A consumer disputes redressal commission in Kerala has ruled that Federal Bank must refund ₹9,854 to a customer who lost the money in two unauthorised UPI transactions triggered by a fraudulent ‘cashback’ scratch card circulating on social media. The bank has also been directed to pay ₹5,000 as compensation and ₹3,000 towards litigation costs, with the full amount payable within thirty days.
The order, delivered on August 5, revisits an episode that dates back to July 2021, but its implications reach well beyond one Thiruvananthapuram household. It lands at a moment when Indian regulators and courts are still working out where the line falls between customer negligence and systemic vulnerability in digital payments, a question that has grown only more urgent as UPI has become the default mode of transacting for hundreds of millions of Indians.
The commission’s reasoning rests on a principle now well established in Indian banking jurisprudence: a bank cannot simply point to the fact that correct UPI credentials were used and declare the customer responsible. It must produce credible evidence of negligence or complicity. In this case, Federal Bank could not.
A Scratch Card, Two Debits, and a Reversal
The complainant told the commission that he came across a scratch card while browsing social media in July 2021, styled to resemble the branding of PhonePe and promising unlimited cashback. As a regular user of Google Pay and PhonePe who was accustomed to genuine promotional scratch cards from such platforms, he scratched it, not once but twice. Within moments, ₹4,885 and then ₹4,969 were debited from his savings account in two separate transactions.
He reported the fraud to Federal Bank soon after discovering it, and the bank initially appeared to treat the transactions as unauthorised, crediting both amounts back to his account on July 15, 2021. But on August 4, 2021, without new evidence surfacing in the interim, the bank reversed that credit and debited the full ₹9,854 again. That reversal became the crux of the dispute that followed.
Federal Bank’s defence before the commission leaned heavily on the mechanics of UPI itself. Its counsel argued that a UPI transaction requires the account holder to key in a payment address and PIN, details ordinarily known only to the customer, and that an internal enquiry showed the complainant transacted on UPI almost daily. The bank suggested the debits were either made by the customer or by someone he had shared his credentials with, and that consent could therefore be inferred from the credentials alone.
Why the Commission Rejected the Bank’s Defence
The commission was unpersuaded. It held that demonstrating a transaction was completed using a customer’s UPI credentials does not, by itself, establish that the customer authorised or participated in that transaction, particularly when the fraud originated from a deceptive third-party interface designed to imitate a legitimate payment platform. The complainant’s prompt reporting of the fraud, and the bank’s own initial decision to recredit the amount, weighed against the bank’s later claim of negligence.
This approach mirrors the framework the Reserve Bank of India laid down in its 2017 circular on customer protection in unauthorised electronic banking transactions, which places the burden of proof on the bank rather than the customer in most disputed cases, and mandates zero liability for the customer where the fraud stems from a third-party breach reported promptly. Courts and consumer forums across India, including the Allahabad High Court in a 2022 matter, have leaned on the same logic to prevent banks from shifting losses onto customers by default.
The Kerala case is a small one in monetary terms, but it echoes a pattern regulators have flagged repeatedly at the national level. Government data placed before Parliament this year showed UPI-related fraud losses of ₹981 crore in FY 2024-25 and ₹805 crore in the current financial year through November, even as case volumes have begun to moderate from their FY24 peak. Officials attribute much of this to social engineering scams, of which spoofed cashback offers and lookalike scratch cards remain a persistent and low-cost vector for fraudsters targeting UPI users.
