Phishing, Smishing, and Vishing in Spain: How to Report and Recover Your Money

Hand using a gaming mouse and keyboard in a dark environment, symbolizing the origin of a smishing cyberattack.

If you are reading this, you have probably received a suspicious message from the “bank”, an SMS from Correos about a non-existent package, or a threatening call from someone claiming to be from your financial institution. You are not alone.

During the first quarter of 2025, phishing cases in Spain increased by 40% compared to the same period in 2024, affecting thousands of people every week. Most victims believe they cannot recover their money… but we have good news for you! The law is on your side, and we will tell you everything you need to know.

In this comprehensive guide, you will learn:

  • What phishing, smishing, and vishing are,
  • How to identify fraud,
  • What to do step-by-step,
  • How to report it,
  • When the bank must return your money,
  • What evidence you need,
  • And how a specialized firm like IN DIEM Abogados can help you recover it.

What are Phishing, Smishing, and Vishing? Clear Definitions

Phishing: Fraudulent Emails

Phishing is a fraud technique where criminals send emails that appear to come from legitimate entities (banks, companies, public bodies) to steal your personal or banking data.

A real example of this maneuver is: You receive an email seemingly from BBVA stating that your account has been “blocked for security” and that you must “verify your identity” by clicking on a link. Upon doing so, you are redirected to a website identical to the bank’s, where you enter your access credentials. Minutes later, the scammers empty your account.

Smishing: SMS Scams

Smishing uses fraudulent text messages to trick users into clicking malicious links or sharing private data, such as bank account numbers.

Real example: You receive an SMS supposedly from Correos: “Your package is pending delivery. Pay €1.99 at this link to receive it.” The link leads to a fake page where you enter your card details, giving scammers direct access.

Vishing: Fraudulent Phone Calls

Vishing involves fake phone calls that pressure victims into revealing codes, credentials, or saying “yes.” Scammers record your voice saying “yes” to use it in fraudulent transactions.

Real example: Someone calls you claiming to be from your “bank’s security department,” alerting you to “suspicious activity.” They ask you to “confirm” your identity by providing codes sent to you via SMS. These codes are actually authorizations to transfer your money.

Why are these scams increasing in Spain?

1. Use of Artificial Intelligence by Cybercriminals.

94% of Spanish companies have suffered phishing or vishing attacks, many enhanced by deepfake techniques. AI allows for the creation of synthetic voices indistinguishable from real ones and extremely convincing personalized messages.

2. Perfect Impersonation of Banks and Organizations.

Scammers can make the official number of your bank or the National Police appear on your phone. This technique, called “spoofing,” makes calls seem completely legitimate.

3. Main Targets in Spain.

Cybercriminals focus on impersonating entities with a high level of trust:

  • Banking entities: BBVA, Santander, CaixaBank, Ibercaja, Bankinter
  • Public bodies: Hacienda (Tax Agency), DGT (Traffic Authority), Seguridad Social (Social Security)
  • Courier companies: Correos, MRW, SEUR
  • Popular platforms: Amazon, Bizum, PayPal

How to Detect a Phishing, Smishing, or Vishing Attempt?

Infallible Warning Signs

  • Artificial urgency or threats: “Your account will be blocked in 24 hours“, “Act now or you will lose your package
  • Shortened or strange links: bit.ly, tinyurl.com, or URLs that do not exactly match the official one (e.g., “bbva-seguridad.com” instead of “bbva.es”)
  • Request for sensitive data: No bank asks for passwords, PINs, or coordinates via SMS, email, or phone
  • Spelling or grammatical errors: Although increasingly less frequent, they still appear in some attempts
  • Generic senders: “Dear customer” instead of your name

From IN DIEM, we provide some examples of real messages we have collected this year to help you prevent these types of scams:

Fake BBVA SMS:

BBVA: We have detected unusual activity. Verify your identity here: bit.ly/xxxxx
You have 24h before permanent blocking. 

Fake “bank” call:

“Good morning, we are calling from your bank’s anti-fraud department.
We have detected three suspicious transfers. Do you recognize them?
We need you to confirm the codes we will send you via SMS to block them.”

