Fallen Victim to a Bank Scam in UAE? Here’s When Your Bank May Have to Refund the Money and What the Law Says

Fallen Victim to a Bank Scam in UAE? Here’s When Your Bank May Have to Refund the Money and What the Law Says

UAE law provides strong protections for customers facing unauthorised transactions, cyber-attacks and financial fraud.

AuthorStaff WriterAug 10, 2026, 12:38 PM

 

Victims of bank scams in the UAE may have legal protection against financial losses arising from unauthorised transactions, cyber-attacks, financial crimes and misuse of their assets or information. UAE banking regulations place significant responsibilities on licensed financial institutions to protect customers, investigate fraud and, in qualifying cases, reimburse losses.

 

The UAE’s current legal framework combines the Federal Decree-Law No. 6 of 2025 on the Central Bank and Regulation of Financial Institutions and Activities and Insurance Business with the Central Bank of the UAE’s Consumer Protection Regulation and its accompanying Consumer Protection Standards. These rules require financial institutions to maintain appropriate systems to detect and prevent fraud and to protect customers’ funds and information.

 

The law also treats the unauthorised use or manipulation of electronic payment instruments as a serious criminal offence. Under Article 15 of Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes, anyone who forges, clones or copies a credit card, debit card or other electronic payment instrument, or captures its data or information using information technology systems, may face imprisonment and a fine of between Dh200,000 and Dh2 million.

 

The same penalties can apply to those who create or design information technology tools or software intended to facilitate such offences, use a payment instrument or its information without authorisation to obtain another person’s funds or property, or knowingly accept forged, copied or illegally obtained payment instruments or data.

 

However, criminal liability for the scammer is only one part of the legal protection available to a victim. The Central Bank’s Consumer Protection Standards impose specific obligations on licensed financial institutions in relation to fraud and unauthorised transactions.

 

Financial institutions are required to have adequate systems and processes to monitor and respond to external fraud and must provide customers with procedures for reporting theft, loss and fraud. They must also maintain appropriate security and protection systems and continuously develop their cybersecurity measures to respond to evolving threats.

 

Importantly, the Consumer Protection Standards provide that licensed financial institutions must compensate consumers in a timely manner for financial losses and expenses resulting from financial crimes, misappropriation, cyber-attacks and misuse of assets and information, unless it can be proven that the loss resulted from the customer’s gross negligence or fraudulent behaviour.

 

There is also a specific requirement concerning unauthorised payments. Once an unauthorised transaction is reported, the financial institution must document the report, including the date and time it was received, inform the customer about options to block or close the affected account, card or digital payment instrument, and take appropriate steps to prevent further unauthorised transactions.

 

Under the current standards, unauthorised payments must generally be reimbursed after the investigation is completed or within 30 calendar days from the date the matter was first reported by the customer or identified by the financial institution, whichever is earlier. This reimbursement requirement does not apply where there is evidence that the customer acted fraudulently or with gross negligence.

 

This means that a customer who discovers suspicious withdrawals, card payments, online transfers or other transactions should not delay reporting them to the bank. Prompt notification creates a formal record of when the unauthorised activity was reported and enables the bank to take steps to prevent further losses.

 

Customers should also preserve all relevant evidence. This may include transaction records, bank statements, SMS or email alerts, screenshots, details of suspicious websites or communications, telephone numbers used by scammers and copies of correspondence with the bank. Such evidence can be important in establishing that the transaction was not authorised and that the customer did not act fraudulently or with gross negligence.

 

The fact that a customer was deceived by a scam does not automatically mean that the bank is liable in every case. The circumstances surrounding the transaction remain important. Where the evidence shows that the customer acted fraudulently or with gross negligence, the regulatory protection concerning reimbursement may not apply.

 

At the same time, financial institutions cannot simply disregard a customer’s complaint. The Central Bank framework requires banks and other licensed financial institutions to maintain complaint-handling procedures and investigate customer complaints. Under the current framework, a financial institution must provide a written final response to a complaint within the applicable period, giving reasons for its decision and explaining the available escalation process where the customer remains dissatisfied.

 

The UAE’s banking framework has also strengthened the role of Sanadak, the independent financial-sector complaints resolution mechanism established by the Central Bank. Customers who are dissatisfied with the outcome of a complaint can use the external complaints-resolution process after approaching the relevant financial institution.

 

A person who falls victim to a bank scam should therefore act quickly. The first step is to notify the bank immediately through its official fraud-reporting channel and request that the affected account, card or digital payment instrument be blocked or secured. The customer should then submit a formal complaint and retain confirmation of the report.

 

Where a criminal offence is suspected, the victim should also report the matter to the police and provide details of the transactions and supporting evidence. The criminal investigation and the bank’s internal investigation may proceed separately, and providing complete information can assist both processes.

 

If the bank rejects the claim, fails to resolve the matter satisfactorily or does not provide an adequate explanation, the customer can escalate the complaint through the UAE’s financial complaints-resolution framework, including Sanadak where applicable.

 

The UAE’s legal framework therefore does not leave victims of electronic banking fraud without protection. Banks have statutory and regulatory responsibilities to maintain secure systems, detect fraud, protect customer assets and respond to unauthorised transactions. Where a loss results from a financial crime, cyber-attack or misuse of customer information and there is no evidence of fraud or gross negligence by the customer, the applicable Central Bank standards can provide a basis for reimbursement.

 

For anyone who discovers an unexpected transaction, the most important steps are to report it immediately, secure the account, preserve evidence, file a formal complaint and pursue the available escalation mechanisms if the matter is not resolved.

 

For any enquiries or information, contact ask@tlr.ae or call us on +971 52 644 3004Follow The Law Reporters on WhatsApp Channels.