Private Scheduled Banks Amenable to Writ Jurisdiction to Enforce RBI “Zero-Liability” Refunds in Unauthorised E‑Banking (SIM‑Swap) Frauds

Case: SUBODH C KORDE v. UNION OF INDIA THR MINISTRY OF FINANCE AND ORS (Writ Petition No.11990 of 2023)

Court: Bombay High Court (Division Bench: Bharati Dangre & Manjusha Deshpande, JJ.)

Date of Judgment: 06-04-2026

At a Glance: What This Judgment Adds

  • Maintainability: A writ petition under Article 226 can be entertained against a private scheduled bank when enforcement is sought of RBI directions issued in public interest (not merely private contractual claims).
  • RBI “zero liability” regime operationalised: In unauthorised electronic banking transactions where fault lies “elsewhere in the system” (here, SIM swapping), and the customer reports promptly, the customer’s liability is zero and the bank must restore funds.
  • Burden of proof: The bank bears the burden to prove customer negligence; “OTP sent” vendor logs, without robust proof of receipt and in the face of SIM-swap evidence and IP mismatch, were treated as insufficient.
  • No prerequisite of cyber-cell conclusion: Relief under the RBI circular is not contingent upon a completed cyber-crime investigation or a cyber-cell “fraud” finding.

1. Introduction

The petitioner, a senior citizen and freelance business consultant, alleged that he was a victim of a cyber fraud in which Rs. 38,04,000 was siphoned from two HDFC Bank accounts via eight unauthorised net-banking transfers within 41 minutes. The transfers followed two critical account changes: (i) addition of unknown beneficiaries and (ii) enhancement of the third-party transfer limit from Rs. 4,00,000 to Rs. 40,00,000—both allegedly done without his knowledge or receipt of OTPs.

The petition impleaded: the Union of India (Ministries of Finance and Communications), the Reserve Bank of India (RBI), HDFC Bank (drawer bank), ICICI Bank (recipient bank of some beneficiaries), BSNL (telecom provider), and the State police. The petitioner sought, inter alia, directions to enforce RBI internet banking and digital payment security directions and to compel refund of the defrauded amount. HDFC Bank raised a threshold challenge: writ jurisdiction cannot be invoked against a private bank, and the dispute involved complex factual questions.

The central legal issues crystallised into:

  • Maintainability of Article 226 proceedings against a private scheduled bank in a dispute rooted in unauthorised e-banking transactions;
  • Application of the RBI circular dated 06/07/2017 on “Customer Protection - Limiting Liability of Customers in Unauthorised Electronic Banking Transactions”;
  • Whether the customer was negligent (and whether the bank discharged the burden of proving negligence); and
  • How SIM-swapping evidence impacts OTP-based authentication narratives typically used by banks to deny refunds.

2. Summary of the Judgment

The Bombay High Court:

  • Rejected the preliminary objection that the writ petition was not maintainable against HDFC Bank.
  • Held that the petitioner was a victim of unauthorised electronic transactions, attributable to a SIM swapping episode evidenced by BSNL records.
  • Applied the RBI circular dated 06/07/2017 to conclude the petitioner was entitled to “zero liability”, as he did not contribute to the fraud and reported promptly.
  • Directed HDFC Bank to remit Rs. 38,04,000 to the petitioner within eight weeks with 6% p.a. interest; failing which, the amount would carry 8% p.a. interest.

3. Analysis

3.1 Precedents Cited (and How They Shaped the Outcome)

A. Expanding writ reach beyond “State”: foundation cases

Andi Mukta Sadguru Shree Muktajee Vandas Swami Suvarna Jayanti Mahotsav Smarak Trust & Ors. Vs. V.R.Rudani & Ors. was used to reaffirm that Article 226 is not confined to statutory authorities; the critical inquiry is the nature of the duty and whether there is a positive obligation whose breach produces injustice. The Bombay High Court drew from its emphasis that mandamus can enforce duties arising even from contract when a public element exists, and that judicial control should remain flexible “to reach injustice wherever it is found.”

