Unprecedented Cyber Fraud of Banking & Telecom
Order 6.8.2026 dated of the Adjudicating Officer in Complaint No.18 of 2015 of M/s. G.D. Apte & Com Vs. Bank of India, Idea Cellular Limited, Beneficiary Banks and Unknown Persons
CA Firm established in 1958 has filed the complaint under Section 46 of the Information Technology Act, 2000, against Bank of India, Idea Cellular lImited, Beneficiary Banks and Unknown Persons.
he Complainant has approached this Authority alleging, inter alia, failure on the part of the concerned Respondents to adopt and maintain reasonable security practices in relation to its electronic banking facility, resulting in unauthorized access to its banking accounts and consequent unauthorized electronic fund transfers. The Complainant has invoked, inter alia, the provisions of Sections 43, 43A and 85 of the Information Technology Act, 2000. The original complaint was presented before this Authority under the Information Technology Act, 2000.
The internet banking facility of the Bank of India was taken only for the current account. However, such internet facility was not taken for the overdraft account. Thus, any operation of the internet banking for the overdraft account was outside the authority and mandate given to the Bank of India.
There user-wise RTG transaction limit of Rs.50,00,000/- as the maximu cumulative debit limit in a month.
The Complainant was a Corporate User Group (CUG) customer of Idea Cellular Ltd., with post-paid mobile connections for its partners and employees, and that the aforesaid mobile number was being used for receiving banking alerts and One-Time Passwords (OTPs).
On 10.3.2015, the said bank mobile number suddenly became non-functional both for incoming and outgoing communication without any request by the complainant. The complainant asked the mobile company for replacement of the SIM Card. However, it was upon various regulatory and contractual safeguards, including the Banking Codes and Standards Board of India (BCSBI) Code of Bank’s Commitment to Customers, the Reserve Bank of India’s RTGS Systems Regulations, 2013, and the RBI’s circular dated 28 February 2013 concerning security and risk-mitigation measures for electronic payment transactions. found that duplicate SIM Card was issued to an unauthorized third party on 10.3.2015, without prior verification and authority of the complainant.
Not only that but on 11.3.2015, while checking the balance of the current account, it was found that an amount of Rs.6,60,000/- was unauthorizedly transferred. This was brought to the notice of the Bank. Moreover, there was unauthorized transfer of Rs.78,93,000/- from the overdraft account of the complainant. FIR in respect of the cyber fraud and unauthorized transactions with the police.
HELD The Authority therefore holds that the respective failures of Respondent Nos. 1 and 2 were distinct in their nature but interconnected in their effect, and both materially contributed to the occurrence of the unauthorised electronic transactions. Respondent No. 1, having failed to effectively enforce the prescribed banking authorisation and transaction-limit controls, is liable for the financial loss established in the proceedings, whereas Respondent No. 2 is liable for the security lapse attributable to the SIM replacement process. The respective liability is accordingly determined under Section 43A of the Information Technology Act, 2000, having regard to the nature, extent and evidentiary basis of the individual lapses established against each Respondent.

