Searching Case Laws & Precedent on Legal Query.....!
Analysing the retrieved Case Laws
Scanned Judgements…!
Searching Case Laws & Precedent on Legal Query.....!
Analysing the retrieved Case Laws
Scanned Judgements…!
Customer Responsibility for OTP Secrecy - Once the OTP is delivered to the customer's mobile, it is the customer's responsibility to maintain its secrecy. The bank cannot be held liable for losses resulting from the customer's deliberate or inadvertent sharing of OTP or other sensitive information. If the customer discloses OTP, any fraudulent transaction that occurs afterward is generally attributed to the customer's negligence. ["STATE BANK OF INDIA VS PALLABH BHOWMICK S/O LATE P. R. BHOWMICK - 2024 0 Supreme(Gau) 1214"], ["Paresh Chandra Deka, S/o. Late Aditya Deka VS State Of Assam - Gauhati"], ["STATE BANK OF INDIA vs PALLABH BHOWMICK AND 4 ORS. - Gauhati"], ["Bhushan Goyal vs The Banking Ombudsman C/o.Reserve Bank of India - Madras"], ["PUNJAB NATIONAL BANK vs SH. NASIR ALI - Consumer State"], ["Kotak Mahindra Bank Ltd. vs Mehak Kaur - Consumer State"], ["Kotak Mahindra Bank Ltd. vs Mehak Kaur - Consumer State"], ["BRANCH MANAGER AXIS BANK CALL CENTER & ANR vs VIJAY KUMAR SAHU - Consumer State"]
Bank's Liability and Customer's Liability - The bank is not responsible for fraudulent transactions if the customer has shared OTP or other confidential details. However, if the transaction occurs due to third-party breaches where neither the bank nor the customer is at fault, and the customer reports the unauthorized transaction within a stipulated period (usually three working days), liability may be limited or nullified. The bank's guidelines emphasize that confidential information like OTP should not be shared, and failure to adhere to this can lead to customer liability. ["Branch Manager, Axis Bank Call Centre Axis Bank VS Vijay Kumar Sahu - Consumer"], ["STATE BANK OF INDIA VS PALLABH BHOWMICK S/O LATE P. R. BHOWMICK - 2024 0 Supreme(Gau) 1214"], ["STATE BANK OF INDIA vs PALLABH BHOWMICK AND 4 ORS. - Gauhati"], ["PUNJAB NATIONAL BANK vs SH. NASIR ALI - Consumer State"], ["Kotak Mahindra Bank Ltd. vs Mehak Kaur - Consumer State"], ["Kotak Mahindra Bank Ltd. vs Mehak Kaur - Consumer State"], ["Bhushan Goyal vs The Banking Ombudsman C/o.Reserve Bank of India - Madras"], ["Paresh Chandra Deka, S/o. Late Aditya Deka VS State Of Assam - Gauhati"], ["BRANCH MANAGER AXIS BANK CALL CENTER & ANR vs VIJAY KUMAR SAHU - Consumer State"]
Sharing OTP and Negligence - The core issue is whether the customer voluntarily shared OTP. Sharing OTP constitutes negligence, making the customer liable for fraudulent transactions. The guidelines clearly state that sharing OTP or payment credentials leads to customer liability until the transaction is reported promptly. The bank is generally not liable if the customer discloses OTP, even if the transaction is fraudulent. ["STATE BANK OF INDIA vs PALLABH BHOWMICK AND 4 ORS. - Gauhati"], ["Bhushan Goyal vs The Banking Ombudsman C/o.Reserve Bank of India - Madras"], ["PUNJAB NATIONAL BANK vs SH. NASIR ALI - Consumer State"], ["Kotak Mahindra Bank Ltd. vs Mehak Kaur - Consumer State"], ["Kotak Mahindra Bank Ltd. vs Mehak Kaur - Consumer State"], ["STATE BANK OF INDIA VS PALLABH BHOWMICK S/O LATE P. R. BHOWMICK - 2024 0 Supreme(Gau) 1214"], ["Paresh Chandra Deka, S/o. Late Aditya Deka VS State Of Assam - Gauhati"], ["BRANCH MANAGER AXIS BANK CALL CENTER & ANR vs VIJAY KUMAR SAHU - Consumer State"]
