NCDRC Orders SBI to Refund Rs 1.99 Lakh in Cyber Fraud Case
The National Consumer Disputes Redressal Commission (NCDRC) has dismissed the State Bank of India's appeal, ordering the bank to refund Rs 1.99 lakh plus Rs 25,000 compensation to a customer victimized by cyber fraud. The incident originated in July 2022 when the customer received a fake SMS regarding an unpaid electricity bill of Rs 20. Upon contacting the provided number, he was tricked into downloading a malicious application, leading to unauthorized transactions. SBI argued that the fraud resulted from the customer sharing sensitive credentials like OTPs and delayed reporting. However, the apex consumer body ruled that downloading a fraudulent app does not constitute negligence and found no evidence that OTPs were shared voluntarily. The commission emphasized that the bank failed to take adequate remedial action despite the customer reporting the unauthorized transactions within the stipulated period. Consequently, SBI was held fully liable for the loss, reinforcing the principle that banks cannot evade responsibility for unauthorized electronic transactions when customers act promptly. This decision upholds the earlier order by the Karnataka State Consumer Commission, providing significant relief to the consumer and setting a precedent for liability in digital banking fraud cases involving social engineering tactics.
Wire timeline
NCDRC Orders SBI to Refund Rs 1.99 Lakh in Cyber Fraud Case
The National Consumer Disputes Redressal Commission (NCDRC) has dismissed the State Bank of India's appeal, ordering the bank to refund Rs 1.99 lakh plus Rs 25,000 compensation to a customer victimized by cyber fraud. The incident originated in July 2022 when the customer received a fake SMS regarding an unpaid electricity bill of Rs 20. Upon contacting the provided number, he was tricked into downloading a malicious application, leading to unauthorized transactions. SBI argued that the fraud resulted from the customer sharing sensitive credentials like OTPs and delayed reporting. However, the apex consumer body ruled that downloading a fraudulent app does not constitute negligence and found no evidence that OTPs were shared voluntarily. The commission emphasized that the bank failed to take adequate remedial action despite the customer reporting the unauthorized transactions within the stipulated period. Consequently, SBI was held fully liable for the loss, reinforcing the principle that banks cannot evade responsibility for unauthorized electronic transactions when customers act promptly. This decision upholds the earlier order by the Karnataka State Consumer Commission, providing significant relief to the consumer and setting a precedent for liability in digital banking fraud cases involving social engineering tactics.
The Indian Express