Representative image of online banking fraud: Tamil Nadu consumer commission directs a bank to pay ₹1.10 lakh to a woman who lost ₹50,000 in a phishing scam.

Tamil Nadu Woman Lost ₹50,000 in Phishing Scam

The420.in Staff
5 Min Read

New Delhi: A Tamil Nadu woman who lost ₹50,000 in an alleged phishing scam has received relief from a consumer commission, which has directed the bank to pay her a total of ₹1.10 lakh. The Thanjavur District Consumer Disputes Redressal Commission ordered the bank to refund the ₹50,000 lost in the fraudulent transaction, pay another ₹50,000 as compensation for mental distress and deficiency in service, and ₹10,000 towards litigation expenses.

The order was passed on July 28 by commission president T Sekar and member K Velumani. The commission observed that the woman had immediately informed the bank after discovering the unauthorised transaction. However, the bank failed to produce documents showing what effective steps it had taken after receiving the complaint to secure the funds or prevent further loss. The commission held that this amounted to deficiency in service under the Consumer Protection Act, 2019.

The incident began with an alleged phishing message. The woman received an SMS offering a reward of ₹12,980. After clicking the link provided in the message, she allegedly entered her banking credentials. She subsequently received an OTP message. Shortly afterwards, she discovered that ₹50,000 had been debited from her bank account through the addition of an unauthorised beneficiary.

FCRF Launches Flagship Certified Cyber Security Auditor (CCSA) Program for Next-Generation Cyber Auditors

According to her complaint, she immediately contacted the bank’s customer care after noticing the unauthorised transaction and lodged an online complaint. She also approached the cybercrime authorities and reported the incident. She subsequently moved the district consumer commission, seeking a refund of the amount lost along with compensation of ₹1 lakh.

The bank contested the complaint, arguing that the transaction had been completed only because the customer herself entered her username, password and OTP after clicking on the phishing link. The bank maintained that it had followed security procedures prescribed by the Reserve Bank of India and argued that the loss resulted from the customer’s own negligence.

The commission, however, did not fully accept the bank’s defence. It observed that even if the customer had inadvertently disclosed her banking credentials after falling victim to a sophisticated phishing attack, that fact alone could not absolve the bank of its independent responsibility. The commission particularly emphasised that the woman had promptly informed the bank after discovering the unauthorised transaction.

The consumer body said a bank cannot escape accountability merely because a customer entered or disclosed credentials at some stage of a fraudulent transaction. Financial institutions are expected to take appropriate and timely action once an unauthorised electronic transaction is reported. According to the commission, remaining passive after receiving an immediate complaint can attract responsibility on the part of the bank.

FCRF Launches Flagship Certified Cyber Security Auditor (CCSA) Program for Next-Generation Cyber Auditors

The commission also noted that the woman had suffered financial hardship, mental agony and unnecessary inconvenience as a result of the incident and the bank’s failure to act adequately after being informed. It therefore allowed her complaint and directed the bank to refund the ₹50,000, pay ₹50,000 as compensation and provide ₹10,000 towards litigation expenses.

The ruling carries an important message for victims of cyber fraud. Banks cannot automatically be held responsible for every fraudulent transaction, particularly where customers themselves disclose sensitive credentials. However, the commission made clear that banks are expected to respond appropriately once an unauthorised transaction is reported without delay.

The case also highlights the importance of immediate reporting in cyber fraud incidents. Customers who notice suspicious transactions should promptly inform their bank, report the matter to cybercrime authorities and preserve relevant messages, transaction details and other digital evidence. Early reporting can improve the chances of tracing or freezing the funds and can also establish that the customer acted promptly after discovering the fraud.

Stay Connected