Suresh Chandra Singh Negi And Another Vs Bank of Baroda And Others (Allahabad High Court)
The petitioners filed a writ petition under Articles 226 and 227 of the Constitution of India seeking a mandamus directing the respondent bank to restore ₹38,78,000, which they alleged had been fraudulently withdrawn from their bank accounts. Their claim was premised on the RBI Circular dated 06.07.2017 concerning “Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions.” They also relied on two judicial precedents: the Supreme Court’s decision in State Bank of India v. Pallabh Bhowmick & Ors. in SLP No. 30677/2024, and a Bombay High Court judgment in Jaiprakash Kulkarni and others v. The Banking Ombudsman and others (W.P. No. 1150 of 2023), reported in MANU/MH/3477/2024.
The Court examined the material placed on record by the Bank, including debit logs, IP addresses, and beneficiary-addition records. These records showed that all impugned transactions were executed after the petitioners themselves logged into their net-banking accounts. The petitioners added beneficiaries, generated OTPs, and modified passwords before initiating the transfers. On this basis, the Court found that the transactions were not the result of any third-party breach or hacking, but instead were deliberate internal transfers carried out by the petitioners.
The Court further noted that the petitioners received SMS alerts regarding the transactions on 19.06.2022 yet only reported the issue on 20/21 June. This delay in lodging the complaint was viewed as indicative of an afterthought rather than immediate reporting of a genuine cyber incident.
Interpreting the RBI Circular dated 06.07.2017, the Court held that the protection under the Circular applies only in situations where the unauthorised transaction results from a third-party breach or where no negligence is attributable to the customer. The Circular cannot be invoked as a “sword” to recharacterise transactions personally initiated by an account holder as cyber-fraud. Since the record revealed the petitioners’ own involvement and gross negligence, the Circular did not support their claim.
The Court also held that the judgments relied upon by the petitioners were inapplicable. In Pallabh Bhowmick, the issue concerned a genuine third-party cyber-fraud that had been reported immediately. In Jaiprakash Kulkarni, beneficiary additions had occurred without any intimation to the customer. In contrast, in the present case, the bank’s internal records clearly demonstrated that the petitioners themselves added the beneficiaries and conducted the transactions. Accordingly, neither precedent assisted the petitioners.
Finding no evidence of hacking or external breach and holding that the petitioners failed to establish any unauthorised electronic banking transaction as contemplated under the RBI Circular, the Court concluded that there was gross negligence attributable to the petitioners. Consequently, the High Court dismissed the writ petition.