Exceptions - If the fraudulent transaction occurs due to deficiencies outside the customer's or bank's control (system breach), and the customer reports the fraud within the prescribed time, liability may be zero. This is applicable only when the breach is not due to the customer's negligence, such as sharing OTP. ["STATE BANK OF INDIA VS PALLABH BHOWMICK S/O LATE P. R. BHOWMICK - 2024 0 Supreme(Gau) 1214"], ["STATE BANK OF INDIA vs PALLABH BHOWMICK AND 4 ORS. - Gauhati"], ["PUNJAB NATIONAL BANK vs SH. NASIR ALI - Consumer State"], ["Kotak Mahindra Bank Ltd. vs Mehak Kaur - Consumer State"], ["Kotak Mahindra Bank Ltd. vs Mehak Kaur - Consumer State"]
Analysis and Conclusion:The prevailing legal and regulatory framework, supported by RBI guidelines, establishes that once a customer shares OTP, the customer bears liability for subsequent fraudulent transactions. The bank cannot be held responsible if the customer negligently discloses OTP, leading to unauthorized transactions. Conversely, if the fraud results from a systemic breach outside the customer's or bank's fault, and the customer reports promptly, liability can be mitigated or nullified. Therefore, sharing OTP intentionally or negligently generally results in customer liability, and the bank is not responsible for losses arising from such disclosures.
In today's digital age, banking frauds are rampant, often involving one-time passwords (OTPs). Imagine receiving a call from someone pretending to be your bank, asking for your OTP to verify a transaction. You share it, and suddenly, your account is drained. The burning question arises: Is the bank liable if the customer shares OTP in fraud?
This post dives deep into RBI guidelines, judicial precedents, and real-world cases to clarify liability. While banks must safeguard accounts, customer negligence like sharing OTPs typically shifts responsibility. Note: This is general information, not legal advice—consult a lawyer for your situation.
OTPs are six-digit codes sent to your registered mobile for authenticating high-value transactions. They're a cornerstone of secure online banking. However, fraudsters exploit trust by phishing for OTPs via calls, SMS, or apps.
RBI guidelines emphasize customer responsibility. As per RBI Circular No. RBI/2017-18/15 DBR.No.Leg.BC.78/09.07.005/2017-18, if a customer shares payment credentials, they bear the loss until they report and the bank takes action STATE BANK OF INDIA VS PALLABH BHOWMICK S/O LATE P. R. BHOWMICK - 2024 0 Supreme(Gau) 1214SBI Cards & Payments Services Ltd. VS Vishal Sabharwal - Consumer (2020). Sharing OTP constitutes negligence, making the customer liable STATE BANK OF INDIA VS PALLABH BHOWMICK S/O LATE P. R. BHOWMICK - 2024 0 Supreme(Gau) 1214SBI Cards & Payments Services Ltd. VS Vishal Sabharwal - Consumer (2020).
Generally, banks are not liable for fraudulent transactions if the customer shared the OTP. Courts and RBI hold that such actions indicate customer negligence, absolving the bank unless proven otherwise.
RBI circulars on electronic banking customer protection state:- Customers must report unauthorized transactions promptly (Clause 9) SBI Cards & Payments Services Ltd. VS Vishal Sabharwal - Consumer (2020).- Sharing credentials like OTP, MPIN, or passwords makes the customer liable until reporting (Clause 7) SBI Cards & Payments Services Ltd. VS Vishal Sabharwal - Consumer (2020).- Banks provide secure systems, but negligence shifts liability (Clause 7) SBI Cards & Payments Services Ltd. VS Vishal Sabharwal - Consumer (2020).
Explicitly: In cases where the loss is due to negligence by a customer, such as where he has shared the payment credentials, the customer will bear the entire loss until he reports the unauthorised transaction to the bank SBI Cards & Payment Services Ltd. VS Durga ChauhanState Bank of India Represented by the Chief Manager, State Bank of India VS Justice (Retd. ) Mr. Basu Deo Agarwal S/o Late Nowrang Rai Agarwala - 2022 Supreme(Gau) 275.
