On Quora Geetanjali M, an employee of Infoedge posting this following complaint
On 15.9.2017, starting from 1:27 am and ending at 1:33 am, 10 fraudulent transactions were made from my bank salary account back-2-back.
Payments of a total of 26,000 INR (rupees twenty six thousand) were made to PayU as per my A/C e-statement.
I lost my hard earned money and I want it back from Icicibank .
Transaction details as I can see from my e-statement are as follows:
The summary is as follows:
MIN/ /20170915012731/0 ---- Rs. 5000
MIN/PAY*WWW PAY/20170915012820/0 ---- Rs. 5000
MIN/PayU /20170915012950/0 - Rs. 2000
MIN/PayU /20170915013039/0 - Rs. 2000
MIN/PayU /20170915013112/0 - Rs. 2000
MIN/PayU /20170915013150/0 - Rs. 2000
MIN/PayU /20170915013222/0 - Rs. 2000
MIN/PayU /20170915013254/0 - Rs. 2000
MIN/PayU /20170915013320/0 - Rs. 2000
MIN/PayU /20170915013348/0 - Rs 2000
I am not sure how intelligently the bank is investigating the matter. I did not authorize these transactions. I was at home fast asleep and no notification for OTP for these 10 transactions were sent to my phone. Amounts were debited and SMS alerts and email alerts were sent to me after debits!
Lack of TWO FACTOR AUTHENTICATION at the end of ICICI BANK, one of the largest Private Banks of India, comes as a shocking revelation to me! This is my salary account, what is the guarantee that my money is safe with ICICI BANK in the future as well? This is so so very very dangerous! All the money went to some PayU thing. From what I can see online, PayU is a third party e-wallet which can receive money 24/7. The bank can easily pull back my money from them.
I also lodged an FIR with CYBER SECURITY CELL, NOIDA, UP POLICE DEPT. I personally wrote to PayU and attached the FIR copy in the email. They sent me the following details after 3 days. From this, you can see that my money floated seamless into into another website (and I am not sure where it floated away from here!) The IP is different from the ones I have in my possession and the location of this IP is Nasik, Maharashtra (I stay in Noida). I was just so tired of following up with everyone!!! Yet, I forwarded these details to ICICIBANK and CYBER CELL. I wrote to Ombudsman Reserve Bank of India (RBI) describing the entire case.
I have been with ICICI Bank (God only knows why) since 2010 and have always used the same ATM pin for all offline transactions. (Until that night, when I had to change my PIN and block my card before all my money got drained out!) For online transactions, I always use OTP as per the bank’s safety guidelines. But using OTP to authorize an online transaction is not a mandate, but a choice, which varies from app to app and website to website. 3D Secure (or insecure) pin can also be used WITHOUT OTP authentication for an online transaction. (This is insane as anyone can generate a 3DSECURE PIN with basic card details and DOB then and there!!!) Bank should make Internet Banking as the only valid option on websites/apps/portals which do not have 2 factor authentication and allow 3D Secure Pin usage/generation without OTP authentication.
I regularly update my login passwords from time to time, as advised by ICICI bank. But I was still cheated. How did card details leak (is it an internal hack/practice at the bank;’s end?) and how could they authorize not 1 or 2 but 10 fraudulent transactions back-2-back (clearly not a human-like phenomenon, but a bot/program/hacker carrying them out as 10 transactions were done in under 6 minutes) from my salary a/c? How much more irresponsible and careless can the bank be!?! ICICI Bank needs a stronger monitoring system in place to stop fraudulent transactions. I see copy-book similar cases have been reported as early as Dec last year and also in Aug/Sep 2017 on by so many customers. Spoke to some of them as well. Most of them are still waiting for the bank to take action. Some of them have even lost 5 figure amounts from their ICICI Bank Salary A/c. Its all over the internet that ICICI bank has topped the list in DEBIT CARD frauds in India. What are they doing to curb the situation? Why are they not taking necessary actions to stop such fraud debit card transactions which occur when innocent customers like me trust them with the money and sensitive card details?
Or is the bank carrying out this folly itself? I want my hard earned salary money back. I would rather donate it to a homeless person than allow some rich-as-hell hacker to squander on more cyber crimes. ICICIBANK must Stop these frauds from draining my account. They must assure me that I will not bear such losses ever and this was just an exception. Clearly, I have been cheated. This has to be taken up and considered as a case of sheer negligence on the PART OF ICICI BANK and deficiency in ICICI BANK customer service. This is inclusive of and not limited to legal action for compensation of full amount, inclusive of interest.
The ICICIBANK Dispute form (CDF) along with complaint details and identification documents have been submitted at ICICI Bank, Sector 110 Branch (Noida, UP). ICICI BANK, where Ankur Thomas, Asst. Manager told me that this investigation will take anything between 30 to 120 days. I lodged a complaint at CYBER CRIME CELL, NOIDA POLICE (UP) - FIR copy was scanned and saved to submit to ICICIBANK, RBI and other authorities.
I wrote to the following email ids with all requisite documents:
I also tried writing to Narendra Modi, but emails are bouncing back as his mailbox is full.
So tried writing to the PM from this portal - I don’t know what else to do! My hard earned 26000 is at stake, thanks to the sheer negligence of ICICI BANK CUSTOMER CARE and their DATA SECURITY TEAMS. Worst bank of India = Icicibank
Update as received on 22nd Sep 2017: SMS from ICICI BANK - “SR493750445: Dear Customer, Dispute for INR 26000 on Account ..XXXX.. has been declined as the transaction was authenticated with a 3D Secure PIN.”

