by
Shourya Singh
CyJurII Scholar
28 July 2026
Abstract
This jurisprudential commentary analyzes the landmark decision of State Bank of India v. Pallabh Bhowmick& Ors. (2025), a case that significantly redefines the allocation of liability in cyber-fraud incidents within India’s rapidly expanding digital banking ecosystem. The Supreme Court of India, affirming the Gauhati High Court’s findings, reinforced the Reserve Bank of India’s (RBI) “zero liability” and “limited liability” framework for unauthorized electronic banking transactions. This analysis delves into the Court’s emphasis on the bank’s affirmative duty to prove customer negligence and to deploy “best technology available” to prevent fraud, thereby rebalancing the power asymmetry between financial institutions and individual account holders. The commentary also examines the case’s implications for digital consumer protection, the evidentiary burden in cybercrime, and its alignment with CyJurII’s pillars on digitalization and the reconceptualization of legal notions in the digital age. It highlights how this judgment contributes to a more robust and equitable digital justice system in India.
Keywords: Digital Banking Fraud, Consumer Protection, Zero Liability, Reserve Bank of India, Supreme Court of India, Cyber Jurisprudence, Burden of Proof, Cybercrime, India.
1. Introduction: Rebalancing Digital Banking Liability in India
The case of State Bank of India v. Pallabh Bhowmick & Ors. (2025) addresses a question of growing urgency in India’s digital banking economy: who bears the loss when a customer’s account is drained through a technologically sophisticated cyber fraud, despite the customer having taken reasonably prompt precautions? This dispute arose from three unauthorized debit transactions totaling ₹94,204.80 from the savings account of Pallabh Bhowmick, an SBI customer. Bhowmick was induced by a fraudster, impersonating a customer-care representative, into downloading a malicious application. What began as a writ petition before a Single Judge of the Gauhati High Court travelled through an intra-court appeal to the Division Bench, and finally to the Supreme Court, which dismissed SBI’s Special Leave Petition on January 3, 2025, thereby rendering the High Court’s findings final.
This case is significant because it reinforces, at the highest judicial level, the “zero liability” and “limited liability” framework laid down by the Reserve Bank of India (RBI) for unauthorized electronic banking transactions. Crucially, it places the evidentiary burden of proving customer negligence squarely on the bank rather than on the account holder. This judgment aligns with CyJurII’s Pillar 1: Digitalization and Legal Evolution, as it demonstrates how legal frameworks adapt to the complexities of digital transactions, and Pillar 4: Reconceptualization of Legal Notions, by redefining the burden of proof in the context of cyber-fraud. This commentary will explore the factual background, legal issues, judicial reasoning, and broader implications of this landmark decision for digital consumer protection and cyber jurisprudence in India.
2. Background and Facts of the Case
On October 18, 2021, Pallabh Bhowmick received a call from an individual purporting to represent the customer-care department of the apparel brand Louis Philippe. Following the caller’s instructions, Bhowmick downloaded what he believed to be a legitimate remote-assistance or refund-processing application. Shortly thereafter, three unauthorized transactions, totaling ₹94,204.80, were debited from his SBI savings account. Throughout the proceedings, Bhowmick consistently maintained that he never disclosed his One-Time Password (OTP), password, Mobile Personal Identification Number (MPIN), or any other sensitive banking credential to the fraudster. Crucially, his actions demonstrated diligence: complaints were lodged with SBI’s customer care center on the very day of the fraud, October 18, 2021, and a formal written complaint followed on October 19, 2021. This timeline was well within the parameters stipulated by the RBI’s Circular dated July 6, 2017, on customer protection in unauthorized electronic banking transactions 1 .
Significantly, in January 2022, Bhowmick received an email revealing that the merchant (Louis Philippe/Aditya Birla Fashion) had experienced a data-security breach, leading to unauthorized access to customer profile information. This fact provided independent corroboration for his assertion that the fraud originated from a third-party breach rather than from his own carelessness. Despite this evidence, SBI rejected his claim via an order dated March 7, 2022. This rejection prompted Bhowmick to first approach the Banking Ombudsman and subsequently the Gauhati High Court by way of a writ petition. The Single Judge ruled in his favor, directing SBI to refund the disputed amount. SBI’s intra-court appeal was dismissed by the Division Bench on September 13, 2024, and its Special Leave Petition before the Supreme Court met the same fate on January 3, 2025.
3. Issues Presented
The core legal questions addressed by the courts in this case were:
1. Whether the unauthorized transactions in Bhowmick’s account constituted “fraud” attributable to a third party or resulted from his own negligence in sharing sensitive credentials.
2. Whether the burden of proving customer negligence, under the RBI Circular of July 6, 2017, lay on the bank, and whether SBI had successfully discharged that burden.
3. Whether SBI had complied with its own procedural obligations—including timely acknowledgment, investigation, and shadow reversal of disputed transactions—under clauses 7, 8, 9, and 10 of the RBI Circular.
4. Whether a bank can resist liability merely on the basis of unproven or “perceived” negligence, absent cogent evidence.
4. Applicable Rules and Regulatory Framework
The Courts primarily relied on the RBI’s Master Circular/Direction on customer protection, titled “Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions,” dated July 6, 2017. This circular is a cornerstone of digital consumer protection in India. Clause 7 of the Circular meticulously calibrates customer liability into three distinct bands:
• Zero Liability: Applies where the unauthorized transaction results from a third-party breach with no fault attributable to either the bank or the customer, provided it is reported promptly.
• Limited Liability: Applies where the customer is partly at fault or delays reporting the unauthorized transaction.
• Full Liability: Applies where the customer’s own negligence, such as sharing payment credentials, is unequivocally established.Furthermore, Clause 9 obliges banks to credit (by way of shadow reversal) the disputed amount to the customer’s account within ten working days of notification, without awaiting the outcome of any internal investigation or insurance claim 2 . Clause 10 imposes a continuing duty on banks to resolve the customer’s liability determination and complete restitution within a defined timeframe 3 . The Courts also invoked the general administrative-law principle that a party asserting negligence—in this instance, the bank—bears the burden of proving it with cogent material, not mere suspicion or the technical fact that an OTP was generated. This aligns with CyJurII’s Pillar 4: Reconceptualization of Legal Notions, as it addresses the evidentiary challenges in digital contexts.
5. Judgment and Judicial Reasoning
The Gauhati High Court, at both the Single Judge and Division Bench stages, unequivocally held that SBI failed to present any reliable material to establish that Bhowmick had shared his OTP, password, or MPIN with the fraudster. The Division Bench specifically observed that while a customer’s negligence in disclosing sensitive credentials can absolve a bank of liability, such negligence “must be cogently established by the Bank,” and banks “cannot absolve themselves of liability… based on perceived negligence” 4 . The Court found that Bhowmick had reported the fraud within a day, thereby satisfying the RBI Circular’s requirement for zero liability. Moreover, it noted independent evidence of a data breach at the merchant’s end, further corroborating Bhowmick’s claim.
On appeal, the Supreme Court bench of Justices Pardiwala and Mahadevan fully concurred with these findings and dismissed SBI’s Special Leave Petition (SLP). The Supreme Court’s order extended beyond mere affirmance, holding that the bank, possessing access to the “best technology available today,” bears an affirmative duty to detect and prevent unauthorized and fraudulent transactions. This duty, the Court emphasized, does not conclude with the mere issuance of an OTP to the customer’s registered device 5 . The Supreme Court’s brief but incisive observations effectively elevate the RBI Circular’s protective architecture into a constitutionally sanctioned standard of banking conduct, enforceable through writ jurisdiction under Article 226 of the Indian Constitution. This judicial interpretation underscores CyJurII’s Pillar 1: Digitalization and Legal Evolution, showcasing how traditional legal instruments are adapted to address modern digitalChallenges.
6. Analysis: Doctrinal Features and Implications:
The ruling in State Bank of India v. Pallabh Bhowmick & Ors. represents a significant, albeit concise, contribution to India’s evolving digital-consumer-protection jurisprudence. Three doctrinal features are particularly noteworthy:
A . Burden of Proof Allocation: The Court firmly allocates the burden of proof to the bank—an institutional party with vastly superior access to transaction logs, IP records, and device metadata—rather than the individual customer, who is structurally disadvantaged in proving a negative (i.e., that they did not share their credentials). This aligns with CyJurII’s Pillar 4: Reconceptualization of Legal Notions, as it addresses the inherent power imbalance in digital interactions.
B. OTP as Non-Conclusive: The decision resists the temptation to treat the mere existence of an OTP-authenticated transaction as conclusive proof of customer consent or negligence. It recognizes that modern malware and social-engineering attacks can facilitate transactions without the victim’s informed participation, thereby protecting consumers from sophisticated cyber threats.
C. Dynamic Standard of Care: By holding that banks must deploy the “best technology available” to prevent fraud, the Supreme Court imports a dynamic, technology-linked standard of care into banking regulation, moving beyond a static compliance checklist. This emphasizes the continuous need for technological vigilance and innovation in safeguarding digital transactions.
However, subsequent decisions—such as the Allahabad High Court’s ruling in Suresh Chandra Singh Negi v. Bank of Baroda 6 and certain Gauhati High Court proceedings distinguishing Pallabh Bhowmick—illustrate the judgment’s necessarily fact-sensitive boundaries. Courts have been careful to confine the zero-liability presumption to cases involving genuine third-party breaches and prompt reporting, declining to extend it to self-initiated transactions falsely presented as cyber fraud. This distinguishing trend suggests that while Pallabh Bhowmick strengthens customer protection, it does not create an irrebuttable presumption in the customer’s favor; banks retain a real, though now more demanding, opportunity to prove negligence through concrete digital forensic evidence.
7. Aftermath of the Judgment: Precedential Impact
Since January 2025, Pallabh Bhowmick has rapidly become a standard citation in cyber-fraud banking litigation across High Courts and consumer fora in India. It has been relied upon in the Madras High Court 7 , the Allahabad High Court, and various District Consumer Disputes Redressal Commissions 8 to reinforce the zero-liability principle and the bank’s obligation to use robust technological safeguards. Litigants have also invoked it to argue that liability for post-reporting losses is extinguished the moment a customer notifies the bank, reinforcing the “cut-off” effect of prompt reporting under Clause 9 of the RBI Circular. This widespread adoption highlights the judgment’s significant precedential value.
Concurrently, several High Courts have distinguished the ruling on facts, relying instead on comparable authorities such as Jaiprakash Kulkarni & Ors v. Banking Ombudsman & Ors and Hare Ram Singh v. Reserve Bank of India. These courts have refused to apply Pallabh Bhowmick where transaction logs, IP addresses, and device data indicate self-initiated transfers rather than genuine third-party fraud, thereby preventing its misuse as a blanket shield for disputed but voluntary transactions. This nuanced application ensures that the judgment’s protective scope is appropriately balanced against potential abuse.
8. Conclusion: A Template for Digital Justice
State Bank of India v. Pallabh Bhowmick & Ors. consolidates, at the Supreme Court level, a customer-protective reading of the RBI’s 2017 Circular on unauthorized electronic banking transactions. By insisting that banks must affirmatively prove customer negligence rather than merely assert it, and by linking banking due diligence to the “best technology available,” the decision meaningfully rebalances the asymmetry of information and power between individual account holders and institutional banks in the digital payments ecosystem. Its true significance, however, lies not merely in the modest sum it restored to one customer, but in the evidentiary and regulatory template it has since supplied to courts across the country adjudicating the far larger wave of cyber-fraud disputes generated by India’s rapid digital-banking expansion 11 12 . This case serves as a crucial precedent for fostering digital trust and ensuring equitable justice in the evolving landscape of cyber jurisprudence.
Declaration of Interest
The author declares no conflicts of interest regarding the publication of this research.
Acknowledgments
This research brief was prepared in alignment with the Cyber Jurisprudence International Initiative (CyJurII) guidelines.
Resources:
1 Reserve Bank of India, ‘Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions’ (Circular No RBI/2017-18/15, DBR.No.Leg.BC.78/09.07.005/2017-18, 6 July 2017) cl7.
2 ibid cl 9.
3 ibid cl 10.
4 State Bank of India v Pallabh Bhowmick and Ors 2024 SCC OnLine Gau 1519 [40].
5 State Bank of India v Pallabh Bhowmick, SLP (C) No 30677 of 2024, order of 3 January 2025 (SC) (n 1).
6 Suresh Chandra Singh Negi v Bank of Baroda, Writ-C No 24192 of 2022 (Allahabad HC).
7 Bhushan Goyal v Banking Ombudsman, WP No 28100 of 2022 (Madras HC, 23 September 2025).
8 Roopam Kumar v SBI Cards and Payment Services Pvt Ltd (District Consumer Disputes Redressal Commission, Chandigarh, 6 February 2026).
9 Jaiprakash Kulkarni and Ors v Banking Ombudsman and Ors 2024 SCC OnLine Bom 1666.
10 Hare Ram Singh v Reserve Bank of India MANU/DE/8030/2024 (Delhi HC) [32].
11 Sukriti Mishra, ‘SC Upholds SBI’s Liability in Fraudulent Transactions Case; Highlights Banks’ Responsibility to Protect Customers’ (Verdictum, 6 January 2025) https://www.verdictum.in/court-updates/supreme-court/state-bank-of-india-v-pallabh-bhowmik-and-ors-special-leave-to-appeal-c-no-306772024-1563572 accessed 9 July 2026.
12 The420.in, ‘Guwahati HC Upholds “Zero Liability” Principle in Cyber Fraud Cases’ (The420, 3 December 2025) https://the420.in/guwahati-hc-zero-liability-cyber-fraud-sbi-refund-supreme-court/ accessed 9 July 2026