Indian courts consistently side with banks when OTP sharing is involved.
In one case, transactions over six days via net banking required OTPs. The court rejected claims of SIM duplication without evidence, holding the account holder responsible as passwords were known only to them Sanjiva Kumar Sinha VS Senior Manager, Indian Bank. It is not in dispute that without OTP being sent on the mobile phone of the customer, transaction through net banking facility cannot be made Sanjiva Kumar Sinha VS Senior Manager, Indian Bank.
Liability isn't absolute. Banks must prove customer negligence and exercise reasonable care.
In a credit card fraud case under Consumer Protection Act, 2019, no OTP was received, and the complainant blocked the card promptly. The bank bore liability as no negligence was proven: Even if there is no specific security lapse or contributory negligence on part of petitioner, there is no negligence/contributory negligence on part of complainant-respondent too SBI Cards & Payment Services Ltd. VS Durga Chauhan.
Another instance: If banks don't prevent fraud post-notification, or if duplicate SIM claims lack evidence of non-sharing, banks may lose Sanjiva Kumar Sinha VS Senior Manager, Indian Bank. However, banks must cogently establish negligence with reliable evidence—perceived negligence isn't enough Pallabh Bhowmick S/o Late P. R. Bhowmick VS Ombudsman, Reserve Bank of India - 2022 Supreme(Gau) 753.
In a school account fraud, tagging personal accounts wrongly led to bank scrutiny, but sharing credentials doomed the claim Sanjiva Kumar Sinha VS Senior Manager, Indian Bank.
Customers should report unauthorized transactions immediately and keep records of communication STATE BANK OF INDIA VS PALLABH BHOWMICK S/O LATE P. R. BHOWMICK - 2024 0 Supreme(Gau) 1214.
The consensus from RBI and courts is clear: Sharing OTP typically makes you liable for fraud, as it proves negligence STATE BANK OF INDIA VS PALLABH BHOWMICK S/O LATE P. R. BHOWMICK - 2024 0 Supreme(Gau) 1214SBI Cards & Payments Services Ltd. VS Vishal Sabharwal - Consumer (2020). Banks aren't insurers against poor judgment, but they must prove lapses and handle third-party breaches fairly.
Key takeaways:- Don't share OTP—it's your firewall.- Report fast to limit losses.- In disputes, evidence rules.
Stay vigilant in digital banking. For personalized advice, reach out to legal experts.
References:1. STATE BANK OF INDIA VS PALLABH BHOWMICK S/O LATE P. R. BHOWMICK - 2024 0 Supreme(Gau) 1214: Liability hinges on customer negligence.2. SBI Cards & Payments Services Ltd. VS Vishal Sabharwal - Consumer (2020): RBI on sharing credentials.3. Chief Manager, State Bank of India VS Shaik Abdul Saheed - 2019 0 Supreme(AP) 168: Kerala HC on OTP sharing.4. SBI Cards & Payment Services Ltd. VS Durga Chauhan, Pallabh Bhowmick S/o Late P. R. Bhowmick VS Ombudsman, Reserve Bank of India - 2022 Supreme(Gau) 753, Sanjiva Kumar Sinha VS Senior Manager, Indian Bank: Contrasting cases on proof and exceptions.
#BankFraud #OTPSharing #RBIGuidelines
Once the OTP is delivered to the customer's mobile it is his responsibility to ensure secrecy and sanctity of the OTP. Bank cannot be responsible for any mistake committed by the customer deliberately or inadvertently. ... Undoubtedly, it is correct that if a customer is negligent in handling his or her account and discloses sensitive information such as, password, OTP,....
The transactions disputed by the customer are secured two factor authenticated transactions done using PIN/ OTP. As per RBI guidelines, the card & OTP related information is confidential information which is not supposed to be shared with anyone else. ... Hence, the dispute has been closed under customer liability. Please check the below OTP details triggered to customer’s registered mob....
from the Bank on the part of the customer in notifying the Bank of such transaction, the per transaction liability of the customer shall be limited to the transaction value or the amount mentioned in Table-1 whichever is lower. ... In addition to that this is not a case where OTP details were shared by the petitioner. ... on the part ....
the loss is due to negligence by a customer, such as where he has shared the payment credentials, the customer will bear the entire loss until he report the unauthorized transaction to the bank. ... Once the OTP is delivered to the customer's mobile it is his responsibility to ensure secrecy and sanctity of the OTP. Bank cannot be responsible....
