In a significant landmark court order under India’s Information Technology Act, 2000, the Maharashtra Government’s Adjudicating Officer (civil court for cyber matters) has held Bank of India and Idea Cellular Limited (now Vodafone Idea Limited) liable for failures in the electronic authentication chain that contributed to a major unauthorised banking fraud.
The order, passed by the Secretary, Electronics, Information Technology & Artificial Intelligence Department, Government of Maharashtra, arises from a cyber-fraud complaint filed by M/s G.D. Apte & Co., a Pune-based professional firm.
The case concerned unauthorised electronic fund transfers aggregating to ₹85.53 lakh from the firm’s Current and Overdraft Accounts. The complaint alleged failures in banking security controls as well as the unauthorised issuance of a duplicate SIM connected to the firm’s banking authentication mechanism.
The complainant was represented by Cyber Law Expert Lawyer Advocate (Dr.) Prashant Mali.
The cyber-fraud began with a SIM going dead
The sequence of events is striking.
On 10 March 2015, the mobile number registered with the bank for SMS alerts and OTPs suddenly stopped functioning. The complainant says it immediately contacted the telecom operator and informed it that no request had been made to disconnect the number and that the SIM had not been lost.
Despite this warning, a duplicate SIM was subsequently issued.
The following day, the complainant discovered an unauthorised RTGS transaction of ₹6.60 lakh. Further examination revealed another 12 RTGS transactions aggregating ₹78.93 lakh from its Overdraft Account.
The total disputed transactions therefore amounted to ₹85.53 lakh.
The case became particularly significant because the firm’s internet banking system had not been left without security controls.
It had a specific maker-checker architecture. Transactions were supposed to be initiated by a lower-level user and authorised by any two of three higher-level users.
There was also a stipulated transaction limit.
Yet the disputed transactions went through.
The bank’s defence: the transactions were authenticated
Bank of India argued that the transactions had been processed using valid internet-banking credentials, transaction passwords, the maker-checker mechanism and OTP authentication.
The bank also suggested that the customers’ credentials may have been compromised or disclosed.
But the Adjudicating Officer looked beyond the mere fact that credentials and OTPs appeared to have been used.
That distinction is critical.
The question was not simply “Was the transaction authenticated?”
The more important question was:
“Was the transaction authenticated in accordance with the security architecture agreed between the bank and its customer?”
The Authority found that the prescribed H2 + 2H1 authorisation workflow was not established as having been followed.
More importantly, transactions aggregating ₹78.93 lakh were permitted from the Overdraft Account despite the material on record indicating a prescribed cumulative transaction limit of ₹50 lakh per month.
The order therefore rejected the idea that simply passing through a technological authentication mechanism automatically absolves the institution operating that mechanism.
The SIM replacement became the second link in the chain
The telecom side of the case was equally important.
The Authority found that the duplicate SIM request and accompanying documents were not adequately cross-verified before the replacement was issued.
This was not treated as an isolated telecom-service failure.
The registered mobile number was part of the authentication mechanism used for the firm’s banking facility.
The Authority therefore found that the telecom operator’s failure to properly verify the person seeking the duplicate SIM contributed materially to the compromise of the authentication chain.
The order makes an important distinction: the telecom operator did not itself conduct the fraudulent banking transactions. Its liability was therefore characterised as contributory and distinct, while the bank carried the primary financial liability.
Advocate Prashant Mali: “Authentication cannot become a shield for negligence”
Advocate Dr. Prashant Mali, who represented the complainant, says the significance of the order goes far beyond the individual amount recovered.
“This case establishes a fundamental principle of digital banking: authentication cannot become a shield for negligence. A transaction is not secure merely because a password, OTP or login credential appears in the system logs. The institution must also demonstrate that the transaction complied with the security architecture, authorisation hierarchy and transaction limits agreed with the customer.”
According to Mali, the case also demonstrates why cyber-fraud investigations cannot be confined to the bank’s internal systems.
“Modern cyber fraud rarely respects institutional boundaries. The criminal may exploit one weakness in telecom, another in banking and another in human or credential security. The law must therefore examine the entire authentication chain rather than looking at each technology in isolation.”
That principle is particularly relevant today, when OTPs, SIMs, device binding, passwords, biometrics and behavioural authentication operate as interconnected components of a single digital identity ecosystem.
Section 43A becomes the centrepiece
The Authority ultimately held that the acts and omissions of the bank and telecom operator constituted a failure to maintain reasonable security practices and procedures, attracting liability under Section 43A of the Information Technology Act, 2000.
The finding is significant because Section 43A is often discussed primarily in the context of data-security failures.
This order demonstrates the importance of examining reasonable security practices as an operational obligation, particularly where digital authentication mechanisms are being used to protect financial transactions.
The Authority found that the failures of the two respondents occurred at different points but had an interconnected effect: the duplicate SIM compromised control over the registered mobile authentication channel, while the bank failed to enforce the agreed maker-checker and transaction-limit controls.
₹64.44 lakh against the bank and ₹5 lakh against the telecom operator
The final order directs Bank of India to pay ₹64,44,123, representing the principal loss established in the proceedings, along with 12% annual interest from the date of contravention until actual payment.
The telecom operator, Idea Cellular Limited, now Vodafone Idea Limited, was directed to pay ₹5 lakh as compensation for the security lapse relating to verification and issuance of the duplicate SIM.
Both amounts were directed to be paid within 30 days of the order.
The bigger lesson for India’s digital economy
For banks, the message is straightforward: having security controls on paper is not enough. They must actually be enforced.
For telecom operators, SIM replacement is no longer merely a customer-service function. Where the mobile number is linked to banking, financial services or other high-value authentication mechanisms, the integrity of the SIM-replacement process becomes part of the wider digital-security ecosystem.
For corporates, the lesson is equally important.
A company cannot simply assume that because its bank uses OTPs, passwords and maker-checker systems, its money is automatically protected.
Corporate customers should periodically verify:
- who has internet-banking access;
- what transaction limits have been configured;
- whether maker-checker controls are actually enforced;
- whether dormant or unnecessary users have been removed;
- which mobile numbers and email addresses are linked to authentication;
- how SIM replacement is controlled;
whether unusual transaction velocity triggers alerts; and - how quickly the bank will respond when a compromise is reported.
As Mali puts it: “Cybersecurity liability is moving from the era of ‘Did you have a security system?’ to the much harder question—‘Did your security system actually enforce the safeguards you promised to your customer?’ That is where the real accountability of banks and digital-service providers will increasingly lie.”
The case also offers a warning for the emerging digital economy: security is only as strong as the weakest institution participating in the authentication chain.
A bank may have sophisticated fraud controls. A telecom operator may have robust network security. A company may have strict internal policies.
But if the authentication chain breaks at any one critical point, the criminal does not need to defeat every layer.
The criminal only needs to defeat one.
And this order demonstrates that where institutional security failures materially contribute to that breach, the question of liability can follow the chain.
Follow the Centre for Police Technology on LinkedIn to stay updated on the latest developments in policing, cybersecurity, digital forensics, investigations, fraud risk management, and technology-driven public safety.
Centre for Police Technology on LinkedIn
About the author — Ananya Aradhya writes on cybercrime, fraud, scams, cybersecurity, digital safety, and emerging threats. Her work also covers major criminal cases, financial frauds, consumer scams, and stories that highlight risks affecting people in the real and digital world.