Imagine checking your bank account and discovering that ₦2 million has been transferred without your permission. You immediately report the transaction to your bank and request a reversal. The bank investigates and tells you that the transaction was successfully authenticated. It then refuses to refund the money. At this point, two important questions arise: Can you sue a bank for an unauthorised transaction in Nigeria? And if the bank refuses to refund the money, what can you do to recover it? The answer is yes, a bank can be sued where the facts establish a valid legal claim against it. However, the mere fact that a customer did not personally initiate a transaction does not automatically make the bank liable. The circumstances surrounding the transaction must be examined carefully. This includes how the transaction was initiated, what authentication was used, whether the customer’s credentials were compromised, whether the customer disclosed any security information, what the bank’s systems detected, how quickly the transaction was reported and what the bank did after receiving the complaint. This article explains when a bank may be liable for an unauthorised transaction, whether a bank is required to refund the money, what evidence you need, what to do if the bank refuses to reverse the transaction and when legal proceedings may be appropriate. What Is an Unauthorised Bank Transaction? An unauthorised bank transaction is a transaction carried out on a customer’s account without the customer’s authority. It can include: Unauthorised bank transfers. Unauthorised ATM withdrawals. Unauthorised POS transactions. Unauthorised card payments. Unauthorised online payments. Unauthorised debits. Transactions resulting from compromised banking credentials. The circumstances differ from case to case. For example, a person may gain access to a customer’s banking application, obtain the customer’s card details through fraud, compromise the customer’s account or use other means to initiate a transaction. The legal consequences depend substantially on how the transaction occurred. Can You Sue a Bank for an Unauthorised Transaction? Yes. A customer can sue a bank where the facts establish a legally recognisable claim. However, the customer must establish the basis of the claim. A court will not simply order a bank to refund money because the customer says, “I did not authorise the transaction.” The evidence surrounding the transaction must be examined. Relevant questions include: How was the transaction initiated? What authentication was used? Was the customer’s device compromised? Was an OTP used? Was the customer’s PIN used? Did the customer disclose any security credentials? Did the bank detect unusual activity? Did the bank comply with applicable security requirements? When did the customer notify the bank? What action did the bank take after receiving the complaint? Can the recipient of the funds be identified? These questions can determine whether a claim against the bank is likely to succeed. Will a Bank Refund an Unauthorised Transaction? Not automatically. Whether a bank is required to refund an unauthorised transaction depends on the circumstances in which the transaction occurred and whether the bank breached a legal, contractual or applicable regulatory obligation. A bank is entitled to investigate a disputed transaction before deciding whether to reverse or refund it. However, the bank should not treat the fact that a transaction was successfully authenticated as automatically ending the customer’s claim. The relevant questions include: How was the transaction initiated? Was the customer’s PIN, OTP, password or other authentication credential used? Did the customer disclose any security credentials? Was the customer’s device or account compromised? Did the transaction display unusual or suspicious characteristics? Did the bank’s systems detect or respond appropriately to the transaction? How quickly did the customer report the transaction? What steps did the bank take after receiving the complaint? Therefore, the answer to “will a bank refund an unauthorised transaction?” depends on the evidence. Where the evidence establishes that the bank was responsible for the loss or breached a duty owed to the customer, the customer can pursue appropriate reliefs, including recovery of the money and, where justified, damages or other consequential relief. On the other hand, where the evidence establishes that the customer’s own conduct caused or materially contributed to the loss, the bank may rely on that conduct in defending the claim. The correct approach is therefore to establish how the transaction occurred and who bears legal responsibility, rather than assuming that either the bank or the customer is automatically liable. What If the Bank Says the Transaction Was Authenticated? This is one of the most common responses from banks. The bank may say that: Your PIN was correctly entered. Your OTP was successfully used. Your mobile banking application was used. The transaction came from your registered device. The transaction passed the bank’s authentication system. That evidence is relevant, but it does not necessarily end the dispute. Authentication establishes that the bank’s system received the required credentials. It does not, by itself, answer every question concerning who actually initiated the transaction or whether the transaction resulted from fraud, compromise or another circumstance for which the bank may bear responsibility. The particular facts must therefore be examined. What If You Gave the Fraudster Your OTP? This can significantly affect the case. Suppose a fraudster impersonated your bank and persuaded you to disclose an OTP. The fraudster then used the OTP to transfer money from your account. The bank may argue that you authorised the transaction or were negligent in disclosing the OTP. Whether that argument succeeds depends on the circumstances. The customer’s conduct is important, but so are the bank’s security, fraud-detection and customer-protection obligations. A customer should therefore provide the complete facts when reporting the incident rather than withholding information that may later become relevant. What If You Did Not Give Anyone Your PIN or OTP? That can strengthen the customer’s position, particularly where the evidence indicates that the transaction occurred despite the customer’s security credentials not being disclosed. The bank may still investigate how the transaction was completed. However, where there is evidence of a compromised account, security failure, unusual transaction activity or other