Praga Tools Corporation Vs. C.A.Imanual was referenced for the principle that mandamus can lie to compel entities (including corporations) to carry out duties placed on them by statute—reinforcing that “form” (private/public) is secondary to “function/duty.”

B. The “private bank” line: limits and exceptions

Federal Bank Ltd. Vs. Sagar Thomas & Ors. formed the main plank of HDFC’s maintainability objection. That decision held that merely because RBI regulates banking does not convert a private bank’s commercial activity into a public duty, and that writs do not ordinarily enforce private employment/contract disputes. The Bombay High Court did not discard Federal Bank; instead, it distinguished the context: here the petitioner sought enforcement of RBI customer-protection directions issued in public interest and bearing a public-law element, not adjudication of a purely private contract claim.

Binny Ltd. & Anr. Vs. V. Sadasivan & Ors. was used to articulate the controlling principle: mandamus is a public law remedy; it can issue against a private body only to enforce a public duty, and courts must identify a “public law element” in the action challenged. The Court used this framework to anchor why RBI’s statutory directions to scheduled banks can supply that public element.

VST Industries Limited Vs. VST Industries Workers' Union & Anr. was cited through the administrative law distinction: not all activities of private bodies are governed by public law; judicial review may apply where statute or public-interest duties are involved.

LIC of India Vs. Escorts Ltd. was invoked for the caution that courts must demarcate “public law” and “private law” case-by-case, considering the action’s character and surrounding circumstances.

C. The “function test” re-stated: the Supreme Court’s recent guidance

S. Shoba Vs. Muthoot Finance Ltd was heavily relied upon by HDFC. It clarified that bodies should not be labelled amenable/non-amenable in the abstract; maintainability turns on the “function test”: whether a public function/duty is involved. The Bombay High Court carefully navigated S. Shoba by differentiating a non-banking finance company from a scheduled bank embedded within RBI’s statutory control architecture, and by locating a public element in enforcement of RBI directions intended to protect the banking public.

D. Bombay High Court’s own writ-restrictive decisions—distinguished on context

M/s. Ruchi Soya Industries Ltd. & Ors. Vs. IDFC Bank Limited & Ors. and VJ Jindal Cocoa Pvt. Ltd. & Anr. Vs. Union of India & Ors. were cited to show Bombay High Court’s consistent reluctance to entertain Article 226 disputes that are essentially private contractual conflicts with banks. The Court distinguished the present case as involving enforcement of RBI circulars framed for customer protection in electronic transactions, thereby introducing the necessary public law element.

Chanda Deepak Kochhar Vs. ICICI Bank Ltd. Mumbai & Anr. was noted (through VJ Jindal) as reaffirming that private banks are not State instrumentalities; again, the present bench accepted that proposition but held that non-State does not immunise a body from writs when it performs public-law duties in a given domain.

E. “Public function” by private bodies: monopoly/public importance analogy

Board of Control for Cricket in India Vs. Cricket Association of Bihar & Ors. was used for the proposition that even if an entity is not “State” under Article 12, it can still be amenable to writ jurisdiction under Article 226 if it discharges important public functions. The Court used this as an analogy to emphasise that scheduled banks, though private, operate in a highly regulated public-facing domain, where RBI-imposed customer protection obligations are not merely private bargains but systemic safeguards.

F. The emerging refund jurisprudence under the RBI circular (06/07/2017)

The Court reviewed multiple High Court decisions granting refunds by enforcing RBI’s “limiting liability” framework:

