Wire Transfer Fraud: Codes Do Not Prove Consent
Cass. com., July 1, 2026: the recorded use of security codes does not prove the payer's consent. Analysis and consequences for businesses.
Analysis of a judgment by Cass. com., July 1, 2026, no. 25-13.134, by Pierre-Louis Roquet, a business law avocat in Lyon.
On November 23, 2020, three wire transfers left the account of an industrial company held with Crédit Lyonnais. The company claims it never ordered them. The bank's computer records tell another story: identifier entered, online access code validated, “token” generated by the security device assigned to an employee. From the system's perspective, everything is regular.
It is this apparent regularity that caused the company to lose its case before the Paris Court of Appeal. The reasoning of the Parisian judges was brief: since the payment instrument was used in the form agreed upon in the contract, the account holder's consent is presumed.
The commercial chamber overturned this shortcut. The judgment of July 1, 2026, published in the Bulletin, annuls the Parisian decision of January 22, 2025, in all its provisions and refers the case to the Versailles Court of Appeal. The reason is clear: by inferring consent from the use of the contractually agreed form, the Court of Appeal reversed the burden of proof.
The mechanism of articles L. 133-6 and L. 133-7 of the French Monetary and Financial Code is nevertheless clear. A payment operation is authorized if the payer has consented to its execution. This consent is given in the form agreed upon between the payer and their payment service provider. Failing this, the operation is deemed unauthorized. The agreed form is the channel for consent; it is not proof of it.
Article L. 133-23 completes the provisions. When the user denies having authorized an executed operation, it is up to the service provider to prove that it was authenticated, duly recorded and accounted for, and that it was not affected by a technical or other deficiency. The same text adds a sentence that institutions sometimes prefer to leave in the dark: the use of the payment instrument as recorded by the service provider is not necessarily sufficient, as such, to prove that the operation was authorized by the payer.
The connection log is not a signature
The entire difficulty lies in this distinction. A bank that produces its technical records satisfies the first requirement of the text, that of authentication. It demonstrates that its systems worked. It does not demonstrate that a will stood behind the order. Confusing the two amounts to imposing a negative proof on the victim company, which it cannot, by hypothesis, provide: that it did not want the operation.
This solution is not a break with previous rulings. It extends Cass. com., January 18, 2017, no. 15-18.102, which already ruled that proof of the payer's gross negligence cannot be inferred solely from the fact that the payment instrument or the data linked to it were actually used. In 2017, the Court held the second stage of the reasoning, that of the user's fault. In 2026, it holds the first, that of the authorization of the operation itself. Both locks are now in place, and they close in the same direction.
The practical effect is considerable. A bank will no longer win a wire transfer fraud dispute by simply providing the computer trace of the connection. The technical debate shifts to what its logs do not say: the originating IP address, the device used, the timestamp, the consistency of the beneficiary with the account history, the existence of an unattended security alert.
What this changes for businesses and their account agreements
For Lyon-based companies facing embezzlement, the useful sequence begins before litigation. Article L. 133-18 requires the service provider to reimburse the amount of the unauthorized operation immediately after becoming aware of it, and at the latest by the end of the first business day following, unless it has good reasons to suspect fraud by the user, reasons which it must then communicate in writing to the Banque de France. This reimbursement is a prerequisite, not the outcome of a judicial debate. Reminding this in writing, with the text in hand, often changes the tone of the discussion.
A reservation must be made, and it is a significant one for legal entities. Article L. 133-2 allows the parties to derogate by contract from Article L. 133-23, as well as from Articles L. 133-19 and L. 133-20, provided that the user is not a natural person acting for non-professional purposes. The evidentiary rule that the Court of Cassation has just enforced is therefore supplétive (default, non-mandatory) with respect to a company. The definition of an authorized operation, in Articles L. 133-6 and L. 133-7, however, is not subject to this derogation power.
