Twenty-seven percent of German internet users have fallen victim to cybercrime at some point. Some of the most common cybercrimes include fraud that affects online shopping and online banking, plus unauthorised access to online accounts and phishing attacks. Nine out of ten victims have suffered some form of damage, with many experiencing financial losses.
Online fraud is often directly related to the broader phenomenon of identity theft. In this article, we’ll discuss what identity theft is, what forms of it exist, and who is liable when identity theft occurs. We’ll also explore how businesses can reduce the risk of fraud effectively.
Key takeaways
- Identity theft is not a distinct criminal act in Germany, but the actions involved in stealing someone’s identity can qualify as a number of different criminal offences.
- Identity theft is where fraudulent actors use the personal information of third parties without their permission for fraudulent purposes or to deceive others.
- Perpetrators use stolen identities to initiate unauthorised payments, conclude contracts, or take over accounts.
- In principle, victims are not liable for any damages, as long as they did not act negligently.
- Modern solutions such as Stripe Radar help businesses detect suspicious transactions early and reduce fraud risks through secure processes, effective data protection, and technical safeguards.
What is identity theft?
Identity theft occurs when a fraudulent actor uses someone else’s personal information without permission in order to obtain a benefit for themselves or third parties. The bad actor uses identifying features such as a person’s name, date of birth, address, or digital login for fraudulent purposes. Their aim is often to impersonate the original person or to perform actions in their name.
Identity theft largely affects private individuals whose personal information is used unlawfully. The personal consequences range from financial losses to long-term issues using services, or problems verifying and correcting personal information.
Businesses can also be indirectly affected. This happens most frequently when a bad actor uses a stolen identity to conduct fraudulent business, such as making purchases or concluding contracts in someone else’s name. The companies involved can suffer financial losses and also have to spend additional time reviewing and processing transactions. Fraud can damage a business’s reputation and lead to a loss of trust among customers and business partners.
What types of identity theft are there?
Identity theft comes in different forms. Methods vary according to the context and the perpetrator’s aim, and range from typical digital fraud to less common, more complex scenarios.
- Payment fraud: Bad actors use someone else’s payment details or payment service login to perform unauthorised transactions.
- Impersonation in order to conclude contracts and place orders: Fraudulent actors pretend to be someone else in order to conclude purchase, rental, or service agreements, or to order goods.
- Account takeover fraud (ATO): Bad actors gain access to existing online accounts which they then use without permission. They can use these accounts to place orders, view data, or communicate in the name of the Account holder.
- New account fraud: Perpetrators can use stolen identities to open new accounts with banks or online services. These accounts are used for things such as loans, subscriptions, or other financial obligations which are attributed to the person whose identity has been stolen.
- Impersonation when interacting with public authorities: In rare cases, stolen identities are used to prove a person’s identity to a government agency or to apply for state benefits.
- Subscriber Identity Module (SIM) swapping: Fraudulent actors take control of someone’s mobile phone number by transferring their number to a new SIM card. They can then intercept security passcodes and gain access to other accounts.
- Social media impersonation: Bad actors copy or take over people’s social media profiles in order to share content under their name or to deceive others.
How do fraudulent actors access identity information?
In order to commit identity fraud, perpetrators first need to gain access to personal information. Lots of this information comes from publicly available sources, such as social networks or online profiles. Fraudulent actors can also use information obtained from data breaches or hacked databases.
Often, however, victims hand over their details to bad actors themselves without even realising. Victims of phishing attacks, for example, enter credit card details, passwords, or security codes on fake websites. These attacks commonly start as emails or text messages which look like official communication from banks, payment-service providers (PSPs), or well-known businesses. These often contain a link which leads to a deceptively genuine-looking website which prompts users to enter their data.
If you’ve been a victim of identity theft, the Federal Office for Information Security (BSI) provides a first aid checklist.
Who is liable in the event of identity theft?
With online fraud, the main question for businesses and retailers in Germany, as well as for private individuals, is who is liable in the event of identity theft. The answer depends on the particulars of each case. Primarily, it is about which duties of care have been breached.
