Who Bears the Loss in Mobile App Fraud? Analyzing Equity Bank vs. Irene Birungi

Equity Bank Uganda Limited v Irene Birungi HCCA No.0032 of 2024 [2026] UGCommC 333 Judgement by Hon. Lady Justice Anna B Mugenyi dated 25th June 2026

Rebecca Mutesi

Related practice

Brief facts

On 30th December 2019, the Respondent, Ms. Irene Birungi, opened a bank account (Account No. 1003101398764) with the Appellant, Equity Bank Uganda Limited, at its Katwe Branch, making an initial deposit of UGX 500,000. Subsequently, the Respondent made further deposits, bringing her total account balance to UGX 27,000,000. On 7th July 2020, the Respondent withdrew UGX 2,000,000, leaving a verified credit balance of UGX 25,000,000.

On 12th October 2020, when the Respondent visited the Appellant bank to conduct transactions, she was shocked to discover that her account balance had been depleted to a mere UGX 27,100. Unauthorized withdrawals totaling UGX 25,000,000 had been executed via the bank's mobile application ('Eazzy Banking App'), which had been registered on her telephone number (0705742289).

The Respondent instituted Civil Suit No. 0821 of 2020 before the Chief Magistrates Court of Kampala at Mengo, seeking recovery of UGX 25,000,000, general damages, and costs.

The Appellant Bank defended the suit by alleging that the Respondent was approached in October 2020 by telecommunication (Airtel) officials requesting a SIM swap for her registered number, and that she willingly handed over her phone number, National Identification details, and banking information.

The Bank contended that third parties used these details to download and self-register on the Eazzy Banking App using her phone number, rendering the Respondent contributorily negligent for compromising her account security.

The trial Magistrate entered judgment in favour of the Respondent, holding the Bank liable for the loss of UGX 25,000,000, awarding UGX 5,000,000 in general damages, interest at 8% per annum, and costs. Dissatisfied, Equity Bank lodged Civil Appeal No. 0032 of 2024 before the High Court (Commercial Division).

Issues

The High Court determined the appeal upon five consolidated grounds (treated as substantive issues):

1. Whether the Learned Trial Magistrate erred in law and fact in finding the Appellant Bank liable for the loss of the Respondent's funds amounting to UGX 25,000,000.

2. Whether the Learned Trial Magistrate erred in failing to evaluate the evidence regarding the Respondent's alleged contributory negligence in sharing her banking and SIM registration details.

3. Whether the Learned Trial Magistrate erred in law and fact in awarding UGX 5,000,000 as general damages.

4. Whether the Learned Trial Magistrate erred in awarding interest on the principal sum at the rate of 8% per annum from the date of filing until payment in full.

5. Whether the Appellant proved that the unauthorized mobile banking transactions were authorized by or attributable to the negligence of the Respondent

The Law Relied Upon

The High Court evaluated statutory provisions, international trade/banking standards, and binding appellate jurisprudence:

Statutory Law: The Financial Institutions Act (Cap 54) [Now Cap 57]; The Computer Misuse Act [Now Cap 96]; The Evidence Act (Cap 6) [Now Cap 8], regarding the burden of proof in electronic and banking transactions; and The Civil Procedure Act (Cap 71) [Now cap 282], governing appellate review, damages, and costs.

Appellate Case Law: Uganda Electricity Board v. Musoke (SCCA No. 13 of 1999) (principles governing appellate interference with discretionary awards of damages); Orient Bank Ltd v. Fredrick Zaabwe (SCCA No. 1 of 2005) (bank liability, fiduciary duties, and unauthorized debits); and established common law principles governing banker-customer relationships and electronic fraud liability.

The Ruling

Hon. Lady Justice Anna B. Mugenyi dismissed the appeal in its entirety with costs, ruling definitively in favor of the Respondent:

• On Bank Liability & Unauthorized Withdrawals (Grounds 1, 2, & 5): The Court held that the primary contractual relationship between a bank and its customer imposes an absolute duty on the bank not to disburse or debit customer funds without explicit authorization. The Appellant Bank failed to discharge its evidentiary burden to prove that the mobile app self-registration and subsequent withdrawals were authorized by the Respondent. The Bank's unverified assertions regarding SIM swap fraud did not absolve it from its institutional security and verification obligations.

• On Contributory Negligence: The Court rejected the Bank's defense of contributory negligence, noting that the Bank failed to substantiate any direct causal link between the Respondent's alleged interactions with third-party telecommunication agents and the systemic security vulnerabilities exploited within the Eazzy Banking App registration process.

