Particle.news
Download on the App Store

Court Rules Cyber Add‑On Doesn’t Cover €2,000 Chatroom Fraud

A Bernau judge said entering IBAN and card numbers and then authorizing a bank app payment is not the same as theft of confidential access data and falls outside the policy’s phishing wording.

Overview

  • The Amtsgericht Bernau dismissed a claim after a Vinted seller lost almost €2,000 when a buyer-directed email led her to a chatroom where she gave IBAN and credit‑card details and then confirmed a payment in her banking app.
  • The court found IBANs and card numbers are routinely shared in payments and are not ‘confidential access data’ like passwords, PINs, or TANs that typical cyber clauses protect.
  • Judges said the loss resulted from the claimant’s own authorization in her banking app rather than misuse of online‑banking login credentials, so the insurer’s phishing cover did not apply.
  • The ruling left open whether chatroom or non‑email fraud falls under the policy because the clause specifically mentions forged e‑mails, highlighting how narrow wording can decide claims.
  • The decision follows earlier cases since late 2024 where courts rejected payouts for phishing or social‑engineering losses when policies distinguish channels or define access data narrowly, raising questions for consumers, insurers, and regulators.