What is my liability if fraudsters make an unauthorised transaction from my bank account?
Someone made an unauthorised online transaction from my account through phishing and I reported it to my bank promptly. I want to know how much of the loss I have to bear. I have been reading conflicting things online and I would like to understand what Indian law actually says about this, which Act and Section applies, what the realistic timelines and costs are, and what I should be doing right now to protect my position. If the matter can be resolved without litigation I would prefer that route, but I want to know what my rights are before I agree to anything or sign any document.
What is my liability if fraudsters make an unauthorised transaction from my bank account? is governed in India primarily by RBI Circular on Customer Protection - Limiting Liability of Customers in Unauthorised Electronic Banking Transactions, 2017, Information Technology Act 2000, Section 43, Consumer Protection Act 2019, Section 2(11) and RBI Master Circular on Customer Service in Banks. The short answer is set out below, followed by the practical steps most people in this situation need to take. Read it alongside the specific provisions named, because the exact relief available to you turns on the facts you can prove on paper.
The RBI's 2017 circular on limiting customer liability provides that if the customer reports an unauthorised electronic transaction within three working days of receiving the communication from the bank, the customer bears zero liability regardless of who was at fault.
If the report is made between four and seven working days, the customer's liability is capped at a limited amount depending on the type of account, and beyond that period liability is determined as per the bank's board-approved policy.
The bank must credit the disputed amount to the customer's account within ten working days of the complaint, even before completing its own investigation, to protect the customer from being deprived of funds during the inquiry.
Section 43 of the Information Technology Act 2000 makes unauthorised access to a computer resource or account actionable, and the bank as the entity responsible for the security of its digital channels can be held liable if its system safeguards were deficient.
A bank's failure to credit the shadow amount within the prescribed period or to correctly apply the zero/limited liability framework is a deficiency in service under Section 2(11) of the Consumer Protection Act 2019, entitling the customer to a consumer complaint for the balance amount and compensation.
What to do next: 1) Report the unauthorised transaction to the bank by phone or email immediately and follow up with a written complaint; 2) Also register a complaint on the National Cyber Crime Reporting Portal (cybercrime.gov.in) or dial 1930; 3) Check that the shadow reversal credit is made to your account within ten working days as mandated by RBI; 4) File a complaint with the RBI Integrated Ombudsman or the consumer commission if the bank denies the zero/limited liability protection.
If the other side has already issued a notice, filed a case or set a deadline, treat the matter as time-sensitive — most remedies under RBI Circular on Customer Protection - Limiting Liability of Customers in Unauthorised Electronic Banking Transactions, 2017 carry limitation periods, and a delay you cannot explain weakens an otherwise strong case. You can post the details on the MyVakeel forum for a practising advocate to review, or book a paid consultation with a Bar Council verified lawyer in this practice area.
Disclaimer: This information is for general awareness and does not constitute legal advice. Statutes and their interpretation change, and outcomes depend on the facts of your case. Please consult a qualified advocate before acting on it.