Money Taken From Your Account Without Permission? Your Right to a Refund for Card Fraud and Unauthorised Payments (UK)
You check your statement and there it is: a payment you know you never made. A contactless tap in a town you have never visited, an online order you did not place, a cash withdrawal after your card was stolen, or your whole balance drained after someone got into your banking app. The first thing many people hear from the bank is the most discouraging: “The payment was authenticated with your card and PIN, so you must have authorised it.” That is not how the law works. For an unauthorised payment — one you did not consent to — the starting position under UK law is that the bank refunds you, fast, and it is the bank that has to prove otherwise. Here is exactly what you are owed and how to make it happen.
General information for the UK. Not legal advice. This is about payments you did not authorise — fraud on your card or account. It is not about being tricked into sending money yourself (a “scam”), which is a completely different regime covered near the end.
Do this first, today: tell your bank immediately — use the app’s “report fraud” option, the number on the back of the card, or the fraud line. Ask them to freeze or cancel the card and to log a formal unauthorised transaction claim. Get a reference number and the date you reported it — your liability stops the moment you notify them. Change your online banking password and check no new payees or limits have been added. The sooner you report, the stronger your position.
The core rule: refund by the end of the next business day
Card and bank payments are governed by the Payment Services Regulations 2017. A payment is “unauthorised” if you did not give your consent to it (regulation 67). Where you tell your bank about an unauthorised payment, regulation 76 says it must refund the amount and restore your account to the state it would have been in “as soon as practicable, and in any event no later than the end of the business day following the day” it becomes aware of the unauthorised transaction. That means:
- The money is put back, and your account is corrected as if the payment had never happened — including no loss of interest, because the refund must carry the original date.
- This is the default. The bank does not get to sit on your money for “an investigation” as a matter of routine.
- There is one narrow exception: the next-business-day deadline does not apply if the bank has reasonable grounds to suspect that you yourself acted fraudulently and reports this to the authorities. That is a high bar — it is not a licence to delay every claim.
The burden of proof is on the bank — not you. This is the single most important point, and the one banks gloss over. Under regulation 75, if you say a payment was unauthorised, it is for the bank to prove that the payment was properly authenticated, accurately recorded, and not hit by a technical fault — and, if it wants to refuse you, to provide evidence that you authorised it, acted fraudulently, or were grossly negligent. The regulation says in terms that the mere use of your card or app is not, by itself, enough to prove you authorised the payment or were negligent. So “chip and PIN was used” is not the end of the argument — it is the start of one the bank has to win.
When you can be made to bear some of the loss
The protection is strong, but not unconditional. The regulations set out exactly when a bank can push loss back onto you — and the limits are tight:
- Before you report a lost or stolen card, your liability is capped at £35 (regulation 77). And even that £35 does not apply if the loss was something you could not reasonably have detected, or was caused by the bank’s own staff.
- You are liable for the full amount only if you acted fraudulently, or with intent or gross negligence failed to keep your card, PIN or security details safe and to report a loss without undue delay (regulation 77(3)). This is the bank’s main line of attack — and the one it must prove.
- Once you have reported it, you are liable for nothing further (regulation 77(4)) — any fraud after your notification is the bank’s problem, unless you were in on it.
“Gross negligence” is a high bar — do not accept it lightly. Banks reach for “you were grossly negligent” because it is the one label that removes your protection. But the Financial Ombudsman has repeatedly treated gross negligence as much more than ordinary carelessness — a serious, obvious disregard for security, such as writing your PIN on the card. Being fooled by a convincing fraudster, having your details stolen in a data breach, or falling for a professional-looking phishing site is generally not gross negligence. If the bank asserts it, ask them to put in writing the specific evidence they rely on — because under regulation 75 they have to have it.
Did the bank actually check it was you? Strong Customer Authentication. Since March 2022 for online card payments, banks generally have to use Strong Customer Authentication (regulation 100) — the two-step check (app approval, a code, biometrics) before an online or remote payment goes through. If a payment that should have been through that check went out without it, and it turns out to be fraud, regulation 77(4) says you are not liable — the bank cannot pin a loss on you for a payment it failed to authenticate properly. It is always worth asking: how exactly was this payment approved?
The one deadline that matters: 13 months
You must tell your bank without undue delay, and in any event no later than 13 months after the payment left your account (regulation 74), to keep your right to a refund. In practice you should report the moment you spot it — delay gives the bank room to argue you did not act promptly — but that 13-month long-stop is your outer limit. (If the bank never gave you the account information it was required to, even that limit may not bite.)
This is NOT the same as a scam — and the difference decides which rules apply
Ask yourself one question: did you yourself instruct the payment?
- No — a criminal made the payment (stolen or cloned card, account takeover, a transaction you never touched). That is an unauthorised payment: this page, regulations 76–77, near-automatic refund.
- Yes — but a criminal tricked you into it (a fake seller, a “move your money to a safe account” call, a bogus invoice). That is an authorised push payment (APP) scam — a separate set of mandatory reimbursement rules that came in on 7 October 2024, with their own cap and their own test.
The two regimes are governed by entirely different rules, so getting the label right matters. If you were tricked into paying, do not rely on this page — claim under the APP scam reimbursement rules instead.
A quick word on contactless
You may have seen that the £100 single-payment contactless limit is reported to be lifting from March 2026, letting banks set their own limits. That changes how much can go on a single tap — it does not change your refund rights: an unauthorised contactless payment is still an unauthorised payment, and regulations 76–77 still put the money back. If anything, keep a closer eye on your statements.
If the bank drags its feet or refuses
If your bank refuses to refund, blames you without evidence, or misses the next-business-day standard, put a formal complaint in writing. It has up to 8 weeks to send a final response. If it still says no (or 8 weeks pass), you can take it — for free — to the Financial Ombudsman Service, generally within 6 months of the final response. The Ombudsman looks at whether the bank met its obligations under the regulations, and can order it to refund you plus compensation. Its maximum award is high (£455,000 for complaints referred from April 2026, uprated each year — check the current figure), but the real value is that it holds the bank to the law at no cost to you.
Getting the letter right
A firm, correctly-framed letter shifts the conversation. The strongest unauthorised-transaction complaint does three things: it states plainly that the payment was not authorised by you; it puts the bank on notice that under regulation 75 the burden is on it to prove authorisation, fraud or gross negligence — and that mere use of the card is not proof; and it requires the refund the regulations demand, with a deadline before you escalate to the Financial Ombudsman. Naming the obligations, in writing, is often what turns a flat “no” into a refund.
Generate Your Unauthorised-Payment Refund Letter in Seconds
WriteMyLegalLetter drafts a clear, firm letter demanding your bank refund an unauthorised transaction, holding it to its duty under the Payment Services Regulations — and ready to escalate to the Financial Ombudsman if it refuses. Answer a few questions and your letter is ready to send.
Write My Letter Now →This applies across the UK — the Payment Services Regulations 2017 and Financial Ombudsman jurisdiction are UK-wide, as financial-services regulation is reserved to Westminster. This is about unauthorised payments; being tricked into authorising a payment yourself (an APP scam) is a separate regime with different rules. The law in this area is being reformed — the government has announced plans to replace the Payment Services Regulations with new rules over time — so this is correct as at September 2026; check the current position before you act. The Financial Ombudsman award limit is uprated each April. Sources: Payment Services Regulations 2017 (SI 2017/752) regs 67, 74, 75, 76, 77 and 100 (legislation.gov.uk); FCA guidance on fraudulent payments; Financial Ombudsman Service. General information, not legal advice.