A recurring type of inquiry received by Pakistani lawyers now begins with an alarming sentence:
“My mobile phone suddenly stopped working, and when I regained access, money had disappeared from my bank account.”
Sometimes there is one transfer. Sometimes there are five or ten. Sometimes substantial sums move in rapid succession. Occasionally, transactions appear across more than one banking application during the same episode.
The customer complains to the bank. The bank investigates. A few days or weeks later comes the response:
“Customer Liability.”
Many customers assume that those two words end the matter.
They do not.
Equally, however, the opposite assumption — that every fraudulent transaction must automatically be reimbursed by the bank — is also legally incorrect.
The real question is much more sophisticated:
What actually happened technically, what did the customer do or not do, what authentication occurred, what did the bank’s systems detect, and what evidence can each side produce?
That distinction is now particularly important in Pakistan.
Online Banking Fraud Is No Longer Simply a Question of “Was I Scammed?”
Pakistan has a statutory regime specifically dealing with electronic fund transfers.
The Payment Systems and Electronic Fund Transfers Act, 2007 treats an unauthorised electronic fund transfer as an “error” for statutory purposes. Section 36 requires the financial institution to investigate an alleged error and report its findings in writing. Section 38 further provides that where the institution concludes that no error occurred, the consumer may request copies of the documents relied upon in reaching that conclusion.
Sections 40 and 41 deal more directly with consumer liability and proof. Section 41 provides that where an action concerns a consumer’s liability for an unauthorised electronic fund transfer, the burden lies upon the financial institution or authorised party to demonstrate the matters prescribed by the legislation.
That provision sounds powerful — and it is important — but it should not be misunderstood as creating automatic bank liability every time a customer says, “I did not mean to lose this money.”
The Lahore High Court addressed precisely this difficulty in United Bank Limited v President of the Islamic Republic of Pakistan, W.P. No. 983 of 2025 and connected petitions, decided on 2 May 2025, reported as 2025 LHC 2736.
The Court drew an important distinction between different forms of digital fraud.
One situation involves money being removed without the customer’s knowledge or approval.
Another involves a customer who, because he has been deceived, actually performs or facilitates some part of the transaction himself — perhaps by providing credentials, entering an OTP or issuing what technically appears to the banking system to be a valid payment instruction.
The latter type is commonly described as authorised push payment fraud.
The legal consequences are not necessarily identical. The Lahore High Court emphasised that the Banking Mohtasib must examine the actual transaction configuration, the customer’s involvement, whether sensitive information was shared, how promptly the fraud was reported, and questions of contributory or comparative negligence rather than simply imposing automatic liability upon a bank whenever fraud is alleged.
This is why the first version of your story matters enormously.
“Customer Liability” Is a Conclusion. Ask What Evidence Produced It.
Suppose a person wakes up to find PKR 1 million missing from his bank account.
The bank says that valid credentials were used.
That does not, without more, answer every relevant question.
A proper investigation may need to determine which device initiated the transactions; whether that device had previously been registered to the customer; whether a new device was registered shortly beforehand; whether credentials were reset; whether new beneficiaries were added; whether transaction limits changed; whether multiple transfers occurred unusually quickly; whether transaction alerts were generated promptly; and whether the bank’s fraud-monitoring systems recognised behaviour inconsistent with the customer’s normal banking pattern.
These are not fanciful questions invented by lawyers after the event.
The State Bank of Pakistan’s BPRD Circular No. 04 of 2023, concerning security of digital banking products and services, required banks and microfinance banks to implement enhanced controls by 31 December 2023. SBP expressly warned that banks failing to implement the stipulated controls could be required to compensate affected customers.
The accompanying liability framework is particularly important. Among other matters, it provides for financial-institution liability where stipulated controls have not been implemented or have failed, and specifically addresses situations in which the institution is unable to establish that disputed transactions were executed through the customer’s registered device.
The regulatory landscape has continued to develop. In October 2025, SBP introduced its Business Conduct and Fair Treatment of Consumers Regulatory Framework, now the governing framework for responsible business conduct and fair treatment of consumers by financial institutions within its scope.
Accordingly, receiving the sentence “Customer Liability” should generally provoke another question:
On what technical, contractual and regulatory evidence has that conclusion been reached?
Five Transfers in Ten Minutes May Tell a Different Story from One Normal Transfer
Transaction pattern matters.
Imagine that a customer ordinarily transfers PKR 10,000 or PKR 20,000 at a time.
One afternoon, four transfers of PKR 200,000 each suddenly leave his account, followed by another substantial transfer.
Legally, that does not automatically prove negligence by the bank.
But neither should it necessarily be treated as an entirely unremarkable sequence merely because the correct password or OTP appears somewhere in the system.
