SAFIAH SULAIMAN BINTI ISMAIL v BANK KERJASAMA RAKYAT MALAYSIA BERHAD

ba-22ncc-59-05-2021 High Court (Mahkamah Tinggi) 24 September 2025 • BA-22NCC-59-05/2021 • 8 min read
3 cases cited (0 SG, 3 foreign)

Outcome

Oleh yang demikian, tuntutan Plaintif dengan ini ditolak.

Quoted verbatim from the judgment of High Court (Mahkamah Tinggi) (ba-22ncc-59-05-2021). Read the full judgment on the official Malaysia Courts portal for the complete decision.

Catchwords

Practice Areas

Judges (1)

Counsel (8)

Parties (2)

Case Significance

Instructive on the limits of a bank's fiduciary duty and duty of care to a customer, holding that a bank need not monitor every transaction and that a customer's disclosure of banking security information enabling an online scam breaks the chain of causation.

This High Court decision at Shah Alam concerns a bank customer's claim against her bank arising from an online scam, and the limits of a bank's duty to protect a customer's account. The plaintiff, an individual savings-account holder, sued the defendant, Bank Kerjasama Rakyat Malaysia Berhad, alleging that it had breached its fiduciary duty and its duty of care in protecting her bank account, in that several unauthorised transactions had been allowed to proceed, causing her substantial financial loss. The bank denied liability, asserting that it had complied with all banking security procedures and requirements, and that the loss stemmed from the plaintiff's own conduct in allowing her banking security information to be used by a third party, in particular by allowing a third party's telephone number to be used to receive the transaction authorisation code or PIN. The court, per Noor Hayati binti Haji Mat J, while acknowledging the reality of the growing incidence of online fraud and financial scams and expressing sympathy for the plaintiff's unfortunate loss, emphasised that the determination of liability must rest on established legal principles and the evidence. On the balance of probabilities it dismissed the claim. It held that a bank should not be burdened with a duty to monitor every transaction, since whether a transaction is suspicious is inherently subjective, and imposing an overarching duty to detect and prevent all transactions later alleged to be suspicious would be impractical and unreasonable. It further held that even if such a duty existed, which it did not find, the plaintiff had failed to prove causation, because the true cause of the loss was her own act in allowing her banking security information to be used by a third party, which broke the chain of causation between any negligence of the bank and the loss. Finding no breach of any fiduciary duty or duty of care, the court dismissed the claim with costs of RM40,000. The judgment is instructive on the limits of a bank's duty to a customer who discloses banking security information enabling an online scam.

Why did the court dismiss the customer's claim against the bank?

The court held that a bank is not obliged to monitor every transaction, since whether a transaction is suspicious is subjective and such a duty would be impractical, and that in any event the plaintiff had failed to prove causation because the true cause of her loss was her own disclosure of her banking security information, including allowing a third party's phone number to receive the authorisation code, which broke the chain of causation.

Did the court find the bank owed and breached a duty of care?

No. The court found no breach of any fiduciary duty or duty of care, holding that imposing an overarching duty to detect and prevent all allegedly suspicious transactions would be unreasonable, and that the customer's own conduct in disclosing her security information was the true cause of the loss.

Cases Cited (3)

UK (3)
[1986] AC 80 [1992] 4 All ER 363 [2023] UKSC 25

Judgment

Read the full judgment on the official Malaysia Courts portal.

Read on eJudgment

Source: eJudgment (ba-22ncc-59-05-2021)