The Telecom Disputes Settlement and Appellate Tribunal (TDSAT) has directed ICICI Bank to pay ₹7,81,772 to a Merchant Navy seafarer after 98 unauthorised online transactions siphoned ₹12.85 lakh from his account, holding that the bank’s failure to send mandatory SMS and email alerts amounted to a lapse in reasonable security practices.
The order was passed on August 4, 2026, in Cyber Appeal No. 10 of 2020 by Justice Ram Krishna Gautam, Member, TDSAT. The tribunal also awarded 7% simple interest on the amount from the date of the complaint until payment, besides ₹50,000 towards damages for mental agony, harassment and litigation. The bank has been directed to make the payment within two months of the judgment.
98 Unauthorised Transactions Drained ₹12.85 Lakh
The dispute arose from transactions carried out in 2015 while Manvir Singh, an Indian national working as a seafarer in the Merchant Navy, was on duty in deep waters. According to the case material, he had no terrestrial network coverage between July and October that year. During this period, 98 unauthorised online transactions were carried out from his bank account, involving a total of ₹12,85,381.67.
Singh’s case was that he had neither disclosed his CVV and debit card credentials nor shared his 3D-Secure PIN. ICICI Bank, however, disputed its liability and maintained that the transactions had undergone second-level authentication through the customer’s 3D-Secure PIN.
After Singh raised the complaint, several transactions were reversed or amounts were credited back. Of the total amount siphoned from the account, ₹5,03,609.95 was eventually returned, leaving ₹7,81,771.72 outstanding. The tribunal ultimately directed the bank to pay ₹7,81,772.
Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions
Failure to Send Transaction Alerts Becomes Key Issue
A central issue before TDSAT was whether ICICI Bank had complied with regulatory requirements concerning SMS and email alerts for online transactions. The tribunal noted that Singh’s mobile number and email address had been registered with the bank, despite the bank’s position that he was not registered for SMS alert facilities.
The tribunal found that the failure to send transaction alerts for the fraudulent transactions amounted to negligence and a failure of the due and expected security practices imposed on the bank through RBI directions. It held that RBI circulars and instructions concerning electronic banking and customer transaction alerts were mandatory, and that real-time SMS and email alerts formed part of the bank’s baseline obligations.
The issue was particularly significant because Singh was at sea and would have been unable to monitor his account through ordinary terrestrial communication. The tribunal also considered the rapid succession of 98 transactions and the bank’s responsibility to maintain reasonable security practices in such circumstances.
ISO Certification and Criminal Investigation did not Absolve Bank
ICICI Bank had also relied on its ISO/IEC 27001 certification as evidence that it maintained reasonable security practices. TDSAT, however, held that production of such a certificate could not by itself defeat a claim under Section 43A of the Information Technology Act where specific security failures and non-compliance with applicable directions were established.
The tribunal separately considered the absence of any criminal finding against bank officials. It distinguished criminal culpability from the question of the bank’s statutory and regulatory obligations, holding that the absence of criminal liability did not automatically establish compliance with its duties in a compensation proceeding.
Singh had initially approached the Adjudicating Officer under Sections 43 and 43A of the Information Technology Act. His complaint was dismissed on February 7, 2020, prompting Cyber Appeal No. 10 of 2020 before TDSAT. The tribunal ultimately set aside that dismissal and granted relief after years of appellate proceedings. Singh was represented by Karnika A. Seth, Gurneev Singh and Garvit Mathur, while ICICI Bank was represented by Anand Shankar Jha and Nandika Kaushik.
Click here to Read the Judgment
Follow the Centre for Police Technology on LinkedIn to stay updated on the latest developments in policing, cybersecurity, digital forensics, investigations, fraud risk management, and technology-driven public safety.
https://www.linkedin.com/company/policetechnology/