District Consumer Commission Rules ICICI Bank Must Refund 5.18 Lakh To Cyber Fraud Victim

In a landmark ruling that reinforces the responsibilities of financial institutions, the District Consumer Disputes Redressal Commission in Nagpur has directed ICICI Bank to compensate a victim of "digital arrest" cyber fraud. The commission, led by President Satish A. Sapre and Member Milind Kedar, underscored that banks hold an ongoing duty to monitor suspicious transactions and cannot evade liability simply because a customer was coerced into authorizing payments through one-time passwords (OTPs).

The Anatomy of a "Digital Arrest" Fraud

The complainant, Ms. Prachi Digambar Dhoke, was targeted in a sophisticated cyber extortion scheme on January 8, 2023. Callers posing as FedEx representatives claimed an international parcel linked to her contained illicit items, including narcotics. Through intimidation and impersonation of Mumbai Police officials, the fraudsters coerced her into transferring ₹6,93,437.50 into a beneficiary account held within another branch of the same bank. Despite her prompt reporting of the fraud, the bank initially granted only a partial credit of 25% through the Banking Ombudsman, leaving her to pursue the remaining balance of ₹5,18,437 through legal channels.

Beyond the OTP: The Bank's Regulatory Duty

ICICI Bank argued that the complaint was not maintainable as the incident was criminal in nature and the transactions were authenticated by the complainant herself. However, the commission rejected these contentions, distinguishing between the criminal act of the fraudsters and the bank’s failure to adhere to statutory guidelines. The bench noted that the beneficiary account, which was previously inactive, saw an inflow of ₹2.84 crore within 48 hours—a red flag that mandated immediate intervention under the Reserve Bank of India's (RBI) Know Your Customer (KYC) norms.

Commission Dismisses Arguments of Criminal Jurisdiction

The commission clarified that while the underlying cyber fraud is a criminal matter, the bank’s failure to flag highly suspicious transaction patterns constitutes a distinct "deficiency in service." The court emphasized that in the era of digital banking, reliance on OTPs is insufficient if the bank ignores its broader obligation to perform "on-going due diligence" as defined by the RBI's Master Direction on KYC.

Key Observations

The commission’s judgment highlighted the critical role banks play in protecting the digital ecosystem:

  • "The bank cannot remain passive after opening the account; it must keep 'knowing' the customer through patterns of transactions and update risk ratings and KYC when necessary."
  • "Such unusual transaction pattern should have triggered enhanced scrutiny under the RBI’s regulatory framework."
  • "The Opposite Party is guilty of deficiency in service , and that it has also acted negligently and adopted unfair trade practices ."

The Final Verdict: A Step Toward Consumer Accountability

The Nagpur District Consumer Disputes Redressal Commission ruled that ICICI Bank’s failure to prevent the transfer or freeze the account—despite the customer’s immediate report—amounted to negligence. Consequently, the bank was ordered to pay the remaining ₹5,18,437 with 9% interest per annum from the date of the complaint filing. Additionally, the bank must pay ₹25,000 for mental agony and ₹10,000 in litigation costs within 45 days. This decision serves as a significant precedent, placing the onus on banks to integrate advanced monitoring systems to safeguard customers against the evolving threats of digital extortion.