Disputed card transactions: Why blaming the Bank was not enough

In Noor Farekh binti Mohamed Kassim v Bank Kerjasama Rakyat Malaysia Berhad, the High Court seems to have also adopted a fault-based approach in determining liability for alleged unauthorised online transactions.

The defendant alleged that her debit and credit cards were used for unauthorised purchases. The Bank’s investigation, however, found no evidence of unauthorised or fraudulent transactions. The defendant had registered the mobile number of her friend and adopted sister (SP-3) for One-Time Password (OTP) verification, effectively authorising SP-3 to use the cards. The disputed transactions were found to have been initiated by SP-3’s son through accounts registered in his own name.

The Bank sued to recover the outstanding amount, while the defendant counterclaimed for breach of contract and negligence in failing to prevent the unauthorised transactions, alleging she had not received any OTPs or SMS notifications. She sought general and exemplary damages.

The Magistrate’s Court allowed the Bank’s claim and dismissed the counterclaim. On appeal, the High Court affirmed the decision, holding that the defendant failed to prove the transactions were unauthorised and that she was in breach of her contractual obligations by permitting a third party to use her cards. The Court further found that the Bank had properly investigated the complaint, complied with Bank Negara Malaysia guidelines, and that no negligence or breach of duty was established.

The Court noted that the defendant had produced no expert or independent evidence to rebut the Bank’s findings. The loss was caused by her own conduct in granting access to third parties, not by any fault in the Bank’s systems.

An earlier version of this case summary was published by Foong Cheng Leong on LinkedIn.


Posted

in

by

Tags:

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *