Bengaluru: In a cyber fraud case, the Karnataka High Court has ruled in favour of 71-year-old Bengaluru resident Pradosh Kumar Banerjee, directing the State Bank of India (SBI) to refund ₹1.99 lakh that was allegedly withdrawn from his account through unauthorised transactions. The court also upheld an order directing the bank to pay ₹25,000 as compensation for deficiency in service. The bench made it clear that merely downloading a fraudulent application cannot, by itself, make a customer responsible for unauthorised electronic transactions.
A bench of Justices D K Singh and T M Nadaf upheld the April 15 order of the National Consumer Disputes Redressal Commission (NCDRC), which had directed SBI to refund ₹1.99 lakh to Banerjee and pay ₹25,000 as compensation. SBI’s C V Raman Nagar branch had challenged the consumer commission’s order before the High Court.
Fake App Allegedly Used to Access Account
The case dates back to July 2022. According to the bank, two unauthorised transactions took place in Banerjee’s account, involving debits of ₹1.99 lakh and ₹25,000. SBI argued before the court that such transactions could not have occurred without negligence on the customer’s part.
The bank claimed that Banerjee had downloaded a fraudulent application through a link sent to his mobile phone by a fraudster. SBI further alleged that he had shared an OTP, enabling the unauthorised transactions. The bank also argued that Banerjee had informed it about the transactions eight days after they occurred and contended that this delay weakened his claim for reimbursement.
Banerjee, however, disputed the bank’s allegations and maintained that he had neither shared any OTP nor initiated the disputed transactions himself.
Victim Denied Sharing Any OTP
Banerjee appeared before the High Court in person and said he had never shared an OTP with anyone. He alleged that a third party had gained control of the bank’s software and unauthorisedly withdrawn money from his account.
According to Banerjee, he informed SBI after noticing the unauthorised transactions and also spoke to the bank manager the following day. He subsequently sent several emails requesting that the money be refunded. He said the bank reversed only ₹25,000, while the remaining amount was not returned.
The court examined the transaction records and noted that Banerjee had himself initiated a payment of only ₹20 from his account. A substantially larger amount was subsequently debited without his apparent involvement. The bench considered this an important circumstance while examining the bank’s claim that the customer was responsible for the transactions.
Downloading an App Does Not Establish Complicity
The High Court held that in cases involving third-party fraud, a customer’s complicity cannot be presumed merely because the person downloaded an application. According to the court, when unauthorised transactions were not initiated by the customer, the person cannot automatically be held liable merely on the allegation that an OTP was shared.
The bench also urged banks to strengthen their online banking systems and make them more secure against misuse by fraudsters. The court observed that weaknesses in banking software can have consequences extending beyond an individual customer. Any failure can affect public confidence in the banking system and potentially have wider economic implications.
RBI Rules Also Cited
The court referred to the Reserve Bank of India’s July 6, 2017 circular concerning unauthorised electronic banking transactions. Under the prescribed framework, banks can be liable to compensate customers for losses from unauthorised transactions when the fraud is reported within the stipulated period and the applicable conditions are satisfied.
The High Court found that Banerjee had informed SBI about the unauthorised transactions within the required period. On that basis, it upheld the direction requiring the bank to refund ₹1.99 lakh and pay ₹25,000 in compensation. The ruling is significant for digital banking fraud cases, particularly in determining when customers can be held responsible and when banks must bear the liability for unauthorised transactions.
About the author — Suvedita Nath is a science student with a growing interest in cybercrime and digital safety. She writes on online activity, cyber threats, and technology-driven risks. Her work focuses on clarity, accuracy, and public awareness.
