Bank Held Accountable in Cyber Fraud Case: In a significant ruling on online banking fraud, a District Consumer Disputes Redressal Commission in Punjab has directed the State Bank of India (SBI) to refund ₹1.64 lakh that was fraudulently withdrawn from a customer’s bank account through an unauthorized online transaction. The Commission held that rejecting the customer’s complaint without conducting a fair and transparent investigation amounted to a deficiency in service. It also ordered the bank to pay ₹15,000 as compensation for mental harassment and ₹10,000 towards litigation expenses.
In its July 28 order, the bench comprising President Charanjit Singh and members Nidhi Verma and V.P.S. Saini observed that SBI had failed to establish any negligence on the part of the customer in relation to the disputed transaction. Consequently, the Commission ruled that the rejection of the customer’s claim was legally unsustainable.
According to the complaint, ₹1.64 lakh was transferred from the complainant’s savings account without his knowledge or consent. The customer stated that he had never shared his ATM PIN, OTP, internet banking password, or any other confidential banking credentials with anyone. Immediately after discovering the unauthorized transaction, he reported the incident to the SBI helpline, the National Cyber Crime Reporting Portal, the concerned bank branch, and the police.
The complainant argued that despite promptly reporting the fraud, SBI rejected his claim without conducting a proper investigation or providing him with any inquiry report. He also relied on the Reserve Bank of India’s July 6, 2017 circular on “Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions,” which provides for limited or zero customer liability in cases of third-party fraud reported without delay.
SBI, however, contended before the Commission that the transaction could not have been completed without entering the customer’s username, password, and the OTP sent to his registered mobile number. The bank argued that the complainant must have knowingly or unknowingly shared his credentials with fraudsters and was therefore responsible for the transaction.
The Commission rejected this argument, noting that SBI failed to produce any technical investigation report, server logs, IP address details, forensic analysis, or any electronic evidence proving that the customer had voluntarily authenticated the disputed transaction. It emphasized that under the RBI guidelines, the burden of proving customer negligence rests with the bank if it seeks to deny protection against unauthorized electronic transactions.
The Commission further observed that the bank had rejected the complaint purely on assumptions without placing any fair, independent, and reasoned inquiry report on record. It stated that once a customer promptly reports an unauthorized electronic transaction, the bank is obligated to conduct a transparent, comprehensive, and evidence-based investigation in accordance with RBI guidelines. Failure to do so constitutes a deficiency in service.
Renowned cybercrime expert and former IPS officer Professor Triveni Singh said that the first few hours after a digital banking fraud are crucial. If a customer reports the incident promptly, banks and investigating agencies should preserve technical evidence and conduct an impartial investigation. He added that customers should not be blamed based on assumptions alone and that banks must strictly comply with the RBI’s customer protection guidelines.
Allowing the complaint, the Consumer Commission directed SBI to refund the disputed amount of ₹1.64 lakh, pay ₹15,000 as compensation for mental harassment, and ₹10,000 towards litigation expenses. The ruling is being viewed as an important precedent reinforcing customer rights and strengthening the accountability of banks in cases involving unauthorized online banking transactions.
