Veste

Not upheld: disputed transactions / unauthorised payments / fraud claim complaint against HSBC UK Bank Plc

Financial Ombudsman decision DRN-6239263 of 2026-06-03T00:00:00+00:00. disputed transactions / unauthorised payments / fraud claim complaint against HSBC UK Bank Plc. Outcome: Not upheld.

Decision detail

ReferenceDRN-6239263
Decision date2026-06-03T00:00:00+00:00
FirmHSBC UK Bank Plc
Productcurrent account, credit card
Claim typedisputed transactions / unauthorised payments / fraud claim
OutcomeNot upheld
RemedyHSBC should pay Mr C £100 compensation for the £840 credit card debit that was not initially refunded. No refund of the disputed transactions is required.

Summary

Mr C complained that HSBC failed to refund over £12,000 in disputed transactions made from his current account and credit card after he claims he was incapacitated due to suspected spiking at a bar on 3 April 2025. HSBC declined to refund the transactions, arguing that Mr C had authorised them using his security credentials. The ombudsman found that under the Payment Services Regulations 2017, all disputed transactions required Mr C's PIN, biometrics, passwords, or device consent, and that even if Mr C was intoxicated or tricked, this does not invalidate consent. The ombudsman concluded that HSBC was entitled to hold Mr C liable for the transactions as they were authorised by him, either directly or through his consent. Although HSBC should have monitored for unusual activity, the bank did suspend the account and Mr C subsequently called to confirm transactions as genuine and passed security checks, meaning any additional intervention would not have prevented the losses. HSBC was ordered to pay £100 compensation for an initial £840 debit that was not refunded.

The Ombudsman's reasoning

The ombudsman applied the Payment Services Regulations 2017, which establish that banks are liable only if customers did not authorise payments. The evidence showed that all disputed transactions required Mr C's security credentials (PIN, biometrics, passwords, or device consent). The credit card transaction used the same Apple Pay token as a genuine transaction made by Mr C in the same bar. Even if Mr C was intoxicated or tricked, being under the influence or coerced does not invalidate consent under the regulations. The ombudsman concluded that Mr C either made the transactions himself, gave his payment information with consent, or allowed someone to make them on his behalf. Regarding whether HSBC should have prevented the transactions, while the activity was unusual and HSBC did suspend the account, Mr C subsequently called the bank, passed security, and confirmed transactions as genuine. Additionally, Mr C provided a live selfie to his other bank hours earlier, demonstrating he would have successfully complied with any intervention. Therefore, any additional intervention by HSBC would not have prevented the losses.

How this compares

GroupDecisionsUphold rate
HSBC UK Bank Plc, all decisions7,53223%

Source

Read the original decision on the Financial Ombudsman Service website