Argentina SIM card binding identity

Argentine Appeals Court Holds Movistar and Banco Galicia Liable for Ignoring a Biometric ID Rule

A Junín court ordered carrier and bank to jointly cover a SIM-swap fraud after Movistar skipped ENACOM's 2023 biometric verification mandate.

Argentina's SIM-Swap Liability Ruling, by the Number… People of Internet Research · Argentina ARS 19.2M Emergent damages awarded Court-ordered payout for funds sto… 7 transfers Fraudulent transfers, minutes Attacker drained the account befor… 60 days ENACOM compliance window Carriers had 60 days to deploy bio… +21% YoY National cybercrime complaints UFECI logged 34,468 cybercrime rep… peopleofinternet.com
Argentina's SIM-Swap Liability Ruling,… People of Internet Research · Argentina ARS 19.2M Emergent damages awarded 7 transfers Fraudulent transfers, minut… 60 days ENACOM compliance window +21% YoY National cybercrime compl… peopleofinternet.com

Key Takeaways

A Junín Court Draws a Line Under "It Wasn't Us"

On June 30, 2026, the Cámara de Apelación en lo Civil y Comercial de Junín confirmed a first-instance ruling holding Telefónica Móviles Argentina (Movistar) and Banco de Galicia y Buenos Aires jointly and severally liable for a SIM-swapping fraud that stripped a customer's account in minutes. In Denis Alejandra de los Ángeles c/ Movistar y otro, judges Ricardo Castro Durán and Gastón Volta ordered the companies to pay 19.2 million pesos in emergent damages, 5.76 million pesos in moral damages, and a punitive fine equal to four INDEC basic food baskets for a household of three, plus interest.

The mechanics were straightforward, and by now familiar:

What the Regulator Already Required

The court didn't invent a new duty — it measured Movistar's process against a standard ENACOM had set three years earlier. Resolución 263/2023, the "Reglamento para la Nominatividad y Validación de Identidad de los Usuarios Titulares de los Servicios de Comunicaciones Móviles," was published in the Boletín Oficial on March 17, 2023, replacing a 2016 predecessor. It gave carriers 60 days to deploy biometric verification — facial capture with liveness detection — or, for handsets that can't support it, documented multi-step authentication for "sensitive" changes such as SIM reissuance and line-ownership transfers. Random knowledge-based questions were never compliant with that standard once the transition window closed in mid-2023.

Banco de Galicia's exposure rested on a parallel theory: Central Bank transaction-monitoring guidance expects banks to maintain customer behavioral profiles capable of flagging a sudden burst of same-day transfers to unfamiliar wallets. The panel also rejected the bank's attempt to net out 9.6 million pesos it had separately refunded the victim, ruling that argument procedurally untimely.

The tribunal found that third-party fraud does not excuse either defendant, characterizing the intrusion as foreseeable and preventable through the security measures each was already obligated to run.

The Case for the Ruling

There's a real case for this outcome, and it deserves to be stated plainly rather than waved away. Identity-linked telecom accounts are now the de facto master key to banking, so a carrier choosing the cheapest verification method externalizes fraud risk onto customers who have no visibility into, and no ability to audit, that choice. Argentina's cybercrime reporting has climbed sharply: the Unidad Fiscal Especializada en Ciberdelincuencia logged 34,468 complaints nationally in 2024, up 21.1% year-over-year, with online fraud accounting for 63% of the total. When a regulator has already written a specific, technically achievable standard, and a carrier keeps running a cheaper legacy flow anyway, "we followed our own internal process" is a weak defense. Assigning the loss to the party best positioned to prevent it — rather than to a victim who had no way to stop a stranger from talking their way past a phone company's help desk — is a coherent allocation of risk.

Where Proportionality Still Matters

Even so, the ruling is worth watching for how far Argentine courts extend it, not for the underlying result. ENACOM's biometric mandate is unusually well-specified as regulation goes: it names the technique, sets a hard compliance deadline, and predates this fraud by roughly a year and a half, so this isn't judges retrofitting a duty that didn't exist. The risk sits elsewhere. Joint-and-several liability paired with an uncapped punitive-damages formula — basic-basket multiples that scale with inflation, not with a carrier's actual degree of fault — gives lower courts a template to impose steep penalties even where a compliance gap was marginal, or where a customer's credentials were compromised through phishing rather than any carrier-side failure. Telecom compliance costs in a market already contending with currency volatility and thin margins should track the clarity of the underlying regulatory duty, not the sympathies of whichever chamber hears the case. ENACOM — issuing updated, technology-specific guidance as fraud techniques evolve — remains the better venue for defining what "adequate" verification means, rather than each civil court reconstructing the standard from scratch on a differing evidentiary record.

The Fix Is Enforcement, Not New Courts

None of this argues for weakening carrier accountability; the Junín court applied an existing, sensible rule correctly, and Movistar had years to comply. The better long-term fix is for ENACOM to keep the standard current — covering wallet-linked accounts, device-risk signals, and viable fallback authentication for the millions of Argentines still on handsets too old for facial capture — so liability tracks a bright line regulators set in advance, not one courts draw after the money is already gone.

Sources & Citations

  1. Boletín Oficial — ENACOM Resolución 263/2023
  2. Argentina.gob.ar — Normativa Resolución 263/2023
  3. Palabras del Derecho — legal analysis of the Junín ruling
  4. La Nación — ENACOM's 60-day biometric mandate
  5. Infobae — 2024 digital fraud complaint data
  6. En Línea Noticias — ruling details and fraud mechanics