State Bank of India Vs Pallabh Bhowmick And 4 Ors (Gauhati High Court)
The appeal before the Gauhati High Court concerned whether a bank was liable to compensate a customer for the loss of ₹94,204.80 due to fraudulent electronic transactions carried out on 18.10.2021. The Single Judge had set aside the Ombudsman’s order dated 07.03.2022—which had absolved the bank of liability—and directed the bank to deposit the disputed amount in the customer’s account, with liberty to recover it from the entity whose database had allegedly been breached. The bank challenged this direction.
The customer, holding a savings account with the bank, had purchased a garment online and sought a refund. On 18.10.2021, he received a call from a person posing as a customer care representative of the retailer. Acting on instructions, he downloaded a mobile application, after which three unauthorized online transactions totalling ₹94,204.80 were executed from his account through UPI and payment gateway modes. The money was transferred first to an account in Federal Bank and then moved further. The customer immediately informed the bank’s customer care, lodged an FIR, and filed complaints with the cybercrime authorities and National Cyber Crime Reporting Portal. He also made a written complaint to the bank on 19.10.2021.
The customer claimed he never shared OTPs, passwords, or MPIN with the fraudster and that the fraud resulted from a data breach of the retailer’s customer database, as confirmed by an email from the retailer on 16.01.2022 reporting illegal access to customer information. He approached the Ombudsman under the RBI Integrated Ombudsman Scheme, which rejected his complaint, attributing negligence to him.
The bank argued that all transactions were authenticated through OTP and MPIN, and therefore must have been completed with the customer’s credentials. It claimed that downloading an unverified app at the behest of a stranger amounted to negligence and that UPI and payment gateway transactions are secure unless credentials are compromised by the customer. It contended that the Single Judge erred in setting aside the Ombudsman’s order without calling for records and submitted that the bank could not be liable where customer negligence was established under RBI Circular dated 06.07.2017. The bank added that no fraudulent transfers occurred after the customer reported the issue and maintained that it took prompt action on receiving the complaint.
The customer argued that he acted bona fide, had never shared sensitive information, and was defrauded through cyber manipulation. He contended that under Clauses 8, 9 and 10 of the RBI Circular, the bank was required to reverse the unauthorized transaction within the prescribed timeline and that the Ombudsman’s order misapplied the circular. He also highlighted that the bank did not initiate any chargeback request with the beneficiary bank and had taken no steps to prevent further loss.
The Court framed the central issue as whether the loss occurred due to customer negligence or whether the bank was liable under the RBI’s Customer Protection Circular of 2017. The Court noted that the transactions were unquestionably unauthorized and fraudulent. Examining Clauses 7 to 10 of the circular, the Court observed that in cases of third-party breaches—where the deficiency lies neither with the bank nor the customer—the customer’s liability is “zero” if the fraud is reported within three working days. Even assuming the fraud resulted from a third-party breach of the retailer’s database, the customer had reported the matter to the bank within one working day.
The Court held that merely downloading a mobile app at the fraudster’s request could not establish negligence. It found no material on record showing that the customer shared OTPs or MPIN, nor any evidence demonstrating complicity. The Single Judge’s observation that it was implausible for a customer to voluntarily share sensitive credentials was affirmed. The Court noted that although the bank claimed to have taken action, the record did not substantiate this. No chargeback was initiated, no complaint was lodged with the cybercrime authority by the bank, and no concrete steps were shown to have been taken to safeguard the customer’s account. Thus, the bank failed to discharge its burden of proving negligence.
The Court affirmed that banks cannot rely on perceived negligence and must establish it with cogent evidence before denying liability. As the bank had failed to do so, it upheld the Single Judge’s direction to refund ₹94,204.80 to the customer, with liberty to recover the amount from the retailer if investigation later revealed their responsibility. The writ appeal was dismissed as devoid of merit.
Read SC Judgment: Bank Held Liable as SC Finds No Customer Negligence in Fraudulent Transactions
FULL TEXT OF THE JUDGMENT/ORDER OF GAUHATI HIGH COURT




