Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Poland Forces Four Banks to Reopen Denied Fraud Refunds, Citing a Legal Line the U.S. Doesn't Draw

Poland Draws a Line the U.S. Still Won't
Poland's Office of Competition and Consumer Protection (UOKiK) announced binding "commitment decisions" Monday against four of the country's largest retail banks: Alior Bank, mBank, BNP Paribas Bank Polska, and Bank Millennium. Each bank must now re-examine every unauthorized-payment fraud complaint it previously rejected and apply the EU's mandatory next-business-day refund rule going forward, according to Tech Times. The decisions close nearly four years of enforcement proceedings. Ten more cases against other Polish banks remain open.
The legal hinge is a distinction that sounds technical but isn't complicated: authentication is not authorization. Entering a correct PIN, unlocking a banking app, or typing in a one-time SMS code proves you're the person operating the account. It does not prove you understood and consented to the specific transfer that code approved, according to Tech Times.
Scammers exploit this gap. A fraudster impersonating a bank employee, a police officer, or a marketplace buyer convinces a victim to enter a real code for a transaction the victim doesn't fully grasp is going to a criminal. Polish banks had been treating the entered code as conclusive proof the victim signed off, then denying refund claims on that basis, per Tech Times.
Same Legal Distinction, Different Rulebook Depending on Where You Live
Cybersecurity firm Bitdefender lays out why the same scam can produce completely different outcomes depending on jurisdiction and payment rail. Under U.S. Regulation E, a transfer stays potentially unauthorized if a fraudster stole a victim's login credentials and initiated the transfer themselves. But if the victim was deceived into personally clicking "send," that transaction generally falls outside Regulation E's protections entirely, per Bitdefender's summary of CFPB guidance. Fedwire and similar bank-to-bank wire systems are excluded from Regulation E altogether.
The United Kingdom has moved further than either Poland's current rules or the U.S. baseline. The FCA already requires banks to refund unauthorized payments by the next business day in most cases, and since late 2024, UK financial firms have generally had to reimburse customers who were tricked into personally authorizing a scam payment, according to The Independent. Some UK victims even get visits from trained social workers.
The EU is trying to close a similar gap through separate machinery: a pending case before the Court of Justice of the European Union, per Tech Times, could take Poland's authentication-versus-authorization standard and apply it across all 27 member states, alongside rules making banks potentially liable for scammed funds if they fail to implement adequate fraud controls, as The Independent reports.
The U.S. Picture: Record Losses, No Refund, and a Tax Bill on Top
An investigation by The Associated Press and FRONTLINE, cited by The Independent, found Americans reported $15.9 billion in scam losses last year to the Federal Trade Commission, a 25 percent jump from the prior year. The FTC itself estimates real annual losses run closer to $200 billion, meaning the official number is likely a fraction of the true damage.
Of 58 victims AP/FRONTLINE interviewed, ranging in age from 32 to 90 and in losses from several thousand dollars to $4 million, only one recovered any money, and that came from her bank voluntarily, not from any legal requirement. Several described contemplating suicide. Two attempted it.
The tax code compounds the damage. Before 2018, scam and theft victims could sometimes deduct their losses from taxable income. Under a provision of the Tax Cuts and Jobs Act, made permanent in 2025, personal losses from most common scams no longer qualify for that deduction, according to The Independent. Retirees who withdraw money from tax-deferred retirement accounts before losing it to a scammer can end up owing the IRS taxes on money that's already gone.
Some banks add insult to injury. AP/FRONTLINE documented victims whose accounts were frozen or closed after reporting fraud, with some banks demanding loan repayment or legal fees on top of it. American Bankers Association Chair Kenneth Kelly pushed back on the framing earlier this year, saying banks spend "time, money and significant resources" fighting fraud. That defense refers mainly to unauthorized transactions, the category where banks already bear more responsibility, not the authorized-but-deceived transfers where U.S. law currently gives victims almost no recourse.
An Open Question and a Broader Pattern
Whether the CJEU adopts Poland's standard EU-wide is still unresolved, and no date for that ruling has been reported. European regulators are willing to force compliance on large institutions rather than negotiate around the edges. Just weeks before the Polish bank decisions, the European Commission pressed Apple into overhauling its App Store fee structure under the Digital Markets Act, a separate enforcement action set to take effect Oct. 1, according to The Epoch Times.
For American scam victims, no comparable federal push exists. Anyone who suspects fraud right now is largely left with the advice cybersecurity experts give for after the fact: contact the bank immediately, document who initiated the payment, freeze exposed accounts, and don't assume a fraud alert alone means identity theft has actually occurred, per Fox News. Whether Congress or the CFPB moves to close the authorized-transfer gap that Poland and the UK have already addressed remains an open question, with no legislation currently pending in either chamber based on the available reporting.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.