Victim of a bank hacking

ESPRIT_GAMER Posted messages 9 Registration date   Status Member Last intervention   -  
brucine Posted messages 24888 Registration date   Status Member Last intervention   -

Hello,

Since June 1st, I've been in a situation that I wouldn't wish on anyone,

I even checked my balance before this happened; since I'm not on it 24/7, even though I check frequently, these fraudulent withdrawals happened.

At the end of the day on June 1, 2026, I saw an email stating that I had been debited, but the worst part was that, without my knowledge, there was validation for these 3 withdrawals. When I saw the amount of €2500, I immediately went to check, and everything collapsed because the 3 withdrawals were all for that amount of €2500, totaling €7500.

I was not notified at all, neither by email, phone, nor SMS... and on top of that, I have a secure pass, I only received the email for the last withdrawal. I searched everywhere in my inbox, in my spam, and found nothing except for the one about the last withdrawal.

So, when there was an issue a year ago because I had a PEL account, I had to explain why this happened, I had to make an appointment, and now I haven't been informed at all, and soon for them (I'm at Caisse d'Épargne), I'm at fault; however, if I had gone into the red, they would have called me.

As there was validation without my knowledge, to them it’s as if I had accepted and entered my secure pass code.

I'm not foolish enough to enter my code, especially since the amount displays for validation, and it shows that I accept 3 times €2500. It's an account from Austria according to my bank.

My bank had to freeze my accounts, I made a stop payment, and then I filed a complaint with the gendarmerie; even they said they've never seen anything like this before, that it was the first time. Moreover, there won't be any follow-up, so I can only cry.

If I had been notified about the first withdrawal, I would have immediately warned my bank, like everyone typically does.

I know very well that I will never see the €7500 again; it's still outrageous.


0

4 answers

  1. BmV Posted messages 43678 Registration date   Status Moderator Last intervention   4 963
     

    So let's stubbornly stay here....

    Question: have you called your bank contact to get to the bottom of this story?
    What did they tell you?

    ______________________________________________
    For your information, the prefecture or even the regional prefecture (!) has no authority in these banking matters, embezzlement, hacking, etc., as disputes fall solely under judicial authorities and not administrative ones, basic legal concepts that apparently are not mastered by everyone.
    It can simply start with a complaint at the police station or gendarmerie.


     
     

    2
  2. Domy31 Posted messages 374 Registration date   Status Member Last intervention   182
     

    Hello #ESPRIT_GAMER

    So it's not certain that you won't find your SouSouS, I don’t know the name of your bank so it would be good if you could tell us just in case.

    So I have a few ideas

    1: Inform your bank that you are seeking help from the prefecture regarding this confirmed fraud case, by registered mail. Ask them to facilitate the action of the justice system to provide any information that may be requested. Don't hesitate to ask your bank for the electronic banking data concerning the direct debit agreements (we'll see the place of request as well as where the often electronic signatures come from), it's not certain that your bank will cooperate immediately but the prefecture will have access. In your request to your bank, remember to specify that you want the normally concealed electronic data.

    2: Write a registered letter to the prefect of your region (you will find his name on their website) it’s good to make your request specifying his name so he can instruct the cyber police, that is the "Digital Gendarmerie," to check the "IPs" that were involved in your case, attach all the elements you have: the complaint already filed, your bank statements regarding the fraudulent transactions, possibly the electronic banking data concerning the direct debit agreements that 'if' your bank has been willing to cooperate, this information proving that it’s not your IPs that were used for the agreements to your request, specify to your Prefect that you have made this request to your bank, this will push him to act just in case!!!

    Once that’s done, inform your bank that the prefecture has been notified and possibly attach a digital copy of your letter to the prefecture, in principle they should make things easier for you.

    Another thing, if you know who is taking money from you, you can report it to the state services Signalement.Gouv.fr

    To the CNIL Complaint CNIL or even Signal Conso

    If these thieves have a website don't hesitate to report it to GOOGLE via reviews asking them not to advertise regarding their frauds.

    Etc. You can type into your favorite search engine the words "where to report scams" and do as you see fit but the more you spread your grievances everywhere you can, the more your bank should do something because today despite what they claim, they know that such scams exist, but they are hesitant to reimburse their own customers, often if they refund you: they themselves will not be automatically reimbursed even with good insurance that will also try to say that after all it's their fault.

    So there are a few ideas.

    Good luck and it’s your turn to play: the more you get involved in your case and the more you make those authorities aware that you are requesting follow-ups on your complaints the more results you should get.


    0
    1. ESPRIT_GAMER Posted messages 9 Registration date   Status Member Last intervention   5
       

      Hello domy31

      First of all, thank you very much for your ideas. My bank is Caisse d'Epargne, I mentioned it in parentheses in my post.

      What I have done is to send a registered letter to the head office, that’s what my bank told me to do. Then I am writing to the prefect with all that you told me in the registered letter with acknowledgment of receipt, and I am attaching a copy to the prefecture.

