The fake call-center scam: bank liability moved from automatic to evidentiary
In July, the STJ held that banks are not automatically liable for the fake call-center scam. Nine months earlier, the same panel had ruled against a bank. The contradiction is only apparent — what shifted was not the doctrine, but the burden of proof.

▸In this article
Update, September 21, 2026. On September 16, the STJ published a special video report (in Portuguese) on the fake call-center scam. It brings no new ruling: the case it describes, with fourteen transactions in a single day on an account that usually saw very few a month, is the one decided on October 21, 2025, covered below. The report does not mention REsp 2.209.868, from July 2026, in which the same Third Panel denied compensation for lack of proof of a security failure by the bank. The picture described in this piece stands. The police officer interviewed in the report tells victims to trigger the MED, Brazil's Pix refund mechanism; how its clock runs is in On the MED clock, the only deadline that releases the money belongs to the victim's bank.
The Third Panel of the Superior Court of Justice ruled unanimously that financial
institutions' liability for losses arising from the fake call-center scam is
not automatic. In REsp 2.209.868, with Justice Humberto Martins as
rapporteur and released on 15 July,
the panel upheld a TJSP decision that had denied compensation to a customer who
fell victim to the fraud.
The detail headlines tend to lose is which rule was set aside. The court held that neither Súmula 479 nor Tema 466 of the repetitive appeals docket applied — the rule approved by the Second Section in June 2012, under which "financial institutions are strictly liable for damages caused by internal contingencies relating to fraud and offences committed by third parties in the course of banking operations".
This was not a reversal
The easy reading of this decision is that the STJ switched sides. It does not hold up against what the same Third Panel decided only months earlier.
On 21 October 2025,
in REsp 2.222.059 and REsp 2.229.519, with Justice Ricardo Villas Bôas Cueva
as rapporteur, the panel held that banks and payment institutions are strictly
liable where there is a security failure, and that liability is discharged only
on proof that the service was not defective or that the consumer was
exclusively at fault.
On 13 November 2025,
in REsp 2.220.333, again with Cueva as rapporteur, the panel went further and
rejected the theory of contributory fault where a security failure exists:
"third-party access to apps and personal passwords does not result from a lack
of care by account holders, but from fraud committed against them".
Three decisions, the same panel, ten months apart, opposite outcomes. Not because the doctrine wavered, but because the records said different things.
The variable that decides the case
Compare what was proven in each case.
In October 2025, according to the court's own release, there was a record of "transactions entirely at odds with the spending profile" — fourteen operations in a single day, on an account that typically recorded very few per month — and a security system that "was not capable of cancelling or preventing the completion of the operations". The anomaly was documented, and so was the bank's inaction in the face of it.
In July 2026, the factual picture was the reverse: the lower court concluded that there was neither a service defect nor a causal link, and the rapporteur noted that the transactions "involved no direct participation by the bank".
Hence the wording of the opinion: strict liability for third-party fraud "presupposes that the event is inherent to the banking service provided, qualifying as an internal contingency". Absent a failure attributable to the service, the event ceases to be internal to the risk of the activity — and the presumption does not apply.
What moved, then, was not the yardstick. It was who has to fill the record. While Súmula 479 operated as a presumption, proving the fraud was enough. With the presumption set aside, the failure has to be proven — and failure, here, is a technical assertion about how a system behaved.
What the court has already said counts as a failure
The October 2025 decision is the more useful one for anyone who has to build a record, because it names criteria. The court stated that institutions must detect operations that depart from the customer's usual profile, taking into account the amount, time, location and sequence of transactions.
Four objective dimensions, all of them captured in logs. None depends on the victim's or the bank's account of events. It is the kind of assertion that stands or falls on a comparison between the account's historical pattern and the window in which the fraud occurred.
For those who will have to prove it
Two practical consequences, neither of them legal.
The first is timing. An argument about deviation from a pattern needs the history to compare against, and banking history does not stay available indefinitely for whoever asks for it later. Full statements covering the window and the preceding period, timestamps with time zones, the origin channel of each operation, records of contact with the purported call centre, the calling number, the device used: none of this improves with time. It is the same point we covered in the first hours, now with an additional reason to take it seriously.
The second is one of kind. "The bank failed" has stopped being pleading rhetoric and become a conclusion that is either demonstrated or not. A claim that transactions were inconsistent with the profile, without the profile documented, is an opinion. With the profile documented, it is a verifiable fact — and, by the very criteria the STJ listed, the kind of fact the court is willing to examine.
It is also worth noting what the July decision did not do: it did not revoke Súmula 479, it did not set a binding thesis in a repetitive appeal, and it has no binding precedential force. Nor could it — the súmula was approved by the Second Section, a broader body, and the July judgment came from one of the panels that make it up, on a specific TJSP ruling. Anyone reading the news as "banks are no longer liable" will be as wrong as those who read the súmula as "banks are always liable".
Information on these judgments was drawn from the official releases published by the STJ itself, linked above; the full texts of the rulings may contain additional grounds. The parties are not identified by the court in its publications.
About the author

Robert F.
request a secure channelRobert F. is the founder of CyberX, a digital intelligence operation applied to investigation, based in Brazil with cross-border reach.
He works in OSINT, on-chain tracing and antifraud for legal teams, corporate compliance, banking antifraud and public authorities.
In CyberX publications we write about what can be said in public — fraud and scam typologies, digital threats, on-chain tracing, regulation, and what separates an investigation from a database lookup. Never about a case we work on, clients, matters under judicial secrecy, or operational detail that would compromise an investigation in progress — ours or anyone else's. A third party's case enters through the public official act, and through what it teaches, not through what it exposed.
Related reading
CyberX works in digital intelligence applied to investigation — OSINT, on-chain tracing, and fraud prevention. This content is informational and does not constitute legal advice.
how we write →Source: https://cyberx.to/en/news/the-fake-call-center-scam-bank-liability-moved-from-automatic-to-evidentiary
Retrieved on