
In February 2026, IDFC First Bank found itself at the center of a banking crisis that would test its operational resilience and leadership credibility. A routine account closure request from a Haryana government department revealed a discrepancy between what the customer believed they had and what the bank's records showed. What followed was the discovery of a ₹646 crore fraud at the Chandigarh branch, involving collusion between bank employees, customer representatives, and external parties. Yet, how the bank handled this crisis offers a masterclass in crisis management that preserved depositor confidence and ultimately strengthened its control framework. Others
The fraud was sophisticated precisely because it exploited human trust rather than technical vulnerabilities. KPMG's forensic review, codenamed "Project Ultra," found that branch staff used modified authorization letters, altered cheques, manipulated approval emails, and fabricated fixed deposit documents to facilitate unauthorized fund transfers. The beneficiaries of these diverted funds had business or family links with former bank employees. Crucially, the Core Banking System records remained accurate throughout—customers received proper monthly statements and SMS alerts. This wasn't a system failure; it was a people failure where legitimate access credentials were weaponized through collusion. Others
The fraud's discovery was accidental. When the Haryana government department requested closure and fund transfer, reconciliation revealed the mismatch. From February 18, 2026 onwards, other government entities approached the bank with similar discrepancies. The aggregate amount under reconciliation was initially estimated at ₹590 crore, later confirmed at ₹646 crore through forensic review. The bank promptly paid this amount plus interest to affected departments, recognizing the expense in Q4 FY2025-26. Others +2
The bank employed advanced machine learning models for anti-money laundering, mule account detection, and transaction monitoring. Yet these systems failed to detect the fraud. The reason reveals a fundamental limitation of algorithmic fraud detection: ML models are designed to identify anomalous patterns based on historical data, but when authorized employees with legitimate credentials process transactions in coordination with customer representatives, the patterns appear normal. There were no unusual transaction velocities, no geographic anomalies, no new account opening patterns, and no cross-border involvement. The fraud evaded detection precisely because it followed established workflows, albeit with fraudulent intent. Others
The maker-checker controls, which assume the "maker" and "checker" operate independently, were neutralized when both parties were colluding. This represents a blind spot in banking control frameworks worldwide—systems designed to prevent individual fraud are vulnerable to coordinated collusion. Others +1
Managing Director & CEO V. Vaidyanathan's immediate visit to Chandigarh and direct engagement with senior Haryana government officials proved decisive. This CEO-level engagement signaled that the incident was treated as a board-level priority, not merely an operational issue. By personally meeting with affected stakeholders, Vaidyanathan demonstrated accountability at the highest level and preserved critical government banking relationships. Others
This decision, costing ₹646 crore plus interest, was driven by multiple considerations: preserving government trust, meeting regulatory expectations for customer protection, preventing reputational escalation, and positioning the bank as a victim rather than perpetrator. The KPMG review subsequently confirmed the amount was accurate, validating the bank's preliminary assessment. Others
The fraud provision dramatically distorted the bank's FY26 financial performance. Reported net profit grew just 7% year-on-year to ₹1,636 crore.
The single incident reduced the bank's growth rate by 32 percentage points. Transcripts
Q4 FY26 bore the brunt of this impact. Reported profit after tax was ₹319 crore, but normalized PAT (excluding fraud impact) reached ₹746 crore—a 145% year-on-year increase. Operating expenses grew 25.2% year-on-year in Q4, but excluding the fraud impact, growth was just 12.3%. The decision to recognize the full amount in Q4, while appropriate for accounting conservatism, created significant challenges for year-over-year performance comparison and temporarily masked the bank's underlying operational efficiency improvements. InvestorPresentations +2
Despite the fraud disclosure and simultaneous savings account rate cuts, deposits remained remarkably stable. Q4 FY26 saw marginal 1% quarter-on-quarter growth, moderating from 24% annual growth as of December 2025.
This resilience was achieved through a comprehensive confidence-building strategy. The bank conducted a nationwide verification exercise covering all government and trust account holders, sending physical and email statements reflecting closing balances as of February 28, 2026. The outcome was definitive: no discrepancies or claims were received from any other customers across the country. This clean verification provided empirical validation that the fraud was truly isolated to the Chandigarh branch, eliminating rational basis for deposit migration. Others
The bank implemented comprehensive control enhancements addressing the specific gaps exposed by the incident. The most significant architectural change was the addition of centralized team oversight on top of existing branch-level authorization. This dual-layer structure creates geographic separation between authorization and verification, making collusion significantly more complex and risky. Others
Customer communication protocols were fundamentally redesigned. A hybrid model now combines branch-mediated routine communications with centralized team communication for sensitive transactions. All electronic statements include cryptographic digital signatures with tamper-evident features. Document version control, secure delivery mechanisms, and proactive verification protocols prevent the sharing of falsified documents that enabled the Chandigarh fraud. Others +1
The bank's risk management systems are evolving from reactive to increasingly predictive, with enhanced behavioral analytics and machine learning models fed by centralized data aggregation. While ML models still struggle with sophisticated collusion involving legitimate credentials, the enhanced data architecture improves their effectiveness over time. Others +1
The bank's swift acceptance of responsibility, transparent disclosure framework, and customer-first approach reinforced its positioning as an institution committed to ethical conduct. Multiple regulatory filings under SEBI (LODR) Regulations, publication of forensic findings in the public domain, and regular analyst communications built trust through transparency rather than attempting to minimize negative information. Others +1
Management accountability extended to the highest levels—the Board of Directors extensively discussed the matter across multiple meetings, and key management personnel compensation was impacted for FY27. Four employees were suspended pending investigation, with strict disciplinary, civil, and criminal action promised. Others +1
The Chandigarh fraud represents a significant but isolated financial event that dramatically distorted IDFC First Bank's FY26 reported performance while revealing fundamental vulnerabilities in banking control frameworks. The bank's response—characterized by CEO-level engagement, same-day customer compensation, nationwide verification, and comprehensive control enhancements—demonstrates leading practice in crisis management. Others
Early indicators suggest the enhancements are effective. The clean nationwide verification results, strong Q1 FY27 deposit recovery, and absence of new fraud incidents provide validation. However, the evolving nature of fraud risk requires continuous monitoring, refinement, and investment. The bank's experience offers valuable lessons for the industry: machine learning alone cannot prevent sophisticated collusion, centralized oversight is essential for breaking collusion chains, and transparent communication builds trust faster than silence ever could. Others +1
The ₹646 crore provision was costly, but the investment in crisis management and control strengthening may yield dividends in enhanced resilience, stakeholder confidence, and competitive differentiation for years to come.