Malta’s Financial Arbiter Blames Fraud Victims for Their “Greed” — While OpenPayd Remains Authorised
Across the world, authorities are finally recognising online fraud as a systemic societal threat—and the manipulation of victims as a core element of the crime. Malta’s Financial Arbiter, however, has developed an extraordinary formula for deciding online investment-fraud cases.
First, he finds that OpenPayd Financial Services Malta Limited committed a regulatory or conduct failure. He sends the decision to the Malta Financial Services Authority for investigation. Then he denies compensation because, in his words, the victim’s loss was caused by “greed and gross negligence”—not by OpenPayd’s failure.
This was not an isolated lapse of language.
In ASF 005/2025, the Arbiter found that OpenPayd had no authority to credit funds to the holder of a vIBAN-linked account instead of the beneficiary named by the remitter. He called this a “breach of conduct”, referred it to the MFSA—and immediately concluded that the victim’s loss had been caused by his “greed and gross negligence”.
In ASF 105/2025, he repeated the same reasoning. He found the same OpenPayd conduct failure, noted that OpenPayd had terminated its relationship with Coin Sonic—a corporate client that had, at minimum, handled fraud payments—and invited the MFSA to investigate whether OpenPayd’s onboarding and KYC processes were effective enough to prevent the facilitation of fraud. He then dismissed the complaint because the victim’s loss had supposedly been caused by her “greed and gross negligence”.
In ASF 135/2025, decided in January 2026, the Arbiter again found that OpenPayd had credited funds contrary to the beneficiary information in the payment instructions, again referred the conduct to the MFSA, and again declared that the victim’s greed—not OpenPayd’s conduct failure—had caused the loss.
The pattern is unmistakable:
Provider breach identified. Regulator notified. Compensation denied. Victim condemned. OpenPayd remains authorised and continues operating.
That is not consumer redress. It is victim-blaming institutionalised as causation analysis.
That raises the central question: is Malta offering fraud victims a genuine remedy, or merely a procedural appearance of one?
An Arbiter who blames social-engineering victims has lost the credibility required for the office
Online investment fraud is not a spontaneous purchasing mistake caused by excessive enthusiasm for profit. It is organised social engineering.
Fraudsters build trust over days or months. They impersonate credible individuals and institutions. They display fabricated trading profits, permit controlled initial withdrawals, manufacture urgency, isolate victims from contrary advice and use remote-access software to control devices and payments. The apparent profitability of the investment is itself part of the deception.
Yet the Maltese Arbiter repeatedly treats the success of this manipulation as proof that the victim caused the loss.
That reasoning is not merely offensive. It is analytically defective.
A victim’s mistake and a payment provider’s control failure can exist simultaneously. The fact that a victim believed a fraudster does not make an opaque vIBAN structure transparent. It does not authorise a payment institution to credit money to an undisclosed corporate client rather than the named beneficiary. It does not cure deficient corporate-client onboarding. It does not eliminate transaction-monitoring duties. And it does not break causation merely because another actor committed the primary fraud.
The relevant question is whether the regulated payment infrastructure materially enabled the fraud by providing credibility, speed, concealment or access to the financial system. The Arbiter avoids that question by substituting a moral judgment about the victim.
Once he labels the victim greedy, OpenPayd’s identified breach becomes legally irrelevant.
EFRI’s position is therefore clear: an Arbiter who repeatedly reduces victims of organised social-engineering fraud to “greed and gross negligence” has forfeited the impartiality and credibility required for a consumer-redress office and should be removed from that position. Such conduct brings the office of Financial Arbiter into disrepute.
The Arbiter’s Causation Analysis Made OpenPayd’s Breach Consequence-Free
The most revealing aspect of the decisions is not only their language. It is the artificial separation between OpenPayd’s conduct and the resulting loss.
The Arbiter found that OpenPayd had no authority to apply normal IBAN rules to a vIBAN structure and credit funds to the holder of the underlying vIBAN-linked account rather than the beneficiary named by the payer. In ASF 005/2025, he expressly classified this as a regulatory failure and a conduct breach requiring MFSA investigation.
But the very purpose of the relevant payment instructions was to determine where the payer intended the money to go.
Where the payer believed that funds were being transferred to an account held in the payer’s own name—or to the regulated institution identified in the transfer—while the money was actually credited to a third-party corporate account, the discrepancy is not peripheral. It is at the heart of the fraud mechanism.
