A Junín Court Draws a Line Under "It Wasn't Us"
On June 30, 2026, the Cámara de Apelación en lo Civil y Comercial de Junín confirmed a first-instance ruling holding Telefónica Móviles Argentina (Movistar) and Banco de Galicia y Buenos Aires jointly and severally liable for a SIM-swapping fraud that stripped a customer's account in minutes. In Denis Alejandra de los Ángeles c/ Movistar y otro, judges Ricardo Castro Durán and Gastón Volta ordered the companies to pay 19.2 million pesos in emergent damages, 5.76 million pesos in moral damages, and a punitive fine equal to four INDEC basic food baskets for a household of three, plus interest.
The mechanics were straightforward, and by now familiar:
- A fraudster impersonated the victim through Movistar's self-service SIM-duplication channel, clearing verification with random security questions rather than any biometric or device-bound credential.
- Once the duplicate chip activated, the attacker intercepted the SMS one-time codes Banco de Galicia sent to authorize online banking.
- Seven transfers followed in rapid succession, draining roughly 16.2 million pesos to Personal Pay digital-wallet accounts before the bank's systems flagged the pattern.
What the Regulator Already Required
The court didn't invent a new duty — it measured Movistar's process against a standard ENACOM had set three years earlier. Resolución 263/2023, the "Reglamento para la Nominatividad y Validación de Identidad de los Usuarios Titulares de los Servicios de Comunicaciones Móviles," was published in the Boletín Oficial on March 17, 2023, replacing a 2016 predecessor. It gave carriers 60 days to deploy biometric verification — facial capture with liveness detection — or, for handsets that can't support it, documented multi-step authentication for "sensitive" changes such as SIM reissuance and line-ownership transfers. Random knowledge-based questions were never compliant with that standard once the transition window closed in mid-2023.
Banco de Galicia's exposure rested on a parallel theory: Central Bank transaction-monitoring guidance expects banks to maintain customer behavioral profiles capable of flagging a sudden burst of same-day transfers to unfamiliar wallets. The panel also rejected the bank's attempt to net out 9.6 million pesos it had separately refunded the victim, ruling that argument procedurally untimely.
The tribunal found that third-party fraud does not excuse either defendant, characterizing the intrusion as foreseeable and preventable through the security measures each was already obligated to run.
The Case for the Ruling
There's a real case for this outcome, and it deserves to be stated plainly rather than waved away. Identity-linked telecom accounts are now the de facto master key to banking, so a carrier choosing the cheapest verification method externalizes fraud risk onto customers who have no visibility into, and no ability to audit, that choice. Argentina's cybercrime reporting has climbed sharply: the Unidad Fiscal Especializada en Ciberdelincuencia logged 34,468 complaints nationally in 2024, up 21.1% year-over-year, with online fraud accounting for 63% of the total. When a regulator has already written a specific, technically achievable standard, and a carrier keeps running a cheaper legacy flow anyway, "we followed our own internal process" is a weak defense. Assigning the loss to the party best positioned to prevent it — rather than to a victim who had no way to stop a stranger from talking their way past a phone company's help desk — is a coherent allocation of risk.
Where Proportionality Still Matters
Even so, the ruling is worth watching for how far Argentine courts extend it, not for the underlying result. ENACOM's biometric mandate is unusually well-specified as regulation goes: it names the technique, sets a hard compliance deadline, and predates this fraud by roughly a year and a half, so this isn't judges retrofitting a duty that didn't exist. The risk sits elsewhere. Joint-and-several liability paired with an uncapped punitive-damages formula — basic-basket multiples that scale with inflation, not with a carrier's actual degree of fault — gives lower courts a template to impose steep penalties even where a compliance gap was marginal, or where a customer's credentials were compromised through phishing rather than any carrier-side failure. Telecom compliance costs in a market already contending with currency volatility and thin margins should track the clarity of the underlying regulatory duty, not the sympathies of whichever chamber hears the case. ENACOM — issuing updated, technology-specific guidance as fraud techniques evolve — remains the better venue for defining what "adequate" verification means, rather than each civil court reconstructing the standard from scratch on a differing evidentiary record.
The Fix Is Enforcement, Not New Courts
None of this argues for weakening carrier accountability; the Junín court applied an existing, sensible rule correctly, and Movistar had years to comply. The better long-term fix is for ENACOM to keep the standard current — covering wallet-linked accounts, device-risk signals, and viable fallback authentication for the millions of Argentines still on handsets too old for facial capture — so liability tracks a bright line regulators set in advance, not one courts draw after the money is already gone.