Fake Tax Agency email:

Subject: Pending tax refund - €873
You have a pending tax refund. Click here to claim it before 12/31/2025. 

What to Do If You Have Already Fallen for the Scam? Step-by-Step Guide

It is important to understand that the first 30 minutes are “CRITICAL TIME”

  1. Block your bank account:
    • Immediately call your bank’s customer service number
    • Request urgent blocking of cards and online banking access
    • Do not hang up until you have an incident number
  2. Change all your passwords:
    • Online banking
    • Email
    • Any service where you use the same password

This step should be done, if possible, within 24 hours

Critical evidence:

  • Screenshots of received SMS messages
  • Complete emails (do not delete them, forward them to your own email as backup)
  • Phone numbers from which you were called
  • URLs of fake websites (do not click, just copy the address)
  • Bank statements showing fraudulent transactions
  • Call records with time and duration
  • WhatsApp conversations, if any

Ideally, this should be done within the first 48 hours

⌖ Where to report:

  1. National Police:
  2. Civil Guard:
  3. INCIBE (National Cybersecurity Institute):
  4. Bank of Spain

Important: You have up to 13 months to report unauthorized transactions, but the sooner, the better.

When is the Bank Liable? Updated Legal Analysis 2025

The PSD2 Regulation: Your Legal Shield

The European Payment Services Directive (PSD2), transposed into Spanish law through Royal Decree-Law 19/2018, clearly establishes:

Article 45: The payment service provider (the bank) must immediately reimburse the customer the amount stolen, unless it can prove that the user acted with gross negligence or fraud.

It is not you who must prove that you did not authorize the transaction. It is the bank that must prove that:

  1. The transaction was correctly authenticated
  2. You gave your express consent
  3. You acted with fraud or gross negligence
  • Voluntarily sharing your credentials in a public forum
  • Ignoring multiple obvious security warnings
  • Consciously providing access to unknown persons
  • Clicking on an SMS that appears to be from your bank
  • Entering your data on a website that perfectly replicates the official one
  • Providing codes to someone who identifies themselves as your bank
  • Being deceived by voice deepfakes

Key Ruling 2025: Supreme Court 571/2025

The High Court confirmed the conviction of Ibercaja for a phishing case where fifteen unauthorized transfers were made via online banking and Bizum. The bank was ordered to return over €56,000.

➜ The bank must prove gross negligence.

➜ The victim does not have to prove anything.

What to Do If the Bank Refuses Reimbursement?

Do not accept “no” as a final answer. Phishing lawsuits are being won in 95% of cases.

  1. Formal complaint to Customer Service (Response time: 1 month)
  2. Complaint to the Bank of Spain (if the bank does not respond or rejects without justification)
  3. Judicial route with a specialized lawyer (This is where IN DIEM Abogados makes the difference)

Evidence needed to recover the money

  • Police report
  • Original SMS and emails
  • Dated screenshots
  • Bank statements
  • Communications with the bank
  • Digital witnesses (INCIBE)

Real Possibilities of Recovering Money

Factors That Increase the Probability of Recovery

  1. Speed of action: Acting quickly recovers more than 40% of losses
  2. Immediate police report: Essential for the judicial process
  3. Formal claim to the bank: With all attached evidence
  4. Having a specialized lawyer: They know banking tactics and how to combat them
  5. Complete documentation: The more evidence, the better
  6. Persistence: 80% of banks initially reject claims hoping victims will give up

Common Mistakes That Make Recovering Money Difficult

  1. Not Reporting in Time
    Many victims feel ashamed or believe it’s “not worth it.” Serious mistake: Without a police report, your claim loses legal force.
  2. Not Collecting Evidence
    Deleting fraudulent messages “to forget about it” destroys crucial evidence. Keep everything.
  3. Deleting or Modifying Messages
    Any alteration of evidence can be used against you. Do not modify anything.
  4. Accepting the Bank’s Refusal Without Claiming
    Banks count on you giving up. 80% initially reject, hoping victims will abandon.
  5. Not Seeking Professional Advice
    Facing a bank’s legal department alone is an unequal battle. They have specialized teams in rejecting claims.
  6. Delaying Account Blocking
    Every minute that passes without blocking your access allows more fraudulent transfers.
  7. Not Formally Notifying the Bank
    A phone call is not enough. You need written communication with acknowledgment of receipt.