Principle: Victims are not liable
In principle, victims of identity theft are not personally responsible for any damages caused by the use of their stolen identity. That’s because, legally speaking, the responsibility lies with the persons who are using this identity unlawfully to conclude contracts, make payments, or perform other acts. Consequently, a victim of identity theft is not a party to any contractual obligations entered into using their identity.
Exception: Contributory negligence
This principle does not apply if the victim’s own misconduct contributed to their identity being stolen. Anyone who is reckless with sensitive data or who fails to observe basic security measures can, in some cases, bear at least partial responsibility. The deciding factor is always whether a duty of care has been breached.
Online banking and payment services
In online banking, users bear significant responsibility for keeping their login details and security processes safe. In many cases, banks will compensate any losses suffered as a result of unauthorised payments. However, a deductible might also apply. The law typically limits this deductible to €50 if the payment instrument is lost or misused, and the losses could not be prevented in time. In certain cases, this deductible might be waived in full, such as if the user could not have spotted the loss or the bank itself was responsible for the loss.
However, there is no limitation of liability if a person acted with fraudulent intent or gross negligence. Gross negligence includes sharing login details or failing to store login details securely. Section 675v, Paragraph 3 of the German Civil Code (BGB) stipulates that the user can be personally liable for losses in such cases.
Customers are generally not liable for any losses they incur if banks or Payment service providers (PSPs) do not employ legally mandated Strong Customer Authentication (SCA). They are also not required to compensate for any losses that occur after they report their Card as stolen or missing, provided they did this sufficiently quickly.
Phishing and intentional deception
In the eyes of the law, actively entering sensitive data on fake websites or in fraudulent messages can be seen as an act of gross negligence. In such cases, the victim might be at least partially liable for any losses incurred.
However, the legal assessment of phishing always depends on the specifics of each case. In particular, the courts take into account how professional the appearance of the scam was, and whether there were clear warning signs for the victim. Modern scams often use deceptively genuine communication channels and know lots of details about their victims, giving the impression that they are legitimately acting on behalf of a bank, public authority, or other trustworthy body.
The latest court decisions illustrate that simply because a phishing attack is successful does not mean that it can be automatically concluded that the victim acted with gross negligence. Rather, it must be assessed in each case whether it would also have been difficult for the average diligent user to spot the scam. As cyberattacks become increasingly professional, these differentiated benchmarks are becoming more important in regard to who is liable and whether victims can claim damages.
Fraudulent orders and contracts
A person whose identity is used to order goods or conclude contracts without their involvement is not typically liable for any damages incurred as a result. Invoices, Dunning letters, or Collection letters do not have to be paid, as long as it can be clearly demonstrated that identity fraud has occurred. However, it is important to respond to such requests promptly and to clarify what has happened.
In such cases, the company affected typically bears the financial risk in the first instance. If it cannot be demonstrated that a contract was actually established with the person in question, then any claims for payment from them are usually ineffective. Businesses must therefore check whether the person placing an order or concluding a contract was in fact who they said they were.
If a business suffers a loss as a result of fraud (e.g., because it shipped goods or rendered services), it is unlikely to recover anything unless the actual perpetrators can be identified or claims are brought against them. The risk of concluding a contract with someone who is using a fake identity therefore lies with the company that failed to properly verify its customer’s identity before signing.
How can businesses in Germany reduce the risk of fraud?
It is virtually impossible to protect against identity fraud entirely. However, businesses can reduce the risk significantly and mitigate potential damages by taking appropriate technical, legal, and organisational measures.
Implement identity checks and secure authentication
Businesses should verify their customers’ identities carefully, especially when conducting high-risk transactions, such as expensive orders, contracts with longer terms, or new customer accounts. Additional verification procedures, multifactor authentication (MFA), and plausibility checks can help flag fraudulent users early.
Flag suspicious activity
In a lot of cases, there are certain warning signs that fraud is being committed. These include unusually high order values, last-minute changes to delivery addresses, multiple orders in a short timespan, or contradictory customer information. Suspicious activity can often be identified before a contract is executed by using automatic risk assessments and training employees.
