Quick Summary
An NSE appellate tribunal directed IIFL Securities to pay a client ₹22,74,539 after finding the broker had not implemented the two-factor login security that regulations required, and then could not produce complete records of the internet addresses behind the disputed trades. The claim had been rejected twice before the appeal overturned it. The client won on a modern point most people never think to argue: the broker’s own security and record-keeping failed, so it could not prove the client placed the trades. This page shows how that works.
Unauthorised trading is simple to describe and brutal to live through. Trades appear in your account that you never placed and never approved.
With most brokers, the fight is about missing call recordings or absent order logs. With IIFL, the reviewed wins turned on something more technical and, frankly, more damning: the security and the digital records that were supposed to prove who placed the trades either did not exist or could not be produced.
That shifts the whole battlefield in the client’s favour, and one case shows it better than any other.
IIFL Unauthorised Trading Arbitration Case That Set the Ceiling
The client alleged that trades were run through his account by someone who had obtained his user ID and password, leaving him with a loss of over ₹22 lakh.
The grievance committee rejected him. A sole arbitrator rejected him again. He appealed.
On appeal, his argument was precise. Regulations required brokers to protect logins with two-factor authentication, meaning something the user knows, like a password, plus something only the user has, like a one-time password sent to their phone.
IIFL, he argued, had used only knowledge factors, a password plus a PAN or date of birth, both of which sit in the broker’s own systems and can be compromised there.
Had a proper second factor been in place, no one could have logged in as him.

Why IIFL Lost
The tribunal worked through two regulatory failures, and both are worth knowing.
First, the login security. IIFL argued that a second factor of OTP only became mandatory in a 2022 exchange circular, not the 2018 SEBI circular. The tribunal rejected that flatly.
It held that the SEBI circular was binding from the date SEBI set, and that the later exchange circular merely explained how to follow it.
A broker cannot treat a SEBI instruction as dormant until an exchange repeats it. So, IIFL had been non-compliant on login security throughout the disputed period.
Second, the internet addresses. A separate SEBI circular requires brokers to capture the IP address behind every internet trade, precisely so that disputes like this can be resolved.
When the client had the logs examined, the cyber cell reported that the addresses IIFL supplied were incomplete and could not be decoded.
The tribunal pointed this out: the broker had even filed an affidavit swearing the addresses did not belong to it or anyone acting under it, yet if the addresses were incomplete, there was no basis on which such an affidavit could be sworn.
The conclusion followed cleanly. When a broker fails to maintain the security and records that regulations require, and losses result, the broker bears them. The tribunal set aside the earlier award and ordered IIFL to make good the full ₹22,74,539.

The Same Principle, at Every Size
That case is the ceiling, but the same reasoning won others.
In one, a client alleged her entire ₹15 lakh was wiped out by unauthorised trades she said were placed from the franchisee’s terminal, not by her.
The broker insisted she had traded online herself. The tribunal focused on one duty: SEBI requires brokers to capture the IP addresses of online orders, exactly so this question can be answered. IIFL never produced them.
The tribunal held that an investor cannot be expected to prove she did not place a trade when the broker withholds the one record that would settle it, and awarded her ₹14,71,471.
In another, a 70-year-old with a migrated Karvy account found a trading account had been opened in his name using a one-time password his ailing wife had shared, believing it was for a routine KYC update.
The tribunal examined the account-opening file and found blank KYC columns, no branch official’s signature, a blank page bearing an electronic signature, and no proof of any offer by the client to open a trading account at all.
It held there was no valid bilateral agreement and the trading was unauthorised, awarding ₹6,04,419 and cancelling the brokerage.
The thread is unmistakable. You win these claims when the broker’s own systems fail the test. Missing authentication. Incomplete IP logs. An account-opening file that falls apart on inspection. The moment the digital trail cracks, the trades become unauthorised.
Want to look at the numbers? Read our detailed post on IIFL Securities Unauthorised Trading to see full yearly complaint stats and trends.
What to Do If It Happened to You?
If trades appeared in your account that you never placed, the case will turn on the records the broker holds, so the demands you make matter enormously.
Pull these together now:
- Your full trade ledger and contract notes for the disputed period
- Every SMS and email the broker sent about the trades, with dates
- Your account-opening file and KYC documents, if you can obtain them
- The dates you first noticed and first objected
- Any dealing you had with a franchisee, authorised person, or relationship manager around the disputed trades
The demands that win these cases: ask the broker, in writing, to produce the IP address logs for the disputed trades and to confirm what second factor of authentication was in force. In the winning cases, the broker’s inability to produce complete IP logs, or to show a proper second factor, is what decides them. These are technical requirements, but they are mandatory, and a tribunal will hold the broker to them.
Watch the authentication point specifically. If your login was protected only by a password plus a PAN or date of birth, with no one-time password to your phone, that may itself be a regulatory failure, as it was in the ₹22.7 lakh case.
If you are still at the complaint stage and have not escalated formally, our guide on filing a complaint against IIFL Securities covers the full route to the point where arbitration begins.
Did trades appear in your IIFL account that you never placed?
We demand the IP logs and authentication records, test them against the regulations the broker was bound by, and build the claim on the exact failures tribunals have acted on. Register with us to get help around your complaint.
An Honest View of the Odds
Let us be straight. These claims are winnable, and the data shows it from ₹6 lakh to ₹22 lakh, but they are not automatic.
Where the broker can show a proper authentication trail and produce complete, decodable IP logs pointing to your own devices, the claim is hard. Where the broker cannot, where the second factor was weak, or the logs are incomplete, the burden shifts onto the broker, and that is where clients win.
You will not know which situation you are in until the records are demanded and examined. That demand is the work, and it is the step most people never take.
Conclusion
The ₹22.7 lakh award set the rule for the digital age of trading: a broker that skips mandated login security and cannot produce the IP records regulations require will answer for the losses that follow.
The ₹14.7 lakh and ₹6 lakh awards reinforce it from different angles, one on missing IP logs, one on an account-opening file that could not withstand scrutiny.
Recovery for unauthorised trading against IIFL is real. It comes down to whether the broker’s systems can prove you placed the trades, and whether your claim is built to expose the gap when they cannot.
Report. Recover. Stay Fraud Free.
Frequently Asked Questions
Any trade executed in your account without your instruction or consent. In the reviewed IIFL cases, this included trades placed after a login was compromised and trades in an account that was opened without a valid agreement. The burden sits with the broker to prove you authorised a disputed trade.
Two-factor authentication means a login needs two independent proofs: something you know, like a password, and something you have, like a one-time password sent to your phone. In the ₹22.7 lakh case, the tribunal found IIFL had used two knowledge factors that both sat in its own systems, which did not meet the requirement, and held the broker liable.
SEBI requires brokers to capture the IP address behind every internet order, so disputes over who placed a trade can be resolved. In two reviewed wins, IIFL either did not produce the IP logs or produced incomplete ones, and the tribunals held that failure against the broker.
In the reviewed awards, amounts included ₹22,74,539, ₹14,71,471, and ₹6,04,419. Each turned on a failure in the broker's authentication, IP records, or account-opening process. The amount always depends on the loss proven.






