A marked increase in the occurrence of cyberattacks and other payment instrument abuses has accompanied the expansion of electronic banking. Particularly complex are situations in which perpetrators by employing methods of social engineering, induce the user to authorise a payment transaction, thereby rendering the technical security mechanisms of the payment service provider ineffective. In such cases the question arises as to the allocation of liability for damages between the provider and the user. The central research question of this thesis concerns the circumstances and extent of a bank’s liability for damage arising as a consequence of cyberattacks and other abuses of payment instruments, especially in cases where the user, albeit under the influence of fraud, authorises the execution of the payment.
The thesis examines the most common forms of cyber-related abuse of payment instruments and presents statistical trends in Slovenia and at the European Union level. This is followed by an in-depth analysis of the legal framework governing the liability of banks under European Union law and its implementation into the Slovenian legal order, with particular attention devoted to issues of the validity of user consent, the bank's burden of proof, and the application of strong customer authentication. The work also includes a comparative analysis of domestic and foreign case law, as well as an overview of anticipated legislative amendments at the European Union level.
|