You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 9, 2026

Who Pays for Fraud? Thailand’s Supreme Court Shifts Credit Card Liability to Banks

When unauthorized credit card transactions occur, who bears responsibility—the cardholder or the issuing bank? In Thailand, a landmark 2025 ruling by the country’s Supreme Court has clarified this question, establishing a stricter standard for banks in fraud disputes and significantly strengthening consumer protections.

The case centered on disputed charges where a customer claimed their credit card had been used without authorization. The bank sued to recover the amount, and both the court of first instance and the Court of Appeal ruled in favor of the bank. However, the Supreme Court overruled their judgments and decided that the customer did not need to pay for the unauthorized transactions, placing liability squarely on the bank.

This ruling was based on three key findings, which are outlined below.

Finding 1: Insufficient Expert Testimony

In this case, the bank bore the burden of proving matters related to the credit card system’s manufacture, design, security, and operation, as required under the Consumer Case Procedure Act B.E. 2551 (2008). To meet this requirement, the bank presented testimony from two employees in its credit card department regarding ’security measures and issuance procedures.

However, the Supreme Court found these witnesses unqualified as experts, as they did not present technical or academic evidence and did not possess specialized expertise in credit card technology. As a result, their testimony failed to establish that the bank’s credit card technology was sufficiently secure against fraudulent misuse.

Finding 2: Contradictory Terms and Conditions

The bank’s own credit card terms and conditions included a provision acknowledging that despite the card’s EMV security standards, cardholders must still exercise caution to prevent unauthorized access. The Supreme Court interpreted this clause as an explicit admission that credit card systems remain vulnerable to hacking and fraud, even with high-level security measures in place. This acknowledgment undermined the bank’s argument that the unauthorized transactions could not have resulted from system vulnerabilities.

Finding 3: Inadequate Evidence Collection

The court also noted the bank’s failure to obtain crucial evidence. The signature on the receipt from the disputed transaction differed significantly from the signature on the customer’s credit card, making CCTV footage from the merchant necessary to determine who was actually using the card for the transaction.

The bank argued that it could not obtain this footage because it was not the “injured party” and only the police could request it. However, the bank made no effort to ask the police, the customer, or the court to facilitate obtaining the footage. This lack of diligence led the Supreme Court to conclude that the bank had failed to meet its burden of proof regarding the authenticity of the transaction.

Implications for Financial Institutions

Thailand’s Supreme Court ultimately emphasized that banks providing credit card services have a duty to monitor and verify card usage to prevent harmful conduct such as fraud and unauthorized access. When customers dispute transactions, banks must conduct thorough investigations and explain their findings to the customer, rather than relying solely on contractual clauses to shift the burden to cardholders. Accordingly, the Supreme Court dismissed the bank’s claim, ruling that the customer was not liable for the unauthorized transactions.

This precedent establishes a more rigorous standard of proof for banks in cases involving unauthorized credit card transactions. The court’s findings—particularly regarding the lack of expert testimony, the vulnerabilities acknowledged in the terms and conditions, and the insufficient effort to obtain crucial evidence—underscore that banks must now demonstrate a higher level of diligence and responsibility. They are expected not only to maintain secure systems but also to actively investigate disputed transactions and present credible, comprehensive evidence to support their claims. The ruling confirms the principle that, in Thailand, the burden of ensuring the integrity of credit card usage rests primarily with the bank. This is a strong stance in favor of consumer protection, and raises expectations placed on financial institutions in similar disputes.

