Case Note & Summary
The petitioners, a director and a closely held family company, maintained a bank account with Respondent No. 2 for 15-20 years. On 1 October 2022, unknown persons added beneficiaries without any OTP being sent to the petitioners. On 2 October 2022, the accountant informed the petitioners that Rs. 76,90,017/- was debited in several tranches. The petitioners immediately informed the Cyber Cell and the bank manager. On 3 October 2022, they lodged an FIR under Section 379 IPC and Sections 43A and 66 of the IT Act. Despite repeated follow-ups, the bank did not refund the amount. The petitioners filed a complaint with the Banking Ombudsman, which was rejected on 10 January 2023 on the ground that the transactions were completed with valid credentials. The High Court, under Article 226, examined the RBI Circular dated 6 July 2017 on customer protection. The court found that the bank failed to provide evidence of OTP or proper authentication, and the addition of beneficiaries without OTP indicated a deficiency in service. The court quashed the Ombudsman's order and directed the bank to refund the amount with interest at the rate applicable to the savings account from the date of the transactions until payment, within four weeks.
Headnote
A) Banking Law - Cyber Fraud - Unauthorized Electronic Transactions - Deficiency in Service - RBI Circular dated 6 July 2017 - The petitioners' bank account was fraudulently accessed and Rs. 76,90,017/- was transferred without OTP. The Banking Ombudsman rejected the complaint holding no deficiency. The High Court set aside the order, finding that the bank failed to ensure proper authentication and that the transactions were unauthorized. Held that the bank is liable to refund the amount under the RBI Circular (Paras 1-30).
B) Banking Law - Customer Protection - Limiting Liability - RBI Circular dated 6 July 2017 - The Circular provides that in case of unauthorized electronic transactions, the customer's liability is limited if the loss is due to negligence by the bank. The court found that the bank did not provide evidence of OTP or proper authentication, and thus the petitioners were not liable. Held that the bank must refund the amount with interest (Paras 11-30).
C) Banking Law - Banking Ombudsman - Scheme, 2021 - The Ombudsman's order was quashed as it failed to consider the RBI Circular and the bank's failure to secure the account. The court directed the bank to refund the amount within four weeks (Paras 17-30).
Issue of Consideration
Whether the Banking Ombudsman's rejection of the complaint alleging deficiency in service by the bank in unauthorized electronic transactions was correct, and whether the bank is liable to refund the amount under the RBI Circular dated 6 July 2017.
Final Decision
The High Court allowed the writ petition, quashed the Banking Ombudsman's order dated 10 January 2023, and directed Respondent No. 2 to refund the amount of Rs. 76,90,017/- to the petitioners' bank account with interest at the rate applicable to the savings account from the date of the transactions until payment, within four weeks.
Law Points
- Cyber fraud
- unauthorized electronic banking transactions
- deficiency in service
- RBI Circular dated 6 July 2017
- customer protection
- limiting liability
- Banking Ombudsman
- Article 226 of the Constitution of India
- Information Technology Act
- 2000
- Indian Penal Code
- 1860
Case Details
2024 Lawtext (BOM) (6) 136
WRIT PETITION NO.1150 OF 2023
Mr. Siddhesh Bhole a/w. Yakshay Chheda, Ms. Anushree Koparkar i/b. SSB Legal & Advisory for the Petitioners. Ms. Aditi Pathak a/w. Parag Sharma, Mr. Vijay Salokhe, Ms. Kirti Ojha. Ms. Megha More i/b. BLAC & Co. for Respondent Nos.1 and 3. Ms. Anvita Ail a/w. Mr. Naresh H. Manghnani for Respondent No.2. Mr. Mohit Jadhav, Addl. G. P. for the State.
The Banking Ombudsman Ors.
Subscribe to unlock Case Details (Citation, Judge, Date & more)
Subscribe Now
Nature of Litigation
Writ Petition under Article 226 of the Constitution of India challenging the order of the Banking Ombudsman and seeking refund of amount lost in unauthorized electronic transactions.
Remedy Sought
The petitioners sought a writ of certiorari to quash the Ombudsman's order and a writ of mandamus directing the bank to refund Rs. 76,90,017/- with interest and compensation under the RBI Circular dated 6 July 2017.
Filing Reason
The petitioners' bank account was fraudulently accessed and Rs. 76,90,017/- was transferred without OTP. The bank refused to refund the amount, and the Banking Ombudsman rejected the complaint.
Previous Decisions
The Banking Ombudsman rejected the complaint on 10 January 2023, holding that there was no deficiency in service as the transactions were completed with valid credentials.
Issues
Whether the Banking Ombudsman's order rejecting the complaint was correct.
Whether the bank is liable to refund the amount under the RBI Circular dated 6 July 2017.
Submissions/Arguments
The petitioners argued that the beneficiaries were added without OTP, and the bank failed to secure the account, constituting deficiency in service.
The bank contended that the transactions were authorized as valid credentials were used.
Ratio Decidendi
The court held that the bank failed to provide evidence of OTP or proper authentication for the addition of beneficiaries and the transactions. The RBI Circular dated 6 July 2017 places the burden on the bank to prove that the customer was negligent. Since the bank did not discharge this burden, the petitioners were not liable, and the bank must refund the amount.
Judgment Excerpts
This Petition deals with a Cyber Fraud and is an example of how increasingly the innocent persons are becoming victims of Cyber Fraud.
The Petitioners had maintained a bank account ... with Respondent No.2 for the previous 15 to 20 years.
On 1st October 2022, certain entities/ individuals were added as beneficiaries to the said bank account without any OTP being sent to the Petitioners.
The Petitioners, within a period of 30 minutes to 1 hour of the aforesaid illegal transactions, informed the Cyber Cell at Worli Police Station, Mumbai and the Bank Manager of Respondent No.2.
The said complaint filed by the Petitioners before Respondent No.1 was rejected by Respondent No.1 by an Order dated 10th January 2023 on the ground that the transactions were completed post addition of the beneficiaries and input of valid credentials/2FA known only to the account holder.
Procedural History
The petitioners filed a complaint with the Banking Ombudsman on 12 October 2022, which was rejected on 10 January 2023. The petitioners then filed the present writ petition under Article 226 of the Constitution of India. The High Court passed an order on 26 April 2023 requiring further information, and subsequently heard the matter and delivered the final judgment.
Acts & Sections
- Indian Penal Code, 1860: 379
- Information Technology Act, 2000: 43A, 66
- Constitution of India: 226