The District Consumer Disputes Redressal Commission, Nagpur, ruled in favour of a cyber fraud victim who fell prey to a "digital arrest" scam involving impersonators claiming to be courier officials and police personnel.

The Commission held ICICI Bank liable for gross deficiency in service, negligence, and unfair trade practices for failing to enforce mandatory Reserve Bank of India (RBI) anti-money laundering and transaction-monitoring guidelines.

The Commission observed that despite the customer’s prompt reporting, the bank failed to freeze the funds transferred to a dormant, suspicious "money mule" beneficiary account within its own branch network, thereby violating the RBI's Zero Liability Policy.

The Bench of Justice Satish A Sapre and Justice Milind Kedar observed, "This is because the complainant immediately informed the Opposite Party Bank after the occurrence of the fraudulent transaction. In such circumstances, several circulars and guidelines have been issued regarding Zero Liability. In particular, the Reserve Bank of India Circular dated 06 July 2017 provides that where a complainant or customer reports the fraudulent transaction within three working days of its occurrence, the customer is entitled to Zero Liability...Considering all these facts and circumstances, the Commission is of the opinion that the Opposite Party failed to exercise the degree of care required of it. Even after the complainant promptly informed the Opposite Party immediately after the incident, the Opposite Party failed to take immediate steps to stop or freeze the amount that had been transferred to another branch of the same bank before it came under the control of the stranger or fraudulent person. This conduct is wholly improper."

Advocate Mahendra Limaye appeared for the Complainant, while Advocate PG Mewar appeared for the Opposite Party/Bank.

Brief Facts

The complainant received a phone call from an individual impersonating a customer service representative of a courier company, who falsely alleged that an international parcel containing contraband and illegal items had been booked in her name. The caller subsequently connected her to fake law enforcement officials and coerced her with threats of criminal prosecution for alleged misuse of her identity. Overawed by fear and intimidation, the complainant was induced to make multiple online fund transfers aggregating to a substantial sum into a designated bank account towards alleged investigation and processing charges.

Upon realizing that she had been subjected to cyber fraud, the complainant promptly reported the matter to the customer care of the Opposite Party Bank, lodged a complaint on the National Cyber Crime Portal, and registered a formal police complaint resulting in the registration of an FIR.

While the Opposite Party Bank initially extended a temporary shadow credit to her account, the same was subsequently reversed on the premise that the disputed transactions were authenticated through One-Time Passwords sent to her registered mobile number.

Aggrieved by the reversal, the complainant approached the Banking Ombudsman, which directed a partial refund of twenty-five percent of the disputed amount, leaving the remaining loss uncompensated.

Contentions of the Complainant

The complainant contended that the Opposite Party Bank committed a grave deficiency in service and acted with sheer negligence by failing to adhere to mandatory Reserve Bank of India guidelines. She submitted that the beneficiary account, despite belonging to a small trader with modest turnover, witnessed sudden, exorbitant, and suspicious transactions running into crores within a span of two days after remaining largely dormant, yet the bank failed to trigger velocity checks or flag the account.

She further asserted that under the Reserve Bank of India's Zero Liability Policy, she was entitled to complete reimbursement of the defrauded amount along with compensation for mental agony and costs, and that the bank wrongfully shifted the burden of seventy-five percent of the financial loss onto her.

Contentions of the Bank

The Opposite Party Bank resisted the complaint, contending that the proceedings were non-maintainable, false, and vexatious, as the underlying matter involved complex criminal cyber fraud requiring elaborate evidence and strict proof before a competent civil court.

The bank stated that the complainant herself voluntarily initiated and authorized the transactions using OTP authentication from her registered mobile number after being duped by third-party fraudsters, and therefore no liability or deficiency in service could be attributed to the institution.

The bank further argued that under the applicable RBI circulars, where a loss occurs due to customer negligence or voluntary sharing of credentials, the liability rests entirely with the account holder.

