The Digital Vault Keeper’s Duty: Karnataka HC Holds BSNL Accountable for SIM-Swap Fraud

In a landmark judgment that reinforces the responsibility of service providers in the digital economy, the High Court of Karnataka has ruled that telecom companies act as the "vault keepers" of our financial authentication systems. Hon'ble Mr. Justice Suraj Govindaraj underscored that when a telecom provider negligently enables a SIM-swap fraud , they bear the full brunt of civil liability for the resulting financial loss.

The court's decision in Sri Basaveshwara Pattana Sahakara Bank Niyamitha v. Canara Bank & Others dismissed Bharat Sanchar Nigam Limited ’s ( BSNL ) challenge to a Permanent Lok Adalat award, instead enhancing the compensation awarded to the Bank from a token Rs 5 lakhs to over Rs 50 lakhs, citing the telecom entity's institutional accountability .

The Breach at the Digital Border

The dispute arose in February 2019 when the Basaveshwara Pattana Sahakara Bank Niyamitha , a co-operative society, discovered that Rs 87.70 lakh had been siphoned from its current account through seven unauthorized RTGS/NEFT transactions . Investigation revealed a sophisticated "SIM-swap" attack: fraudsters had obtained a duplicate SIM for the bank's registered mobile number without authorization from the bank, allowing them to intercept One-Time Passwords (OTPs) crucial for banking authentication.

While BSNL argued that the fraud was a result of internal credential theft at the Bank’s end and that its employee's alleged collusion was an "independent act" outside the scope of employment, the High Court rejected these contentions.

The "Vault Keeper" Analogy

Justice Govindaraj’s ruling provides a striking metaphor for the role of telecom operators in contemporary India. "Telecom service providers are the custodians of the mobile numbers that serve as the authentication anchors for the entire OTP-based digital payment system," the court observed.

Comparing telecom infrastructure to a bank vault, the court added: "Just as a vault keeper who carelessly or dishonestly gives access to unauthorized persons bears responsibility for the resulting theft, a telecom service provider that carelessly or dishonestly issues a duplicate SIM bears responsibility for the financial fraud that the duplicate SIM enables."

Key Observations of the Court

The High Court’s ruling emphasized that telecom providers cannot hide behind the criminal actions of their employees to escape civil liability . Key legal principles established include:

  • Vicarious Liability : The court held that since the employee used BSNL ’s infrastructure and authority to issue the SIM card, the act was performed " in the course of employment ." BSNL ’s own initiation of departmental disciplinary proceedings served as an institutional admission of this connection.
  • The Collateral Source Rule : Addressing the treatment of recoveries, the court clarified that insurance proceeds are a "collateral benefit" obtained through the victim's own prudence. Consequently, insurance payouts do not mitigate the tortfeasor 's ( BSNL ) liability to pay for the loss caused.
  • Deficiency in Service : The failure to adhere to mandatory KYC guidelines and identity verification protocols before issuing a duplicate SIM constituted a clear deficiency in service .

Enhancing Access to Justice

Beyond the liability ruling, the court criticized the Permanent Lok Adalat for arbitrarily restricting compensation to Rs 5 lakhs without a reasoned basis. Finding the lower award an " error apparent on the face of the record ," Justice Govindaraj enhanced the principal amount to Rs 50,50,762/-, plus interest at 9% per annum from the date of the loss, and awarded an additional Rs 5 lakh for consequential damages including reputational harm and liquidity crisis.

Proactive Steps for Banking Institutions

While holding BSNL responsible, the court also urged banks to bolster their own digital borders. It suggested institutions implement multi-channel transaction alerts, time-delays for large transfers following a SIM-swap notification, and mandatory customer education on digital fraud risks.

Ultimately, the judgment serves as a stern warning: in an era where mobile numbers are the keys to the digital vault, telecom operators must guard those keys with rigorous vigilance. Bureaucratic negligence in verification is no longer just a technical failure—it is a financial liability.