The regulatory question may include whether the pattern ought to have engaged fraud-monitoring controls, whether beneficiaries were newly created, whether device characteristics changed, whether the IP address or geographical information was unusual, and what happened between the first suspicious transaction and the last.
Timing can therefore become evidence.
So can the customer’s previous transaction history.
Fraud Across Two Banking Apps Can Be Particularly Important
Another increasingly interesting scenario involves a customer who discovers unauthorised activity affecting accounts at two different banks during the same period.
At first sight, a person may conclude:
“Both banks were hacked.”
That may be entirely wrong.
The common point of compromise might instead be the customer’s telephone, SIM, email account, Android permissions, Google account, malicious APK, remote-access application or another element common to both banking relationships.
But that does not automatically dispose of the banks’ own responsibilities either.
If a device was compromised, one still needs to understand what each bank’s authentication and device-binding architecture permitted the attacker to do.
The correct legal investigation therefore works backwards from evidence rather than forwards from assumptions.
One of the Biggest Mistakes Victims Make: Writing Too Much, Too Quickly
When frightened people lose money, they understandably want immediate action.
They email the branch.
Then the helpline.
Then the complaint department.
Then State Bank.
Then the Banking Mohtasib.
Then a cybercrime authority.
Then perhaps Facebook, LinkedIn and X.
Increasingly, they ask an AI system to draft every complaint.
By the time a lawyer sees the matter, there may be six versions of the same incident — and they do not always match.
One says:
“I never received an OTP.”
Another says:
“I received an OTP but never entered it.”
A third says:
“I entered the OTP because the caller said he was from the bank.”
A fourth says:
“My phone was completely hacked and I had no control over anything.”
Those are not stylistic differences.
They can describe legally different cases.
A person who genuinely had no knowledge of a transaction occupies a potentially different evidential position from someone who personally communicated the instruction after being deceived.
The Lahore High Court’s 2025 decision makes that distinction particularly important.
AI Is Useful. Unsupervised AI Legal Pleadings Can Be Dangerous.
Artificial intelligence can be extremely useful after a fraud.
It can help organise a timeline.
It can convert screenshots into a chronology.
It can identify missing documents.
It can help a customer prepare questions for a lawyer.
It can assist in comparing bank correspondence.
What it should not be allowed to do unsupervised is invent the legal theory of a live banking dispute and then populate that theory with assumed facts.
An AI system does not have the bank’s server logs.
It does not know whether a device was newly registered.
It does not know whether an OTP was generated, delivered or entered.
It does not know whether the customer had installed a remote-access application.
It does not know whether the beneficiary existed previously.
And unless carefully grounded in current law, it may cite provisions which are irrelevant, outdated or simply wrong.
The danger becomes still greater when the generated text is submitted to an adjudicatory forum.
Under section 82D of the Banking Companies Ordinance framework governing the Banking Mohtasib, a complaint is made in writing on solemn affirmation or oath, setting out the particulars of the complained-of transaction. The Mohtasib also has power to receive evidence on affidavit.
Accuracy therefore matters.
An elegant paragraph containing an inaccurate fact is not an improvement.
It is a potential evidential problem.
Do Not Confuse Sunwai, SBP, the Banking Mohtasib and Cybercrime Authorities
Another common mistake is “complaint spraying”: submitting substantially the same text to every organisation whose name appears on Google.
Pakistan’s complaint architecture is more structured than that.
SBP’s Sunwai portal is designed to route banking complaints to the appropriate redressal forum. The bank is ordinarily the first forum, Banking Mohtasib Pakistan is a second forum for relevant complaints, while SBP itself deals directly with certain categories of matters.
The Banking Mohtasib is expressly authorised to deal with matters including failures to follow banking laws and regulations, fraud relating to transfer of funds, and fraudulent or unauthorised withdrawals or debit entries.
A cybercrime complaint serves another function: identifying and prosecuting the person who committed the criminal act and tracing the digital trail.
Those objectives can overlap, but they are not identical.
Finding the fraudster and establishing the bank’s civil or regulatory responsibility are different legal questions.
Similarly, the fact that the Banking Mohtasib procedure is designed to be accessible and does not require a lawyer does not mean that every complex digital-fraud case is best pursued without legal advice.
A citizen can represent himself.
The question is whether he should first understand what case he is actually presenting.
What Should Be Preserved Before You Start Writing?
In serious digital-banking fraud cases, evidence preservation should generally precede lengthy argumentative correspondence.
Depending upon the facts, relevant material can include bank statements, exact transaction timestamps, complaint acknowledgements, SMS and email alerts, telephone call records, screenshots, device-security notifications, mobile-network information, evidence concerning SIM replacement or loss of connectivity, Google or Apple security notifications, information concerning applications recently installed, and correspondence with the bank.
