Upheld: Fraud reimbursement (APP scams) complaint against HSBC UK Bank Plc
Financial Ombudsman decision DRN-5867638 of 2026-06-19T00:00:00+00:00. Fraud reimbursement (APP scams) complaint against HSBC UK Bank Plc. Outcome: Upheld.
Decision detail
| Reference | DRN-5867638 |
|---|---|
| Decision date | 2026-06-19T00:00:00+00:00 |
| Firm | HSBC UK Bank Plc |
| Product | Current account |
| Claim type | Fraud reimbursement (APP scams) |
| Outcome | Upheld |
| Remedy | HSBC must reimburse Mrs M's outstanding loss of £28,953.40, pay 8% simple interest per year from the date the claim was declined to the date of reimbursement, and pay £300 compensation for distress and inconvenience caused by service issues (overpayment and reversal of recovered funds). |
Summary
Mrs M fell victim to a sophisticated APP scam between 1-12 August 2024 where scammers impersonated HSBC's anti-fraud team using phone number spoofing and social engineering to convince her to make payments totalling £61,012 as part of a fake internal investigation into fraudulent employees. HSBC reversed two payments (£10,000 and £14,000) and recovered £20,058.60, but Mrs M suffered an outstanding loss of £28,953.40. HSBC declined reimbursement under the CRM Code arguing they provided effective warnings and Mrs M lacked reasonable basis for belief. The ombudsman upheld the complaint, finding HSBC's warnings were not effective as they lacked detail about spoofing and social engineering tactics, and Mrs M had reasonable grounds to believe she was assisting the bank given the sophisticated nature of the scam, her age and religious background, and the reversal of the first payment which she interpreted as confirmation of legitimacy.
The Ombudsman's reasoning
The ombudsman found that HSBC failed to provide effective warnings under the CRM Code. While HSBC gave warnings about safe account scams, they lacked sufficient detail about how scammers use social engineering and spoofing to gain trust, meaning the warnings did not break the spell of the scam. Mrs M was not considered vulnerable under the CRM Code definition because Mr M was supporting her and her belief was based on lack of knowledge about spoofing rather than cognitive vulnerability. Critically, Mrs M had a reasonable basis for believing she was assisting HSBC in catching criminals given the sophisticated social engineering used by the scammers, including number spoofing, fake security codes, specific geographic details, and the reversal of the first £10,000 payment which she interpreted as confirmation of the scammer's legitimacy. The ombudsman also considered Mrs M's age, religious background, and personal circumstances (recent loss of sister) as factors that made her more likely to trust authority and want to help catch wrongdoers.
How this compares
| Group | Decisions | Uphold rate |
|---|---|---|
| HSBC UK Bank Plc, all decisions | 7,578 | 23% |
| Fraud reimbursement (APP scams), all decisions | 20,976 | 21% |
| Current account, all decisions | 52,014 | 19% |
Source
Read the original decision on the Financial Ombudsman Service website