Cyber fraud victims face delays and little accountability from banks | #cybercrime | #infosec


Cybercrimes have disrupted our conventional understanding of both how crimes take place and how the systems responding to them function. While there is much to be said about the non-financial cybercrimes that may be just as prevalent as financial cybercrimes, the latter have captured the public’s imagination and fears in unprecedented ways.

A recent study by Common Cause and Lokniti, CSDS, the Status of Policing in India Report (SPIR) 2026: Cybercrimes — Victim Perspectives and Systemic Responses, brings out the perspectives of the common public, victims, and domain experts on this issue, focusing on how victims navigate through the complex systems. The study is based on a survey of 8,306 respondents from across 16 States/U.T.s, along with in-depth interviews with 37 stakeholders, including victims, cybercrime experts, and others.

In financial cybercrime cases, the banking sector becomes an integral part of the reporting and resolution process, widening the traditional understanding of the core criminal justice institutions such as the police and courts. In this context, the study explores, among other things, whether banks as an institution are prepared to deal with these cases and to take accountability for security lapses.

According to the survey data, 13% of the overall respondents were victims of cybercrimes in the last 2-3 years. Among the victims, more than half (54%) were victims of digital financial frauds.

One of the first actions taken by the victim after the incident was complaining directly to the banks. More than half of the victims of digital financial fraud (52%) who were surveyed said that they had complained to the bank separately after the incident. A majority, 63%, complained within the first 24 hours.

Banks’ response

Despite the promptness in reporting shown by many victims, the response by the banks leaves much to be desired. A 2017 RBI guideline states that in cases of third-party breach due to no deficiency by either the bank or the customer, and if the customer notifies the bank within three days, the loss must be borne by the bank entirely. This was extended on a pilot basis in 2026 to include those cases wherein the customer had been tricked or coerced into making scam payments, with limited liability being placed on the bank in such cases.

In-depth interviews with victims revealed, however, that the banks’ response to cybercrimes is almost entirely focused on evading accountability and liability. The standard response from the banks in cases of digital financial fraud is that the victim “collaborated” with the perpetrator of the cybercrime. All the victims of digital financial cybercrimes who were interviewed qualitatively, barring one, said that the bank maintained this in their case, even in cases where the victims did not interact with the perpetrators at any point. Notably, the one case in which the banks did not give this response included a high net-worth individual with a long-standing relationship with the bank.

Low satisfaction

Vipin (name changed), a Gurgaon-based journalist, got a scam call for SIM upgradation on a Saturday. The caller, pretending to be an Airtel employee, shared some of his personal information to appear legitimate, including his name, date of birth, Aadhaar number, and debit card number. Despite cutting the call, ₹5,000 was withdrawn from a payment wallet linked to his number the following day. He immediately blocked his number and emailed his bank, since it was closed on Sunday. However, by Monday afternoon, his account had still not been blocked, and the fraudsters had taken a loan of ₹5 lakhs against his credit card, half of which had already been withdrawn. The bank, however, took “zero accountability” for this loss and was “apathetic” to the complaint, as reported by him.

Other victims reported similar instances of delays by the banks in stopping the flow of unauthorised transactions immediately following the complaint. While the banks become directly liable for such losses when presented with such evidence of negligence in taking prompt action, there is little accountability for the mental, physical and financial costs to the victim in the recovery process necessitated by such negligence

Data (in)security

A more serious allegation levelled against the banks, both by cybercrime experts as well as victims, is that of complicity in the cybercrimes, whether directly or indirectly. The survey data shows that amongst victims who complained to the bank separately, as many as 40% were of the opinion that the cybercrime occurred due to their financial data being leaked by a bank insider. Amongst those who did not complain to the bank separately, 26% hold this opinion. Overall, while a significant proportion of the victims feel that the breach of their personal data enabled the cybercrime incident, this sentiment is amplified amongst those who had first-hand experience with the bank in dealing with their case.

In-depth interviews with victims made similar grave allegations against the banks. Of the 13 digital financial fraud victims interviewed, five victims were of the opinion that bank officials were directly or indirectly complicit in the crime. One of the victims was told by the police officer investigating her case that the bank must be complicit, though no charges were filed against it.

Cybercrime experts and senior police officers dealing with these cases strongly supported this perception. They further stressed the lack of accountability for the common leakages of customer data, due to inadequate security systems.

Another major systemic loophole is the lack of due diligence by banks when opening bank accounts, which can be used as mule accounts in cybercrime cases. Policing and cybercrime experts were of the opinion that banks prioritise their business interests over building secure systems. “People like you and me will lose access to our accounts due to KYC procedures, but these accounts [the cyber criminals’] will never be closed”, stated a former police officer.

Satisfaction with the banks

Overall, the levels of satisfaction with the banks remained low across the victims of digital financial cybercrimes, as is emerging both from the survey data as well as the in-depth interviews with victims. More than one out of five victims of digital financial fraud surveyed reported being “very dissatisfied” with the bank’s role in recovering money, while 16% said that they were somewhat dissatisfied.

Amongst the in-depth interview respondents, the satisfaction levels were lower, with the victims rating the banks a poor one out of five. Even in cases where the victims were able to recover their money fully or partially, the satisfaction with the banks remained low. Notably, there was not much variation in the reported experience or satisfaction levels across private and public-sector banks.

(Radhika Jha is Project Lead (Rule of Law) at Common Cause and lead researcher and author of the Status of Policing in India Report (SPIR) series. Views expressed are personal)

Published – October 07, 2026 08:30 am IST



Click Here For The Original Source.

——————————————————–

..........

.

.