A Tamil Nadu consumer court has ordered a bank to pay ₹1.10 lakh to a phishing victim, ruling that banks cannot remain passive after receiving immediate reports of fraudulent transactions.
- Bank ordered to refund ₹50,000, pay ₹50,000 compensation, and ₹10,000 for litigation.
- Ruling emphasizes that prompt reporting by customers triggers a mandatory duty of care for banks.
- Court rejected the bank's defense that customer negligence absolves the institution of liability.
In a significant victory for consumer rights, the Thanjavur District Consumer Disputes Redressal Commission in Tamil Nadu has directed a banking institution to pay a total of ₹1.10 lakh to a customer who fell prey to a phishing scam. The ruling underscores the critical responsibility of banks to act decisively when notified of unauthorized transactions.
The dispute began when the complainant received an SMS promising a reward of ₹12,980. After clicking the embedded link and providing her banking credentials, an unauthorized beneficiary was added to her account, resulting in a loss of ₹50,000. The woman acted swiftly by contacting the bank's customer care, lodging an online complaint, and notifying cybercrime authorities.
Bank's Defense vs. Judicial Reasoning
The bank contested the claim, arguing that the transaction was only possible because the customer voluntarily entered her username, password, and OTP. The institution maintained that it had followed all RBI-mandated security protocols and that the loss was a direct result of the customer's negligence.
"The failure to act upon immediate information regarding a fraudulent transaction constitutes a deficiency in service under the Consumer Protection Act, 2019."
Why This Matters
BozokMedia analysis shows that this judgment shifts the power dynamic between massive banking corporations and individual consumers. For years, banks have used 'customer negligence' as a blanket shield to avoid liability in cyber-fraud cases. By ruling that a bank's independent obligation to act persists regardless of how the breach occurred, the commission has set a precedent that prevents banks from mechanically attributing every fraud to the user.
President T Sekar and member K Velumani observed that the bank failed to produce any documentation proving what actions were taken after the complaint was lodged. The commission noted that banks cannot be mere passive observers once a fraud alert is triggered by the customer.
| Stakeholder | Core Argument | Outcome |
|---|---|---|
| The Bank | Customer shared OTP; therefore, no deficiency in service. | Rejected |
| Consumer Commission | Bank's inaction after reporting is a statutory failure. | Upheld |
Frequently Asked Questions
Q1: Can a customer get a refund if they shared their OTP?
Yes, provided they report the fraud immediately. This ruling shows that the bank's failure to act on that report can make them liable for compensation.
Q2: What is the legal basis for this compensation?
The compensation was granted under Section 2(11) of the Consumer Protection Act, 2019, which defines 'deficiency in service'.