A Fake PNB Credit Card Ad on Facebook Ends in ₹7.80 Lakh Cyber Fraud

Contents

One senior citizen, one social media ad, and a legal question that matters to every account holder: who bears the loss when the bank itself was impersonated?

A 69-year-old resident of Noida, Uttar Pradesh, has allegedly lost ₹7.80 lakh in a cyber fraud after responding to a purported Punjab National Bank (PNB) credit card advertisement on Facebook. According to the complaint, fraudsters posing as bank representatives contacted the victim via WhatsApp, convinced him to complete a credit card application, and obtained sensitive banking information. The stolen credentials were then used to transfer funds from his bank accounts through internet banking.

The pattern is a familiar one in Noida’s recent cybercrime caseload — a near-identical scheme drained ₹9.63 lakh from a 66-year-old retired engineer after he clicked a “credit card upgrade” ad, and another cost a Bisrakh senior citizen ₹21.27 lakh through a fake utility-bill payment link. What makes this fraud category distinct isn’t the technology; it’s the brand impersonation. The victim wasn’t tricked by an anonymous stranger — he believed, reasonably, that he was dealing with his own bank.

69Victim’s Age

₹7.80LAmount Lost

3Platforms Used: FB, WhatsApp, Net Banking

1. Anatomy of the Fraud

The Funnel: From Ad Click to Account Drain

Unlike the mule-account and hacking cases in this series, this fraud required no technical breach at all — it relied entirely on the victim trusting a familiar brand name at each step of a carefully staged funnel.

  1. The bait: A Facebook advertisement offering a PNB credit card — a plausible, everyday financial product — caught the victim’s attention.
  2. The handoff: Clicking the ad routed the victim to fraudsters posing as bank representatives, who moved the conversation to WhatsApp — a channel banks rarely use for official onboarding, but one victims associate with personal, trustworthy contact.
  3. The application: The victim was walked through what appeared to be a genuine credit card application, during which sensitive banking details — likely including card numbers, OTPs, or net-banking credentials — were extracted under the guise of “verification.”
  4. The extraction: Using the harvested credentials, the fraudsters allegedly executed transfers directly through the victim’s internet banking, moving ₹7.80 lakh out before the fraud was discovered.

2. The Statutory Framework

What the Fraudsters Can Be Charged With

Bharatiya Nyaya Sanhita (BNS), 2023 — Cheating & Impersonation

A near-identical Noida case was booked under the BNS provisions covering cheating and fraudulent impersonation. Posing as a PNB representative to extract banking credentials is a straightforward fit for both offences — the impersonation induces trust, and the trust induces the transfer.

Information Technology Act, 2000 — Section 66D

Section 66D — cheating by personation using a computer resource — covers exactly this scenario: fraudsters using a fake ad, a WhatsApp identity, and a spoofed application process to impersonate a bank and extract money through electronic means.

Information Technology Act, 2000 — Section 66C

If the fraudsters used the victim’s harvested credentials (login ID, password, card details) to operate his net banking as though they were him, that additionally constitutes identity theft under Section 66C.

3. The Bank’s Angle

Does PNB Owe the Victim Anything?

This is the question that separates this case from a pure criminal matter: because the fraudsters impersonated PNB itself, the victim has a separate — and often stronger — avenue of recourse against his own bank, independent of whether police ever catch the fraudsters.

The RBI’s 2017 circular on customer protection in unauthorised electronic banking transactions sets out a graded liability framework specifically for cases like this one, where a third party fraudulently induces a customer to part with credentials:

Reporting TimelineCustomer Liability
Reported within 3 working days of receiving transaction notificationZero liability — bank must credit the full amount, provided the loss isn’t due to customer negligence
Reported within 4–7 working daysLimited liability, capped per the customer’s account/card type
Reported after 7 working daysLiability determined by the bank’s own board-approved policy — can be significant

The determining factor is almost always how quickly the fraud was reported after the transactions occurred, and whether the loss stemmed from the bank’s own systemic vulnerability versus the customer’s own negligence — a line that gets blurry precisely in social-engineering cases like this, where the customer was actively deceived rather than careless. This distinction is likely to be central if the victim pursues a complaint with the RBI Banking Ombudsman.

4. The Platform Question

What About Facebook?

The fraud began with a paid advertisement carrying PNB’s brand identity, run on a platform that approved and displayed it. Under Section 79 of the IT Act, intermediaries like Meta (Facebook’s parent) generally enjoy safe-harbour protection from liability for third-party content — but that protection is conditional, not absolute. It depends on the platform exercising “due diligence,” a standard sharpened considerably by the IT Rules, 2021, which require intermediaries to act on complaints of impersonation and fraudulent content within defined timelines once notified.

Banks have increasingly begun reporting fake-ad networks impersonating their brands directly to platforms and to the Indian Cyber Crime Coordination Centre (I4C), and PNB itself maintains a dedicated security-alerts channel warning customers about exactly this category of scam. Whether platform-level takedown obligations were triggered — and met — in this specific case is likely to become relevant if regulators or the bank pursue the ad network itself, separate from the individual fraudsters who ran the WhatsApp conversation.

5. Closing Assessment

What This Case Signals

Cases like this one are less about technical sophistication and more about the erosion of a specific kind of trust — the assumption that if an ad looks official and a WhatsApp contact sounds professional, it must be legitimate. For elderly account holders in particular, who are frequently and specifically targeted in this fraud category, the practical defence remains the same one banks keep repeating: banks do not solicit card applications or OTPs over WhatsApp, and any “representative” who asks for credentials through an unsolicited chat should be treated as a red flag, not a convenience.

For the victim, timing now matters as much as the criminal investigation. Reporting the fraud to the bank and via the National Cyber Crime Helpline (1930) as quickly as possible directly affects both fund-freezing odds and the customer-liability calculation under RBI’s framework — a step that, cybercrime cell data consistently shows, dramatically improves recovery outcomes when taken within the first hour.

Picture of Adarsh Singhal & Associates
Adarsh Singhal & Associates

Leave a Reply

Your email address will not be published. Required fields are marked *