Veste

Not upheld: disputed transactions / unauthorized payments complaint against HSBC UK Bank Plc trading as first direct

Financial Ombudsman decision DRN-6229085 of 2026-05-18T00:00:00+00:00. disputed transactions / unauthorized payments complaint against HSBC UK Bank Plc trading as first direct. Outcome: Not upheld.

Decision detail

ReferenceDRN-6229085
Decision date2026-05-18T00:00:00+00:00
FirmHSBC UK Bank Plc trading as first direct
Productcurrent account
Claim typedisputed transactions / unauthorized payments
OutcomeNot upheld
RemedyNo remedy ordered. The complaint was not upheld.

Summary

Mr M complained that first direct failed to reimburse £25,138.17 in disputed transactions to TapTap Send, Remitly, and Lemfi made between 12-15 October 2025. Mr M claimed he was victim of a job scam and that a fraudster had hacked his device via a WeChat app and cloned his voice to authorize the payments. First direct declined the claim, arguing the payments were authorized using Mr M's genuine device, facial biometrics, and phone number. The ombudsman found that Mr M's device, FaceID, phone number, and IP address were consistently used throughout the disputed transactions, and that first direct's VoiceID systems detected no tampering across multiple calls. Although Mr M could not technically evidence how his device was manipulated, the ombudsman concluded on the balance of probabilities that it was more likely Mr M himself authorized the payments, and therefore did not uphold the complaint.

The Ombudsman's reasoning

The ombudsman applied the balance of probabilities test required under the Payment Service Regulations 2017. The key evidence was that Mr M's genuine device, facial biometrics, phone number, and IP address were consistently used throughout the disputed transactions over multiple days. While Mr M alleged a fraudster downloaded WeChat and obtained his identification to hack his device and clone his voice, the ombudsman found this scenario unlikely because: (1) there was no evidence WeChat was actually downloaded or that identification was obtained; (2) there was no evidence of device hacking or screen sharing software; (3) first direct's VoiceID systems detected no tampering across numerous calls; (4) Mr M's own phone number was used to contact first direct; and (5) Mr M provided accurate information about his genuine trading account during calls, suggesting he was the person speaking. The ombudsman concluded it was more likely Mr M authorized the payments himself than that a third party gained autonomous control of all his applications including mobile banking.

How this compares

GroupDecisionsUphold rate
HSBC UK Bank Plc trading as first direct, all decisions2914%

Source

Read the original decision on the Financial Ombudsman Service website