Banking Law And Critical Financial Infrastructure Offenses Spain .

1. Constitutional and regulatory framework

Spain protects the financial system through a combination of criminal sanctions and administrative supervision.

Important institutions include:

  • Banco de España — banking supervision and prudential functions;
  • CNMV — securities and investment-market supervision;
  • SEPBLAC — prevention and enforcement framework for money laundering/terrorist financing;
  • Ministry of the Interior / CNPIC — protection of critical infrastructures;
  • Spanish courts and Fiscalía — criminal enforcement.

The financial system is expressly recognised as a strategic sector for critical-infrastructure purposes. The consolidated Ley 8/2011 on Protection of Critical Infrastructures includes the financial and tax system among Spain's strategic sectors.

The important distinction is:

A violation of banking regulations is not automatically a criminal offence.

Many banking-law breaches are administrative offences. Criminal liability arises where the conduct satisfies the elements of a specific offence in the Código Penal.

2. Principal legislation

A. Spanish Criminal Code — Código Penal

The principal criminal statute is Organic Law 10/1995 (Ley Orgánica 10/1995). It contains the offences most relevant to banking, including:

  • fraud (estafa);
  • computer fraud;
  • misappropriation (apropiación indebida);
  • disloyal administration (administración desleal);
  • falsification of documents;
  • money laundering;
  • corruption;
  • market manipulation;
  • insider dealing;
  • damage to computer systems;
  • interruption of computer systems;
  • offences involving confidential information.

The current Criminal Code specifically criminalises serious attacks against computer data and systems.

B. Ley 10/2010 — Anti-Money Laundering

The Ley 10/2010, de 28 de abril, de prevención del blanqueo de capitales y de la financiación del terrorismo is fundamental to banking law.

Its objective is expressly to protect the integrity of the financial system by imposing preventive obligations against money laundering and terrorist financing.

Banks and credit institutions are expressly classified as obliged entities (sujetos obligados). Payment institutions and electronic-money institutions are also covered.

The obligations include, among other things:

  • customer identification;
  • beneficial-owner identification;
  • due diligence;
  • monitoring of transactions;
  • reporting suspicious transactions;
  • internal control;
  • record keeping;
  • enhanced due diligence in high-risk situations.

The important point is that Ley 10/2010 primarily establishes preventive/administrative obligations, while the actual criminal offence of money laundering is principally found in the Criminal Code.

3. Banking fraud — Estafa

One of the most important banking-related offences is estafa, generally translated as fraud or fraudulent deception.

The classic structure is:

deception → error → disposition of property → economic loss → unlawful benefit.

Banking examples include:

  • obtaining a loan through fraudulent documentation;
  • fraudulent transfers;
  • manipulating banking instructions;
  • using another person's credentials;
  • fraudulent online banking transactions;
  • false representations to obtain credit;
  • fraudulent use of payment instruments.

Where computers or automated systems are used, the conduct may fall under computer fraud (estafa informática) rather than ordinary interpersonal deception.

4. Computer fraud and payment-card fraud

Spanish Supreme Court jurisprudence has treated manipulation of electronic/payment systems as capable of constituting computer fraud.

The Supreme Court's jurisprudential materials discuss cases involving fraudulent use of payment cards and POS/ATM systems, including STS 692/2006, 26 June, and STS 1476/2004, 21 February. The Court explained that unauthorised manipulation or use of an electronic system can satisfy the statutory concept of manipulation or a similar device for computer fraud.

This is particularly important for modern banking because the victim does not necessarily have to be deceived in the traditional sense.

Example

Suppose A obtains B's card information and uses it through a payment terminal to cause funds to be transferred without B's consent.

The legal analysis can focus on:

unauthorised manipulation of the information-processing/payment mechanism

rather than requiring the traditional model of a victim personally believing a false statement.

5. Misappropriation — Apropiación indebida

Another important banking offence is apropiación indebida.

It generally concerns property or money that was lawfully received but is subsequently appropriated or dealt with unlawfully.

Banking examples may involve:

  • an employee entrusted with company funds;
  • a financial intermediary holding client assets;
  • a person entrusted with money who converts it for personal use;
  • misuse of funds held on behalf of another person.

The distinction from fraud is important:

Fraud

The unlawful acquisition is produced through deception.

Misappropriation

The defendant may initially have obtained lawful possession or control, but later unlawfully appropriates the property.

6. Disloyal administration — Administración desleal

This offence is particularly important for bank directors, managers and senior officers.

It addresses abuse of entrusted management powers causing patrimonial damage.

A classic scenario is:

A director has authority to manage the bank's assets but deliberately uses that authority contrary to the interests of the bank for personal or connected-party benefit.

