Case Note & Summary
The petitioner, a freelancer in business consultancy, maintained savings and current accounts with HDFC Bank since 2011 and 2016 respectively. On 14 July 2021, three unknown individuals were added as beneficiaries to his account and the net banking transaction limit was enhanced from Rs. 4,00,000 to Rs. 40,00,000 without any OTP being received by him. Despite internal security alerts flagging the additions as suspicious and recommending decline, the bank manually approved the changes. The following day, on 15 July 2021, eight unauthorized transfers totaling Rs. 38,04,000 were executed within 41 minutes to the newly added beneficiaries. The petitioner received an SMS alert for only one small transfer nearly two hours after the last transaction. He immediately contacted the bank, blocked the account, and filed an FIR. The bank denied liability, asserting the transactions were authenticated through valid credentials and OTPs, and accused the petitioner of breaching confidential information. The petitioner's subsequent grievance to the RBI Ombudsman was rejected. He then filed the present writ petition under Article 226 seeking a mandamus to direct RBI to take action against HDFC Bank and ICICI Bank for violating various RBI guidelines and master directions, a certiorari to quash the Ombudsman's rejection, and a direction for refund of the amount. The petition also sought action against BSNL for violating DoT instructions. After hearing all parties, the High Court issued Rule nisi and made it returnable forthwith, admitting the petition for final hearing.
Issue of Consideration
Whether the respondent banks violated RBI guidelines on internet banking and whether the petitioner is entitled to refund of the fraudulently transferred amount and other consequential reliefs.
Final Decision
By consent of parties, the court took up the petition for hearing at the stage of admission and issued 'Rule', making it returnable forthwith. The final adjudication on the reliefs prayed for was not recorded in the available excerpt.
Law Points
- RBI's I-Banking Guidelines dated 14.06.2001
- RBI Notification dated 06.07.2017
- RBI Master Directions dated 18.02.2021
- RBI Guidelines dated 29.04.2011
- RBI Master Circular dated 01.07.2008
- DoT Instruction dated 01.08.2016
- Article 226 of the Constitution of India
- writ of mandamus
- writ of certiorari
Case Details
2026 LawText (BOM) (04) 19
Writ Petition No. 11990 of 2023
Bharati Dangre, Manjusha Deshpande
Mr. Sharan Jagtiani, Senior Advocate with Mr. Priyank Kapadia, Ms. Sapna Pande for Petitioner; Mr. Prateek Seksaria, Senior Advocate with Mr. Ishwar Nankani, Mr. Huzefa Khokhawala, Mr. Karan Parmar, Mr. Kartik Gupta for Respondent No. 3; Mr. Mayur Khandeparkar with Mr. Mayur Bhojwani, Mr. Ulrik Jehangir, Ms. Dhamini Nagpal for Respondent No. 4; Adv. Prasad Shenoy with Ms. Aditi Phatak, Ms. P. Zaiwalla for Respondent Nos. 2 and 7; Mr. Ashutosh Mishra with Mr. Vinit Jain, Mr. Ashok R. Varma, Mr. Gaurav Mhatre for Respondent No. 1 – UOI; Mr. M.M. Pable, A.G.P. for the State/Respondent; Adv. Aparna Shrivastava for Respondent No. 5
Union of India (through Ministry of Finance and Ministry of Communications), Reserve Bank of India (through Governor), Managing Director, HDFC Bank Ltd, Managing Director, ICICI Bank Ltd, Bharat Sanchar Nigam Ltd, State of Maharashtra (through Wakad Police Station, Pune)
Subscribe to unlock Case Details (Citation, Judge, Date & more)
Subscribe Now
Nature of Litigation
Writ Petition under Article 226 of the Constitution of India alleging cyber fraud and seeking enforcement of RBI guidelines and refund of fraudulently transferred amount.
