
Customer’s Mere Denial Of Sharing OTP Cannot Automatically Fasten Liability On Bank In Cyber Fraud Cases: Delhi High Court
|The Court held that the RBI’s 2017 framework on unauthorised electronic banking transactions distinguishes between bank deficiency and customer negligence, and that liability cannot automatically be shifted onto the bank merely because the customer denies sharing OTPs.
The Delhi High Court has held that mere denial by a customer of sharing One Time Passwords (OTPs) cannot automatically result in fastening liability upon a bank in cases involving unauthorised electronic banking transactions.
The Court observed that the framework under the Reserve Bank of India’s 2017 Circular contemplates different categories of unauthorised transactions and recognises that customer negligence may also arise where suspicious links or unknown applications are accessed, thereby compromising banking credentials.
The Court was hearing an appeal filed by the State Bank of India challenging a judgment of a Single Judge directing the bank to refund ₹2.60 lakh along with interest to a customer whose account had allegedly been subjected to cyber fraud through unauthorised internet banking transactions.
A Division Bench comprising the Chief Justice Devendra Kumar Upadhyaya and Justice Tejas Karia observed: “The learned Single Judge, however, held that, since Respondent No. 1 had denied sharing the OTPs, the liability would necessarily fall upon the Appellant-Bank. Such an interpretation dilutes the operation of Clause 7(i) of the 2017 RBI Circular and the distinction contemplated therein between different categories of unauthorised transactions.”
The Court also held: “In matters involving digital banking fraud, customer negligence cannot be confined solely to cases of express disclosure of OTPs or passwords”, while adding that “compromise of such credentials may also occur where a customer interacts with suspicious links or unknown applications, thereby exposing the banking credentials to misuse.”
Senior Advocate Harin P. Raval appeared for the appellant, while Advocate Ravi Chandra Prakash represented the respondent.
Background
The dispute arose after an aggregate amount of ₹2.60 lakh was unauthorisedly withdrawn from the respondent’s savings account maintained with State Bank of India through two internet banking transactions on 18 April 2021.
According to the bank, the transactions were carried out through internet banking using valid login credentials and OTP-based two-factor authentication, with OTPs successfully delivered to the mobile number registered with the account.
The customer alleged that he had received an SMS containing a suspicious link stating that his account services would be discontinued if the link was not clicked. After clicking the link, he allegedly received SMS alerts regarding unauthorised debit transactions from his account.
The customer claimed that although OTPs were generated and delivered to his registered mobile number, he had never shared them with anyone, and therefore, the transactions reflected negligence and deficiency in service on the part of the bank.
The Banking Ombudsman partly allowed the complaint and directed SBI to pay one-third of one disputed transaction amounting to ₹33,340/-, while observing that the customer had fallen victim to vishing fraud after clicking upon an unknown link.
Subsequently, the Single Judge allowed the customer’s writ petition and directed SBI to refund the entire disputed amount with interest, holding that the customer could not be treated as negligent and that the fraud occurred because of a deficiency attributable to the bank.
Court’s Observation
The Division Bench extensively examined the RBI Circular dated 06 July 2017 titled Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions and the distinction it draws between bank deficiency and customer negligence.
The Court observed that Clause 6 of the Circular contemplates “zero liability” where the deficiency lies with the bank or elsewhere in the system, while Clause 7(i) places liability upon customers where loss occurs due to their negligence, including compromise of banking credentials. The Bench clarified that customer negligence under the RBI framework is not confined only to explicit disclosure of passwords or OTPs.
The Court observed: “The expression ‘such as where he has shared the payment credentials’ occurring in Clause 7(i) of the 2017 RBI Circular is plainly illustrative and not exhaustive; it does not confine customer negligence only to cases of express disclosure of payment credentials.”
The Court further remarked: “In the context of digital banking and cyber fraud, negligence may equally arise where a customer, despite repeated advisories and security warnings, accesses suspicious or unknown links, thereby compromising the security of the banking credentials.”
The High Court noted that the respondent had admittedly clicked upon a suspicious link immediately before the disputed transactions and that the transactions had been successfully carried out through internet banking secured by two-factor authentication.
The Court observed: “There is no material presently on record to indicate that the Subject Transactions bypassed the authentication process prescribed by the Appellant-Bank or that there was any established compromise of the banking system of the Appellant-Bank.”
The Division Bench also held that the findings returned by the Single Judge regarding the absence of negligence on the part of the customer and the deficiency on the part of the bank could not have been conclusively determined without technical and forensic examination.
The Court observed: “The issues considered by the learned Single Judge, particularly whether the user ID and password of the INB profile linked to the Bank Account or the OTPs were compromised following interaction with a suspicious link received from an unknown source; whether negligence was attributable to Respondent No. 1; whether security protocols such as 2FA or OTP verification had been breached by malware deployed by cyber fraudsters… are matters that necessarily require technical and forensic examination and adjudication on evidence and could not have been conclusively determined in exercise of writ jurisdiction.”
The Bench further observed: “The observations in the Impugned Judgment to the effect that Respondent No. 1 ‘cannot be said to be negligent in any manner’ and that the Subject Transactions occurred solely on account of deficiency attributable to the Appellant-Bank are, in our opinion, ordinarily could not have been returned in the absence of any technical or forensic examination and are, moreover, not in consonance with the framework contemplated under the 2017 RBI Circular.”
The Bench also distinguished the Kerala High Court judgment in Tony Enterprises v. RBI (2019), relied upon by the customer, observing that the said case involved investigative findings establishing SIM swapping and identity theft through duplicate SIM cards, unlike the present matter, where no such finding had emerged.
The Court further observed: “In the present case, no such investigative finding has, to date, emerged to establish that the Subject Transactions were carried out through any breach of the Appellant-Bank’s system.”
Conclusion
The Delhi High Court held that the Single Judge was not justified in presuming a deficiency in service on the part of the bank and fastening liability upon it in exercise of writ jurisdiction without a technical or forensic examination.
Accordingly, the Court allowed the appeal filed by the State Bank of India and set aside the judgment directing the refund of the disputed amount to the customer.
Cause Title: State Bank of India v. Hare Ram Singh & Anr. (Neutral Citation: 2026:DHC:4833-DB)
Appearances
Appellant: Senior Advocate Harin P. Raval, along with Advocates Rajiv Kapur, Akshit Kapur, Riya Sood and Shreya Bansal.
Respondents: Advocates Ravi Chandra Prakash and Purushottam S. Tripathi, Atul Sharma, Abhinav Sharma, Ayush Srivastava and Snehashish.