Author: Priyanka Ratnakar Musale
College: ILS Law College, Pune
LinkedIn Link: www.linkedin.com/in/priyankamusale
Abstract
Online financial fraud has emerged as a serious legal and social challenge in India with the rapid growth of digital banking, UPI, mobile applications, internet banking, and online payment platforms. Cybercriminals use various methods such as phishing, identity theft, fake customer-care calls, OTP fraud, UPI scams, investment fraud, and impersonation to unlawfully obtain money or confidential financial information from individuals. India has established a legal and regulatory framework to deal with such offences through the Bharatiya Nyaya Sanhita, 2023, the Information Technology Act, 2000, Reserve Bank of India (RBI) regulations, and the National Cyber Crime Reporting Portal. The law provides criminal remedies against offenders as well as mechanisms for reporting unauthorized transactions and seeking redressal. However, the increasing sophistication of cyber fraud, delays in investigation, difficulties in tracing digital transactions, and lack of public awareness continue to create challenges. This article examines the legal framework, important judicial decisions, and remedies available to victims of online financial fraud in India.
To the Point
Online financial fraud refers to the use of digital platforms, electronic communication, banking systems, or payment applications to deceive individuals and unlawfully obtain money or financial information. With the increasing use of UPI, internet banking, debit cards, credit cards, and digital wallets, the risk of financial cybercrime has also increased. Online financial fraud may take different forms, including phishing, OTP fraud, identity theft, fake investment schemes, QR-code fraud, impersonation, and unauthorized electronic transactions. Victims may suffer immediate financial loss and may also face risks relating to misuse of their personal and financial information. India regulates cyber financial fraud through the Bharatiya Nyaya Sanhita, 2023 (BNS)a nd the Information Technology Act, 2000. The RBI has also issued directions relating to customer protection in cases of unauthorized electronic banking transactions. Further, the Government has established the National Cyber Crime Reporting Portal and the cybercrime helpline 1930 for reporting cyber financial fraud. Effective protection requires immediate reporting, preservation of electronic evidence, cooperation between banks and law-enforcement authorities, and greater public awareness regarding digital security.
Use of Legal Jargon
Online financial fraud is governed by principles of cybercrime, electronic evidence, unauthorized electronic transactions, identity theft, cheating, personation, due diligence, customer liability, grievance redressal, and regulatory compliance. Section 318 of the Bharatiya Nyaya Sanhita, 2023 deals with cheating, while Section 319 deals with cheating by personation. These provisions may apply where a fraudster deceives a victim and dishonestly induces the victim to transfer money or property. The Information Technology Act, 2000 contains provisions relating to computer-related offences, identity-related offences, and cheating by personation using computer resources. Depending upon the facts of a case, these provisions may operate alongside the BNS.
The RBI’s framework on customer protection in unauthorizedelectronic banking transactions provides for zero or limited liability in specified circumstances. The extent of liability depends upon factors such as the role of the bank, the customer’s conduct, and the time taken to report the unauthorised transaction. The concept of electronic evidenceis also important in cybercrime proceedings. Bank statements, transaction records, emails, messages, call records, screenshots, IP-related information, and other digital records may assist investigators and courts in establishing the commission of an offence.
The Proof
The rapid expansion of India’s digital payment ecosystem has created significant opportunities for cybercriminals. Fraudsters frequently impersonate bank officials, police officers, government authorities, customer-care representatives, or investment professionals to obtain confidential information or induce victims to transfer money.The legal framework provides several remedies to victims. A person who notices an unauthorised electronic transaction should immediately inform the concerned bank or payment service provider. Prompt reporting is particularly important because the RBI framework recognizes the importance of timely notification in determining customer liability. The Government’s National Cyber Crime Reporting Portal provides a mechanism for reporting cybercrime. In cases of financial cyber fraud, victims can also contact the national cybercrime helpline 1930. Immediate reporting may assist authorities and financial institutions in taking steps to prevent further movement of the fraudulent funds.
The RBI has also established the Reserve Bank – Integrated Ombudsman Scheme, 2021, which provides a mechanism for addressing complaints relating to deficiency in service by covered regulated entities, subject to the conditions of the Scheme. Despite these mechanisms, several challenges remain. Cybercriminals often operate through multiple bank accounts, digital wallets, mobile numbers, and online platforms. Tracing the ultimate beneficiary can therefore be difficult. Cross-border transactions and the use of sophisticated technologies can further complicate investigation and recovery. Therefore, effective enforcement requires coordination between banks, payment service providers, cybercrime authorities, law-enforcement agencies, and regulatory bodies.
