The Raipur Consumer Commission ordered State Bank of India to refund ₹99,900 lost in cyber fraud, ruling that OTP authentication does not absolve banks from RBI zero-liability rules.

Bank Failed to Refund ₹99,900 After Cyber Fraud Complaint, Consumer Commission Holds SBI Responsible

The420 Web Correspondent
5 Min Read

Reaffirming the statutory rights of bank account holders in an era of escalating cyber fraud, the Raipur District Consumer Disputes Redressal Commission has held the State Bank of India (SBI) responsible for deficiency in service and unfair trade practices. The commission directed India’s largest public sector lender to refund ₹99,900 to a 23-year-old victim of unauthorized online transactions, along with interest, ₹10,000 in compensation for mental agony, and ₹5,000 toward litigation expenses.

The landmark judgment establishes that financial institutions cannot evade legal liability simply by proving that disputed transfers were authenticated via one-time passwords (OTPs) or internet banking systems. When a consumer promptly reports fraudulent debits within statutory timelines, the burden of proof shifts to the financial institution to demonstrate thorough investigation and immediate loss-mitigation efforts.

The Digital Authentication Defense and Its Limits

The case originated on March 30, 2019, when a series of seven fraudulent online transactions drained ₹99,900 from the victim’s savings account without her authorization. Acting swiftly upon receiving transaction SMS alerts, the account holder obtained her account statement and lodged a complaint with the local Cyber Cell on the same day. She subsequently delivered a formal written complaint to SBI on April 2—within three working days of the incident—followed by a legal notice on April 6 demanding a full reversal of the unauthorized debits.

In its defense before the consumer forum, SBI argued that internet banking services were active on the account and that every disputed transaction was successfully authenticated through the registered mobile number via valid OTP mechanisms. The bank contended that the technical completion of the transfers suggested the customer might have compromised her own credentials or shared confidential information with third parties. SBI further maintained that because the funds were successfully processed through secure digital architecture, the bank possessed no mechanism or obligation to reverse the completed transactions.

The consumer commission rejected SBI’s line of reasoning, ruling that technical completion alone does not absolve a lender of its statutory duty toward account security. The bench observed that automated credential checks cannot be weaponized to presume customer fault, particularly in an environment where sophisticated phishing, SIM-swapping, and malware attacks frequently bypass traditional two-factor authentication without direct user involvement.

Institutional Failure and the RBI Zero Liability Mandate

Central to the commission’s July 27 ruling was the Reserve Bank of India’s benchmark circular dated July 6, 2017, titled Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions. The regulatory framework explicitly mandates zero customer liability when unauthorized electronic transactions are reported to the bank within three working days of receiving communication. Under these central guidelines, financial institutions are legally required to initiate a shadow reversal or provisional credit within ten working days, while bearing the absolute burden of proving customer negligence.

The Raipur tribunal highlighted that SBI failed to execute its statutory obligations upon receiving the victim’s timely complaint. Rather than investigating the transaction trail or attempting to place an administrative hold on the recipient accounts to prevent further movement of funds, the bank demonstrated complete operational inertia. Furthermore, SBI failed to present any forensic evidence or internal investigative reports before the commission to substantiate its allegations of customer compromise.

By neglecting to act during the critical post-reporting window, SBI committed a clear deficiency in service. The commission noted that prompt notification by a customer triggers an immediate duty of care, requiring the bank to deploy active fraud containment measures rather than passively relying on automated transaction records.

Broader Implications for Cyber Fraud Accountability in India

The verdict carries profound systemic implications for millions of digital banking consumers across India, where public and private lenders routinely reject fraud claims by citing successful OTP delivery. By enforcing the RBI’s zero-liability mandate, the consumer commission has reinforced that electronic payment security is an ongoing operational commitment rather than a static technical defense.

The ruling serves as a vital reminder that banking institutions must modernize their fraud response infrastructure, moving beyond post-facto denial toward real-time transaction monitoring and swift interbank coordination. As digital financial inclusion expands across India, judicial decisions holding state-owned and private lenders strictly accountable for post-reporting negligence remain essential to maintaining public trust in the national digital payments ecosystem.

Stay Connected