The beneficiary information created the appearance of a safer payment. The underlying vIBAN architecture enabled the funds to be credited to an undisclosed corporate client rather than to the beneficiary visible to the payer.
To acknowledge that failure and then declare it causally irrelevant is not a serious analysis of the payment chain. It is a method of insulating the provider from the consequences of the very breach the Arbiter identified.
The outcome is institutionally convenient. The Arbiter can claim that he detected misconduct. The MFSA can treat any subsequent supervisory work as confidential. OpenPayd can continue operating. Only the victim leaves with a public finding of “greed and gross negligence”.
The Klickl Case: Five Transfers, Six Days—and No Review of OpenPayd’s Conduct
The anonymised case ASF 101/2026 brought by an EFRI member shows where Malta’s two failures meet: an opaque payment structure and a redress mechanism that refused to examine it.
Between 15 and 25 September 2025, an EFRI member made five transfers totalling €44,100 in connection with an alleged investment fraud. The payment evidence identified OpenPayd as the receiving institution. It made no reference to Klickl Europe, the Polish crypto company that OpenPayd later disclosed as its corporate client. Klickl was entirely unknown to the victim.
OpenPayd’s own formal response exposed what happened behind the payment information visible to the payer.
Klickl was OpenPayd’s corporate client. A master account and linked virtual IBANs were made available for Klickl’s use. Klickl could allocate individual vIBANs to receive payments from particular persons. The victim’s name could therefore appear in connection with the vIBAN even though the victim did not own the payment account. Funds sent through that vIBAN entered Klickl’s master account and were treated as Klickl’s funds.
OpenPayd also confirmed that it acted as the receiving payment service provider, had visibility over the transactions and was responsible for conducting customer due diligence on Klickl both at onboarding and throughout the business relationship.
This was not a neutral reconciliation function.
The structure separated the identity visible to the payer from the identity of the company legally receiving the money. The victim saw OpenPayd and an individualised payment route. The actual economic recipient was an undisclosed Polish crypto company.
That asymmetry is precisely what made the payment structure useful in the fraud.
OpenPayd argued that it had been “completely removed” from the fraudulent arrangement. That may be true in the narrow sense that there is no evidence in this case that OpenPayd operated the scam platform or made the fraudulent investment representations.
But OpenPayd was not removed from the payment.
It provided the regulated receiving infrastructure. It made the vIBAN architecture available. It received the funds. It had transaction visibility. It credited its corporate client. And it owed ongoing due-diligence obligations in relation to that client.
The relevant regulatory question was therefore not whether OpenPayd personally contacted the victim. It was whether OpenPayd adequately understood, monitored and controlled Klickl’s use of its payment infrastructure.
The Arbiter never examined that question.
The reason was a six-day cut-off.
The final transfer was made on 25 September 2025. Malta’s widened definition of an “eligible customer” became applicable on 1 October 2025. Six days determined whether the victim obtained a substantive review of OpenPayd’s conduct.
The victim argued that he qualified even under the previous law because he had “sought the provision of a financial service” from OpenPayd. OpenPayd was identified in the payment documentation, OpenPayd handled the funds and Klickl—the actual corporate recipient—was undisclosed and unknown to him.
The Arbiter nevertheless relied on an earlier Court of Appeal ruling involving materially different facts. In that case, the victim knew that she was transferring money in favour of SWAPS. In ASF 101/2026, the payer did not know that the funds were being credited to Klickl.
The Arbiter acknowledged that distinction but treated it as legally irrelevant. He focused on the absence of a direct contractual relationship between the victim and OpenPayd.
That answered the wrong question.
The former statutory definition did not apply only to persons who already had a contract with the provider. It expressly included persons who had sought the provision of a financial service. By collapsing those separate categories, the Arbiter transformed a fact-specific appellate decision into a general jurisdictional shield for payment providers.
Malta had already recognised that this exclusion was defective. Act IX of 2025 extended eligibility to victims with an immediate, genuine and legitimate interest in suspicious fraudulent payment transactions—but only for transactions processed from 1 October 2025. More than 100 earlier cases were consequently closed without examination of the merits.
The original reform was expected to enter into force upon publication. Its application was postponed following consultations with banking and payment-industry representatives. The official justification was that providers needed time to update their procedures and monitoring systems, even though the OAFS simultaneously maintained that the reform imposed no new regulatory duties.