Need help? If you have been a victim of phishing, smishing, or vishing, contact a specialized firm. At IN DIEM Abogados, we can advise you, prepare the claim, and represent you before the bank or in court to maximize the chances of recovering your money.

Phishing, smishing y vishing

Los fraudes digitales pueden llegar por correo electrónico, SMS o llamadas telefónicas. Actuar rápido es clave para bloquear operaciones, conservar pruebas y reclamar la recuperación del dinero.

📧

Phishing

Correos electrónicos fraudulentos que imitan a bancos, empresas o administraciones.

📱

Smishing

SMS o mensajes móviles con enlaces falsos para obtener datos personales o bancarios.

☎️

Vishing

Llamadas falsas en las que el estafador se hace pasar por una entidad de confianza.

Qué hacer si has sido víctima
1

Bloquear la operación

Contactar de inmediato con el banco o proveedor de pago para intentar frenar cargos o transferencias.

2

Guardar pruebas

Conservar mensajes, correos, números de teléfono, justificantes, capturas y movimientos bancarios.

3

Denunciar el fraude

Presentar denuncia y dejar constancia formal de los hechos, importes y medios utilizados.

4

Reclamar el dinero

Analizar la responsabilidad de la entidad financiera y preparar la estrategia de reclamación.

Dato clave: cuanto antes se actúe, mayores son las posibilidades de bloquear movimientos, reconstruir la trazabilidad del fraude y reclamar la devolución de las cantidades sustraídas.

¿Has sido víctima de phishing, smishing o vishing?

IN DIEM Abogados puede ayudarte a analizar el caso, preparar la denuncia y reclamar la recuperación del dinero.

Consulta con expertos

How Can IN DIEM Help You?

The first thing you need to know is that we are specialists in recovering funds lost to Phishing. At IN DIEM Abogados, we understand the devastating impact of being a victim of digital fraud. It’s not just about the money lost, but the feeling of vulnerability, frustration, and helplessness.

Our specialization makes the difference:

Comprehensive Legal Analysis of Your Case. We evaluate the following in detail:

  • Type of fraud suffered
  • Bank’s liability according to PSD2
  • Feasibility of recovery
  • Optimal legal strategy

Specialized Bank Claims. Most banks agree to a refund when a specialized attorney gets involved.

  • Preparation of technical documents based on PSD2 regulations
  • Argumentation based on Supreme Court jurisprudence
  • Deep knowledge of banking rejection tactics
  • Effective legal pressure to achieve reimbursement

Strategic Criminal Complaint. A well-prepared criminal complaint strengthens your civil claim.

  • Submission of a complete criminal complaint
  • Provision of all evidence in legal format
  • Monitoring of criminal proceedings
  • Coordination with authorities (Police, Civil Guard, INCIBE)

Effective Debt Collection. We focus on tangible results:

  • Direct negotiation with banking entities
  • Legal action if necessary
  • Claim for legal interest in addition to the principal
  • Complete management until your money is recovered

Digital Test Preparation

  • Legal certification of digital evidence
  • Forensic technical analysis (if applicable)
  • Organization of documentation
  • Presentation of evidence in judicially admissible format

Comprehensive Support. From the very beginning until you get your money back:

  • Direct and transparent communication
  • Explanations in clear language, without unnecessary technical jargon
  • Constant updates on the status of your case
  • Emotional and legal support

Contact us. We are here to help you.


Preguntas frecuentes sobre reclamaciones bancarias

¿Qué pasa si el banco dice que la operación fue autorizada?

Esta es la defensa más habitual de los bancos, pero no significa que tengas la culpa. Que se usaran tus claves no implica que dieras consentimiento real. La normativa PSD2 obliga al banco a demostrar negligencia grave, no simplemente que se usaron credenciales válidas.

Un abogado especializado puede acreditar que no diste consentimiento, que el banco no aplicó medidas de seguridad suficientes y que la operación mostraba patrones sospechosos.

¿Es culpa mía haber caído en la estafa?