Case Laws
1. Shreya Singhal v. Union of India, (2015) 5 SCC 1
The case arose from a challenge to various provisions of the Information Technology Act, 2000. The petitioners challenged Section 66A, which criminalized sending certain online communications considered offensive or objectionable. The issue before the Supreme Court was whether the provision violated the fundamental right to freedom of speech and expression under Article 19(1)(a) of the Constitution. The Supreme Court struck down Section 66A of the Information Technology Act, 2000 in its entirety as unconstitutional. The Court held that the provision violated Article 19(1)(a) and was not protected by the reasonable restrictions under Article 19(2). The judgment is important in understanding the constitutional limits on regulation of online activities and the use of the IT Act.
2. Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473
The case arose from an election dispute in Kerala where the appellant relied upon CDs and other electronic records to support allegations concerning the election. The Supreme Court had to determine how electronic records should be admitted as evidence under the Indian Evidence Act. The main issue concerned the requirements of Section 65B for proving electronic records. The Supreme Court held that secondary electronic evidence must satisfy the requirements of Section 65B of the Indian Evidence Act, 1872. The Court emphasized the need for proper certification and authentication of electronic records. This judgment is highly relevant to online financial fraud because digital transaction records, emails, messages and other electronic evidence may be crucial for proving the offence.
3. Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1
The case involved a reference concerning the interpretation of Section 65B of the Indian Evidence Act and the admissibility of electronic records. The Supreme Court was required to clarify the law laid down in Anvar P.V. v. P.K. Basheer and determine the circumstances in which a certificate is required for electronic evidence. The Supreme Court reaffirmed the principles laid down in Anvar P.V. and held that the certificate under Section 65B(4) is generally a condition for admitting secondary electronic evidence. The Court stressed that safeguards are necessary because electronic records can be altered or manipulated. This case is directly relevant to online financial fraud, where digital records can establish the transaction, communication and other circumstances of the alleged fraud.
Conclusion
Online financial fraud is a growing challenge in India’s rapidly developing digital economy. The increasing use of UPI, internet banking, digital wallets, and online financial services has made financial transactions convenient but has also created new opportunities for cybercriminals. India has established a legal framework through the Bharatiya Nyaya Sanhita, 2023, Information Technology Act, 2000, RBI regulations, and cybercrime reporting mechanisms. Victims can seek criminal action against offenders, report unauthorized transactions to their banks, approach the cybercrime authorities, and use appropriate grievance-redressal mechanisms.
However, legal remedies are most effective when victims act immediately. Delay in reporting may make it more difficult to trace and recover fraudulently transferred funds. Preservation of electronic evidence is equally important for investigation and prosecution. Stronger coordination between banks, payment platforms, regulatory authorities, and law-enforcement agencies, along with greater public awareness and effective cybersecurity measures, is necessary to control online financial fraud. Protecting victims in the digital economy requires not only effective laws but also timely enforcement and responsible use of technology.
FAQs
Q1. What is online financial fraud?
Online financial fraud refers to the unlawful use of the internet, digital platforms, banking applications, UPI, or electronic payment systems to deceive people and obtain money or financial information. It includes phishing, OTP fraud, UPI scams, identity theft, fake investment schemes, and impersonation. Such fraud may attract criminal liability under applicable laws in India.
Q.2 What should a victim do immediately after an online financial fraud?
A victim should immediately contact the concerned bank or payment service provider and report the unauthorizedtransaction. The fraud should also be reported through the 1930 cybercrime helpline and the National Cyber Crime Reporting Portal. Transaction details, screenshots, messages, call records and other digital evidence should be preserved. Immediate reporting may help authorities trace or prevent further movement of the funds.
Q.3 Can a victim recover money lost through online financial fraud?
Recovery depends on the facts of the case, the nature of the transaction and the circumstances in which the fraud occurred. RBI’s customer protection framework provides zero or limited liability in certain unauthorized electronic transactions. The victim’s conduct and the time taken to notify the bank are important factors. Therefore, reporting the fraud immediately is extremely important.
Q4. What legal remedies are available to victims of online financial fraud in India?
Victims can report the offence to the cybercrime authorities and initiate criminal proceedings against the offender. Relevant provisions of the Bharatiya Nyaya Sanhita, 2023 and the Information Technology Act, 2000 may apply depending on the facts. Victims can also approach their bank and, where applicable, use the RBI’s grievance-redressal mechanism. Electronic evidence should be preserved to assist investigation and prosecution.


