SupremeToday Landscape Ad
Back
Next
Judicial Analysis Court Copy Headnote Facts Arguments Court observation
Listen Audio Icon Pause Audio Icon
judgment-img

2026 Supreme(Online)(NCDRC) 343

NATIONAL CONSUMER DISPUTES REDRESSAL COMMISSION
J. Rajendra, Presiding Member, Anoop Kumar Mendiratta, Member
State Bank Of India – Appellant
Versus
Prodosh Kumar Banerjee – Respondent
SECOND APPEAL NO. 540 OF 2025



Advocates:
For the Appellants/Petitioners: Vipin Jai
For the Respondents: In person

A bank is liable for unauthorized electronic transactions involving third-party breaches if a customer reports the incident within three working days, unless the bank can cogently establish customer negligence in sharing sensitive credentials like OTPs.

Headnote:(A) RBI Circular dated 06.07.2017 - Customer protection in unauthorized electronic banking transactions - Liability - Where a fraudulent transaction is due to a third-party breach and is reported within three working days, the customer's liability is zero - Banks cannot absolve themselves of liability based on perceived negligence without cogent proof of the customer sharing sensitive credentials. (Paras 8 and 9)

(B) Appellate Jurisdiction - Consumer dispute - A customer cannot be held liable for unauthorized withdrawals simply because they downloaded an application where no OTP was received or shared for the specific fraudulent transactions, provided the incident was notified to the bank promptly. (Paras 6, 7 and 9)

Facts of the case:
The complainant received a fraudulent call regarding a pending electricity bill, leading them to download an application. Subsequently, an unauthorized amount of Rs.25,000/- and Rs.1,99,000/- was debited from the bank account without the complainant receiving or sharing any OTPs. The complainant reported the incident to the police and the bank immediately, and though the Rs.25,000/- was reversed, the bank refused to credit back the Rs.1,99,000/-.

Findings of Court:
The Commission directed the bank to re-credit Rs.1,99,000/- to the complainant's account along with Rs.25,000/- compensation, noting that since the fraud was reported within the stipulated period, the bank failed to establish negligence on the part of the complainant to avoid liability.

Issues: Whether the bank is liable for unauthorized electronic transactions where the customer was induced to download a malicious application but did not compromise sensitive credentials like OTPs.

Ratio Decidendi: Following principles of limited customer liability for third-party breaches in electronic transactions, a bank must reverse unauthorized debits unless it can strictly prove the customer's active negligence in sharing secure codes.

Result: Appeal dismissed.

Table of Content
1. procedural history of the dispute regarding unauthorized bank transactions. (Para 1 , 2 , 3)
2. apposing contentions regarding customer negligence vs. bank's duty of care. (Para 4 , 5 , 7)
3. application of zero liability clause for reported third-party fraud. (Para 6 , 8 , 9)
4. final order directing bank to re-credit disputed amount. (Para 10)

JUSTICE ANOOP KUMAR MENDIRATTA, MEMBER

ORDER

1. Second appeal preferred on behalf of the Appellant/Opposite Party assails Order dated 26.05.2025 passed in Appeal No.1742 of 2023 by the learned Karnataka State Consumer Disputes Redressal Commission, whereby the appeal filed by the complainant was allowed and the opposite party has been directed to re-credit the amount of Rs.1,99,000/- within 60 days with compensation of Rs.25,000/-.

2. In brief, Complainant/Respondent is an account holder with the State Bank of India/Opposite Party. On 19.07.2022, complainant received an SMS from mobile No.08910621736 on his mobile regarding disconnection of electricity connection, in case the Electricity Bill for the last month was not paid. Also, a number was indicated for clarification. On calling the aforesaid number by the complainant, the dues were confirmed and further on downloading the application the screen of BESCOM (Bangalore Electricity Department) appeared. An amount of Rs.20/- was initially tried to be paid online by the complainant but a message was received from the bank that the complainant wrongly entered the password three times and, as such, was not permitted to do any transaction. Thereafter, a message was received by the complainant that an amount of Rs.25,000/- was deducted from his SBI account. Again an SMS was received by the complainant for payment of Rs.1,99,000/- even without entering the OTP. Further, the mobile of the complainant was found to be not working thereafter and attempt to inform SBI failed. Complainant fearing loss of any further amount switched off the mobile. Since the server of SBI was down, an e-mail was forwarded by complainant at ‘unauthorisedtransaction@sbi.co.in’ for reporting ‘fraudulent online transaction’. The matter was also reported to Cyber Crime Police, who raised CIRO number 12895 on the same day pursuant to which FIR was subsequently registered as Crime No.451/2022 at East CEN Crime Police, Bengaluru. The matter was thereafter reported by the complainant to OP on 20.07.2022, upon which the account was freezed with an assurance to look into the issue. In the meantime, amount of Rs.25,000/- was credited back to the account of the complainant. Complaint was further filed by the complainant with OP along with relevant documents on 26.07.2022, which was acknowledged by OP vide e-mail dated 27.07.2022. In the absence of any resolution of his grievance by OP, a complaint was preferred by the complainant before the learned District Forum claiming refund of Rs.1,99,000/- along with compensation.

3. The complaint was dismissed by the learned District Forum vide Order dated 14.08.2023. Aggrieved against the same, Appeal No.1742 of 2023 was preferred by the complainant which was allowed by the learned State Commission vide Order dated 26.05.2025, directing OP to re-credit the amount of Rs.1,99,000/- as noticed above. Present SA No.540 of 2025 has been preferred on behalf of Opposite Party, challenging the Order passed by the learned State Commission.

4. Learned counsel for the opposite party submits that crucial facts relating to fraudulent transaction have been suppressed by the complainant. He argues that money could not have been withdrawn without sharing of OTP by the complainant. He further submits that opposite party had been informed of the fraudulent transaction only vide letter dated 26.07.2022 after a delay of eight days of the impugned transaction. He urges that negligence cannot be attributed to opposite party since the credentials were shared by the complainant after voluntarily downloading the application which turned out to be

Click Here to Read the rest of this document
1
2
3
4
5
6
7
8
9
10
11
SupremeToday Portrait Ad
supreme today icon
logo-black

An indispensable Tool for Legal Professionals, Endorsed by Various High Court and Judicial Officers

Please visit our Training & Support
Center or Contact Us for assistance

qr

Scan Me!

India’s Legal research and Law Firm App, Download now!

For Daily Legal Updates, Join us on :

whatsapp-icon Back to top