A quarter of a million incidents of computer fraud in a year – that’s how many CERT Polska registered in 2025 (an increase of 158%), adding a quarter of a million domains to the warning list and blocking nearly 1.9 million malicious SMS messages with operators during that time. If you have a Polish bank account (or help family in Poland), you need to know today’s fraud schemes – and, more importantly, your hard rights: the bank has a statutory obligation to reimburse unauthorized transactions by the end of the next business day, and the burden of proof lies with it. This guide describes current scams, free defensive infrastructure (number 8080, CERT warning list, blocking), and a step-by-step path to recovering money – even remotely, from abroad.
What They Are Fishing For in 2025/2026 (CERT Polska Data)
- Fake investment sites – according to CERT, “the most financially damaging” scams: platforms impersonating Orlen or Baltic Pipe with images of well-known individuals (more in the guide on bonds and saving).
- Brand phishing: 78,000 incidents of login data theft in 2025 – most commonly impersonating OLX (28,000) and Allegro (22,000): “buyers” send a link to “collect money,” which steals card data.
- Fake payment requests: “e-TOLL” sites with overdue road fees, “refund from NFZ,” “overpayment for electricity” – two-step forms first extracting personal data, then the card with CVV code.
- SMS without a link (new trend): after successfully blocking SMS with links, criminals write “Mom, my phone broke, text me on WhatsApp…” – bait to contact outside SMS.
- BLIK: a friend’s compromised Facebook account asks for a BLIK code “because they urgently need it”; in 2025, CERT also warned of a campaign impersonating the BLIK service itself.
- Fake applications: 119 applications impersonating well-known Polish companies were removed from Google Play after CERT reports – only install official bank applications and check the publisher.
- Phone spoofing “from the bank”: still active despite the law – since 2023, impersonating a number is a crime (up to 5 years), operators block fake calls and registered SMS overlays, but approach every incoming call “from the bank” with the assumption that it may be fake. Scenarios targeting seniors (“for the grandchild,” “safe account”) are described separately in the guide on protecting parents from scammers.
Free defensive arsenal – save these three things: forward a suspicious SMS (without editing) to number 8080 (CERT Polska – feeds the warning list and blocking patterns with operators); report an incident or suspicious site at incydent.cert.pl; you can block cards with one phone call to all banks: +48 828 828 828 (available 24/7; from February 2026, you can also block documents in the mObywatel app). Before you pay someone, check the public warning list of KNF and the CERT warning list.
Your Hard Rights: Payment Services Act
| Principle | Basis |
|---|---|
| The bank reimburses unauthorized transactions no later than by the end of the next business day after reporting – unless it has documented suspicion of fraud on the part of the client and has notified law enforcement | art. 46 of the Payment Services Act |
| The burden of proof lies with the bank: the bank must prove that the transaction was authorized – simply stating “your card/login was used” is not sufficient to demonstrate authorization or “gross negligence” | art. 45 |
| Your liability for a stolen card/instrument: a maximum of 50 euros; full liability only in cases of intent or gross negligence; zero after reporting loss | art. 46 in conjunction with art. 42/44 |
| You have a maximum of 13 months to report an unauthorized transaction from the charge – but report immediately | art. 44 |
| The bank responds to complaints within 15 business days (in particularly complicated cases up to 35, with written justification) | art. 15a |
Context worth knowing: UOKiK has been pursuing banks for the practice of “we reject because the client was negligent” – it charged several banks in 2022 and 2024 for not returning funds from unauthorized transactions within the D+1 deadline. A fair note: there is a difference between an unauthorized transaction (someone stole the data) and a transfer that you authorized under manipulation – in the latter case, banks defend themselves more effectively and the chances of reimbursement are lower.
Step-by-Step Money Recovery
Immediately: bank + blocks
Call the bank’s official hotline: report the transaction, block the card/access, request an attempt to stop/cancel the transfer (every minute counts before settlement). Block your PESEL (mObywatel/gov.pl – from 1.06.2024 banks must check the register before granting credit) and consider BIK Alerts (48 PLN/year) to catch attempts to defraud your data.
Written complaint
Describe the incident, cite art. 46 (D+1 reimbursement) and art. 45 (burden of proof on the bank). When paying by card to a fraudulent seller, ask the bank for a chargeback (payment organization procedure; deadlines depend on the scheme – report as soon as possible, typically counted in weeks to months).
Report a crime
You can file it at any police station (there is no dedicated online form from CBZC). Prepare according to the CBZC list: website addresses, correspondence, account numbers, and crypto wallets, payment confirmations. Living in the USA: the report can be sent by mail to the prosecutor's office or filed through a proxy in Poland.
Bank refused? Financial Ombudsman – for free
After exhausting the complaint process, submit an application for free intervention proceedings with the Financial Ombudsman (email biuro@rf.gov.pl, e-Doręczenia, ePUAP – operates fully remotely). The Ombudsman does not issue binding decisions, but their intervention often changes the bank's position, and the final opinion is valuable in court. Note: the application to the Ombudsman does not interrupt the statute of limitations – do not postpone the matter for years.
Banking from Abroad: Digital Hygiene
- Log in only through the official bank app with mobile authorization on a trusted phone – authorization apps work worldwide. Before a long trip, update your phone number and contact details with the bank.
- Some banks apply additional verifications when logging in from foreign IP addresses – this is normal; avoid logging in through public Wi-Fi and random VPNs.
- Never install software “at the bank's request” (AnyDesk and similar remote desktops are classic account takeover methods) and remember: the bank never asks for a transfer to a “technical account.”
- A cautionary tale: criminals even exploit bank rebranding – after the ownership change, Santander Bank Polska redirects addresses to the new brand, and every such confusion is a harvest for phishing. You can verify the authenticity of any financial site using methods from the guide on recognizing true sources.
Five reflexes that protect your money: (1) phone “from the bank”? Hang up and call the number on your card; (2) SMS with a link for “payment of 2.50 PLN”? Forward to 8080 and delete; (3) a friend asks for a BLIK code in chat? Call them vocally; (4) “investment opportunity” from an ad? Check the KNF warning list; (5) something has already happened? Bank → complaint (art. 46!) → police → Financial Ombudsman. Don’t be ashamed to report – with a quarter of a million incidents annually, it’s not “naivety,” just statistics.
Sources
| Source | Type | Status / Credibility |
|---|---|---|
| CERT Polska: annual report 2025 | Official report | Primary source (incident statistics) |
| CERT Polska: warning list and number 8080 | Official site | CERT Polska / NASK |
| incydent.cert.pl – reporting incidents | Official service | CERT Polska |
| Payment Services Act – art. 46 (D+1 reimbursement) | Legal act | Text of the law (also art. 44, 45, 15a) |
| UOKiK: unauthorized transactions – customer rights and procedures | Official site | UOKiK |
| Financial Ombudsman: free intervention proceedings | Official site | rf.gov.pl |
| CBZC: how to report cyber fraud | Official site | Police |
| KNF: public warning list | Official register | KNF |
| gov.pl: block your PESEL number | Official service | gov.pl |
| Document Blocking System (ZBP) | Official service | ZBP (from 02.2026 also in mObywatel) |
| zastrzegam.pl – blocking cards (828 828 828) | Official service | ZBP / NBP |
| BIK: BIK Alerts | Official institution | Credit Information Bureau |
| Act on Combating Abuse in Electronic Communication | Legal act | Text of the law (spoofing = crime) |
Comments (0)
No comments yet. Be the first!