Skip to main content

When Banks Compromise, Cyber Criminals Capitalize, and Courts Penalize!

Cyber fraud is something most of us have encountered, either as victims or witnesses. But what happens when a bank’s negligence facilitates such fraud? In a recent ruling, the adjudicating authority (AA) under the Information Technology (IT) Act has set a precedent for accountability in the banking sector. On 21st January 2025, in Complaint Case No. 3 of 2019, the principal secretary of IT for Maharashtra state and the AA under the IT Act ordered Axis Bank to pay Rs 1.76 crore with 18% interest, Rs 50 lakh as compensation, and Rs 3 lakh in legal costs to Dhule Vikas Sahakari Bank (DVSB) for unauthorized transactions caused by the bank’s negligence.

Under the IT Act, the AA, who is the state IT secretary, has the authority to adjudicate cyber fraud cases involving claims for injury or damage up to Rs 5 crore. The AA has powers of a civil court and can hear complaints related to violations under the IT Act. Victims of cyber fraud, whether individuals or entities, can approach the AA for redressal.

This case involved unauthorized transactions amounting to Rs 2.06 crore from DVSB’s account on 7-8 June 2020, between 7 am and 10 am—outside the cooperative bank’s working hours. Interestingly, neither the maker nor the checker—two different individuals using separate mobile numbers—received the one-time passwords (OTPs) required to authorize these transactions. The AA found Axis Bank guilty of failing to maintain reasonable security safeguards, as required under Section 43A of the IT Act, and for non-compliance with Reserve Bank of India (RBI) guidelines. Lapses included the absence of real-time fraud detection mechanisms and failure to verify KYC details of beneficiary accounts where the stolen funds were transferred, including those at ICICI Bank and HDFC Bank.

Although Axis Bank argued that the fraud occurred due to remote access software installed on DVSB’s systems, the AA dismissed this defence, noting contradictory claims and unreliable evidence. The ruling highlights the importance of banks ensuring robust data protection and adherence to security regulations.

This judgment actually tells us that victims of cyber fraud can seek justice through the AA, ensuring that financial institutions/ banks are held accountable for lapses in cyber security.

[The author can be contacted at gupta.ampslegal@gmail.com. Readers should not act on the basis of this information without seeking professional legal advice.]

Comments

Popular posts from this blog

Maintenance Charges Default: No Water, No Sympathy

In what can only be described as a case of forum shopping (trying to find the friendliest court), an apartment owner in Shiv Vihar CHS, Dombivali (East), took his complaints on a legal tour. The petitioner, Vilas Gopal Dongare member of the society was unhappy. Why? Because his water supply was cut off. The reason? He had not paid his maintenance bills, which had piled up to a whopping Rs. 7 Lakhs! Despite making several complaints about the alleged harassment by the society and even a water tank causing structural issues in his building, his cries were heard and promptly dismissed. The Maharashtra State Human Rights Commission looked into his case and, on 05.02.2020, decided it was not a human rights violation. They said, “Pay your bills first.” The society initiated proceedings under Section 101 of the Maharashtra Co-operative Societies Act, 1960 (MCS Act) to recover arrears and got a Recovery Certificate issued in its favour. When the petitioner’s appeal against this certificate wa...

AMORTISED COST CALCULATION: THE EFFECTIVE INTEREST RATE (EIR)

IAS 39 mandates some financial assets and liabilities to be subsequently measured at ‘amortized cost’.  This measurement concept is a management theory put in accounting practice. It means that the contractual interest rate each period should be adjusted to amortize the transaction costs over the expected life of the financial instrument. The amortization is calculated on an effective interest rate (EIR) / yield-to-maturity (YTM) basis. The EIR is the rate that exactly discounts the stream of principal and interest cash flows excluding any impact of credit losses, to the initial net proceeds. It is important to note that EIR method does not take into account any future credit impairments anticipated on that instrument. The carrying amount of the financial instrument subsequently measured at amortized cost is computed as: Transaction costs are an integral part of the amortized cost calculation. They are defined as costs that are directly attributable to the acquisit...

Court Upholds Co-operative Membership Transfer with Release Deed

In the case of Bima Nagar Co-operative Housing Society Ltd. v. Divisional Joint Registrar & Ors. WP 10768 of 2024 , the Bombay High Court on 23.09.2024 dismissed the society’s petition challenging the membership transfer to Pushpa Morey, a widow, following her husband's death. Initially, Pushpa was granted provisional membership but was later denied full membership by the society. Pushpa applied for full membership after her husband's passing. When the society refused, she sought help from the Deputy Registrar, who ordered that the society admit her as a full member under Section 22(2) of the Maharashtra Co-operative Societies Act, 1960. The society’s appeal to the Divisional Joint Registrar was unsuccessful, prompting the writ petition in the Bombay High Court. The society argued that the "family arrangement" concept under Section 154B-13 of the Maharashtra Co-operative Societies Act applies only to a Hindu Undivided Family (HUF). Pushpa, however, contended tha...