Possible examples include:

  • preferential loans to related companies;
  • transactions with companies controlled by directors;
  • deliberately disadvantageous asset transfers;
  • diversion of corporate opportunities;
  • manipulation of related-party transactions;
  • use of bank resources for personal interests.

7. Important Supreme Court case: Eurobank

A particularly relevant Spanish banking case is the Eurobank case.

In 2018, the Spanish Supreme Court increased the defendants' sentences after finding both continued disloyal administration and misappropriation. The conduct involved the creation of a group of companies and transactions involving a banking entity, abuse of functions and appropriation of the bank's money, ultimately contributing to its dissolution and causing losses to shareholders.

The Supreme Court's reasoning is particularly useful because it illustrates that the same factual circumstances can involve different forms of patrimonial criminality.

The Court distinguished between:

  • abuse of managerial powers/defective administration, and
  • actual appropriation of money.

It therefore accepted the coexistence of administración desleal and apropiación indebida in the circumstances of the case.

Why Eurobank matters

It demonstrates that criminal liability of banking executives does not depend merely on whether a transaction was commercially unsuccessful.

The prosecution must establish the specific criminal elements, including the abuse/appropriation and the resulting patrimonial harm.

8. Falsification of banking documents

Banking activity relies heavily on documentary evidence.

Consequently, the following can generate criminal liability when the statutory requirements are satisfied:

  • falsified loan applications;
  • falsified financial statements;
  • forged signatures;
  • manipulated corporate documents;
  • false accounting documentation;
  • falsified electronic documents;
  • fraudulent documentation used to obtain financing.

Falsification can also operate together with other crimes.

For example:

false document → fraudulent loan application → financial loss

could potentially involve:

falsification + fraud

depending on the facts and the applicable provisions.

9. Money laundering — Blanqueo de capitales

Money laundering is particularly important in banking law because banks are frequently used as channels through which illicit proceeds are transferred or concealed.

The preventive legislation defines money laundering broadly, including conversion or transfer of assets known to derive from criminal activity and concealment of their illicit origin.

Typical banking laundering structure

Predicate offence

illegal proceeds

deposit/transfer through financial institution

conversion or concealment

integration into apparently legitimate assets

The bank may therefore become:

  • the instrument through which laundering occurs;
  • an obliged entity with preventive duties;
  • a victim of fraud;
  • or, in appropriate circumstances, a potential participant whose employees/officers may incur liability.

10. Banks' AML obligations

Under Ley 10/2010, credit institutions are obliged entities.

This means that the bank must have systems for:

  • identifying customers;
  • identifying beneficial owners;
  • understanding the purpose and nature of relationships;
  • monitoring transactions;
  • detecting suspicious activity;
  • reporting appropriate cases;
  • maintaining internal AML controls.

The legislation also applies to a much broader group of financial-sector entities, including investment firms, payment institutions and electronic-money institutions.

Criminal versus administrative liability

This distinction is essential for an examination:

Failure to comply with an AML control requirement ≠ automatically money laundering.

A regulatory breach can produce an administrative sanction.

Criminal money laundering requires satisfaction of the elements of the Criminal Code offence.

11. Attacks against banking computer systems

This is where Spanish banking law intersects with critical-infrastructure criminal law.

The Criminal Code contains specific offences concerning destruction, alteration, deletion or making inaccessible computer data.

Under Article 264, unauthorised and serious damage, deterioration, alteration, deletion or inaccessibility of another person's computer data can constitute an offence punishable by imprisonment. More serious circumstances increase the penalty.

Particularly important is Article 264.2.

The aggravated circumstances include conduct:

  • committed by a criminal organisation;
  • causing particularly serious damage;
  • affecting a large number of systems;
  • seriously affecting essential public services;
  • affecting a computer system belonging to critical infrastructure; or
  • creating serious danger to the security of Spain, the EU or an EU Member State. 

This is directly relevant to banking infrastructure.

12. Article 264 bis — interruption of computer systems

Article 264 bis criminalises unauthorised and serious obstruction or interruption of another person's computer system.

It covers, among other things:

  • introducing/transmitting data;
  • destroying or damaging a system;
  • making a system unusable;
  • deleting or replacing systems or electronic storage.

The basic penalty is imprisonment of six months to three years, with enhanced consequences where the conduct seriously affects business or public administration.

Where circumstances equivalent to those in Article 264.2 occur, the penalty can rise to three to eight years' imprisonment plus a fine linked to the damage.

13. Why a bank cyberattack can become a critical-infrastructure offence

This is one of the most important points.

Imagine a cyberattack against a bank's:

  • core banking system;
  • payment-processing infrastructure;
  • ATM network;
  • clearing infrastructure;
  • electronic-payment platform.

If the attack merely compromises an individual account, ordinary offences such as fraud may be appropriate.

But if the attack:

seriously compromises the operation of a system forming part of critical infrastructure

the Criminal Code provides aggravated treatment.

Article 264 expressly refers to computer systems of critical infrastructure.

Therefore:

ordinary cybercrime

can become

aggravated critical-infrastructure cybercrime

when the statutory requirements are satisfied.

14. What is “critical infrastructure” in Spain?

The principal statute is Ley 8/2011, de 28 de abril, por la que se establecen medidas para la protección de las infraestructuras críticas.

Its purpose is to coordinate the protection of critical infrastructure and protect essential services from deliberate attacks, including cyberattacks.

The law creates the Sistema de Protección de Infraestructuras Críticas and provides for:

  • identification of critical infrastructures;
  • identification of critical operators;
  • security planning;
  • specific protection plans;
  • security officers;
  • inspections;
  • coordination with government authorities.

The financial and tax system is expressly included among the strategic sectors.

15. Critical operator obligations

An operator designated as critical has enhanced security responsibilities.

Among other obligations, the law provides for:

  • a Plan de Protección Específico for each critical infrastructure;
  • designation of a Responsable de Seguridad y Enlace;
  • designation of a security delegate for relevant infrastructures;
  • cooperation with inspections;
  • implementation of required security measures. 

This is primarily a protective/regulatory regime, not a separate general criminal offence called "critical infrastructure offence."

That distinction is important.

16. Cybersecurity of essential financial services

Spain also has the Real Decreto-ley 12/2018, de seguridad de las redes y sistemas de información.

It establishes rules concerning:

  • security of networks and information systems;
  • essential services;
  • incident notification;
  • supervision;
  • cybersecurity measures.

The financial system was specifically included within the strategic sectors covered by the regime for essential services.

Operators of essential services must adopt appropriate security measures and notify incidents having significant disruptive effects.

The legislation also provides administrative sanctions for serious and very serious non-compliance.

Thus there are two different legal consequences:

Cyberattack by an offender

Potential criminal liability under the Criminal Code.

Failure of an operator to satisfy cybersecurity obligations

Potential administrative/regulatory liability.

Both can arise from the same incident.

17. Market-abuse offences

Banking law also intersects with securities-market criminal law.

Important conduct includes:

  • insider dealing;
  • unlawful disclosure of inside information;
  • market manipulation;
  • fraudulent market practices.

The principal regulatory framework includes Ley 6/2023, de los Mercados de Valores y de los Servicios de Inversión, together with EU market-abuse legislation and the Criminal Code.

The 2023 law also establishes the national framework for investment services and incorporates the European prudential architecture applicable to financial firms.

A bank may therefore be involved in criminal proceedings both as:

a credit institution

and, where authorised activities are involved,

an investment-services provider.

18. Corporate criminal liability

A major issue in financial criminal law is whether liability falls only on the individual or can extend to the company.

Spanish criminal law recognises criminal liability of legal persons in specified circumstances.

This is particularly relevant to:

  • banks;
  • financial companies;
  • payment institutions;
  • investment firms;
  • corporate groups.

However, corporate criminal liability does not mean that every offence committed by an employee automatically makes the bank criminally liable.

The statutory requirements concerning:

  • who committed the offence;
  • position of the individual;
  • benefit to the company;
  • organisational failures;
  • compliance/control measures;

must be examined.

19. Relationship between banking regulation and criminal law

A useful examination framework is:

ConductPossible legal consequence
Failure to perform AML due diligenceAdministrative/regulatory sanction
Concealing criminal proceedsMoney laundering
Fraudulent loan applicationFraud
Taking entrusted client fundsMisappropriation
Abuse of managerial powersDisloyal administration
Forging banking documentsDocument falsification
Manipulating payment systemsComputer fraud
Destroying bank dataComputer damage offence
Disrupting banking infrastructureArticle 264 bis
Attack on critical financial infrastructureAggravated cyber offence where statutory conditions are met
Insider tradingMarket-abuse offence/regulatory liability
Manipulating securities marketMarket-abuse offence/regulatory liability

20. Important Spanish case-law principles

1. Eurobank — administration + appropriation

The Supreme Court's Eurobank decision demonstrates that abusive management of a bank and subsequent appropriation of bank funds can support both administración desleal and apropiación indebida.

