Get all your news in one place.
100's of premium titles.
One app.
Start reading
The Economic Times
The Economic Times

Bank OTPs were sent to duplicate SIM card instead of real one, audit company loses Rs 79 lakh; Bank of India ordered to pay Rs 1.5 crore

A Pune-based audit firm lost close to Rs 79 lakh to cyber fraudsters after they managed to get a duplicate SIM card issued in place of the firm's own registered mobile number, and used it to intercept the OTPs meant to protect its bank account. According to a report by the Times of India, an adjudicating authority under the Information Technology Act, 2000 has now held Bank of India primarily responsible for the loss and ordered it to pay compensation with a decade's worth of interest attached.

The order relates to a 2015 cyber fraud in which G D Apte & Co, a Pune-based chartered accountancy and audit firm, saw its accounts at Bank of India drained through a series of unauthorised transactions carried out over a single day. The authority has directed the bank to pay Rs 64.44 lakh along with 12% annual interest, a figure that, once calculated over ten years, brings the total payout to nearly Rs 1.5 crore.

READ ALSO: Real estate firm promised Rs 60,000 every month for a Rs 17.5 lakh investment, paid Rs 30,000 for six months, then stopped; court orders company to pay client over 55 lakh

How the fraud unfolded

Per the Times of India report, the trouble began on March 10, 2015, when the firm's registered mobile number suddenly stopped working. The firm had no way of knowing at the time that a duplicate SIM card linked to that very number had already been issued to someone posing as its authorised representative. Once activated, this duplicate SIM began receiving all the banking alerts and one-time passwords that were meant to reach the firm's own phone, effectively handing the fraudsters a direct line into its account security.

The very next day, March 11, 2015, 13 unauthorised RTGS transactions were carried out in quick succession. One transfer of Rs 6.6 lakh was made from the firm's current account, while the remaining 12 transactions, adding up to Rs 78.93 lakh, were pushed through from its overdraft account. By the time the fraud was detected, only around Rs 14 lakh could be recovered, leaving the firm to pursue the rest of its loss through legal channels for close to a decade.

Bank's own security checks found wanting

The adjudicating authority placed the larger share of blame on Bank of India, holding that it had failed to properly enforce its own internal safeguards. As per the arrangement agreed with the firm, any transaction was required to be initiated by a designated user and then authorised by two senior-level users before it could go through, a system commonly known as maker-checker authorisation. Cyber lawyer Prashant Mali, cited in the Times of India report, pointed out that the records placed before the authority did not establish that this process had actually been followed at the time the fraudulent transactions took place.

Adding to the bank's troubles, the firm's account carried an agreed monthly ceiling of Rs 50 lakh on RTGS transfers. Despite this cap, nearly Rs 79 lakh moved out of the overdraft account alone, and the bank was unable to satisfactorily explain how transactions of this scale slipped past a limit that should have stopped them. This gap between the agreed safeguard and what actually happened formed a central plank of the authority's finding against the bank.

Telecom operator fined over lax SIM verification

Idea Cellular Ltd, now known as Vodafone Idea Ltd, was separately held liable and ordered to pay Rs 5 lakh as compensation. The authority found that the telecom operator had failed to adequately verify the identity documents, letterhead and stamp presented by the individual who obtained the duplicate SIM in the firm's name. However, its liability was treated as contributory rather than primary, since the company had no role in either initiating or processing the fraudulent bank transactions itself. The authority's view was that while the SIM swap created the opening for the fraud, it was the bank's failure to enforce its own transaction controls that allowed the money to actually leave the firm's account.

Both companies have been directed to make their respective payments within 30 days of the order. During the proceedings, Bank of India denied any lapse on its part, maintaining that it had no fault in how the transactions were processed. Idea Cellular, for its part, argued that it had been misled by a person posing convincingly as the firm's authorised representative, using documents that appeared valid at the time the duplicate SIM was issued.

The case, which took roughly a decade to reach a resolution, is being seen as a significant reminder of how gaps in coordination between banks and telecom operators can be exploited by fraudsters, and of the weight regulators are now placing on financial institutions to enforce their own stated security protocols rather than treating them as a formality.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.