Mumbai: A duplicate SIM, alleged lapses in banking security and 13 unauthorised RTGS transactions have resulted in accountability being fixed on a bank and a telecom company in a nearly 11-year-old cyber fraud case.
An adjudicating authority under the Information Technology Act, 2000, has directed Bank of India to pay Pune-based audit firm G D Apte & Co ₹64.44 lakh in compensation along with 12% annual interest. With interest, the amount is expected to be around ₹1.5 crore.
The authority has also ordered former Idea Cellular Ltd, now known as Vodafone Idea Ltd, to pay ₹5 lakh for issuing a duplicate SIM linked to the firm’s internet banking facility without adequate verification. Both payments have to be made within 30 days. The authority held the bank primarily liable, while the telecom company’s role was treated as contributory negligence.
13 Unauthorised RTGS Transactions Exposed the Fraud
The case dates back to March 11, 2015, when 13 allegedly unauthorised RTGS transactions were carried out from the firm’s current and overdraft accounts at Bank of India’s Jangli Maharaj Road branch in Pune. One transaction worth ₹6.6 lakh was made from the current account, while 12 transactions totalling ₹78.93 lakh were made from the overdraft account.
Around ₹14 lakh was recovered after the fraud came to light. The firm alleged that the transactions were carried out without its authorisation and that the bank’s security controls failed to operate as required.
According to the firm, its registered mobile number stopped functioning on March 10, 2015. A duplicate SIM was subsequently issued without its authorisation. The same number was registered to receive banking alerts and one-time passwords, or OTPs.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Maker-Checker System and Transaction Limit Under Scrutiny
The adjudicating authority raised significant questions over the bank’s internal security controls. Under the firm’s banking arrangement, transactions had to be initiated by a lower-level user and finally approved by at least two of three senior authorised users.
The accounts also had a cumulative monthly RTGS limit of ₹50 lakh. Despite this, 12 transactions totalling ₹78.93 lakh were processed from the overdraft account. The authority said the available records did not establish that the transactions had been authorised through the prescribed Maker-Checker process.
Bank of India also failed to satisfactorily explain how transactions exceeding the stipulated limit were permitted. On this basis, the bank was held primarily responsible for the loss.
Serious Lapse in Issuing Duplicate SIM
The authority also examined the role of Idea Cellular. It found that the telecom company had failed to adequately verify the applicant’s authorisation, identity details, company letterhead and stamp before issuing the duplicate SIM.
However, the telecom operator was assigned limited liability compared with the bank because it did not directly initiate or process the banking transactions. Its lapse in the SIM issuance process nevertheless weakened the authentication channel linked to the firm’s bank account.
Bank and Telecom Company Denied Liability
Bank of India denied any negligence on its part. Idea Cellular, meanwhile, said that an individual had presented himself as the firm’s authorised representative and submitted documents that appeared valid on the face of it. The company maintained that the duplicate SIM was issued on the basis of those documents.
The authority, however, found the verification process inadequate. The order also treated the prescribed multi-level approval system and transaction limits as important safeguards in banking operations.
Expert Says One Weak Link Can Put the Entire System at Risk
Renowned cyber crime expert and former IPS officer Prof. Triveni Singh said the case demonstrates that cyber security does not depend only on a bank’s servers or passwords. The mobile number, SIM issuance process and customer identity verification are equally important parts of the security chain. If verification fails at one level while internal banking controls are also not enforced effectively, criminals can find it easier to gain access to accounts and facilitate unauthorised transactions.
Accountability Fixed After Nearly 11 Years
The case highlights how cyber fraud could exploit mobile connectivity and banking authentication mechanisms, particularly when criminals gained control of a registered mobile number and accessed banking alerts and OTPs. If safeguards such as Maker-Checker authorisation and transaction limits are not effectively enforced, large sums can potentially be transferred without the account holder’s approval.
The ruling has fixed responsibility on the bank and telecom company at different levels. Bank of India was held primarily liable for failing to enforce its authorisation process and transaction controls, while the telecom company’s failure to conduct adequate verification before issuing the duplicate SIM was treated as contributory negligence.
The 30-day deadline for payment now gives effect to the accountability determined in the long-running cyber fraud case.
Follow the Centre for Police Technology on LinkedIn to stay updated on the latest developments in policing, cybersecurity, digital forensics, investigations, fraud risk management, and technology-driven public safety.
https://www.linkedin.com/company/policetechnology/