Soares, Goulart & Caetano Advogados

December 05, 2025

Bank liability in cases of fraud: analysis of a recent ruling and its impacts for business owners

Back to articles
Bank liability in cases of fraud: analysis of a recent ruling and its impacts for business owners

In a context of growing use of electronic transactions by companies — whether through corporate cards, PIX (Brazil's instant payment system) or other digital payment methods — the risk of fraud and scams against account holders and consumers is also rising. A recently reported case, in which a judge declared debts resulting from a scam against a consumer unenforceable and ordered the bank to make partial restitution, highlights a topic of significant interest to business owners and managers: to what extent are financial institutions liable for fraud, and what precautions should companies adopt to protect their assets?

Following rulings like this one is essential to understanding the civil liability regime applicable to financial institutions and to adopting sound corporate governance practices.

Overview of the case and grounds for the decision

According to the report, the judge of the 2nd Small Claims Court (JEC) — Vergueiro, in São Paulo, ruled in favor of a claim seeking to have a debt declared unenforceable combined with a request for damages against a financial institution. In the case, the consumer alleged that unrecognized purchases had been charged to their credit card, and that they had also been induced — through a scam — to make a PIX transfer in the amount of R$17,980. In total, the disputed charges and transactions amounted to sums incompatible with the consumer's usual spending pattern. As a result, the judge declared the debts unenforceable and ordered the bank to reimburse, at least partially, the amount transferred via PIX, recognizing a failure in the bank's security measures.

The decision was based on the strict liability regime set out in the Consumer Protection Code (CDC), particularly Article 14, as well as on the case law consolidated by Precedent 479 of the Superior Court of Justice (STJ), which holds financial institutions liable for theft and fraud whenever there is a failure in banking security services.

It is important to note that, in this case, the defendant bank did not present technical reports or evidence demonstrating the legitimacy of the disputed transactions — such as system logs, authentication evidence, or any effective security mechanism. As a result, the claim that the challenged transactions were regular could not be sustained.

Strict liability and the duty of security owed by financial institutions

For business managers, the central lesson is clear: by offering banking services, financial institutions assume the risk inherent to their activity, which includes protecting customers against fraud and scams. Current case law, including the most recent rulings from the Superior Court of Justice (STJ), reaffirms this duty. For example, in October 2025, the 3rd Panel of the STJ ruled that banks and payment institutions must compensate customers who fall victim to social engineering scams whenever there is a failure in data protection or an inability to identify atypical transactions.

In practice, the application of strict liability requires the bank to prove either the absence of a defect in its service or the exclusive fault of the consumer or third parties — which, in many cases involving sophisticated fraud, will not be possible.

For a company, this means that when using banking services — whether for payments, receipts, transfers or other operations — it may have legal grounds to seek restitution or compensation, even in the case of fraud, whenever it is shown that the bank failed to adopt adequate security mechanisms.

Practical implications for companies and managers

From a business standpoint, this precedent carries several practical implications. First, it reinforces the need to adopt strict internal governance regarding the use of payment channels and controls over account access, passwords and authorizations. Even though the bank bears responsibility for protecting against fraud, the company should also adopt good security practices — segregation of duties, transaction confirmation, multi-factor authentication, among others. This approach helps both to reduce risk and to strengthen any future judicial or administrative claim related to fraud.

Second, for companies that provide services to third parties or handle high transaction volumes, it is worth considering the adoption of contractual policies and specific clauses with financial institutions or payment service providers, requiring minimum security standards, regular audit reports, and obligations to notify in the event of atypical or suspicious transactions.

Moreover, the case shows that, despite the prevailing judicial understanding, the outcome of each claim may vary depending on the account holder's conduct — particularly if there are indications of gross negligence or recklessness, such as voluntarily transferring large sums to unknown recipients without verification. In the case analyzed, the judge found there to be "contributory fault" on the part of the consumer, which led to only partial restitution of the transferred amount.

Migalhas

Therefore, companies should pay special attention to gathering evidence of internal diligence — records of who authorized transactions, data verification, internal communications, and control system logs — demonstrating that they acted carefully, even in the face of fraud. This can positively influence a future court ruling and reduce the risk of liability.

Recent case law as a warning to the financial sector

The STJ precedent from October 2025 was particularly emphatic in stating that, in cases of fraud resulting from failures in security systems, the compensation should not be reduced on the grounds of contributory fault by the victim, unless a conscious assumption of risk is demonstrated.

This understanding consolidates a clear trend: the Judiciary tends to place on banks and payment institutions the burden of ensuring effective security for their customers, and is largely unreceptive to defenses based solely on the account holder's fault. This requires the financial system — and, consequently, the companies that depend on it — to adopt robust controls to mitigate risk.

For managers, this means that the choice of financial partners should take into account not only fees and convenience, but also technical capacity for fraud prevention and detection. Contracts, terms of service, audits and certifications now play a relevant role in corporate risk analysis.

The recent case decided by the 2nd Small Claims Court (JEC) — Vergueiro clearly shows that the banking system is responsible for ensuring the security of transactions, and that failures may result in the restitution of amounts wrongly charged. This underscores, for companies and managers, the importance of adopting governance practices, internal controls, and diligence in authorizing payments.

Companies should treat the security of financial transactions with the same seriousness given to other corporate risks — fraud, compliance, data governance. Adopting internal control mechanisms, enhanced authentication, clearly defined authorization powers, and documented records of transactions is not merely good management practice, but a decisive factor in safeguarding rights in the event of future litigation.

Finally, whenever there is suspicion of fraud or an atypical transaction, it is advisable to seek specialized legal counsel to assess the feasibility of a claim to declare a debt unenforceable, seek restitution of amounts, and, where applicable, pursue compensation for material or moral damages.

Written by Julia Tosi