Summary and Facts
Noor Farekh bt Mohamed Kassim v Bank Kerjasama Rakyat Malaysia Bhd [2026] 10 MLJ 137 concerned a cardholder who registered her friend's mobile number, not her own, for OTP verification. Eight transactions totalling RM11,500 were later made on the cards – actually by the friend's son – which she disputed as unauthorised. The bank found no fraud and sued for the outstanding RM8,060.03; she counterclaimed for negligence.
Legal Issues
Whether the disputed transactions were unauthorised, given they were authenticated by OTPs sent to her own registered number.
Whether the bank owed a “Quincecare” duty to query the transactions before processing them.
Court’s Findings
The cardholder failed to prove the transactions were unauthorised – by registering her friend's number for OTP verification, she had ceded control of the authentication channel, in breach of the card agreement's prohibition on third-party use.
Every OTP was delivered to the registered number and used to authenticate the transaction; the bank had no reason to suspect anything was irregular.
The Quincecare duty did not arise, since Malaysian law confines it to circumstances placing the bank on inquiry - none existed here, as the transactions appeared entirely regular.
The bank's monthly statements and certificate of indebtedness, never challenged for a specific manifest error, were conclusive proof of the debt.
Practical Implications
This case is a clear warning that cardholders remain responsible for safeguarding the authentication channel tied to their cards – registering someone else's number for OTPs effectively authorises that person to transact.
Banks that show OTPs were correctly delivered and that a reasonable investigation was conducted are unlikely to face a successful Quincecare-style claim in Malaysia.
Certificates of indebtedness remain strong evidence of a debt unless the customer can point to a specific, provable computational error – a bare denial is not enough.