Train employees
Phishing attacks and social engineering methods don’t just affect customers, they can also target businesses. Regular training sessions can help employees to identify suspicious calls, emails, or messages, and react appropriately. This reduces the risk of sensitive company or customer data ending up in the hands of fraudulent actors.
Increase data protection and information technology (IT) security
Since stolen personal information frequently comes from data breaches or security incidents, it is particularly important that companies protect any information they store. Businesses in Germany must take appropriate technical and organisational measures to protect personally identifiable information, restrict access rights, and regularly review security loopholes.
The principles for the proper management and storage of books, records, and documents in electronic form (GoBD) also stipulate requirements relating to the security and traceability of digital business processes. Businesses must ensure that tax-related information is protected against loss, manipulation, and unauthorised access, and that it remains transparent and auditable at all times. Therefore, effective information security and data protection management is about more than just complying with the statutory regulations. It can also help to stop identity fraud and financial losses happening in the first place.
Establish clear processes on what to do in case of fraud
Even with all of these precautions, fraud can still happen. Businesses should therefore define how they review suspicious activity, how they inform affected customers, and how any damages are documented. Clear internal processes make it easier to react quickly and can help to mitigate financial losses and reputational damages.
What legal aspects do businesses in Germany need to know?
Identity theft doesn’t just pose a financial risk to businesses in Germany, it can also have legal implications. German companies must observe a number of different legal obligations, particularly with regard to handling personally identifiable information, preventing fraud, and reacting to security incidents.
Data protection obligations
Businesses that process personally identifiable information must comply with the regulations of the General Data Protection Regulation (GDPR), in particular Article 32, which stipulates that businesses must implement appropriate technical and organisational measures to ensure the security of this data. If a data breach occurs due to inadequate security measures, supervisory authorities can impose fines and, in some cases, data subjects can claim damages.Reporting obligations in case of personal data breaches
If a security incident leads to a breach in the protection of personal data, the company in question is obliged to report the incident to the relevant data protection authority. This report must be filed within 72 hours of the business becoming aware of the breach.Accountability and documentation requirements
As part of their accountability obligations, businesses must maintain transparent documentation on their data protection and security measures. The GoBD also stipulates that tax-related digital processes must be properly documented and transparent. Having complete documentation that demonstrates that a business has complied with the statutory obligations can be helpful in the event of a dispute.Contractual duty of care towards customers
Businesses are obliged to take appropriate measures to prevent fraud and abuse. Which measures they must take depends on the type of business model, risk potential, and typical industry standards. Businesses that ignore clear risks or fail to implement basic security measures could be held liable for any damages.Data processors and supplier screening
Lots of businesses use external service providers for IT systems, payment processing, or cloud services. If these service providers process personally identifiable information, then the requirements of the GDPR regarding processors must be observed. In principle, these businesses are still responsible for the lawful processing of this data. They should therefore review their service providers’ security standards on a regular basis.Prosecution of identity fraud
Identity theft itself is not a distinct criminal offence under German law. However, the underlying acts often qualify as other criminal offences, such as fraud, computer fraud, or data espionage. Businesses should therefore always document suspicious incidents and assess whether it makes sense to file a criminal complaint.
How Stripe can help you prevent fraud
These days, preventing identity and payment fraud effectively requires automated systems that flag suspicious activities early and assess risks in real time. Stripe Radar is a Fraud prevention solution that automatically analyses transactions and identifies potential fraud. Built on artificial intelligence (AI), the technology uses data from Stripe’s global payments network to identify known fraud patterns and consistently factor in new risk signals.
Radar uses different factors to assess transactions, including suspicious purchase patterns, unusual device or Location information, and indications of previous attempted fraud. The solution uses this information to produce a real-time Risk score, so that suspicious payments can be reviewed or blocked with greater accuracy. Radar’s goal is to identify fraudulent users early, without having to reject a large number of legitimate transactions.
Frequently asked questions around identity theft
The content in this article is for general information and education purposes only and should not be construed as legal or tax advice. Stripe does not warrant or guarantee the accuracy, completeness, adequacy, or currency of the information in the article. You should seek the advice of a competent lawyer or accountant licensed to practise in your jurisdiction for advice on your particular situation.