August 12, 2026

UAE Bank Scam Victims Could Recover Lost Funds Under These Rules: What Customers Need to Know

UAE bank fraud and scam recovery

UAE's regulatory framework protects victims of bank fraud, but reimbursement depends on the circumstances.

A customer who discovers money missing from a UAE bank account following an unauthorised transaction may have a right to seek reimbursement from the financial institution, depending on the circumstances of the case.

The UAE has established a regulatory framework requiring banks and other licensed financial institutions to protect customers against financial crime, cyber-attacks and the misuse of their assets and information. The framework also sets out responsibilities for financial institutions when customers report unauthorised payments.

The relevant rules include the Federal Decree-Law No. 6 of 2025 on the Central Bank and Regulation of Financial Institutions and Activities and Insurance Business, together with the Central Bank of the UAE's Consumer Protection Regulation and Consumer Protection Standards.

Banks and other licensed financial institutions are required to maintain appropriate security and protection systems and have the ability to develop and implement new cybersecurity measures as threats evolve. They must also have systems and procedures to detect, prevent and respond to financial crime.

The regulations place particular emphasis on protecting consumers from fraud. Financial institutions are expected to educate customers about financial crime risks and the steps they can take to protect themselves against fraud and other threats.

The Legal Framework for Cybercrime Protection

The legal framework also provides protection when customers become victims of cybercrime.

Under Article 15 of Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes, forging, cloning or copying a credit card, debit card or other electronic payment instrument, or obtaining its data or information through information technology systems, is a criminal offence.

A person convicted of such an offence can face imprisonment and a fine of between Dh200,000 and Dh2 million.

The same penalties may apply to anyone who creates or designs information technology tools or software with the intention of facilitating such offences. They can also apply to individuals who use a credit card, debit card, electronic payment instrument or related information without authorisation to obtain another person's money, property or services.

The law further covers people who knowingly accept forged, copied or illegally obtained payment instruments or data.

However, the punishment of the person responsible for the fraud is separate from the question of whether the victim can recover the money from the bank.

When Banks Must Compensate Customers

The Central Bank's Consumer Protection Standards require licensed financial institutions to compensate consumers in a timely manner for financial losses and expenses resulting from financial crimes, misappropriation, cyber-attacks and misuse of assets and information.

There is an important exception. A financial institution may not be required to compensate the customer where it can establish that the loss resulted from the customer's fraudulent behaviour or gross negligence.

This distinction is particularly important in cases involving online scams, phishing messages, fake websites and fraudulent payment links. Customers should therefore be careful about sharing banking credentials, card information, one-time passwords and other security details.

Unauthorised Payments and Reimbursement Timeframes

The rules also contain specific requirements concerning unauthorised payments.

Once a customer reports an unauthorised transaction, the financial institution must record the report, including when it was received. It must also inform the customer about measures available to block or close the affected account, card or digital payment instrument and take appropriate steps to prevent further unauthorised transactions.

Unauthorised payments are generally required to be reimbursed after the investigation has been completed or within 30 calendar days from the date the customer reported the matter or the financial institution identified it, whichever is earlier.

The reimbursement requirement does not apply where there is evidence that the customer acted fraudulently or with gross negligence.

For customers, speed is therefore critical. Anyone who notices an unfamiliar transaction should contact the bank immediately through its official channels rather than waiting for further transactions to appear.

Practical Steps to Protect Your Rights

The customer should also request that the affected card, account or payment instrument be secured or blocked and should obtain confirmation that the fraud report has been registered.

Evidence should be preserved from the outset. Bank statements, transaction details, SMS and email alerts, screenshots, suspicious links, telephone numbers, social media conversations and other communications connected to the scam could all help establish what happened.

A formal complaint should also be submitted to the bank, particularly where the customer disputes the outcome of an initial investigation. Keeping records of all communications with the bank can be important if the dispute is subsequently escalated.

The bank is required to have procedures for receiving and handling customer complaints and must provide a response within the applicable regulatory timeframe. Where a customer remains dissatisfied with the outcome, the response should explain the reasons for the decision and the available avenues for further action.

Complaint Resolution and Escalation

Customers who cannot resolve a complaint directly with their financial institution may also have access to Sanadak, the UAE's independent financial-sector complaints resolution mechanism.

Where criminal activity is suspected, reporting the matter to the police is also an important step. Customers should provide details of the unauthorised transactions and submit the available supporting evidence. The criminal investigation can help establish how the fraud occurred and identify those responsible.

Summary: Protection is Not Automatic

The UAE framework therefore provides several layers of protection for victims of banking fraud. Financial institutions have responsibilities to maintain secure systems, protect customer assets and information, respond to reports of unauthorised transactions and, where the regulatory conditions are met, reimburse customers for qualifying losses.

For customers, however, protection is not automatic in every case. The circumstances surrounding the transaction, the customer's conduct and the evidence available can all influence whether reimbursement is required.

Anyone who discovers an unauthorised transaction should therefore report it without delay, secure the affected account or payment instrument, preserve all relevant evidence and pursue the formal complaint process. If the bank's response is unsatisfactory, the customer can consider the available escalation and dispute-resolution mechanisms under the UAE's financial regulatory framework.