Background
Lincotek Tarbes claimed it was the victim of three fraudulent wire transfers executed on November 23, 2020, from its account at Crédit lyonnais. The company sued the bank seeking restitution of the transferred funds, arguing that its security credentials were used without authorization. The Court of Appeal of Paris rejected Lincotek Tarbes’s claim, finding that the bank had proven the transactions were properly authenticated, recorded, and that the payment token generated by the authorized device had been used. Based on this evidence, the appellate court presumed that Lincotek Tarbes had given its consent. Lincotek Tarbes appealed to the Court of Cassation.
The Court’s Holding
The Court of Cassation reversed the Court of Appeal, holding that the lower court had improperly reversed the burden of proof. Under Articles L.133-6, L.133-7, and L.133-23 of the French Monetary and Financial Code, a payment operation is authorized only if the payer gave consent in the form agreed between the payer and the payment service provider. Critically, when a user denies authorizing a payment and claims unauthorized use of security credentials, it is the payment service provider’s burden to prove that the operation was authenticated, properly recorded, and not affected by technical defects.
The Court held that “the use of the payment instrument as recorded by the payment service provider does not necessarily suffice by itself to prove that the operation was authorized by the payer.” The Court found that the Court of Appeal erred by inferring consent merely from the fact that the contractually agreed-upon form (the token from the device) had been used. This inference constituted an improper reversal of the burden of proof, violating the statutory framework. The case was remanded to the Court of Appeal of Versailles for reconsideration.
Key Takeaways
- Banks and payment service providers cannot rely solely on proof that a payment instrument (such as a token) was used to establish that a customer authorized a transaction when the customer disputes authorization and claims fraudulent use.
- The burden of proof in disputed payment transactions remains with the payment service provider, not the customer; use of agreed-upon authentication methods does not shift or satisfy this burden.
- Proving a transaction was technically authenticated and recorded is necessary but not sufficient to establish authorization; the provider must separately demonstrate that the payer actually consented.
Why It Matters
This decision reinforces consumer and business protections in payment fraud disputes under French and EU payment services law. It prevents banks from using circular logic—arguing that because the correct authentication token was used, the customer must have authorized the transaction. In an era of sophisticated cybercrime and credential compromise, requiring affirmative proof of authorization (beyond merely technical use of security devices) protects legitimate account holders from liability for fraudulent transactions where their credentials may have been stolen or misused.
The ruling has practical implications for fraud dispute resolution in France and potentially across the EU, clarifying that payment service providers cannot shift fraud risk to customers simply by pointing to the mechanical use of authentication technologies. Banks must instead investigate and prove the circumstances of authorization when transactions are genuinely disputed.
✉️ Get tomorrow’s cases before your first coffee
Daily Case Law is our free morning digest — the most substantive new decisions, filtered to your jurisdictions and topics, each linking back here for the full analysis.