The bank’s own evidence can be equally important.
A legal review may focus upon authentication logs, registered-device records, beneficiary creation, credential-reset activity, transaction limits, IP information, transaction alerts and whatever material formed the basis of the bank’s finding that the transaction was authorised or represented “customer liability”.
Section 38 of the Payment Systems and Electronic Fund Transfers Act, 2007 is important in this regard because, following a finding that no error occurred, the consumer may request copies of the documents upon which the financial institution relied.
The point is not to bombard the bank with twenty technical buzzwords copied from the internet.
The point is to identify which evidence actually matters in the particular case.
What if the Customer Did Make a Mistake?
This is where legal advice should be candid rather than theatrical.
Some customers do disclose OTPs.
Some install remote-access software after being deceived.
Some provide their PIN.
Some click a malicious link.
Some approve a transaction believing that they are reversing another transaction.
Those facts can substantially affect the case.
Hiding them from one’s own lawyer is usually disastrous.
A lawyer who knows the bad fact can analyse it.
A lawyer who discovers the bad fact from the bank’s response after having already filed an absolute denial on the client’s behalf has a much more difficult problem.
The Lahore High Court has expressly recognised that contributory negligence and comparative negligence may be relevant in these disputes.
The objective should therefore not be to manufacture a perfect victim.
It should be to establish the truthful legal character of the transaction and then determine what obligations remained upon the bank notwithstanding the customer’s conduct.
Why Early Legal Advice Can Be Worth More Than Late Litigation
People often approach lawyers backwards.
They spend nothing when the evidence is fresh.
They draft their own letters.
They copy language from Facebook.
They submit AI-generated complaints.
They allow deadlines to pass.
They make inconsistent statements.
They lose screenshots.
They reset the compromised phone.
They discard the SIM.
They pursue several forums simultaneously without understanding jurisdiction.
Then, six months later, after the case has become difficult, they ask a lawyer to “fix it”.
That is false economy.
A good legal opinion obtained early does not necessarily mean filing litigation.
Quite the opposite.
The best advice may be to obtain particular records, supplement an existing complaint, correct a misconception, wait for an investigation, make a targeted representation, or conclude that litigation would not be commercially sensible.
Good lawyers are not merely people who take disputes to court.
Much of their value lies in preventing a manageable problem from becoming a badly documented lawsuit.
The Banking Mohtasib Is Handling a Very Large Complaint Burden
This is not an obscure area of consumer grievance.
Banking Mohtasib Pakistan reported 21,392 complaints received and 18,482 disposed of as at 30 June 2026, together with PKR 762.76 million in monetary relief provided to banking customers during the first half of 2026.
That volume itself illustrates why a carefully constructed complaint matters.
A forum dealing with thousands of files needs to understand quickly:
What happened?
What is disputed?
What evidence supports the allegation?
Which banking obligation is said to have been breached?
What exactly is the relief sought?
A twenty-page AI-generated essay containing every banking statute ever enacted is rarely a substitute for a disciplined evidential case.
The Practical Lesson
If you discover an unauthorised digital banking transaction, act quickly.
Notify the bank.
Secure the affected banking channels.
Preserve the device and evidence.
Report criminal activity to the appropriate authority where required.
But before submitting elaborate explanations across several regulatory and adjudicatory forums, consider obtaining legal advice.
Your first detailed complaint may later become part of the evidence by which your credibility, your conduct, the nature of the transaction and ultimately the allocation of liability are assessed.
The fraud itself may have taken five minutes.
Do not spend the next five months accidentally helping the other side explain why you should bear the loss.
At Josh and Mak International, we increasingly receive inquiries concerning unauthorised bank transfers, compromised mobile banking applications, disputed electronic transactions and findings of “customer liability”. Our approach is to examine the evidence first: what the customer actually did, what the bank’s systems apparently did, what the applicable statutory and SBP framework required, and which remedy is commercially and procedurally appropriate.
A formal legal opinion can then provide a roadmap which a client may use either to pursue the matter personally or, where representation is warranted, through counsel.
Disclaimer: This article is general legal information concerning Pakistani banking and electronic-funds-transfer law. Individual liability in digital fraud cases is intensely fact-sensitive. Nothing in this article constitutes a prediction that a particular customer or bank will succeed in any individual dispute.
Filed Under: online banking fraud Pakistan, unauthorised bank transfer Pakistan, customer liability bank fraud, Banking Mohtasib Pakistan, SBP online banking fraud, mobile banking fraud Pakistan, electronic fund transfer Pakistan, bank fraud lawyer Pakistan, hacked bank account Pakistan, digital banking fraud Pakistan
