Unauthorised Transaction on Your Account: Who Bears the Loss

The bank's first answer is almost always that you authorised it. That is a position, not a finding - and it is regularly reversed on complaint.

By Tayyab Ashraf · 2026-08-26

Unauthorised Transaction on Your Account: Who Bears the Loss

An unauthorised debit appears on your account. The branch tells you the transaction was authenticated with your credentials and the bank is not liable. Whether that is right depends on facts that the bank holds and you do not, and the way to get at them is to escalate properly rather than argue at the counter.

Report first, argue later

Everything that follows depends on the report being immediate and in writing.

  1. Call the helpline and have the card or account blocked. Note the time and the reference number.
  2. Follow up in writing the same day to the branch and the bank's complaint unit, describing the transaction, stating it was not authorised, and asking for it to be reversed and for the beneficiary account to be frozen.
  3. Where money has moved to another account, say explicitly that you are asking the bank to request a freeze on the beneficiary account. Speed here decides recovery.
  4. Report to the FIA Cybercrime Wing where the transaction was electronic.

Delay is the factor most often cited when a claim is refused, and it is the one entirely within your control.

How liability is actually analysed

There is no single statutory rule allocating the loss. The analysis draws on the account terms, the State Bank's consumer protection and conduct framework, and the facts.

The bank's position is strong where the customer disclosed credentials - OTP, PIN, card details, internet banking password - to a third party, and the bank's systems performed as designed.

The customer's position is strong where:

  • There was a failure in the bank's systems or controls - a data breach, a transaction processed without the required authentication, a card cloned at the bank's own ATM.
  • The customer had already reported a compromise or a lost card, and the transaction occurred afterwards.
  • The transaction pattern was one the bank's fraud monitoring should have flagged - an unusual amount, an unusual location, rapid successive transactions.
  • The bank failed to act promptly on the report, and the money was withdrawn in the interval.
  • Required alerts were not sent, depriving the customer of the chance to react.

The middle category - a customer socially engineered into giving an OTP to a caller who already knew their account details, card expiry and recent transactions - is genuinely contested. The fact that the caller held that data is itself evidence that it leaked from somewhere, and that argument is worth making rather than conceding.

Escalation, in order

  1. The bank's complaint unit, in writing, with the transaction details and your report timeline.
  2. The Banking Mohtasib, after the bank rejects the complaint or the period for its response expires. Free, no lawyer needed, and it can order compensation. Unauthorised-withdrawal complaints are squarely within its jurisdiction.
  3. The State Bank's public complaint facility, in parallel.
  4. Banking Court, for a substantial claim you wish to litigate.

Cards specifically

For card transactions there is an additional route: the chargeback. Card scheme rules allow a cardholder to dispute a transaction through the issuing bank, and the issuer raises it with the acquiring bank. There are strict time limits - often measured in weeks from the statement date - so raise a dispute rather than waiting for the bank's fraud investigation to conclude.

Ask the bank explicitly to raise a chargeback, and get the response in writing. Banks do not always volunteer it.

What to preserve

  • The SMS and email alerts for the disputed transaction
  • Your bank statement covering the period
  • The call log and any recording, where a caller was involved
  • Your report to the bank and its acknowledgment, with times
  • The beneficiary details, where the money was transferred
  • Your device, unwiped, where malware may be involved

Prevention that actually works

  • Set transaction limits on internet and mobile banking, and lower them to what you actually use.
  • Disable international and online use on cards you do not use that way, and enable it only when needed.
  • Keep alerts on for every transaction, however small - card testing usually begins with a trivial amount.
  • Never share an OTP. No legitimate bank, regulator or agency asks for one, and a caller displaying the bank's number proves nothing; caller ID is trivially spoofed.

This article describes the general position on unauthorised banking transactions in Pakistan. Liability turns on the account terms and the facts of the case. It is not advice on any specific dispute; report to your bank immediately and escalate to the Banking Mohtasib if refused.

This article is general legal information, not legal advice on your own facts. Read our legal disclaimer or speak to an advocate.