SBI Refunds ₹5 Lakh in Cyber Fraud Case with 9% Interest, Payable Immediately
SBI Ordered to Refund ₹5 Lakh in Cyber Fraud Case, Pay 9% Interest The Nagpur District Consumer Disputes Redressal Commission ruled that the State Bank of India’s Tumsar branch was negligent in addressing a cyber fraud incident involving a customer’s account. The commission mandated the bank to return ₹5,00,250 to the affected individual, along with 9% annual interest starting from July 18, 2021. Additionally, the bank was ordered to cover ₹30,000 in compensation and legal expenses.
Incident Details
The incident involved Vindhyan Meshram, who reported unauthorized transactions following a phishing attempt. On July 18, 2021, Meshram contacted customer support regarding a faulty online purchase. A caller claiming to assist with a refund guided him to install a mobile application, which subsequently enabled the theft of funds.
Phishing Attempt
The caller claimed to assist with a refund and guided Meshram to install a mobile application, which led to the theft of funds. This method is a common phishing tactic used to gain unauthorized access to user accounts.
Unauthorized Transactions
Over 13 transactions totaling ₹5,00,250 were executed, with multiple online payment gateways listed as beneficiaries. The unauthorized activity was discovered by Meshram, who immediately contacted the bank, froze his account and debit card, and reported the crime to law enforcement.
Customer’s Actions
Meshrum submitted a formal complaint to the government’s cybercrime portal on July 19, 2021. He provided detailed transaction records and requested the reversal of the unauthorized transactions within 24 hours of detecting the breach.
Bank’s Defense
The bank contested the claim, asserting that Meshram had shared his One-Time Password (OTP) and was negligent in handling the transaction. However, the commission dismissed this defense, noting that the evidence suggested the OTP was obtained through fraudulent means rather than intentional disclosure.
Commission’s Ruling
The commission determined that the bank’s failure to implement preventive measures and respond effectively constituted a service deficiency under the Consumer Protection Act, 2019. The ruling emphasized that the complainant acted within 24 hours of detecting the breach, providing detailed transaction records and requesting reversal.
Implications and Lessons
The decision highlights the critical need for financial institutions to swiftly address fraud reports and enhance monitoring of high-risk transactions. The order underscores the legal and operational responsibilities of banks in safeguarding customer assets. It also reinforces the importance of proactive measures to detect and mitigate cyber threats, particularly those involving social engineering tactics like phishing calls and malicious applications.