      So a registered letter for the prefecture, it’s not through websites, because I have the name of the person who hacked me that I gave to the gendarmerie. If it were a site on my statement, I would have had the sites, I’ve already had that differently, there were the sites there. It's possible that I had a remote control of my phone.

      So after all that, I can also report to the state services on their site and with the 2 other sites, okay, I will do all that.

      Thank you for your help, yes, I will need courage.

      0
  3. BmV Posted messages 43678 Registration date   Status Moderator Last intervention   4 963
     

    This is not really a computer question, but a legal one.
    Its reformulation seems much more appropriate and efficient
    with our neighbors here >>> https://droit-finances.commentcamarche.com/forum/

    0
  4. Winux01 Posted messages 266 Registration date   Status Member Last intervention   18
     

    Hello,

    It's really strange what you have. Do you have an online bank? In my opinion, you must have been impersonated and your identity hacked, or something like that for these amounts to go through easily.


    -2
    1. ESPRIT_GAMER Posted messages 9 Registration date   Status Member Last intervention   5
       

      Hello winux01,

      Oh yes, that's strange, yes I have an online bank, as I mentioned in my post when I had to transfer money from one account to another, I was soon going to have to explain why this was happening, and that's when I had three withdrawals without my knowledge and I wasn't alerted.

      I have no idea what happened, my account was compromised and hacked somehow, as I mentioned earlier, or maybe someone gained control of my phone, although we see plenty of things about web hackers or otherwise, I don't share my credentials whether it's on me or elsewhere, I am very vigilant, I hardly ever withdraw from an ATM and still I stay alert and bam.

      1
    2. BmV Posted messages 43678 Registration date   Status Moderator Last intervention   4 963 > ESPRIT_GAMER Posted messages 9 Registration date   Status Member Last intervention  
       

      "3 transactions without my knowledge I was not alerted" : if the control and authentication rules imposed by the bank or by the applicable regulatory texts have been respected, there is no reason for you to be "alerted" for every transaction! Banks process millions of transactions a day; they are not going to alert all account holders for every little thing.
      And you are not an exception.

      There is nothing stopping you from checking your accounts every day or even twice a day if you want to know precisely what is happening with your money instead of letting your bank's agents act on your behalf… perhaps.

      "I have the name of the person who hacked me that I gave to the police" : what luck!
      A hacker who leaves his name, his business card with his address and everything! That is still very, very rare!
      Really very rare.
      And of course you have filed a complaint against this person with that same police station while you were at it?

      "I had a remote control of my phone" : what is that?
      A "control" of your phone?
      What does that mean?
      By whom?
      And how?
      Your phone is not secured either?

      "even I stay vigilant" : what exactly does "being vigilant" mean to you?

      And then it's been almost two days since a question was asked >>> https://forums.commentcamarche.net/forum/affich-38293964-victime-d-un-piratage-bancaire#p38294533 to which there is still no answer.

      0
    3. Winux01 Posted messages 266 Registration date   Status Member Last intervention   18 > BmV Posted messages 43678 Registration date   Status Moderator Last intervention  
       

      Uh... Bank advisors are not there to look pretty; only small amounts do not require any monitoring or alerts. For any large incoming or outgoing sums, I assure you that your advisor can call you.

      The problem that needs to be understood is the alerts from banking applications and the information needed for external transfers and large transactions. The hacker needs to have everything redirected to them in order to infringe upon large sums, as if they were the account holder.

      0
    4. BmV Posted messages 43678 Registration date   Status Moderator Last intervention   4 963 > Winux01 Posted messages 266 Registration date   Status Member Last intervention  
       

      “For all large incoming or outgoing sums, I assure you that your advisor can call you.”: yes, everything is in the "can"!
      I have made transfers and payments involving three or even four zeros, and no advisor has ever called me.
      So?

      “The hacker must have redirected everything to himself in order to affect large amounts, as if he were the account holder.”: noooOOOooon?
      Is that really true?
      That’s incredible!
      How can this be tolerated?
      We learn so much here, with all these specialists.

      And I will, once again, generously overlook the level of French...

      Well, good luck with all your speculations.
      Which, let’s remember, are still worth €7,500...

      0
    5. brucine Posted messages 24888 Registration date   Status Member Last intervention   4 175 > BmV Posted messages 43678 Registration date   Status Moderator Last intervention  
       

      Hello,

      For the record, my banking app alerts me by SMS if I request an occasional transfer (and I suppose also if "someone else" does it) but not for any other payments like credit card, direct debit, scheduled transfers... and the bank will indeed not alert every client for every transaction.

      Online credit card transactions are generally subject to two-factor authentication, and common sense dictates that you should check your accounts every day just to verify your credit card limit outside of "unusual" transactions.

      The bank is able to prove during a payment whether the authentication methods were provided or not and from which terminal, it will be compelled to refund if the former do not exist and probably even if they were used from another terminal for failing to use a two-factor authentication method.

      2