Bombay HC Reinforces RBI Circular for protectioCyber Fraud Victims
Cyber Fraud of Rs.38 lakhs from two HDFC Bank accounts
Judgment dated 8.4.2026 of the High Court of Bombay in Civil Writ Petition No.11990 of 2023 of Subodh C. Korde Vs. Union of India and others
The Petitioner, a freelancer in Business Consultancy, has approached this Court stating that he is a victim of Cyber fraud and a sum of Rs. 38,04,000/- was unauthorizedly withdrawn from his two bank accounts maintained with HDFC Bank Ltd., in a time gap of 41 minutes. According to the Petitioner, he was defrauded by the online unauthorized withdrawals, the transactions being permitted by the Bank and his grievance is, the HDFC Bank has refused to reverse the amount to his account, which according to him is in complete breach of applicable directions /guidelines issued by the Reserve Bank of India (“RBI”).
It is the specific case of the Petitioner that no OTPs was received by him from HDFC Bank for both the activities i.e. addition of beneficiaries or enhancement of transfer limit. Although the security system of the HDFC Bank flagged and alerted, the addition of these beneficiaries and the alert recommended ‘Decline add payee’ and also alerted “Transaction IP does not match with genuine transaction IP of customer” the addition of beneficiaries was manually approved by the Bank.
In the report submitted by Wakad Police Station on 23/12/2021, the Police Inspector, addressed a communication to Branch Manager, HDFC Bank, where he specifically stated 10/100 WP-11990-23.odt that no error or negligence was found against Mr. Subodh Korde.
The Banking Ombudsman closed the complaint of the petitioner on 28.3.2022.
Circular dated 6.7.2017 of the RBI on the subject, ‘Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions’ has limited the liability of the customers, where unauthorized transaction result in debit of their accounts and his liability is zero on the occurrence of events mentioned therein.
Clauses 9 and 10 of the said Circular for the reversal Timeline for Zero Liability / Limit Liability of Customer.
RBI has directed the banks to put in place a suitable mechanism and structure for the 13/100 WP-11990-23.odt reporting of the customer liability cases to the Board and a mechanism has been clearly chalked out for reviewing the unauthorized electronic banking transactions reported by the customers or otherwise, as also the action taken thereon, alongwith the functioning of the Grievance Redressal Mechanism and steps taken to improve the systems and procedures.
In fixing the liability on the customer, in case of unauthorised transaction, the Reserve Bank has bifurcated liability into two types; ‘zero liability’ and ‘limited liability’. A customer’s entitlement to zero liability is said to arise when the unauthorised transaction involving third party breach where the deficiency lies neither with the bank nor with the customer but lies elsewhere in the system, and the customer notifies the bank within three working days of receiving the communication from the bank regarding the unauthorised transaction.
The Reserve Bank of India, on 18/02/2021,has issued the Master Direction on Digital Payment Security Controls, by formulating it in form of the Reserve Bank of India (Digital Payment Security Controls) Directions, 2021, which are specifically made applicable to the Scheduled Commercial Banks, Small Finance Banks, Payment Banks and Credit card issued NBFCs.
In our view, the circular of the RBI dated 06/07/2017 is independent of any criminal investigation to be conducted to establish any cyber crime, as the RBI intended to protect the customer who has suffered financial loss on account of fraudulent or unauthorized electronic banking transactions. Without even a semblance of reference to any cyber investigation, the RBI deemed it appropriate to issue directions for limiting the liability of the customers in unauthorized electronic banking transactions and particularly, when the customer is not at fault. The burden to establish that the customer is at fault is on the bank and once a customer has notified the bank about the fraudulent transaction, from the date when he received communication from the bank, it is imperative for the bank to credit the amount involved in the unauthorized electronic banking transaction to the customer’s account and if the reporting is within three days, then the liability of the customer is zero.
In no case, we put the blame of the unauthorized transactions on the Bank, but when the fault is neither with the Bank nor with the customer/Petitioner, the RBI circular dated 06/07/2017 and in particular, the clause fixing zero liability on the customer gets triggered and the Petitioner is entitled for its benefit.
Since the Bank had denied him the benefit, despite clear directions from the RBI, we deem it appropriate to direct HDFC bank to remit the amount of Rs.38,04,000/- to the Petitioner’s account within a period of eight weeks alongwith interest at the rate of 6% p.a., as for no fault of his, the Petitioner was deprived of his own money. The HDFC Bank shall make the aforesaid remittance within a period of eight weeks and if it failed to do so within the aforesaid period, it shall carry interest at the rate of 8% p.a.

