Online Bank Fraud

    If you have lost money while performing an online transaction or have been a victim of online fraud, you have the right to take measures to recover your money. You can also file a criminal complaint against the offender.

    Customer’s Right to be Protected

    As a customer of a bank, you have the following rights so as to be protected from online bank fraud:

    • The right to register and receive SMS notification of all electronic banking transactions that take place through your account.
    • The right to register and receive email alerts for electronic banking transactions through your account.

    Lodging a complaint with the bank

    Most banks have staff dedicated to matters like this. The relevant contact details are found on the backside of your card as well as the website of the bank. Telephone numbers of help desks are also displayed at every ATM machine.

    If you have suffered a loss you must immediately contact the banks via phone (preferable) or email. Do not forget to note the complaint number and follow up your complaint using the same number. The bank should acknowledge your email.

    The Code of Bank’s Commitment to Customers (CBCC) enacted by the Banking Codes and Standards Board of India (BCSBI) mandates each bank branch to display the name of the official at the bank branch responsible for addressing customer grievances.

    If your complaint is unresolved at the branch level, you may approach the Regional or Zonal Manager or the Principal Nodal Officer (PNO) at the address displayed at the branch.

    Typically, within 30 days of receiving the complaint, the bank will send you a final response or explain why more time is needed to investigate. The Bank will also tell you the process to take the complaint forward in the event you are still unsatisfied after the final response from the bank.

    Filing a complaint with the Banking Ombudsman in your jurisdiction

    If you are not satisfied with the solution provided by the bank and would like to further enquire the matter, you can approach the Banking Ombudsman established by the Reserve Bank of India under the Banking Ombudsman Scheme, 2006. Each bank is required to display at its branch the details of the Banking Ombudsman under whose jurisdiction the branch falls. Complaints may be lodged with the respective Banking Ombudsman here.

    You can only do this once you have tried to settle matters with the bank, and failed. If you file a case in Court, such as the Consumer Court, you cannot approach the Ombudsman while the case is going on.

    If you are not satisfied with the decision of the Banking Ombudsman, you may approach the appellate authority against the Ombudsman’s decision – the Deputy Governor, Reserve Bank of India. This appeal must be made within 30 days of the Ombudsman’s decision.

    Filing a complaint with the nearest cyber crime cell/police station

    This may either be done in person, or in some states, through an online portal.

    Filing a case with the relevant consumer forum

    The Consumer Forum is present at the District, State and National Levels. You can file a case there depending on 2 factors:

    1. The amount of money you lost:
      • District Forum : Upto Rs. 20 Lakhs
      • State Commission : Rs. 20 Lakhs to Rs. 1 Crores
      • National Commission : Exceeding Rs. 1 Crores
    2. Where the loss happened :
      • You can file the complaint in the place where the money was lost, or where the opposite party (that is, the bank) carries on their business.

    You should approach consumer forums only when you feel that the bank has been negligent, and has not given you proper service. The forum does not prosecute the actual culprit.

    Generally, cases cannot be simultaneously filed before the consumer courts as well as the Banking Ombudsman.

    Banks Responsibility to Prevent Online Bank Fraud

    Banks must ask their customers to mandatorily register for SMS alerts for electronic banking transactions. Wherever available, they must ask their customers to register for e-mail alerts, for electronic banking transactions.

    The SMS alerts shall mandatorily be sent to the customers, while email alerts may be sent, wherever registered in the event of an electronic banking transaction. To facilitate the customers to report any unauthorized use of their electronic banking services, banks must provide customers with 24x7 access through multiple channels (at a minimum, via website, phone banking, SMS, e-mail, Instant Voice Response, a dedicated toll-free helpline, reporting to home branch, etc.) for reporting unauthorised transactions that have taken place and/ or loss or theft of payment instrument such as card, etc. Banks have to also enable customers to instantly respond by 'Reply' to the SMS and e-mail alerts so that the customers are not required to search for a web page or an e-mail address to notify the objection to an electronic transaction.

    Banks have to also provide a direct link for lodging the complaints, with specific option to report unauthorised electronic transactions on the home page of their website. The loss/ fraud reporting system should ensure that immediate response (including auto response) is sent to the customers acknowledging the complaint along with the registered complaint number. The banks must record the time and date of delivery of the alerts and receipt of customer’s response, if any.

    The banks cannot offer facility of electronic transactions, other than ATM cash withdrawals, to customers who do not provide mobile numbers to the bank. On receipt of report of an unauthorised transaction from the customer, banks must take immediate steps to prevent further unauthorised transactions in the account

    Reversing an Unauthorized Transaction

    After receiving the notification from the customer of the unauthorized transaction, the bank will reverse the transaction and will credit the amount involved in the authorized electronic transaction. This should be done within 10 working days from the date of the receipt of notification from the customer. The banks should not wait for settlement of insurance claims to do this. The Bank will credit the money as per the value as of the date of the unauthorised transaction.

    Customer’s Responsibility

    The customers must be advised to notify their bank of any unauthorised transaction as soon as they can or at the earliest possible opportunity. The longer the time taken to notify the bank, the higher will be the risk of loss to the bank/ customer.

    The Bank will note the time of the sms sent notifying the customer of the electronic banking transaction and the sms/response received by the customer. This is done to ascertain the extent of a customer’s liability.