Lastly, the bank highlighted that the Banking Ombudsman found no operational fault on its part and passed directions against the beneficiary bank, making the present complaint bad for non-joinder of necessary parties, namely the beneficiary and the beneficiary bank.

Findings and Observations 

The District Commission observed that the relationship between the complainant and the Opposite Party Bank was indisputably that of a consumer and a service provider. Addressing the preliminary objection raised by the bank regarding jurisdiction, the Commission noted that while the criminal aspects of cyber fraud and identity theft fell under the domain of law enforcement agencies, the failure of the banking institution to adhere to regulatory mandates constituted a distinct and independent issue relating to deficiency in service.

The Commission further recorded that the maintainability of the complaint before the consumer forum was also supported by the directions of the Hon'ble Supreme Court in a related writ petition, which relegated monetary and compensation claims to the appropriate legal forum.

Evaluating the merits of the case, the Commission expressed deep concern over the findings recorded by the Banking Ombudsman regarding the beneficiary account.

The Commission observed that the beneficiary was merely a retail plastic trader with a modest turnover, whose account had remained dormant for months before suddenly witnessing exorbitant inflows and outflows running into crores within a span of just two days. The Commission held that such abnormal and inconsistent activity clearly constituted a "suspicious transaction" as defined under the Master Direction – Know Your Customer (KYC) Direction, 2016, which obligated the bank to exercise ongoing due diligence and close monitoring.

The Commission said, "Continuous monitoring helps banks quickly detect if a customer’s account is hijacked for fraud, mule activity, or money-laundering, which can prevent larger loss or criminal misuse of the customer’s name. If unusual transactions are spotted early, banks can block or question them and alert the customer, increasing overall safety of digital and RTGS operations."

The Commission observed that the bank failed to deploy mandatory fraud prevention mechanisms, velocity checks, and automated transaction monitoring systems required under the Reserve Bank of India guidelines to curb the operation of "money mule" accounts.

The Commission highlighted a critical lapse on the part of the Opposite Party Bank, noting that since the funds were transferred between two branches of the exact same banking institution, the bank owed a higher degree of duty to verify the destination account and immediately freeze or trace the defrauded amount upon receiving a prompt reporting from the complainant.

It held, "In the present case, the objection raised by the Opposite Party cannot be accepted because the Opposite Party failed to consider and implement the regulatory guidelines that were required to be followed in relation to banking transactions and the operation of bank accounts. The Commission is, therefore, of the clear opinion that such failure constitutes deficiency in service on the part of the Opposite Party."

The Commission distinguished the judicial precedents relied upon by the bank, observing that the prompt reporting of the fraudulent transactions by the customer attracted the protection of the Reserve Bank of India’s Zero Liability Policy.

It was observed that the bank’s complete non-compliance with regulatory directions and failure to exercise due care directly contributed to the financial loss suffered by the complainant.

Consequently, the Commission held the Opposite Party Bank guilty of gross deficiency in service, negligence, and adoption of unfair trade practices, concluding that the complainant was fully entitled to recover the balance uncompensated amount along with interest, compensation for mental agony, and litigation costs.

Accordingly, the Opposite Party Bank was directed to pay to the complainant a sum of Rs. 5,18,437/- (Rupees Five Lakh Eighteen Thousand Four Hundred Thirty-Seven only), together with interest at the rate of 9% per annum calculated from the date of filing of the complaint until the date of actual realization.

The Opposite Party Bank was further directed to pay to the complainant a sum of Rs. 25,000/- (Rupees Twenty-Five Thousand only) towards compensation for the physical and mental agony suffered by her.

Cause Title: Prachi Digambar Dhoke v. ICICI Bank [DC/AB1/484/CC/187/2023]

Appearances:

Complainant: Advocate Mahendra Limaye 

Opposite Party: Advocate PG Mewar

Click here to read/download the Judgment

Tags: