Case Details
Case Title: Suresh Chandra Singh Negi and Another v. Bank of Baroda and Others
Court: The High Court of Judicature at Allahabad (Allahabad High Court).
Bench: Division Bench consisting of Hon’ble Mr. Justice Shekhar B. Saraf and Hon’ble Mr. Justice Praveen Kumar Giri.
Citation: WRIT-C No. 24192 of 2022, 2025: AHC:115460-DB (hereinafter referred to as the “Suresh Chandra Negi case”
Introduction
Cybercrime can be defined as any illegal activity that harms individuals, organizations, governments and is carried out using computers, the internet, or any digital technology. It includes crimes such as stealing money online, harassing people on social media, cheating through fake websites. There are several types of cybercrime are phishing, identity theft, Denial of service attack (DoS), Distributed denial of service (DDoS) attack, stalking, bullying, ransomware attack, hacking, intellectual property fraud etc. This case is related to the Cybercrime. The Suresh Chandra Singh Negi case arose from a writ petition filed in under Article 226 of Indian Constitution by Suresh Negi and his son. and the judgement highlights the growing importance of electronic evidence, including Ip logs, device identification, OTP verification, in determining liability in online banking disputes.
Facts of the Case
The petitioners, Suresh Chandra Singh Negi (Petitioner no. 1) along with his son (Petitioner no. 2), ran their respective companies in the business of technical business of transformer fabrication. Both the petitioners had opened their respective accounts with the respondent Bank of Baroda, having a considerable cash credit limit of 1,20,000,000 and 1,30,000,000 respectively in their respective accounts which had internet banking facility activated.
On the day of 19 th June 2022, a sum of money worth 30,00,000 and 7,85,000 was electronically transferred from the (petitioner no.1) Suresh Chandra Singh Negi’s account to the petitioner no.2’s account, from where the amount was siphoned off to other various beneficiaries’ accounts.
Petitioners received an SMS intimation regarding the debiting of a large sum of money from their account around 12:44 PM on the day of 19 th June 2022. Instead of contacting the respondent bank’s fraud detection department or blocking the money transfer through other emergency measures, the petitioners chose to remain quiet and contacted the National Cybercrime portal on the morning of 20th June 2022 to register a complaint about the unauthorized electronic transfer of money from their bank account.
An FIR was registered on 21st June 2022 with the police.
The petitioners (Suresh Chandra Singh Negi & son) moved to Allahabad High Court with a Writ Petition under Article 226 of the Constitution of India, whereby they claimed the respondent Bank of Baroda to return the illegally deducted money from their account via issuing Writ of Mandamus. The petitioners alleged that they were the victim of an elaborate external cybercrime fraud.
They argued that despite taking all due diligence measures, their mobile phone’s SIM card got blocked by an external agency, which did not allow them to take immediate action against the fraudulent activity. They further argued that the IP address from where the money was transferred through electronic mode was different from their regular IP address, whereby the external fraudster must have accessed their bank account details through some phishing means.
On the contrary, the respondent bank argued that the petitioners themselves had misappropriated the funds from their accounts, as the bank detected certain irregularities in the petitioner’s account activities.
The bank further argued that the money transferred from their account had gone through a legitimate procedure, whereby the OTP sent to the petitioner’s mobile number was entered, whereby the mobile phone configuration and IP address matched with the usual configurations used by petitioner no.2 for accessing the internet banking facility.
Issues Framed Before the Court
The Division Bench of the Allahabad High Court framed the following crucial issues for legal adjudication:
1. Whether the petitioners could be legally classified as genuine victims of an unauthorized electronic banking transaction or cyber fraud under the statutory guidelines issued by the Reserve Bank of India (RBI)?
2. What are the evidentiary requirements regarding IP address tracking, device identification logs, and OTP generation metrics needed to establish customer negligence or deliberate involvement in digital transaction disputes?
3. Whether a customer is entitled to the remedy of “Zero Liability” or “Limited Liability” under the RBI’s Master Circular on Customer Protection when there is an admitted delay in notifying the financial institution after receiving transaction alerts?
