Bank OTPs were sent to duplicate SIM card instead of real one, audit company loses Rs 79 lakh; Bank of India ordered to pay Rs 1.5 crore

An IT Act adjudicating authority has ordered Bank of India to pay Rs 64.44 lakh, which works out to nearly Rs 1.5 crore with 12% annual interest, to a Pune-based audit firm that lost close to Rs 79 lakh in a 2015 cyber fraud. The fraud followed th...

Bank OTPs were sent to duplicate SIM card instead of real one, audit company loses Rs 79 lakh; Bank of India ordered to pay Rs 1.5 crore.

A Pune-based audit firm lost close to Rs 79 lakh to cyber fraudsters after they managed to get a duplicate SIM card issued in place of the firm's own registered mobile number, and used it to intercept the OTPs meant to protect its bank account. According to a report by the Times of India, an adjudicating authority under the Information Technology Act, 2000 has now held Bank of India primarily responsible for the loss and ordered it to pay compensation with a decade's worth of interest attached.

The order relates to a 2015 cyber fraud in which G D Apte & Co, a Pune-based chartered accountancy and audit firm, saw its accounts at Bank of India drained through a series of unauthorised transactions carried out over a single day. The authority has directed the bank to pay Rs 64.44 lakh along with 12% annual interest, a figure that, once calculated over ten years, brings the total payout to nearly Rs 1.5 crore.



How the fraud unfolded
Per the Times of India report, the trouble began on March 10, 2015, when the firm's registered mobile number suddenly stopped working. The firm had no way of knowing at the time that a duplicate SIM card linked to that very number had already been issued to someone posing as its authorised representative. Once activated, this duplicate SIM began receiving all the banking alerts and one-time passwords that were meant to reach the firm's own phone, effectively handing the fraudsters a direct line into its account security.

The very next day, March 11, 2015, 13 unauthorised RTGS transactions were carried out in quick succession. One transfer of Rs 6.6 lakh was made from the firm's current account, while the remaining 12 transactions, adding up to Rs 78.93 lakh, were pushed through from its overdraft account. By the time the fraud was detected, only around Rs 14 lakh could be recovered, leaving the firm to pursue the rest of its loss through legal channels for close to a decade.

Bank's own security checks found wanting
ADVERTISEMENT
The adjudicating authority placed the larger share of blame on Bank of India, holding that it had failed to properly enforce its own internal safeguards. As per the arrangement agreed with the firm, any transaction was required to be initiated by a designated user and then authorised by two senior-level users before it could go through, a system commonly known as maker-checker authorisation. Cyber lawyer Prashant Mali, cited in the Times of India report, pointed out that the records placed before the authority did not establish that this process had actually been followed at the time the fraudulent transactions took place.

Adding to the bank's troubles, the firm's account carried an agreed monthly ceiling of Rs 50 lakh on RTGS transfers. Despite this cap, nearly Rs 79 lakh moved out of the overdraft account alone, and the bank was unable to satisfactorily explain how transactions of this scale slipped past a limit that should have stopped them. This gap between the agreed safeguard and what actually happened formed a central plank of the authority's finding against the bank.

Telecom operator fined over lax SIM verification
Idea Cellular Ltd, now known as Vodafone Idea Ltd, was separately held liable and ordered to pay Rs 5 lakh as compensation. The authority found that the telecom operator had failed to adequately verify the identity documents, letterhead and stamp presented by the individual who obtained the duplicate SIM in the firm's name. However, its liability was treated as contributory rather than primary, since the company had no role in either initiating or processing the fraudulent bank transactions itself. The authority's view was that while the SIM swap created the opening for the fraud, it was the bank's failure to enforce its own transaction controls that allowed the money to actually leave the firm's account.

Both companies have been directed to make their respective payments within 30 days of the order. During the proceedings, Bank of India denied any lapse on its part, maintaining that it had no fault in how the transactions were processed. Idea Cellular, for its part, argued that it had been misled by a person posing convincingly as the firm's authorised representative, using documents that appeared valid at the time the duplicate SIM was issued.
ADVERTISEMENT

The case, which took roughly a decade to reach a resolution, is being seen as a significant reminder of how gaps in coordination between banks and telecom operators can be exploited by fraudsters, and of the weight regulators are now placing on financial institutions to enforce their own stated security protocols rather than treating them as a formality.
Download
The Economic Times Business News App
for the Latest News in Business, Sensex, Stock Market Updates & More.
Download
The Economic Times News App
for Quarterly Results, Latest News in ITR, Business, Share Market, Live Sensex News & More.
READ MORE
ADVERTISEMENT

READ MORE:

LOGIN & CLAIM

50 TIMESPOINTS

More from our Partners

Loading next story
Business News › News › Trending › Bank OTPs were sent to duplicate SIM card instead of real one, audit company loses Rs 79 lakh; Bank of India ordered to pay Rs 1.5 crore
Text Size:AAA
Success
This article has been saved

*

+