The consequence for the auditing and negotiation of account agreements is immediate. The stipulations relating to the proof of orders, the presumptions attached to the use of personalized security devices, and the probative force of the bank's records must be re-read. A cleverly drafted clause by the institution can neutralize part of the judgment's contribution. An awkward clause, which would claim to make the mere use of the device proof of consent, will clash with the mandatory core of Articles L. 133-6 and L. 133-7. This examination falls within the scope of current banking practice of a Lyon firm, as do pricing conditions or value dates.
What the judgment leaves open
Cassation (annulment) is not victory. Before the Versailles Court of Appeal, the bank retains two grounds. That of the proof of consent, which it can try to establish otherwise than by its logs. That of the user's gross negligence within the meaning of Article L. 133-19, IV, which releases it from any reimbursement obligation, provided it proves it. The commercial chamber did not examine the second branch of the appeal and says nothing about attributing the actions of the employee holding the device to the company. Knowing under what conditions the behavior of an employee constitutes the payer's consent remains an open question.
A final frontier often determines the outcome of the case. The regime for unauthorized payment operations assumes that the order does not originate from the customer. In cases of fake supplier or fake CEO fraud, where a misled employee issues the transfer themselves, the operation is authorized, and Article L. 133-18 does not apply. The debate then shifts to the banker's duty of vigilance and apparent anomaly, with a much less favorable evidentiary regime for the customer. Drawing this line from the first letter of complaint is crucial.
Frequently Asked Questions
My bank refuses to reimburse me for a fraudulent transfer, what should I do?
Immediately send a written complaint formally contesting that you authorized the operation, referring to Articles L. 133-18 and L. 133-23 of the French Monetary and Financial Code. Request full disclosure of the technical authentication elements. The refusal must be justified. If the bank persists, legal action before the competent court must be initiated quickly, without waiting for the expiry of the challenge deadlines.
The bank produces logs showing the use of my codes, is the case lost?
No. Since the judgment of July 1, 2026, the use of the payment instrument in the form provided for in the contract does not in itself prove that the payer consented. These statements establish authentication, not intent. It is up to the bank to complete its demonstration, provided that you have expressly challenged consent from your first written submissions.
What is the deadline for disputing a fraudulent transfer?
Article L. 133-24 requires the operation to be reported without delay and at the latest within thirteen months following the debit date. After this period, the action for reimbursement is closed. In practice, the report must be made as soon as it is discovered, as any delay fuels the accusation of negligence directed at the company.
Must the bank reimburse before the dispute is settled?
Yes, in principle. Article L. 133-18 provides for immediate reimbursement and at the latest by the end of the first business day following knowledge of the disputed operation. The only escape is a reasoned suspicion of fraud by the user, which the institution must report in writing to the Banque de France. This reimbursement is not suspended pending expert appraisal.
Does my company benefit from the same protection as an individual?
Not necessarily. Article L. 133-2 allows several protective rules to be set aside by contract, including that relating to the burden of proof, when the user is not a natural person acting for non-professional purposes. The account agreement must therefore be read before any decision on litigation strategy.
Is CEO fraud subject to the same regime?
No. When a misled employee issues the transfer themselves, the operation is authorized within the meaning of the texts and Article L. 133-18 does not apply. The bank's liability can then only be sought on the grounds of its duty of vigilance in the face of an apparent anomaly, which requires a much heavier demonstration.
Is the company liable for the misuse of an employee's codes?
The question is not definitively settled. The judgment of July 1, 2026, does not rule on the attribution to the payer of the actions of the holder of the security device. The debate will focus on the internal organization of authorizations, the separation of duties, and the company's diligence in preserving its personalized security data.
Sources
- Cass. com., July 1, 2026, no. 25-13.134, published in the Bulletin
- Cass. com., January 18, 2017, no. 15-18.102, Bull. 2017, IV, no. 6
- Article L. 133-2 of the French Monetary and Financial Code
- Article L. 133-6 of the French Monetary and Financial Code
- Article L. 133-7 of the French Monetary and Financial Code
- Article L. 133-18 of the French Monetary and Financial Code
- Article L. 133-19 of the French Monetary and Financial Code
- Article L. 133-23 of the French Monetary and Financial Code
- Article L. 133-24 of the French Monetary and Financial Code
A matter on this topic? My areas of practice — Contact the firm