New Delhi: If a person is tricked by an online scam and transfers money to fraudsters, the question of who should bear the loss is not always straightforward. A recent consumer commission ruling involving ICICI Bank has highlighted that a bank may still face liability if it fails to meet its regulatory responsibilities, even when transactions were authenticated by the customer.
The Nagpur District Consumer Disputes Redressal Commission directed ICICI Bank to refund Rs 5,18,437, along with 9% annual interest, Rs 25,000 for mental agony and Rs 10,000 towards litigation costs. The case involved a woman who lost nearly Rs 6.93 lakh in a FedEx parcel scam.
However, the ruling should not be interpreted as a blanket rule that banks must compensate customers whenever they voluntarily transfer money to scammers.
What happened in the FedEx parcel scam
The incident took place on January 8, 2023, when a woman from Gurugram reportedly received a call from someone claiming to be a FedEx executive.
The caller allegedly told her that a parcel booked in her name contained two passports, five ATM cards, 300 grams of cannabis and a laptop. When she denied having sent the parcel, the fraudster allegedly claimed that her identity had been misused and threatened her with police action.
Fearing legal consequences, the woman transferred money in four separate transactions to an ICICI Bank account controlled by the alleged scammer.
The transfers amounted to Rs 6,93,437.50, according to the complaint.
Bank initially provided temporary credit
After realising that she had been defrauded, the woman contacted ICICI Bank and reported the incident. She was also advised to report the matter through the National Cyber Crime Reporting Portal and filed a police complaint.
The bank initially provided a temporary or “shadow” credit for the disputed amount.
However, the bank later reversed the credit, arguing that the transactions had been authenticated using OTPs and were therefore authorised by the customer.
The woman subsequently approached the Banking Ombudsman. She received relief relating to around 25% of the disputed amount but sought recovery of the remaining Rs 5,18,437 through the consumer commission.
Why the consumer commission held the bank liable
ICICI Bank argued that the matter arose from a criminal cyber fraud and that the consumer commission should not entertain the complaint.
The commission rejected that argument.
It distinguished between the criminal act committed by the fraudsters and the separate question of whether the bank had fulfilled its own regulatory and service obligations.
The commission noted that banks are required under RBI’s KYC framework to continuously monitor customer accounts and identify unusual or suspicious transactions. It concluded that ICICI Bank had failed to adequately monitor the transactions or respond quickly enough after the fraud was reported.
The bank was therefore held responsible for deficiency in service and negligence in the circumstances of the case.
Does sharing an OTP mean the bank never pays?
Not necessarily.
This is one of the most important takeaways from the case.
A customer voluntarily entering an OTP or approving a payment can make a bank’s defence stronger because the transaction appears to have been authenticated.
But authentication alone may not settle every dispute.
The consumer commission’s reasoning focused on whether the bank had fulfilled its independent responsibilities, including monitoring transactions and responding appropriately to suspicious activity.
The circumstances of each case therefore matter, including the nature and pattern of transactions, how quickly the fraud was reported and whether the bank’s systems should reasonably have detected unusual activity.
RBI rules on unauthorised transactions
The RBI has a separate framework governing unauthorised electronic banking transactions.
Under the RBI’s customer-protection framework, customers can have zero or limited liability in specified circumstances. The rules also place the burden of proving customer liability on the bank in cases of unauthorised electronic transactions.
This framework is different from a situation where a customer is deliberately or unknowingly persuaded by a scammer to authorise a payment.
That distinction is crucial.
A transaction made by a fraudster without the customer’s authorisation is not the same as a transaction that the customer personally approves after being deceived.
RBI strengthens digital fraud protection
The RBI has also strengthened its framework for unauthorised electronic banking transactions in 2026.
The revised framework introduces a compensation mechanism and strengthens safeguards relating to cyber fraud, mule accounts and fraud monitoring. The government said the changes are intended to improve customer protection while encouraging banks to strengthen their fraud-detection systems.
The updated approach also places greater emphasis on technology-driven fraud analytics and faster responses to suspicious transactions.
What customers should do after a scam
The most important step after discovering a fraudulent transaction is to contact the bank immediately.
Customers should report the transaction through the bank’s designated fraud-reporting channel and preserve evidence such as:
- Transaction details and bank statements
- SMS and email alerts
- Phone numbers used by the scammers
- WhatsApp chats and screenshots
- Payment confirmations
- Details of the scammer’s bank account or UPI ID
- Any documents or links shared by the fraudster
The incident should also be reported to the appropriate cybercrime authorities.
Speed matters because the possibility of recovering funds can depend on how quickly the fraudulent money is identified and frozen in the banking system.
Do not assume every scam loss will be refunded
The recent ICICI Bank ruling should not be treated as an automatic reimbursement guarantee.
If a customer is tricked into making a payment, the bank can examine whether the transaction was authorised, whether the customer followed security requirements and whether the bank’s own systems detected or should have detected suspicious activity.
The consumer commission ruling is significant because it shows that customer authentication does not necessarily end the question of bank responsibility.
At the same time, customers cannot assume that every payment made after an OTP or PIN is automatically recoverable.
The role of banks in detecting suspicious transactions
Banks increasingly rely on automated systems to identify unusual activity.
These systems can examine factors such as transaction value, frequency, beneficiary details, account behaviour and deviations from a customer’s normal transaction pattern.
The recent ruling highlights why these systems matter.
If an account suddenly receives or sends unusual amounts, particularly where the activity is inconsistent with its previous behaviour, banks may need to investigate or take appropriate action under applicable rules.
Online scams are becoming more sophisticated
Fraudsters increasingly use impersonation and psychological pressure rather than relying only on technical hacking.
Courier scams, fake police calls, digital-arrest threats, investment scams, bank impersonation and fake customer-service calls are designed to make victims act quickly before they have time to verify the information.
In many cases, the victim technically initiates the transaction but does so because of deception.
That creates a complicated legal and regulatory question: whether the transaction should be treated simply as a customer-authorised payment or whether the circumstances indicate a failure of fraud-prevention and monitoring safeguards.
What the ruling means for customers
The Nagpur consumer commission’s order offers an important lesson for bank customers: reporting a scam immediately and creating a clear record of the complaint is critical.
It also demonstrates that customers may have avenues for seeking compensation when they believe a bank failed to fulfil its regulatory or service obligations.
However, the outcome will depend on the facts of the individual case.
Customers should therefore not deliberately authorise suspicious payments on the assumption that the bank will eventually reimburse them.
Conclusion
The recent ICICI Bank case shows that the question of who pays after an online scam can depend on more than whether a customer entered an OTP.
The Nagpur District Consumer Disputes Redressal Commission found the bank liable for deficiency in service and negligence and ordered it to refund Rs 5.18 lakh, with interest and compensation, after a woman lost Rs 6.93 lakh in a FedEx parcel scam.
At the same time, the ruling does not mean that banks must automatically reimburse customers for every scam in which they voluntarily transfer money.
RBI’s separate customer-protection rules for unauthorised electronic transactions provide important safeguards, while the latest 2026 framework strengthens fraud monitoring and customer protection.
For customers, the safest approach is to report suspicious transactions immediately, preserve all evidence and cooperate with the bank and cybercrime authorities.
