Express theft in Marbella: How €20,000 was drained from an iPhone in 12 hours
An iPhone 15 stolen at Playa Padre, a luxury beach club in Marbella, allowed professional incivil to drain accounts worth €20,000 in less than 12 hours. The case exposes critical security failures in neobanks like Trade Republic and the risks of relying on a single device.
The theft began when the robbers observed the phone's unlock PIN, which the victim kept alongside their DNI (Spanish national ID) in the case. With access to the mobile, they used Apple Pay with the Trade Republic card to withdraw cash and make purchases. They also executed instant transfers from a savings account to a current one. The affected user could not block the Trade Republic account via the app (which required mobile access), and the emergency hotline only offered a bot that failed to stop the transactions.
The security hole in neobanks
Trade Republic took several days to contact the victim, despite multiple reports. Traditional banks, by contrast, can block accounts and cards within minutes. The lack of a rapid blocking process and the dependency on the app on the device itself are heavily criticized. Furthermore, SMS-based two-factor authentication (2FA) is vulnerable if the attacker gains access to the number via SIM swap.
Apple Pay tokenization offers no protection if the phone is unlocked: once inside, the attacker can use stored cards without further verification.
Lessons and protective measures
The debate thread (preceding this article) generated extensive security analysis. Conclusions point to:
- Do not keep your DNI next to your mobile.
- Use facial recognition or fingerprint as the sole unlocking method (without a backup PIN).
- Avoid having cards linked to high-balance accounts in Apple Pay or similar services.
- Use a separate phone for banking apps and another for daily use.
- Enable iOS Stolen Device Protection, which requires Face ID outside trusted locations.
Some participants noted that the sense of security is illusory: the convenience of having everything on one phone comes with high risk. Others argued that the problem is not the phone itself, but the concentration of access points and the lack of rapid protocols in certain banks.
The open question is whether neobanks and mobile payment systems will assume part of the liability, or if users must fortify themselves with measures that are not yet standard. Meanwhile, each individual assesses their own exposure.
Related forum debates