A Tamil Nadu woman who lost ₹50,000 in an alleged phishing scam has received significant relief after the Thanjavur District Consumer Disputes Redressal Commission ordered the bank to pay her a total of ₹1.10 lakh.

This includes a refund of the ₹50,000 lost in the fraudulent transaction, ₹50,000 as compensation for mental distress and deficiency in service, and another ₹10,000 for legal costs. The order also highlighted the duty of banks if customers report unauthorised electronic transactions and seek help when they learn about financial fraud.
The order was passed on July 28 by commission president T Sekar and member K Velumani. The consumer commission also noted that she had immediately informed the bank when she found money had been withdrawn from her account without authorisation. The bank also had not provided sufficient documents demonstrating that it had taken concrete action to secure the funds after receiving the woman's complaint to avoid further financial loss.
The case started when the woman received an SMS offering a reward of ₹12,980. She believed the message to be genuine and clicked on the link provided in the communication. She also entered her banking credentials on the linked page. She received an OTP message later on. She discovered that ₹50,000 had been debited from her account after an unauthorised beneficiary was added.
After noticing the suspicious transaction, the woman immediately contacted the bank's customer service and filed an online complaint. She also approached cybercrime authorities and reported the incident. Still, she claimed that the money had not been recovered and approached the Thanjavur District Consumer Disputes Redressal Commission to seek compensation for the loss of money and for her difficulty and distress.
The bank vehemently denied the complaint and asserted that the transaction occurred because the customer herself had entered sensitive banking information and an OTP when she clicked the phishing link. As the bank's defence pointed out, it conducted security procedures in accordance with Reserve Bank of India rules and the financial loss was due to the customer's own negligence. In other words, the bank tried to avoid responsibility for the disputed transaction.
But the consumer commission did not consider that argument sufficient to reject the woman’s complaint. The commission recognised that the woman might have inadvertently disclosed her credentials after being targeted by a phishing message, but it still considered the bank’s independent responsibility after the unauthorised transaction had been brought to its attention. The timely reporting was a key factor in assessing the case.
The court’s decision highlights a key distinction in cases involving digital banking fraud. A bank is not necessarily to be held responsible for every unauthorised transaction when customers have shared sensitive information like passwords or OTPs. But the commission’s findings indicate that a financial institution may still be expected to take appropriate and timely action after receiving a complaint about an unauthorised electronic transaction.
According to the commission, the bank had not shown what effective measures it had taken after being informed about the fraudulent transaction. The absence of sufficient evidence regarding the bank’s response contributed to the finding of deficiency in service. Therefore, the consumer body directed the bank to refund the entire ₹50,000 lost by the woman and provide an additional ₹50,000 as compensation for mental agony and deficiency in service.
The commission also ordered the bank to pay litigation costs of ₹10,000, which brings the total relief awarded to ₹1.10 lakh. The compensation component was intended to address the distress and inconvenience suffered by the woman and the alleged shortcomings in the bank’s response to her complaint.
This case serves as an important reminder for banking customers to act quickly after noticing suspicious activity.
Any unauthorised transaction that is detected should be reported to the bank immediately, reported to cybercrime authorities, and relevant evidence should be retained (such as SMS messages, transaction alerts, screenshots, and complaint acknowledgements). Prompt reporting can be important both for potential recovery efforts and for demonstrating that the customer acted without unnecessary delay.
Sophisticated phishing scams continue to exploit trust and urgency to persuade people to click on malicious links, which can expose sensitive information. Customers should avoid entering banking credentials or OTPs after following links received through unsolicited messages and should independently verify communications through official banking websites or applications.
The Thanjavur consumer commission's decision therefore carries a broader message for both customers and financial institutions. Customers must remain vigilant and protect their confidential banking information, while banks are expected to respond appropriately when unauthorised transactions are reported.
The ₹1.10 lakh award demonstrates that the circumstances surrounding a cyber fraud complaint, including how quickly it was reported and what action the bank took afterward, can be important when determining responsibility and relief.
Comments
Please to leave a comment on this article.