On Damages and Interest (Grounds 3 & 4): The Court upheld the award of UGX 5,000,000 in general damages as moderate, reasonable, and proportionate to the severe inconvenience and deprivation of funds suffered. Furthermore, the court rate of 8% per annum on the principal sum was upheld as a proper exercise of judicial discretion to compensate for the prolonged loss of use.

Principles emphasized in the case.

The judgment established vital legal principles for commercial banks, financial institutions, and corporate clients engaging in digital banking and international trade, categorized below into systematic subtopics:

A. Strict Liability of Banks for Unauthorized Electronic Debits

A commercial bank is strictly liable to its customer for any unauthorized debits or withdrawals from the customer's account. The contractual mandate between a bank and customer dictates that money deposited remains the property of the customer repayable upon lawful demand, and the bank bears the legal burden of proving that every debit was expressly authorized.

B. Institutional Burden of Proof in Digital and Mobile Banking Fraud

Where fraudulent transactions occur via mobile applications (such as the Eazzy Banking App), the evidentiary burden rests squarely on the financial institution to demonstrate robust system integrity, flawless authentication protocols, and conclusive proof that the account holder personally authorized or executed the transaction.

Mere reliance on self-registration logs or unverified SIM swap allegations is legally insufficient to shift liability to the customer.

C. Insufficiency of Contributory Negligence Defenses Without Causal Proof

A bank cannot escape liability by casually alleging customer negligence (such as sharing phone or ID details) unless it establishes a direct, proximate causal link between the customer's conduct and the security breach. Financial institutions must implement multi-factor authentication (MFA) and rigorous verification layers that cannot be easily bypassed by third-party fraudsters during app onboarding.

D. Non-Interference of Appellate Courts with Discretionary Damages

Reiterating Supreme Court jurisprudence (Uganda Electricity Board v. Musoke), an appellate court will not interfere with a trial court's award of general damages or interest unless the trial court acted on wrong legal principles, misapprehended evidence, or rendered an inordinately high or low award representing an erroneous estimate of loss.

E. Compensatory Nature of Commercial Interest on Wrongfully Withheld Funds

An award of interest at the prevailing court rate from the date of filing until payment in full is a standard equitable remedy designed to compensate a litigant for being wrongfully deprived of capital and liquidity during protracted litigation, and does not constitute a punitive or excessive burden on the defaulting institution.

The Judge's Disposition

The High Court ordered as follows:

1. Dismissal of Appeal: Civil Appeal No. 0032 of 2024 was dismissed in its entirety, upholding the trial court's judgment in favor of the Respondent.

2. Principal Sum Recovery: The Appellant Bank is ordered to pay/refund the principal sum of UGX 25,000,000 to the Respondent.

3. General Damages: The award of UGX 5,000,000 as general damages for financial distress and inconvenience was affirmed.

4. Interest: Interest on the principal sum at the court rate of 8% per annum running from the date of filing suit until payment in full was upheld.

5. Costs of the Appeal: The Appeal was dismissed with costs awarded to the Respondent both in the High Court and the court below.

Practical Compliance Takeaways for Commercial Banks and Corporate Entities.

For Commercial Banks & Digital Financial Service Providers

• Enhanced App Onboarding & MFA Controls: Banks must overhaul mobile banking self-registration protocols. Relying solely on SMS OTPs or phone number verification is legally hazardous; institutions must implement biometric verification or mandatory in-branch validation for high-risk app registrations and large transactions.

• Rigorous Fraud Investigation Standards: When customers report fraudulent withdrawals, banks cannot dismiss claims by blaming third-party SIM swaps without conducting a thorough digital forensic audit and discharging the strict evidentiary burden required by law.

• Risk Mitigation & Insurance: Given the stringent judicial stance holding banks strictly liable for unauthorized digital debits, financial institutions must upgrade cybersecurity infrastructure, tighten fraud detection algorithms, and maintain adequate operational risk insurance.

For Corporate & International Trade Clients

• Vigilance with Digital Credentials: Corporate treasurers and trade clients utilizing mobile and internet banking platforms must maintain strict confidentiality of corporate login credentials, authorized device identifiers, and SIM cards.

• Immediate Dispute Reporting: In the event of unauthorized account activity or suspected SIM compromises, clients must immediately notify their bank in writing and formally log disputes to preserve legal rights for full recovery under established banking precedents.