In today’s digitally connected world, technology has become an integral part of our everyday lives — from banking transactions to social networking. However, alongside its benefits, significant threats also lurk: online fraud, and especially phishing, are increasingly common phenomena with serious legal and financial consequences for victims.
What is Phishing?
Phishing is a cybercrime technique in which attackers send deceptive emails or text messages that appear to come from trusted entities — usually banks, companies, or public services. The goal is to trick recipients into revealing personal information such as passwords, credit card numbers, or bank account details.
Phishing attacks have evolved significantly. Today, fake websites can be almost indistinguishable from legitimate ones, fooling even experienced users.
Legal Aspects: Who is Responsible?
A recent decision by the Court of Peace in Thessaloniki (Judgment No. 232/2023) highlighted the complexity of the legal framework surrounding cybercrime. In this case, the claimant suffered financial loss due to phishing. The court apportioned responsibility:
• To the bank, for failing to adequately secure its systems, as a third party infiltrated its digital environment and sent a deceptive SMS to the customer.
• To the claimant, who failed to follow basic security instructions from the bank and disclosed personal information.
The court made extensive reference to the liability of banks under Article 8 of Law 2251/1994 on consumer protection, emphasizing that they have a duty of care and security toward their clients. However, if the victim contributes to the damage through negligence, that liability may be reduced or waived entirely (based on Article 300 of the Civil Code).
How to Recognize a Phishing Message
Here are some warning signs:
1. A generic greeting (e.g., “Dear customer”) without personalization.
2. A request for personal information — something your bank will never ask via email or SMS.
3. Poor grammar or spelling mistakes.
4. Unexpected communication from an organization with which you have no active relationship.
5. A sense of urgency (e.g., “Your account will be deactivated immediately”).
6. Offers that seem too good to be true.
7. Suspicious domains (e.g., an email from a Chinese domain claiming to be a European bank).
How to Protect Yourself:
1. Stay informed about new phishing techniques.
2. Never provide sensitive information via email or links.
3. Carefully check URLs and domain names.
4. Avoid clicking on suspicious links or downloading unknown attachments.
5. Use trusted anti-phishing software.
6. Regularly monitor your account activity.
Other Types of Online Fraud Beyond Phishing:
• Vishing (voice phishing): Fraud via phone calls.
• Smishing (SMS phishing): Fraud via text messages.
• Fake websites: Lookalike sites used to steal information.
• Scams via social media or ads: Fake products, services, or job opportunities.
• Hacking & data theft.
Legal Framework & Penalties
Online fraud is a criminal offense under Article 386 of the Greek Penal Code, and depending on the specifics, other laws may apply, such as data protection legislation.
Indicative penalties:
• Damage under €120,000: Up to 5 years imprisonment or a fine.
• Damage over €120,000 or organized criminal activity: Imprisonment of 5 years and up.
• Serial or professional fraud: Harsher penalties depending on severity.
Where to Turn for Help:
• The Cyber Crime Division offers educational material (videos, guides) via cyberalert.gr.
• Through Gov.gr, you can submit an online complaint if you fall victim to fraud.
• In case of doubt, always contact your legal advisor or your bank via official channels — never through links found in emails.
Special Attention for Foreign Users
Foreign customers with bank accounts in Greece, who may not be familiar with banking procedures, are often vulnerable targets. It’s vital to know that no legitimate bank will ever request personal or security information via SMS or email. Access to e-banking must only occur through the bank’s official website, and never through suspicious links.
Conclusion:
Phishing is here to stay — it evolves constantly and threatens not only our finances but also our identity. We all — individuals and organizations — have a responsibility to act with awareness, knowledge, and caution.
As the court rightly concluded: Responsibility is shared — both banks and customers must act prudently.
Cybersecurity is an ongoing challenge that requires vigilance, education, and collaboration.