No. Legalmente no eres responsable. Los estafadores utilizan ingeniería social, inteligencia artificial y páginas idénticas a las reales.

Lo relevante es que actuaste de buena fe y sin intención de compartir tus datos. La ley protege a las víctimas, no las culpabiliza.

¿Cuánto tarda una reclamación por phishing?

Los plazos orientativos son:

  • Respuesta inicial del banco: 15 días hábiles.
  • Servicio de Atención al Cliente: 1 mes.
  • Banco de España: 4–6 meses.
  • Vía judicial: 6–18 meses.

Con abogado especializado, los tiempos pueden reducirse notablemente por la presión legal y la correcta fundamentación jurídica.

¿Puedo reclamar aunque hayan pasado meses?

Sí. La PSD2 permite reclamar hasta 13 meses después de la operación fraudulenta.

Eso sí: cuanto antes actúes, mayores serán tus posibilidades de recuperar el dinero.

¿Pueden negarme el reembolso por tener una contraseña débil?

No. Una contraseña débil no equivale por sí sola a negligencia grave.

Los bancos están obligados a implementar sistemas de seguridad eficaces independientemente de la fortaleza de tu contraseña.

¿Necesito un abogado para reclamar?

Puedes reclamar por tu cuenta, pero los bancos suelen rechazar muchas reclamaciones iniciales esperando que el cliente desista.

Un abogado especializado conoce la PSD2, sabe cómo rebatir la posición del banco y puede aumentar significativamente las probabilidades de recuperación.

¿Qué ocurre si los estafadores están en otro país?

Para la devolución del dinero por parte del banco, no afecta necesariamente. Tu derecho al reembolso es independiente de dónde operen los delincuentes.

En cuanto a la denuncia penal, las autoridades españolas pueden cooperar con organismos internacionales, aunque la identificación de los responsables suele ser más compleja.


Lawyers Specializing in Cryptocurrencies: Málaga, Seville, Madrid, Las Palmas de Gran Canaria, Almería, Huelva, Marbella, Estepona

At IN DIEM Abogados and Cryptoveritas 360 we provide our services at all our offices and locations in Spain, offering direct and personalized coverage in Madrid, Seville, Málaga, Marbella, Las Palmas de Gran Canaria, as well as continuous service through our digital channels for clients throughout the country.

Our multidisciplinary team also advises international companies—including Europe, Latin America and Asia—that wish to establish or expand in Spain under the MiCA regulatory framework, whether through obtaining the CASP license from the CNMV or the incorporation of companies and compliance structures adapted to the European market.

Thanks to a hybrid working methodology (in-person and online), we guarantee the same level of quality, confidentiality and efficiency for both local and foreign clients, supporting each project from initial planning to effective regulatory authorization.


Did you know that Abogados IN DIEM offers online and expedited services?

We offer our clients the option of receiving assistance via video call or videoconference, as well as by phone, depending on their preference, so that the assistance is as personalized as possible, provided immediately, and without the need to travel. This service is complemented by communication via email, which facilitates the review and delivery of documentation.

In addition, for businesses and individuals, IN DIEM Abogados offers urgent services and 24-hour support for matters that require a quick response.


Anything else about IN DIEM Lawyers? Here’s a short presentation video…

To acknowledge some of you, here’s this link.

You can find us in Seville, Madrid, Las Palmas de Gran Canaria, Málaga, Tomares, Coria del Río, Dos Hermanas, Mairena del Alcor, Estepona, Marbella, and Mairena del Aljarafe. We look forward to serving you.

Leave a Reply

Your email address will not be published. Required fields are marked *

Legal Vision

Other posts on our blog that might interest you

Swiss Capital case: legal and technical analysis of a fraudulent investment platform

Monexa Holding Scam: Legal and Technical Analysis of a Structured Digital Fraud

Aldisyn Investments Fraud: A Legal Analysis of a Digital Scheme Linked to Terrax, Club Nueva Piedra, and RMAM Vip

Iaxuss Scam: Legal and Technical Analysis of a Digital Fraud Designed to Appear Real

Profit-Trades: How the Fraudulent Investment Network Trapping Thousands of Users in Europe Operates