Tamil Nadu consumer commission ordered bank to pay Rs 1.10 lakh.
Customer lost Rs 50,000 after falling for phishing scam.
Commission held bank responsible for failing to act promptly.
Tamil Nadu consumer commission ordered bank to pay Rs 1.10 lakh.
Customer lost Rs 50,000 after falling for phishing scam.
Commission held bank responsible for failing to act promptly.
The Thanjavur District Consumer Disputes Redressal Commission in Tamil Nadu has directed a bank to pay Rs 1.10 lakh to a customer who lost Rs 50,000 in a phishing scam.
The commission ordered the bank to refund the Rs 50,000 deducted from the customer’s account, pay Rs 50,000 as compensation and Rs 10,000 towards litigation expenses.
The commission passed the order on July 28, holding that the bank failed to take adequate action after the customer promptly reported the unauthorised transaction, according to a news report by the Indian Express.
The commission observed that the failure amounted to a deficiency in service under Section 2(11) of the Consumer Protection Act, 2019.
According to the complaint, the customer received an SMS offering a reward of Rs 12,980. She clicked on a link in the message and entered her banking credentials.
She later received an OTP message. Soon after, Rs 50,000 was debited from her account through the addition of an unauthorised beneficiary.
The customer contacted the bank’s customer care immediately after discovering the transaction. She also lodged an online complaint and approached the cybercrime authorities.
The bank, however, disputed the complaint and argued that the transaction took place after the customer entered her username, password and OTP on the phishing website. It maintained that it had followed the security procedures prescribed by the Reserve Bank of India (RBI) and that the loss resulted from the customer’s negligence.
The commission noted that the customer had informed the bank immediately after discovering the unauthorised debit. It also observed that the bank did not produce documents showing what steps it had taken after receiving the complaint.
The commission held that even if the customer had inadvertently disclosed her credentials after falling for a sophisticated phishing attack, this alone did not remove the bank’s responsibility to act on her immediate complaint.
It also observed that banks cannot automatically attribute every unauthorised digital transaction to customer negligence, particularly when the customer promptly reports the incident.
The commission found that the customer had faced financial hardship, mental agony and inconvenience following the incident. It therefore allowed the complaint and ordered the bank to provide a total relief of Rs 1.10 lakh.
The order includes Rs 50,000 as a refund of the disputed transaction, Rs 50,000 as compensation and Rs 10,000 towards litigation costs.
This incident has pointed to the importance of promptly reporting unauthorised digital transactions to banks. It also underscores that a bank’s responsibilities do not end solely because a customer’s credentials were used in a fraudulent transaction.