In its statement issued on a Sunday--an unusual occurrence in itself but on the eve of a meeting of a group of customers who were victims of the fraud--, BIL says it has become aware of the scale of the fake website scam that has targeted its customers in recent months. The bank says it is actively cooperating with the authorities to identify the perpetrators of the phishing scam and asserts that its own systems have not been compromised. Internally, a dedicated team has been mobilised to deal with complaints from defrauded customers.
BIL also points out the procedures already in place: in the event of bankcard fraud, the case is handled "under the sole responsibility of Worldline", the payment service provider, which the customer must contact to open a dispute file. In the event of a fraudulent transfer, the bank states that it will immediately initiate a request for the return of funds from the disputed transactions--a procedure that can take up to four weeks "with no guarantee of result". In other words, Bil is not promising to automatically reimburse the stolen sums, but to try to recover them via banking channels. Moreover, it requires aggrieved customers to provide "a copy of the police report [and] all the precisely defined details of the fraud", and advises them to be assisted by "a competent body" (consumer association, lawyer...) for any approaches to the banks to which the misappropriated funds were sent.
On the sensitive issue of its liability, the bank adopts a measured tone. It expresses regret that customers have fallen victim to hackers, but does not acknowledge any fault on its part. On the contrary, Bil stresses the robustness of the security measures in place, in particular the LuxTrust authentication required to validate any sensitive transaction, insisting that "the digital online banking tools and the LuxTrust certificate remain technically secure" according to the ABBL. The press release implies that the fraudsters exploited the "weakness of the human link" rather than a technical breach. The bank does not explicitly mention any fault on the part of users, but firmly reiterates the rules of digital prudence.
Finally, the press release details a series of recommendations to customers to avoid further pitfalls. BIL "urges its customers not to access BILnet via Google or other search engines", urging them to use only the official mobile application or to manually type the address of the site. You are advised to carefully check the URL and the presence of the security padlock in your browser before logging on or entering any codes. The bank would also point out that it never asks for its customers' LuxTrust identifiers by e-mail, SMS or telephone. If there is any doubt about the authenticity of a communication, users are invited to contact their branch or Bil's customer service department directly. These security instructions, already issued in July via a fraud alert on the bank's website, are vigorously reiterated in the official press release.
A look back at the scam: a fake BILnet website active from May to July
The Bil warning follows a fraud on an unprecedented scale in Luxembourg, spread over almost three months. Between May and July 2025, cybercriminals put a fake BILnet website online, an almost identical copy of Bil's online banking interface. This fake site, cleverly referenced via sponsored links on search engines, tricked many unwary customers. "One click too many" on a misleading Google result was enough to redirect victims to this convincing visual replica of the official site, where their LuxTrust login details were stolen. Thinking they were entering their codes on the real interface, customers were in fact sending the scammers information to access their bank accounts.
According to initial reports, the scam was repeated several times between May and mid-July 2025. The amounts embezzled were usually in the region of a few thousand euros per compromised account. As early as the first weekend in July, the Grand Ducal police received around twenty complaints linked to this fake site, each of which involved an individual loss of between €6,000 and €9,000. As the days went by, the number of known victims increased steadily. In total, it is estimated that nearly 60 Bil customers have been tricked, with a cumulative loss of around €550,000. While most of the losses reported ranged from a few thousand to tens of thousands of euros, one customer alone reported losing up to €210,000 as a result of this fraud-proof that even large accounts could have been targeted. One victim, for example, said that €8,800 was debited from her account on 10 June after she entered her codes on the fake portal, even though no transaction had been validated on her side. It was only when she reconnected later to the real site that she saw an attempted transfer of €8,000, which she was able to cancel by the skin of her teeth, before having her account blocked and lodging a complaint.
Faced with this financial haemorrhage, Bil claims to have reacted as soon as it became aware of it. The bank says it blocked or cancelled some of the fraudulent transactions before it was too late, thanks to its monitoring mechanisms, thereby limiting the disaster. However, around 25% of customers affected have not been reimbursed and have actually lost their money despite the measures taken (blocking transfers, recalling funds from recipient banks). For the time being, Bil's management is remaining tight-lipped about the total amount stolen, merely confirming that it is a significant six-figure sum.