Arguments of the Parties
Arguments of petitioners
The learned counsel appearing on behalf of the petitioners submitted that despite exercising due diligence in relation to their credentials, the respondents, through unauthorized third parties, have manipulated the digital banking system of the bank. The counsel further submitted that the fraudsters had deactivated the SIM card of the petitioner’s main account, thereby cutting off all communication, including the active verification call.
The counsel argued that the IP addresses of the fraudulent transactions did not coincide with the petitioner’s previous business transactions. Accordingly, the counsel submitted that the petitioner’s account was compromised through a remote unauthorized cyber intrusion. The counsel further submitted that, pursuant to the RBI Master Circular, the bank was obligated to re-credit the respondents’ accounts since the fraudulent transactions resulted from a weakness in the electronic banking system.
Arguments of respondent
The counsel for the Bank of Baroda fiercely contested the petitioners’ claim by presenting the Court with system logs and electronic audit trails. The bank showed that the internet banking profile had been accessed using correct, multi-layer encrypted security credentials. Moreover, the logs revealed that the SIM card had not been blocked; instead, an OTP (One Time Password) had been sent to the petitioner’s phone, and the profile’s password was changed.
Furthermore, the Bank of Baroda’s technical counsel exposed that the IP address and hardware device utilized to transfer the siphoned amount to other accounts were the same as those Petitioner No. 2 used to operate his net-banking services. Lastly, the counsel argued that the petitioners did not inform the bank about the SMS alerts they received at 12:44, thus breaching the RBI’s risk-allocation framework.
Significance of the Judgement
Recent Judgment of Allahabad High Court on “Zero Liability Claims” of RBI – Explained 2 The Division Bench of Allahabad High Court dismissed the writ petition and ruled in favor of the Bank. The Court observed that in order to avail the benefits of the “Zero Liability” as mandated by the Reserve Bank of India (RBI) in its official circulars, the electronic transaction has to be necessarily shown as “unauthorized” and “without any negligence on the part of the customer”. Upon perusal of the detailed electronic records, including the identical Internet Protocol (IP) logs and synchronized hardware device markers, the Court came to the conclusion that the very fact that the transactions were taking place through petitioners’ own banking terminals, vitiated any claim of “fraud” on the part of the Bank.
The Bench also observed that the very proposition of law laid down in the celebrated judgment of Pallabh Bhowmick was attracted only when the genuine accountholder was a victim of cyber fraud and was not involved in any manner whatsoever in the fraudulent transaction and had immediately alerted the bank upon discovery of the fraud. The instant case, however, did not meet any of these ingredients, as evidenced by the fact that over 24 hours had elapsed before the petitioner had intimated the Bank about the fraudulent transactions, and the identical internal IP logs had defeated the very proposition of “external unauthorized access”.
Thus, the writ jurisdiction under Article 226 of the Constitution cannot be misused to circumvent the obligation to repay money erroneously credited to the respondent’s account.
Analysis
The Suresh Chandra Negi judgment gives an extremely important precedent for India’s increasingly complex digital banking ecosystem. While previous High Court judgments have leaned heavily into the consumers’ favor due to the RBI’s “Zero Liability” circulars, this ruling serves as a much-needed restriction to the potential scope of misrepresentation under the cover of ‘cyber fraud’.
In this particular context, the current judgment provides significant credence to the ability of commercial entities to counter spurious complaints. It warns against the usage of RBI sanctioned consumer protection norms via “cyber fraud” as a cover for insider defaulting, self-initiated transfers or even collusion between defaulting borrowers and cyber criminals.
In a very real sense, this judgment helps to restore some of the trust in the banking system’s ability to appropriately govern cyber security and digital transactions. As a case study, this example is also exceedingly valuable in proving the importance of digital forensics in banking disputes. The use of IP tracking, local server logins, hardware specific OTP security and timestamps as evidence has tremendous implications for the digital banking space.
By ruling in this particular manner, the Allahabad High Court has essentially mandated that technical auditing software will hold greater evidentiary value than personal testimony in cyber-fraud cases.
This helps to strike the correct balance between consumer confidence in digital transactions and the need for banks to protect themselves from bad-faith borrowers.
References
- The Information Technology Act,2000.
- The Banking Regulation Act,1949.
- The Constitution of India, Article 226.
- Pallabh Bhowmick v. State of India & Ors. Calcutta High Court

