District Consumer Commission Rules Must Refund 5.18 Lakh To Cyber Fraud Victim
In a landmark ruling that reinforces the responsibilities of financial institutions, the has directed to compensate a victim of "digital arrest" cyber fraud. The commission, led by President Satish A. Sapre and Member Milind Kedar, underscored that banks hold an ongoing duty to monitor suspicious transactions and cannot evade liability simply because a customer was coerced into authorizing payments through one-time passwords (OTPs).
The Anatomy of a "Digital Arrest" Fraud
The complainant, Ms. Prachi Digambar Dhoke, was targeted in a sophisticated cyber extortion scheme on . Callers posing as FedEx representatives claimed an international parcel linked to her contained illicit items, including narcotics. Through intimidation and impersonation of officials, the fraudsters coerced her into transferring ₹6,93,437.50 into a beneficiary account held within another branch of the same bank. Despite her prompt reporting of the fraud, the bank initially granted only a partial credit of 25% through the , leaving her to pursue the remaining balance of ₹5,18,437 through legal channels.
Beyond the OTP: The Bank's Regulatory Duty
argued that the complaint was not maintainable as the incident was criminal in nature and the transactions were authenticated by the complainant herself. However, the commission rejected these contentions, distinguishing between the criminal act of the fraudsters and the bank’s failure to adhere to statutory guidelines. The bench noted that the beneficiary account, which was previously inactive, saw an inflow of ₹2.84 crore within 48 hours—a red flag that mandated immediate intervention under the Reserve Bank of India's (RBI) Know Your Customer (KYC) norms.
Commission Dismisses Arguments of Criminal Jurisdiction
The commission clarified that while the underlying cyber fraud is a criminal matter, the bank’s failure to flag highly suspicious transaction patterns constitutes a distinct "." The court emphasized that in the era of digital banking, reliance on OTPs is insufficient if the bank ignores its broader obligation to perform "" as defined by the RBI's Master Direction on KYC.
Key Observations
The commission’s judgment highlighted the critical role banks play in protecting the digital ecosystem:
-
"The bank cannot remain passive after opening the account; it must keep 'knowing' the customer through patterns of transactions and update risk ratings and KYC when necessary."
-
"Such unusual transaction pattern should have triggered enhanced scrutiny under the RBI’s regulatory framework."
-
"The Opposite Party is guilty of , and that it has also acted negligently and adopted ."
The Final Verdict: A Step Toward Consumer Accountability
The Nagpur District Consumer Disputes Redressal Commission ruled that ’s failure to prevent the transfer or freeze the account—despite the customer’s immediate report—amounted to negligence. Consequently, the bank was ordered to pay the remaining ₹5,18,437 with 9% interest per annum from the date of the complaint filing. Additionally, the bank must pay ₹25,000 for mental agony and ₹10,000 in litigation costs within 45 days. This decision serves as a significant precedent, placing the onus on banks to integrate advanced monitoring systems to safeguard customers against the evolving threats of digital extortion.