Legal information notice: this article provides general information and isn't a substitute for advice from a qualified lawyer.
Unrecognized transactions, a login alert you didn’t trigger, or your net banking suddenly locked you out — a hacked bank account is one of the few situations where minutes genuinely matter. Here’s exactly what to do, in order, starting from the moment you notice something is wrong.
Use your bank’s app, net banking, or helpline to immediately block your debit/credit cards, net banking access, and UPI ID linked to the account. Don’t wait to “confirm” the hack first — block, then investigate.
Every bank has a 24×7 number for exactly this. Report the suspected compromise verbally right away — this starts the clock on your liability protection under RBI’s rules.
Once access is blocked, change your net banking password, UPI PIN, and any related passwords from a device you’re confident isn’t compromised. If you suspect malware on your phone/computer, don’t reuse that device until it’s cleaned.
Follow up the phone report with a written complaint (email works) within 3 working days of noticing the unauthorized activity — this is the key window for RBI’s zero-liability protection.
If any unauthorized transaction actually went through, file on cybercrime.gov.in or call 1930, in addition to your bank complaint — these are separate processes that both need to happen.
While your bank investigates, it’s worth keeping a close eye on your account for a few weeks rather than assuming the incident is fully resolved once you’ve blocked access. A single hack sometimes exposes more than one entry point — for example, both your net banking and a linked wallet or investment account — so a broader check is worth the extra few minutes.
If you suspect the breach happened through a compromised device (a phishing link you clicked, or an app you weren’t expecting to install), get that device properly scanned or factory reset before using it for banking again, even after changing your passwords elsewhere.
With those precautions in mind, it’s worth understanding exactly how much of any loss you’re actually liable for:
Under the RBI’s Customer Protection guidelines (2017), your liability for an unauthorized electronic transaction depends heavily on how fast you report it:
| Reporting Window | Your Liability |
|---|---|
| Reported within 3 working days | Zero liability, regardless of who was at fault, in most cases involving third-party breach |
| Reported between 4-7 working days | Limited liability — capped at a specific amount depending on your account type |
| Reported after 7 working days | Liability determined case-by-case per the bank's own board-approved policy |
This is exactly why calling your bank immediately — even before you’ve fully confirmed what happened — matters so much.
Start with your bank’s fraud helpline (verbal, immediate) and follow up in writing. Separately, file on the National Cyber Crime Reporting Portal or call 1930 if money actually left your account — the portal automatically routes your complaint to the cybercrime cell with jurisdiction, so you don’t need to identify the right police station yourself.
No — reporting to your bank, calling 1930, and filing on cybercrime.gov.in are all free. You’d only incur cost if you later need a lawyer to push back on a liability determination you believe is wrong.
Yes, for the reporting and initial recovery steps — this is designed for you to act on directly and immediately. A lawyer becomes useful if:
Need professional legal help with this?
Find a Lawyer on VidyodayIf the specific unauthorized activity was a fraudulent UPI transaction rather than a broader account compromise, our dedicated guide on UPI fraud recovery covers that process in more detail. If it was your credit card specifically, see reporting credit card fraud.
Check your transaction history and login activity log (most banking apps show this) — unrecognized transactions or logins from unfamiliar devices/locations are the clearest signs. When in doubt, report it anyway; banks would rather investigate a false alarm than miss a real breach.
It’s a rule under RBI’s 2017 Customer Protection guidelines that makes you liable for zero amount in cases of third-party breach (like phishing or a bank system fault) provided you report the unauthorized transaction within 3 working days of receiving communication about it.
They can dispute the circumstances (for example, if they determine you shared your credentials yourself), but if you genuinely reported within the window and the breach wasn’t due to your negligence, you have strong grounds to escalate to the RBI Ombudsman if they refuse.
Not usually necessary — blocking access, changing credentials, and monitoring closely is typically sufficient. Your bank can advise if a full account closure and reopening is warranted for your specific case.
Report immediately anyway — your liability may be assessed case-by-case rather than zero, but you should still report and dispute any unauthorized transactions as soon as you discover them.
The cybercrime portal complaint is generally sufficient and gets routed appropriately, including to police where needed — you don’t need to separately visit a police station first.
Yes — if someone takes control of your registered mobile number (SIM swap), they can intercept OTPs and access your account. If you suddenly lose mobile signal unexpectedly, contact your telecom provider immediately in addition to your bank.
RBI guidelines expect resolution and any applicable credit within 10 working days of your complaint, though complex cases can take longer depending on the investigation.
This article is for general information only and does not constitute legal or financial advice. RBI rules and bank policies can be updated — verify current guidelines on rbi.org.in or with your bank before relying on this for a real case.