  • Pallabh Bhowmick Vs. Ombudsman, Reserve Bank of India & Ors.: The Gauhati High Court held that downloading an app on a fraudster’s prompt does not automatically establish negligence; banks must show how credentials were shared, and should have robust fraud controls. The Bombay High Court treated this as persuasive authority and also highlighted that the decision was upheld by the Division Bench and later by the Supreme Court, with strong remarks that banks have the best technology to detect and prevent such frauds.
  • Dr. R. Pavithra Vs. Commissioner of Police & Ors and Awadhesh Singh Vs. RBI & Ors: cited as additional instances where High Courts enforced the RBI notification to protect customers.
  • Jaiprakash Kulkarni & Anr Vs. Banking of Ombudsman & Orss: a Bombay High Court decision directly applying the RBI circular; crucially it emphasised burden on the bank under the RBI framework. While HDFC attempted to distinguish it on the basis that cyber-cell reports existed there, the Court in the present case held that the RBI circular does not depend on completion of cyber investigation.
  • Hare Ram Singh Vs. Reserve Bank of India & Ors.: relied upon for (i) maintainability where banks violate mandatory RBI guidelines, (ii) an articulation of “negligence” requiring a high threshold, and (iii) the proposition that once fraud is detected the bank has an implied duty to act promptly.
  • Society for Welfare of the Handicapped Persons & Anr. Vs. Union of India & Ors.: used to support the maintainability of writ proceedings against a private scheduled bank when statutory obligations under RBI/Banking laws and RBI directions are implicated.

G. Article 12 “instrumentality” tests referenced in the maintainability discussion

Pradeep Kumar Biswas Vs. Indian Institution of Chemical Biology & Ors. and Ajay Hasis Vs. Khalid Mujib Sehravardi were referred to in the Federal Bank discussion on “instrumentality/agency” analysis. The Bombay High Court accepted that HDFC is not State under Article 12, but pivoted to Article 226’s wider sweep where public duties exist.


3.2 Legal Reasoning: How the Court Reached Its Result

(i) Maintainability: locating the “public law element”

The Court’s reasoning proceeds in two steps:

  • Step 1: A private scheduled bank is not “State” under Article 12, and writs cannot be used to enforce purely private contractual disputes. This is consistent with Federal Bank Ltd. Vs. Sagar Thomas & Ors., Binny Ltd. & Anr. Vs. V. Sadasivan & Ors., and S. Shoba Vs. Muthoot Finance Ltd.
  • Step 2: However, where the relief sought is enforcement of RBI directions issued in public interest—especially in the context of electronic banking safety and customer protection—the dispute acquires a public law character. The Court emphasised the statutory setting: scheduled banks operate within RBI’s supervisory architecture (Reserve Bank of India Act, 1934; Banking Regulation Act, 1949), and RBI’s power under Section 35-A to issue binding directions in public interest.

On that basis, the Court refused to treat the case as merely a customer-bank contract dispute and held the writ petition maintainable.

(ii) The RBI circular (06/07/2017): independence from criminal adjudication

A significant doctrinal move is the Court’s holding that the RBI customer-protection regime is not dependent on completion of cyber-crime investigation or a cyber-cell report. The circular’s logic is regulatory and consumer-protective: once unauthorised electronic debit is reported promptly and customer negligence is not shown, the circular’s allocation of liability applies.

(iii) Evidence and burden: OTP narratives vs SIM-swap reality

HDFC’s defence was that beneficiary addition, limit enhancement, and transfers were authenticated by OTPs sent to the registered mobile and email, and that device ID matched prior genuine transactions. The Court scrutinised:

  • SMS/OTP/email logs: The Court noted that the bank did not place “original” logs proving receipt; what was produced were vendor-prepared logs indicating “sent/delivered”. In a case where the customer asserts non-receipt and SIM swapping is evidenced, such logs were treated as inadequate to discharge the bank’s burden.
  • BSNL affidavit: This became pivotal. BSNL records showed multiple SIM swaps/replacements (12/07/2021 to 15/07/2021) on the petitioner’s number, using replacement forms and identity verification processes. The Court treated this as establishing the mechanism by which OTPs could be received by someone other than the petitioner.
  • IP address mismatch: The bank’s own internal report reflected that disputed transactions originated from an IP located in Chennai, whereas genuine transactions were from Pune. The Court treated this as an additional indicator supporting unauthorised access.
  • Internal bank alerting: The bank’s own internal investigation recorded that beneficiary addition attempt got alerted and monitoring could not reach the customer. The Court found it notable that despite these signals, the bank’s external posture was to blame the customer for “compromising” credentials.