The contradiction is obvious.
If the reform created no new duties, the industry required no transition period. If procedures and monitoring systems had to be strengthened, the problem was substantive rather than merely procedural.
The industry received time to prepare. Earlier victims received exclusion.
OpenPayd is not an isolated case—it is a recurring pattern
OpenPayd was named in 75 formal OAFS complaints during 2025, including 73 classified under banking and payment services. The number does not establish that every complaint was justified or fraud-related. It does establish that the problem cannot credibly be dismissed as a single rogue customer or accidental misuse of one vIBAN.
The OAFS also reported an unnamed “systemic case” involving a licensed payment provider whose corporate clients had received money from retail consumers alleging fraud. The complaints raised concerns about due diligence, onboarding, KYC and monitoring. The OAFS supplied the MFSA with data on the victims, corporate clients, jurisdictions, amounts and transaction dates. It stated that the pattern raised concerns about the provider’s controls and merchant-onboarding process. The report does not identify the provider, so EFRI does not assert that this passage necessarily concerns OpenPayd. The risk pattern described is, however, identical to the one visible in the published OpenPayd cases.
The documented OpenPayd sequence is now repetitive:
OpenPayd provides vIBAN infrastructure to a corporate client. A fraud victim transfers money through an individualised or apparently personal payment route. The visible beneficiary information does not disclose the company actually receiving the funds. OpenPayd credits its corporate client. When the fraud is discovered, OpenPayd states that the victim was never its customer. The Arbiter identifies a conduct failure, sends it to the MFSA, denies compensation and blames the victim.
This is no longer a collection of unrelated incidents.
It is a business-model risk.
Where Is the MSFA?
OpenPayd remains authorised by the MFSA as a financial institution licensed to issue electronic money and provide payment services.
The Arbiter has repeatedly sent OpenPayd decisions to the MFSA for investigation. He has expressly questioned OpenPayd’s onboarding and KYC controls. The OAFS has recorded 75 formal complaints against OpenPayd in one year.
EFRI has nevertheless found no publicly disclosed MFSA enforcement decision, licence restriction or supervisory outcome addressing these specific OpenPayd referrals in the Authority’s public Notices and Decisions database. The absence of a public measure does not prove that no confidential supervisory work has taken place. It does mean that victims, sending banks and other European authorities have no public indication of what the MFSA investigated, what it found or what OpenPayd was required to change.
The MFSA describes consumer protection, effective supervision, market integrity and high standards of conduct as central parts of its mandate.
The public is entitled to ask whether those principles have any operational meaning in the OpenPayd cases.
How many fraud complaints are required before the regulator treats repeated misuse as a systemic issue?
How many corporate clients may appear in fraud payment chains before onboarding and ongoing monitoring are examined across the entire portfolio?
How many conduct breaches may be referred before a visible regulatory consequence follows?
Malta’s fraud remedy protects the system, not the victim
The Maltese system evidently fragments responsibility until it disappears.
OpenPayd says that the victim is not its customer. The corporate client sits behind the vIBAN and may be located abroad. The fraud platform operates under another name. The Arbiter either denies jurisdiction or identifies a breach and denies causation. The MFSA may act confidentially but publishes no identifiable outcome.
Every institution points to the next layer.
The victim is the only participant to whom the system publicly assigns full responsibility.
A functioning fraud remedy would investigate whether the regulated payment infrastructure enabled the fraud. It would examine the relationship between beneficiary opacity, vIBAN design, corporate-client onboarding, transaction monitoring and the victim’s loss. It would not use the victim’s successful manipulation by criminals as a defence for failures in the financial infrastructure used to collect the proceeds.
Most importantly, a consumer-redress official would not describe victims of industrialised social engineering as greedy.
A mechanism that repeatedly identifies provider misconduct but produces neither effective redress nor any publicly visible supervisory consequence is not a fraud remedy.
It is a liability-filtering mechanism carrying a consumer-protection label.
The European Commission says it intends to publish an EU Action Plan on Online Fraud aimed at strengthening prevention, enforcement, victim support and the recovery of stolen funds.
Europe should start in Malta. The European Commission and AMLA should demand a serious, consolidated and transparent MFSA investigation into OpenPayd, require a public account of the outcome to the fullest extent legally possible, and insist on measures capable of preventing the next victim, not merely documenting and blaming the last one.




