Brazilian Bank Ordered to Compensate Elderly Woman Scammed via WhatsApp
Banco do Brasil has been ordered by the 7th Civil Court and Consumer Relations of São Luís, Brazil, to compensate an elderly woman who lost R$ 9,750 in a WhatsApp scam. The victim received messages from an unknown number, impersonating her daughter, who claimed to have a new phone and urgently needed money for medical treatment. Believing the messages, the woman made two Pix transfers totaling R$ 9,750 to an account held at Stone Instituição de Pagamento S.A. under the name Lucas Coletro Silva. She realized she was scammed when the fraudster requested a third, much larger sum. The bank denied her request to block the transactions and refund the money through the Special Refund Mechanism (MED). Consequently, the woman sued for material and moral damages. Banco do Brasil argued that it was not at fault, stating the transfers were authorized by the client using her credentials in a secure environment, and that she was a victim of third-party fraud. However, the judge ruled that financial institutions have a duty to monitor customer transaction patterns and implement preventive measures against fraud. The judge found the two sequential transfers to an unknown recipient to be highly atypical for the customer's profile and that the bank's security system failed to identify and prevent this unusual activity. Citing Superior Court of Justice precedent, the court determined this failure constituted a breach of the bank's duty of security. Banco do Brasil was ordered to pay R$ 9,750 for material damages and R$ 4,000 for moral damages, totaling R$ 13,750.
This judicial decision highlights the evolving responsibilities of financial institutions in safeguarding customers against increasingly sophisticated digital fraud. The court's emphasis on the bank's duty to monitor atypical transactions, even those initiated with customer credentials, suggests a shift towards greater institutional accountability. This ruling implies that standard security protocols may be insufficient if they fail to detect significant deviations from a customer's established financial behavior, particularly when such deviations lead to substantial losses. Future legal and regulatory frameworks may increasingly scrutinize the effectiveness of AI-driven fraud detection systems within banks, pushing for more proactive and context-aware security measures that balance convenience with robust protection against evolving social engineering tactics.
AI-generated to prompt reflection — not editorial opinion, not advice, not a statement of fact. How this works.