Here, it is pertinent to remark here that the Appellant has not filed any document to show any contributory negligence of the Respondent, in support of the contention that the Respondent has voluntarily shared the OTP to effect the fraudulent transaction. ... Third party breach where the deficiency lies neither with the bank nor with the customer but lies elsewhere in the system, and th....
In cases where the loss is due to negligence by a customer, such as where he has shared the payment credentials, the customer will bear the entire loss until he reports the unauthorised transaction to the bank. ... In the present case, the Respondent-Complainant, immediately on getting the SMS about the transaction, reported it to the Bank as fraudulent#HL_END....
Further, such transaction succeeds only when the OTP/PIN is shared with system prompting the transaction and without sharing the OTP/PIN transaction is not completed. ... , such as where he has shared the payment credentials, the customer will bear the entire loss until he reports the unauthorised transaction to the bank#HL_....
Further, such transaction succeeds only when the OTP/PIN is shared with system prompting the transaction and without sharing the OTP/PIN transaction is not completed. ... , such as where he has shared the payment credentials, the customer will bear the entire loss until he reports the unauthorised transaction to the bank#HL_....
Undoubtedly, it is correct that if a customer is negligent in handling his or her account and discloses sensitive information such as, password, OTP, MPIN, Card Number etc., resulting into fraudulent transaction, the Bank cannot be held liable for loss, if any suffered by the customer. ... The prerequisite for entitlement of zero liability is that the customer notifies....
The transactions disputed by the customer are secured two factor authenticated transactions done using PIN/ OTP. As per RBI guidelines, the card & OTP related information is confidential information which is not supposed to be shared with anyone else. ... Hence, the dispute has been closed under customer liability. Please check the below OTP details triggered to customer’s registered mob....
22. Mr. A. Parvez, learned counsel, submits that OTP (One Time Password) is a cyber-security measure adopted by the Bank for every online transaction initiated by the customer. An OTP (One Time Password) will be generated and delivered to the registered mobile number of a client. The transaction will be successful only if the OTP is put in the relevant site/ payment gateway (PG). 2021 i.e., within one working day. Therefore, as per clause-8 of the RBI circular, the liability ....
Yet, it appears from the plain language employed in clause-8 that in case of un authorized electronic banking transaction occurring due to third party breaches i.e where the deficiency neither lies with the customer or the bank, the customer liability will be “zero” if the fraudulent transaction is reported within three working days from the date on which the customer receives the communication. In the present case, even if it is assumed that the fraudulent transaction had taken plac....
(i) In cases where the loss is due to negligence by a customer, such as where he has shared the payment credentials, the customer will bear the entire loss until he reports the unauthorized transaction to the bank. Any loss occurring after the reporting of the unauthorized transaction shall be borne by the bank.” A customer shall be liable for the loss occurring due to unauthorized transactions in the following cases :
8. It is not in dispute that without OTP being sent on the mobile phone of the customer, transaction through net banking facility cannot be made. The case of the complainant in this regard appears to be that someone had obtained a duplicate SIM card against mobile of Mr. Sinha and used that SIM card to make these transactions. The transactions disputed by the complainant lasted 6 days between 5.9.2014 to 10.9.2014.
This is a classic case of fraudulent transaction by the bank. Though we can forward the allegations made in the complaint, to one of the police investigating agencies to proceed with the bank and its officials, we leave the option open to the complainant to proceed with the bankers for the alleged fraud committed.”
Login now and unlock free premium legal research
Login to SupremeToday AI and access free legal analysis, AI highlights, and smart tools.
Login
now!
India’s Legal research and Law Firm App, Download now!
Copyright © 2023 Vikas Info Solution Pvt Ltd. All Rights Reserved.