negligence”art. 45
Your liability for a stolen card/instrument: a maximum of 50 euros; full liability only in cases of intent or gross negligence; zero after reporting lossart. 46 in conjunction with art. 42/44
You have a maximum of 13 months to report an unauthorized transaction from the charge – but report immediatelyart. 44
The bank responds to complaints within 15 business days (in particularly complicated cases up to 35, with written justification)art. 15a

Context worth knowing: UOKiK has been pursuing banks for the practice of “we reject because the client was negligent” – it charged several banks in 2022 and 2024 for not returning funds from unauthorized transactions on time D+1. A fair note: there is a difference between an unauthorized transaction (someone stole the data) and a transfer that you authorized yourself under manipulation – in the latter case, banks defend themselves more effectively and the chances of a refund are lower.

Step-by-Step Money Recovery

Immediately: bank + blocks

Call the bank’s official hotline: report the transaction, block the card/access, request an attempt to stop/cancel the transfer (every minute counts before settlement). Block your PESEL (mObywatel/gov.pl – from 1.06.2024, banks must check the register before granting credit) and consider BIK Alerts (48 PLN/year) to catch attempts to defraud your data.

Written complaint

Describe the incident, cite art. 46 (refund D+1) and art. 45 (burden of proof on the bank). When paying by card to a fraudulent seller, ask the bank for a chargeback (payment organization procedure; deadlines depend on the scheme – report as soon as possible, typically counted in weeks–months).

Report of a crime

You can submit it at any police station (there is no dedicated online form from CBZC). Prepare according to the CBZC list: website addresses, correspondence, account and crypto wallet numbers, payment confirmations. Living in the USA: you can send the report by mail to the prosecutor's office or submit it through an attorney in Poland.

Bank refused? Financial Ombudsman – for free

After exhausting the complaint, submit a request for a free intervention procedure from the Financial Ombudsman (email biuro@rf.gov.pl, e-Doręczenia, ePUAP – operates fully remotely). The Ombudsman does not issue binding decisions, but their intervention often changes the bank's position, and the final opinion is valuable in court. Note: the application to the Ombudsman does not interrupt the statute of limitations – do not postpone the matter for years.

Banking from Abroad: Digital Hygiene

  • Log in only through the bank's official app with mobile authorization on a trusted phone – authorization apps work anywhere in the world. Before a longer trip, update your phone number and contact details with the bank.
  • Some banks apply additional verifications when logging in from foreign IP addresses – this is normal; avoid logging in through public Wi-Fi and random VPNs.
  • Never install software “at the bank's request” (AnyDesk and similar remote desktops are classic account takeover methods) and remember: the bank never asks for a transfer to a “technical account.”
  • A cautionary tale: criminals even exploit bank rebranding – after the ownership change, Santander Bank Polska redirects addresses to the new brand, and every such confusion is a harvest for phishing. You can verify the authenticity of any financial site using methods from the guide on recognizing true sources.

Five reflexes that protect your money: (1) phone “from the bank”? Hang up and call the number on your card; (2) SMS with a link for “payment of 2.50 PLN”? Forward to 8080 and delete; (3) a friend asks for a BLIK code in chat? Call them vocally; (4) “investment opportunity” from an ad? Check the KNF warning list; (5) something already happened? Bank → complaint (art. 46!) → police → Financial Ombudsman. Don’t be ashamed to report – with a quarter of a million incidents annually, it’s not “naivety,” just statistics.

Sources

SourceTypeStatus / Credibility
CERT Polska: annual report 2025Official reportPrimary source (incident statistics)
CERT Polska: warning list and number 8080Official siteCERT Polska / NASK
incydent.cert.pl – reporting incidentsOfficial serviceCERT Polska
Payment Services Act – art. 46 (refund D+1)Legal actText of the act (also art. 44, 45, 15a)
UOKiK: unauthorized transactions – client rights and proceedingsOfficial siteUOKiK
Financial Ombudsman: free intervention procedureOfficial siterf.gov.pl
CBZC: how to report cyber fraudOfficial sitePolice
KNF: public warning listOfficial registerKNF
gov.pl: block your PESEL numberOfficial servicegov.pl
Restricted Documents System (ZBP)Official serviceZBP (from 02.2026 also in mObywatel)
zastrzegam.pl – blocking cards (828 828 828)Official serviceZBP / NBP
BIK: BIK AlertsOfficial institutionCredit Information Bureau
Act on Combating Abuses in Electronic CommunicationLegal actText of the act (spoofing = crime)

Was this guide helpful?

Help others – share your experience

Answer one question below. Your answer will help people in similar situations.

What experiences do you have with bank or internet fraud in Poland? Have you ever fallen victim to such a scam?

Your response will be reviewed before publication.

Comments (0)

No comments yet. Be the first!


Add a comment

Log in to skip email verification, or comment as guest:

Comment may be moderated before publishing.