Online Scam Transfer: When Can A Bank Be Held Responsible For The Customer’s Loss?

Newspoint
A scam victim who personally authorises a payment may assume that the bank has no responsibility for the resulting loss. That assumption, however, may not apply in every circumstance. A recent order by the Nagpur District Consumer Disputes Redressal Commission has brought renewed attention to the issue of online scam bank liability . The commission directed ICICI Bank to refund more than Rs 5.18 lakh, along with interest and compensation, to a woman who was allegedly manipulated into transferring nearly Rs 6.93 lakh to a fraudster.
The case centres on whether a transaction being authorised by a customer through an OTP automatically removes the bank's responsibility. According to the commission's findings, it does not necessarily do so where questions arise about transaction monitoring and the bank's response to reported fraud.
Hero Image


How The Parcel Scam Unfolded

The incident dates back to January 8, 2023. The woman, who was residing in Gurugram, reportedly received a telephone call from an individual claiming to represent FedEx.

The caller allegedly told her that an international parcel booked using her details contained several illegal or suspicious items, including passports, ATM cards, cannabis and a laptop.


When she denied having sent such a package, the caller reportedly escalated the situation by claiming that her identity had been misused. She was allegedly warned of possible police action, creating fear that she could face legal consequences.

Under this pressure, she transferred money in four separate transactions to an ICICI Bank account allegedly controlled by the scammer.


The amounts involved were Rs 95,499, Rs 3,07,939.50, Rs 1,90,000 and Rs 99,999. Together, the four transfers totalled Rs 6,93,437.50.

The incident reflects a common feature of impersonation scams: fraudsters create urgency or fear before persuading victims to move money themselves.

What Happened After The Fraud Was Reported?

Once the woman realised that she had been deceived, she contacted ICICI Bank and was advised to report the matter through the National Cyber Crime Reporting Portal. She also approached the police.

The bank initially provided a temporary credit, commonly referred to as a shadow credit. That amount was subsequently reversed.


The bank's position was that the transactions had been authenticated through OTPs and were therefore authorised by the customer. On that basis, it disputed responsibility for the loss.

The woman then approached the Banking Ombudsman. The matter resulted in a direction for credit of roughly 25% of the disputed amount. Seeking recovery of the balance, she subsequently moved the consumer commission.

Why The Bank's Defence Was Rejected

ICICI Bank argued that the matter arose from a criminal offence and should therefore be dealt with through the criminal justice process rather than a consumer complaint.

The commission did not accept that reasoning. It distinguished the alleged cybercrime from the separate question of whether the bank had met its own regulatory and service obligations.

A key issue was the requirement for banks to monitor customer accounts and identify unusual or suspicious activity. The commission referred to the Reserve Bank of India's KYC Directions while considering the bank's duties.

You may also like



According to the commission, the bank had failed to adequately monitor the disputed transactions and had not acted with sufficient speed after the fraud was reported. It consequently held the bank responsible for deficiency in service and negligence.

What Compensation Was Ordered?

The consumer commission directed ICICI Bank to pay Rs 5,18,437 to the complainant. The amount carries interest at 9% per annum, calculated from the date on which the complaint was filed until the payment is made.

In addition to the disputed amount, the commission awarded Rs 25,000 as compensation for mental agony. Another Rs 10,000 was granted towards litigation expenses.

The bank was directed to comply with the order within 45 days.

The ruling does not mean that banks will automatically have to reimburse every customer who is deceived into making an online payment. Each case can depend on its specific facts, including how the transactions occurred, what monitoring was carried out and how quickly the bank responded after receiving the fraud report.


What The Case Means For Scam Victims

The order highlights why customers should report suspected cyber fraud to their bank and the relevant authorities as quickly as possible. Prompt reporting can be important when attempts need to be made to trace or block funds.

It also shows that OTP authentication alone may not settle every dispute over bank responsibility. The commission's findings indicate that transaction authentication and a bank's wider obligations to monitor accounts are separate considerations.

According to financial and consumer law experts, people affected by online fraud should preserve transaction records, communication details, complaint acknowledgements and other relevant evidence. Such documentation can become important if the dispute later reaches an ombudsman, regulator or consumer forum.

For customers, the broader lesson is to act immediately after discovering a scam rather than assuming that an authorised transaction means there is no possible avenue for redress. At the same time, consumers should not treat the ruling as a guarantee of reimbursement. The outcome of any online fraud dispute will depend on the circumstances and the applicable rules.
Disclaimer:
This content is for informational purposes only and should not be treated as legal, financial or regulatory advice. The outcome of individual cyber fraud or banking disputes may vary depending on the facts and applicable laws and regulations.

Image Courtesy: Meta AI

Loving Newspoint? Download the app now
Newspoint