    Customer Liability

    The customer must not reveal/share payment credentials with any third party. If a customer does this then the customer’s liability will increase because of his or her negligent actions. It is the bank’s responsibility to prove that the customer is liable (to whatever degree) in case of unauthorised electronic banking transactions. At their discretion Banks may also decide to waive off any customer liability in case of unauthorised electronic banking transactions. They can do this even in cases of customer negligence.

    The customer will incur zero liability when:

    • There is an unauthorized transaction due to contributory fraud or negligent behaviour or deficiency in the bank’s services. If you don’t report the unauthorized transaction to the bank, it does not matter because the zero liability occurs whether or not you report it.
    • There is a breach but it is not with the customer or bank, but somewhere else in the system. In this case, you should notify the bank within three working days of receiving communication about the unauthorized transaction.

    The customer will incur limited liability if there is a delay of four to seven working days after receiving the communication from the bank about the unauthorized transaction, in such a situation the per transaction liability of the customer will be limited to the transaction value or the amount mentioned in this Table below, whichever is lower.

    Maximum Liability of a Customer

    The maximum a customer of a Basic Savings Bank Deposit Account can be liable for is Rs 5,000.

    All other Savings Bank Accounts, Pre-paid Payment Instruments and Gift Cards, Current/ Cash Credit/ Overdraft Accounts of Micro, Small and Medium Enterprises, Current Accounts/ Cash Credit/ Overdraft Accounts of Individuals with annual average balance (during 365 days preceding the incidence of fraud)/ limit up to Rs.25 lakh. Credit cards with limit up to Rs.5 lakh, the maximum they are liable for is Rs. 10,000

    For all other Current/ Cash Credit/ Overdraft Accounts and credit cards with limit above Rs.5 lakh, they can be liable up to Rs 25,000.

    If the delay is for more than seven working days, the customer liability will be determined as per the Bank’s Board Policy:

    • Banks should provide the details of their policy in regard to customers’ liability formulated at the time of opening the accounts.
    • Banks should also display their approved policy in public domain for wider circulation.
    • The existing customers must also be individually informed about the bank’s policy.
    Questions and Answers
    Click on a question to view the answer

    The Code of Bank’s Commitment to Customers says that you will have to be reimbursed by the bank, if you inform the bank promptly. Your maximum loss should never be more than Rs. 25,000 - for example, for a fraudulent withdrawal of INR 50,000 the bank will make good your loss of INR. 25,000, and you will only have bear the loss of INR 25,000. This limit will NOT apply if you have acted fraudulently or negligently or have contributed to the disclosure of/unauthorized access to information.

    Electronic Banking Transaction
    Electronic Banking Transaction, also known as internet banking, e-banking or virtual banking, or online banking is a payment system that enables customers of a bank or other financial institutions to conduct a range of transactions through electronic means. It can be understood in contrast to branch banking which was the traditional way customers accessed banking services.
    Customer’s Liability
    A customer who has been subject to online bank fraud will have to bear the loss of the online bank fraud in certain circumstances
    Unauthorized User
    An unauthorized user is a person who is transacting online with your personal details without your permission.
    Internet Banking
    A method of banking in which transactions are conducted electronically via the Internet
    Consumer Court
    Consumer Court is the special purpose court, in India, that deals with cases regarding consumer disputes and grievances. These are judiciary hearings set up by the government to protect the consumer rights. Its main function is to maintain the fair practices by the sellers towards consumers.
    Basic Savings Bank Deposit Account
    A Basic Savings Bank Deposit Account is an account which is a basic bank account without any minimum balance requirement. The services available in this account include deposit and withdrawal of cash at bank branch as well as ATMs; receipt/credit of money through electronic payment channels or by means of deposit/collection of cheques drawn by Central/State Government agencies and departments. To know more please look here.
    Prepaid Payment
    Instruments Prepaid payment instruments are methods that facilitate purchase of goods and services against the value stored on such instruments. The value stored on such instruments represents the value paid for by the holder, by cash, by debit to a bank account, or by credit card.
    Gift Card
    A gift card is a type of prepaid payment instrument.
    Current Account
    The Current Account is a transactional non-interest bearing account wherein a deposit is placed with the Bank for an unspecified period of time and the depositor can withdraw or transfer the funds whenever required through different means.
    Cash Credit
    A cash credit is a short-term cash loan to a company. A bank provides this type of funding, but only after the required security is given to secure the loan. Once a security for repayment has been given, the business that receives the loan can continuously draw from the bank up to a certain specified amount.
    Micro Enterprise
    A micro enterprise is an enterprise where investment in plant and machinery does not exceed Rs. 25 lakh
    Small Enterprise
    A small enterprise is an enterprise where the investment in plant and machinery is more than Rs. 25 lakh but does not exceed Rs. 5 crore
    Medium Enterprise
    A medium enterprise is an enterprise where the investment in plant and machinery is more than Rs.5 crore but does not exceed Rs.10 crore.
    Credit Cards
    A small plastic card issued by a bank, building society, etc., allowing the holder to purchase goods or services on credit.
    Overdraft Accounts
    It is a type of account in which you can withdraw money even if there are no funds in your account. The bank sanctions a specific limit and you can withdraw money up till limit.