RELATED INSIGHTS​ 

August 11, 2026
On July 27, 2026, the State Bank of Vietnam (SBV) released a draft decree proposing amendments to Decree No. 52/2024/ND-CP dated May 15, 2024, on non-cash payments (Decree 52). The draft decree would amend 17 of Decree 52’s 38 articles, with several key changes directly affecting providers of intermediary payment service (IPS). The key proposed changes affecting IPS providers are outlined below. Streamlining IPS Licensing Procedures A central objective of the draft decree is to simplify regulatory procedures for IPS providers. Notably, it would significantly reduce IPS licensing documentation requirements by removing the need to submit enterprise registration certificates, investment registration certificates, and documents evidencing the qualifications of the legal representative and general director. Instead, the SBV would retrieve this information directly from national business registration and other specialized databases, requesting additional documents only where the relevant information cannot be verified electronically or is incomplete. The draft decree also removes the current limit of two rounds for dossier supplementation and shortens processing timelines for several IPS licensing procedures such as issuance, amendment, and reissuance of IPS licenses. The processing time for new IPS license applications would be thereby reduced from 90 to 60 working days. In addition, several continuing IPS business conditions would be removed. For example, IPS providers would no longer be required to maintain certain representations relating to corporate restructuring or the legality of contributed capital. Likewise, the IPS project plan (đề án) would become a one-time application document rather than an ongoing licensing condition. If retained in the final decree, this change could provide IPS providers with significantly greater flexibility to implement post-licensing technology upgrades, system integrations, and corporate restructuring transactions without needing to revisit the originally approved project plan. The draft decree also removes the requirement for the SBV to consult the Ministry of Public
August 11, 2026
Cambodia’s Ministry of Justice has launched a new platform on its official website to publish notices of forced sales issued by each municipal and provincial court of first instance. The platform’s stated purpose is to inform the public and facilitate greater participation in forced-sale auctions conducted in connection with court-ordered enforcement proceedings. How the Platform Works The platform publishes forced-sale notices from courts of first instance across Cambodia’s municipalities and provinces and includes a link where the public can view properties currently subject to forced sale. To participate in a forced-sale auction, individuals can download Khmer-language bidding application forms through links provided on the platform. The form typically requires the applicant’s name, sex, year of birth, identity card number and issue date, and address, together with details identifying the immovable property (including its ownership certificate number), the relevant enforcement case number and date, and the reference to the public auction or tender announcement issued by the court. Completed application forms must be submitted directly to the specific municipal or provincial court that issued the forced sale. For further inquiries about a particular forced sale, interested parties should likewise contact the relevant municipal or provincial court. Forced Sale of Immovable Property in Cambodia The publication of these notices relates to the forced sale procedure for immovable property under Cambodia’s Code of Civil Procedure (CPC). Unlike property seizure by a court, a forced sale is a compulsory execution proceeding—a subsequent enforcement step that arises only after an underlying dispute has been adjudicated and a debtor fails to pay the debt or outstanding amount due under a final and binding judgment or other enforceable title of execution. For the purposes of this procedure, the term “immovable property” under the CPC refers to land, registered buildings, jointly held shares of such property, registered
August 6, 2026
Every month, VAT-registered businesses in Thailand calculate their output and input VAT and file a return to pay the net amount due or claim a refund. Yet a common and costly dispute arises when a business that has paid input VAT to its supplier—and done everything asked of it—later finds that input VAT rejected on the grounds that the tax invoice was issued by “a person not entitled to issue tax invoices.” In these cases, a buyer may have confirmed the supplier’s VAT registration on the Revenue Department’s website, paid through the banking system, received a complete tax invoice, and kept full payment and inventory records. Even so, if the Revenue Department later determines that the supplier did not genuinely make the sale or collected the VAT without remitting it, the department can disallow the input VAT and assess additional tax, surcharge, and penalty—often more than a year after the transaction. A new article from tax and dispute resolution specialists at Tilleke & Gibbins in Bangkok examines how the Revenue Department and the courts approach these disputes, including two recent Supreme Court (Tax Division) decisions confirming that the taxpayer bears the burden of proving a supplier genuinely sold and delivered the goods and received payment. It considers why the VAT registration system offers no legal safe harbor, why the evidentiary burden falls hardest on online and cross-border transactions where buyers and sellers never meet, and how the Revenue Department’s own digital infrastructure could detect non-remitting suppliers at the source rather than shifting the loss to good-faith buyers. The article also sets out practical guidance: how to build a comprehensive “know-your-supplier” file at the time of a transaction, the procedural steps and strict deadlines for challenging a VAT assessment, and why dispute readiness belongs alongside tax planning at the center
August 3, 2026
On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026. Background The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements. Expanded Scope of Regulated Entities and Channels The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking. Strengthened Customer Authentication The draft introduces enhanced authentication requirements in three areas: Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits. Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases. Secure authentication factors. Key requirements include the following: “What-you-know” factors must