Remedy Sought
As per prayer clauses: (a) writ of mandamus to direct RBI to initiate action against HDFC Bank and ICICI Bank for violation of RBI Guidelines; (a-i) writ of certiorari to quash the Ombudsman's rejection order dated 28.03.2022; (a-2) direction to banks to refund the fraudulently transferred amount and provide KYC documents to investigating agency; (b) direction to Union of India to take action against BSNL for violating DoT Instruction; (c) direction to RBI to appoint an independent IS Auditor for HDFC Bank; (d) direction to RBI to initiate action against banks for non-compliance with Master Circular dated 01.07.2008.
Filing Reason
Petitioner's money was unauthorizedly transferred from his HDFC Bank accounts and the bank refused to reverse the transaction, alleging petitioner's breach of confidential information; the RBI Ombudsman also rejected his complaint.
Previous Decisions
The complaint bearing no. N202122021018946 filed by the petitioner before the RBI Ombudsman was rejected on 28 March 2022 (as per Exhibit L).
Issues
Whether the petitioner's money was unauthorizedly withdrawn due to security lapses by HDFC Bank?
Whether HDFC Bank violated RBI's I-Banking Guidelines, Master Directions, and Circulars by manually approving suspicious beneficiary additions and enhancing transaction limits without adequate authentication?
Whether ICICI Bank failed to prevent withdrawals from the fraudsters' accounts despite timely intimation?
Whether the RBI Ombudsman's rejection of the petitioner's complaint was justified?
Whether BSNL violated DoT instructions dated 01.08.2016?
Whether the petitioner is entitled to a refund of Rs. 38,04,000/- from the banks?
Submissions/Arguments
Petitioner contended that no OTP was received for addition of beneficiaries or enhancement of transaction limit, and the bank's security system itself flagged the additions as suspicious but they were manually approved.
Petitioner argued that the bank's denial of liability was in breach of RBI's liability norms for unauthorized electronic banking transactions.
Respondent No.3 (HDFC Bank) denied liability, stating that the transactions were effected using valid NetBanking credentials and OTPs sent to the petitioner's registered mobile number/email, and thus there was no deficiency in service; it alleged breach of confidential information at the petitioner's end.
Judgment Excerpts
The Petitioner, a freelancer in Business Consultancy, has approached this Court stating that he is a victim of Cyber fraud and a sum of Rs. 38,04,000/- was unauthorizedly withdrawn from his two bank accounts maintained with HDFC Bank Ltd., in a time gap of 41 minutes.
Although the security system of the HDFC Bank flagged and alerted, the addition of these beneficiaries and the alert recommended ‘Decline add payee’ and also alerted “Transaction IP does not match with genuine transaction IP of customer” the addition of beneficiaries was manually approved by the Bank.
On 28/07/2021, the HDFC Bank addressed an email to the Petitioner denying its liability and alleging breach of confidential information at the Petitioner’s end.
we deem it appropriate to issue ‘Rule’, which is made returnable forthwith.
Procedural History
On 14.07.2021, three unknown beneficiaries were added to petitioner's HDFC Bank account and the net banking transaction limit was enhanced from Rs. 4 lakh to Rs. 40 lakh without his knowledge. On 15.07.2021, eight unauthorized transfers totaling Rs. 38,04,000 were executed from his account to the newly added beneficiaries within 41 minutes. Petitioner filed an FIR with Wakad Police Station. On 28.07.2021, HDFC Bank denied liability via email. Petitioner pursued internal grievance redressal and filed a complaint (No. N202122021018946) with the RBI Ombudsman, which was rejected on 28.03.2022. Thereafter, he filed the present Writ Petition No. 11990 of 2023 before the Bombay High Court. The court heard the parties and issued Rule nisi.
Acts & Sections
- Constitution of India: Article 226
- Reserve Bank of India (RBI) Guidelines: I-Banking Guidelines dated 14.06.2001, Notification dated 06.07.2017, Master Directions dated 18.02.2021, Guidelines dated 29.04.2011, Master Circular dated 01.07.2008
- Department of Telecommunications (DoT) Instructions: Instruction dated 01.08.2016 bearing File no. 800-09/2010-VAS (part)