Anger and mobilisation of ripped-off customers
For the dozens of ripped-off customers, the moment is one of anger and bitterness. They denounce the lack of initial support from their bank, which they accuse of having delayed in reacting and minimising its responsibility. "I'm outraged by the bank's behaviour, which places all the blame on the customers who let themselves be fooled by the scammers. The only people who showed any empathy were the police", Juliana Mondot, one of the victims of this fraud, told Le Quotidien. Like many others, this customer feels that she was let down by her bank just when she needed it most. "It's a disaster, and the bank doesn't want to take any responsibility", adds Ms Mondot, who saw €8,800 disappear from her current account at the beginning of July.
Several victims report unpleasant exchanges with their banking contact in the days following the discovery of the scam. Juliana Mondot recounts how a Bil employee made her feel guilty, comparing her case to "someone who goes into a fast-food restaurant with a fake McDonald's": in other words, if you are fooled by a fake, you cannot take action against the original--in other words, the bank cannot be held responsible for the trap set by fraudsters. This perceived lack of compassion and the absence of any immediate commercial gesture have fuelled the discontent. "We want proof that the bank did everything it could to try and get our money back", Mrs Mondot and other defrauded customers are now demanding, unable to understand how the scam could have gone on for several weeks without being stopped.
Initially isolated, the aggrieved customers decided to unite to present a united front. At the end of July, dozens of them joined a WhatsApp group, determined to coordinate their actions and share information and advice. Today, the group is made up of nearly sixty people united by a common feeling of frustration with the Bil. "We feel abandoned by our bank", says one member, "while some of us have seen all our savings go up in smoke". The self-help group has no intention of stopping there. A meeting of the victims is scheduled for Monday 7 September, at which they intend to organise themselves to obtain compensation. Many are now considering legal action: a meeting with a lawyer is on the agenda, to explore the legal options for asserting their rights collectively. "We're not just cash cows," says Juliana Mondot in another medium, pointing out that banks also have obligations towards their customers and have insurance cover for this type of claim. Armed with this conviction, the members of the collective hope to put pressure on Bil to compensate the victims or, failing that, to make the public authorities aware of their cause.
Towards a stronger response to cyber-banking fraud
The case of the fake BILnet website is now taking on a public and political dimension. Alerted by the scale of the scandal, several officials have reacted in recent weeks. The Financial Sector Supervisory Commission (CSSF) has issued a general reminder to be vigilant and is working with the Bil on the lessons to be learned from this fraud. On the political front, the issue has been raised in Parliament: at the beginning of August, Mars Di Bartolomeo and Ben Polidori (LSAP) sent an urgent parliamentary question to the Ministers of Finance and Justice. They expressed their concern about the fate of the victims of the fake Bil and LuxTrust websites, and wondered about the loopholes that had allowed such fake websites to remain online for weeks despite the initial complaints. The MEPs are also asking whether there are any gaps in current legislation to protect against this type of attack and "what responsibilities banks have" in such cases, as well as possible compensation arrangements for injured savers. These are all questions that highlight the vagueness surrounding the sharing of blame between customers and banks in the event of sophisticated phishing.
Consumer associations agree. Patrick Schaul, legal adviser at the Union luxembourgeoise des consommateurs (ULC), points out that "banks do not reimburse victims of this type of scam, but must prove the customer's serious fault" in order to be exempted from the obligation to pay compensation. In practice, it is often difficult for a customer to demonstrate good faith after having, albeit by deception, communicated their access codes - which the banks generally regard as negligence on their part. The ULC also points out that this case illustrates the importance of stepping up the monitoring of bank transactions: in a letter sent to Bil in January, the association felt that the bank "should have realised that the fraudulent transactions [were] carried out in a very short space of time, [for] considerable amounts that in no way corresponded to the customer's profile". In other words, an internal alert mechanism could (should) have flagged up these atypical movements. Finally, the ULC regrets that in Luxembourg, victims of financial fraud cannot yet take joint collective action - a legal tool that would greatly facilitate their efforts, but whose introduction is still awaited.
For the authorities and financial institutions, the challenge now is to restore confidence and prevent such scams from recurring. The banking sector, through the ABBL, maintains that the LuxTrust system and Luxembourg's online banking services remain reliable and secure from a technical point of view, but recognises that the vigilance of each user is the keystone of security. However, as Patrick Schaul points out, phishing fraud is nothing new "and it's only going to get worse with the possibilities offered by artificial intelligence", which is increasing the number of sophisticated phishing techniques. Hence the need for banks, in turn, to innovate in terms of security: stepped-up information campaigns, integrated anti-phishing devices (for example, warnings in the event of unusual connections), and international cooperation to shut down fraudulent sites more quickly.
This article was originally published in French.