2. Payment-card/electronic manipulation

Supreme Court jurisprudence has recognised that unauthorised manipulation/use of payment systems can fall within computer fraud, including cases involving POS terminals and payment cards. The Court's jurisprudential compilation refers, among others, to STS 692/2006 and STS 1476/2004.

3. Critical-infrastructure cyberattacks

The significance of critical infrastructure is now expressly incorporated into the Criminal Code's aggravated computer-damage provisions. Article 264.2 specifically identifies attacks affecting a computer system of critical infrastructure as an aggravating circumstance.

21. Hypothetical case study

Facts

A criminal group obtains privileged credentials of employees of a major Spanish bank.

They:

  1. enter the bank's internal network;
  2. modify payment databases;
  3. transfer €50 million;
  4. disable parts of the payment-processing system;
  5. prevent customers from accessing accounts;
  6. use shell companies to receive the stolen funds.

Possible offences

The investigation could potentially involve:

(1) Computer intrusion/access offences

depending on the precise method of access.

(2) Computer fraud

because the electronic system was manipulated to produce unlawful transfers.

(3) Computer damage/interference

if databases or systems were damaged or made inaccessible.

(4) Article 264/264 bis aggravated provisions

if the statutory conditions concerning serious disruption or critical infrastructure are satisfied.

(5) Fraud

for the resulting patrimonial deception where the elements are established.

(6) Money laundering

for transferring/concealing the €50 million proceeds.

(7) Criminal-organisation liability

if the evidence establishes the required organisational structure.

This demonstrates why a single banking cyberattack can produce a multi-offence prosecution.

22. Critical distinction: “financial infrastructure offence”

Spanish law does not create one universal offence called:

“offence against critical financial infrastructure.”

Instead, the legal analysis is constructed from different provisions.

For example:

Attack

→ unauthorised computer interference

→ Article 264/264 bis

→ aggravating circumstance: critical infrastructure

→ potentially much higher punishment.

At the same time:

same conduct

→ fraudulent transfer

→ computer fraud/fraud

and potentially:

proceeds

→ money laundering.

This is the most accurate way to conceptualise Spanish critical-financial-infrastructure criminal law.

23. European dimension

Spanish banking criminal law cannot be studied in isolation from EU law.

Particularly important are:

  • CRR/CRD — prudential banking regulation;
  • PSD2/payment-services framework;
  • MiFID II/MiFIR;
  • Market Abuse Regulation;
  • AML directives/regulations;
  • NIS cybersecurity framework;
  • DORA — Digital Operational Resilience Act.

DORA is especially important for financial-sector ICT risk because it creates a specialised EU framework for digital operational resilience of financial entities.

Consequently, modern Spanish financial-infrastructure law increasingly operates through a three-layer structure:

EU financial regulation + Spanish regulatory law + Spanish criminal law

24. Overall legal framework

A concise way to remember the system is:

                    SPANISH FINANCIAL CRIMINAL LAW                               │             ┌─────────────────┼─────────────────┐             │                 │                 │        BANKING CRIMES    FINANCIAL CRIMES   CYBERCRIMES             │                 │                 │       Fraud               Insider dealing   Data damage       Misappropriation    Manipulation      System attacks       Disloyal admin.     Market offences   Computer fraud       Falsification       AML offences      Infrastructure attacks             │                 │                 │             └─────────────────┼─────────────────┘                               │                     CRITICAL INFRASTRUCTURE                               │                   Ley 8/2011 + cybersecurity                               │                    FINANCIAL SYSTEM / BANKS                               │                 Aggravated Criminal Code rules

 

Key authorities to cite in an academic answer

  1. Código Penal — Organic Law 10/1995, particularly the provisions on fraud, misappropriation, disloyal administration, money laundering and computer offences. 
  2. Ley 10/2010, Anti-Money Laundering and Terrorist Financing Act. 
  3. Ley 8/2011, Critical Infrastructure Protection Act. 
  4. Real Decreto-ley 12/2018, security of networks and information systems. 
  5. Ley 6/2023, Securities Markets and Investment Services Act. 
  6. STS / Supreme Court Eurobank case, concerning the concurrence of disloyal administration and misappropriation. 
  7. STS 692/2006 and STS 1476/2004, relevant to computer fraud/payment-card manipulation. 

Bottom line: Spanish law protects banks and the financial system through a combination of ordinary financial crimes, AML offences, corporate/managerial offences, computer crimes, and special critical-infrastructure aggravations. The most important modern development is that a cyberattack against a banking system is not treated merely as property crime: where the statutory conditions are met, its impact on critical infrastructure and essential financial services can substantially alter the criminal classification and penalty.

LEAVE A COMMENT