(iv) Liability outcome: “zero liability” triggered

The Court concluded:

  • The petitioner did not share credentials/OTP and was not negligent; the bank failed to prove otherwise (burden on bank under the RBI framework).
  • This was a third-party breach “elsewhere in the system” (SIM swap), making the customer eligible for zero liability.
  • Accordingly, the bank must restore the funds with interest.

3.3 Impact: What This Judgment Likely Changes

A. Writ strategy against private scheduled banks

The judgment strengthens a pathway for customers to invoke Article 226 against private scheduled banks when they seek enforcement of RBI consumer-protection directions, rather than mere contractual damages. It does not declare that every banking dispute is writ-worthy; it confines writ maintainability to domains where RBI directions in public interest supply the public law element.

B. SIM swap as a legally significant “system” breach

By treating SIM swapping as the practical explanation for OTP non-receipt—and by granting refund without requiring a cyber-cell “final” finding—the Court effectively operationalises SIM swap as a recognised mode of third-party compromise that can trigger the RBI circular’s zero-liability outcomes.

C. Evidence standards for banks: “sent” is not always “received”

Banks frequently rely on internal OTP/email “delivery” logs. This judgment signals that, especially in SIM-swap scenarios, courts may demand more robust proof and may view vendor-generated logs with caution. It also underscores that banks’ own internal risk signals (blacklist alerts, inability to contact customer, unusual IP geography) can be used against them if ignored.

D. Ombudsman closures are not the final word

The case emerged after an Integrated Ombudsman Scheme closure. The judgment reinforces that ombudsman closure does not immunise banks from judicial review where RBI directions and public-law duties are implicated and where the customer is demonstrably a victim of unauthorised transactions.

4. Complex Concepts Simplified

  • Article 226 / Writ of mandamus: A High Court power to issue directions to enforce rights and public duties. It can sometimes apply to private bodies if they are performing a public duty in the specific context.
  • “Public law element”: A feature that makes a dispute suitable for writ jurisdiction—e.g., breach of statutory/regulatory duties meant to protect the public, not just breach of a private contract.
  • RBI circular dated 06/07/2017 (customer liability): A regulatory framework that caps/limits customer liability for unauthorised electronic transactions. If the customer is not at fault and reports quickly, liability can be zero and the bank must restore funds within prescribed timelines.
  • Burden of proving negligence: The bank must prove the customer acted negligently (e.g., shared OTP). Absence of proof means the bank cannot simply presume negligence.
  • SIM swapping: Fraudsters get a new SIM issued on the victim’s number (often using forged/compromised identity documents), so OTPs and bank alerts go to the fraudster.
  • IP address vs Device ID: “IP address” shows the internet route/location of an activity; “device ID” is a device fingerprint used for risk checks. Courts may treat IP location mismatch as a strong fraud indicator, even if device IDs appear to match.
  • Risk-based authentication / monitoring alerts: Banks use automated scoring to flag suspicious activity. Internal flags (e.g., “Decline Add Payee-Blacklisted Accounts”) can be critical evidence of unusual activity that should have prompted stronger intervention.

5. Conclusion

The Bombay High Court’s decision is a notable addition to the growing body of Indian jurisprudence enforcing RBI’s customer-protection regime for unauthorised e-banking debits. It clarifies that a private scheduled bank may be subjected to writ directions under Article 226 when the claim is anchored in RBI directions issued in public interest and when adjudication turns on enforcing those regulatory duties—thereby supplying the necessary public-law element.

On facts, the judgment is equally significant for recognising SIM swapping as a credible explanation for OTP-based “authorisation” narratives and for holding that the RBI circular’s remedies do not await a completed cyber-crime adjudication. Ultimately, the Court’s approach re-centres the regulatory objective: digital banking can expand only if customers are protected, banks carry the burden of disproving negligence, and refunds are not defeated by formalistic OTP logs when the system itself is compromised.

Relief granted: HDFC Bank directed to remit Rs. 38,04,000 to the petitioner within eight weeks with 6% p.a. interest (8% p.a. on default).