loaderimg
image
Cyber Law

Internet Banking Fraud: How to Report the Fraud and Recover Your Money

Share this article WhatsApp Facebook X

Legal information notice: this article provides general information and isn't a substitute for advice from a qualified lawyer.

Your net banking credentials — user ID, password, sometimes even your transaction PIN — ended up in a fraudster’s hands, and they used your own login to move money out. This is different from a single unauthorized transaction slipping through; your entire net banking access was compromised. Here’s exactly how to respond and recover.

What to Do Immediately

  • Change your net banking password immediately from a different, secure device if possible
  • Call your bank to freeze net banking access entirely if you can’t be certain the compromise is fully contained
  • List every transaction made without your authorization since the compromise likely began
  • File on the cybercrime portal or call 1930 without delay, given credential compromise often enables multiple transactions

How Credentials Usually Get Compromised

Internet banking fraud typically traces back to one of a few sources: a phishing email or SMS with a fake bank login page, a vishing call (a fraudster posing as bank staff, talking you through “verification” steps that actually hand over your credentials), malware on your device capturing keystrokes or screen activity, or a screen-sharing app installed under the guise of “technical support.” Identifying which one happened to you matters for both your bank’s investigation and preventing it from happening again.

Recovering Your Access and Money: Process at a Glance

01
Secure Your Account and Credentials
New password, possibly frozen access
02
Report Every Unauthorized Transaction
With dates, amounts, references
03
File on the Cybercrime Portal
cybercrime.gov.in or 1930
04
Bank Investigates the Compromise
Third-party breach assessment
05
Escalate to RBI Ombudsman if Denied
For a wrongly rejected claim
Step 1: Secure Your Account and Credentials Immediately

Change your password from a device you’re confident is clean, and consider asking your bank to temporarily freeze net banking access entirely if you’re not certain the compromise is contained.

Step 2: Report Every Unauthorized Transaction

List each fraudulent transaction with its date, amount, and reference number — credential compromise often enables multiple transactions in quick succession, so check your full recent history, not just the first one you noticed.

Step 3: File on the National Cybercrime Portal

Report at cybercrime.gov.in or call 1930 — given multiple transactions are often involved, prompt reporting improves the odds of funds still being traceable.

Step 4: Cooperate With Your Bank's Investigation Into the Compromise

Your bank will assess how the credentials were likely compromised — be specific about any suspicious call, message, or app you interacted with recently, since this directly affects the liability determination.

Step 5: Escalate to the RBI Ombudsman if Your Claim Is Wrongly Denied

If the bank denies your zero/limited liability claim without adequate basis, escalate through the RBI’s Complaint Management System.

Need Legal Help? Get expert legal help from experienced professionals with ApniLaw legal services across India. Advertisement

The distinction between “third-party breach” and “customer negligence” gets contested most often in exactly this scenario — a bank might argue you were negligent for entering credentials on a phishing page, while you were, in reality, the target of a genuinely sophisticated, convincing scam. Being deceived isn’t the same as being careless; this is worth pressing on directly if your bank tries to shift full liability onto you based on a technically-true-but-misleading framing.

If you installed a screen-sharing app because someone claiming to be from your bank or a payment app’s “support team” asked you to, be specific about this in your complaint — this is a well-documented, extremely common fraud pattern, and banks and law enforcement are generally familiar with recognising it as third-party deception rather than negligence.

Once your immediate situation is secured, review your device for malware (a full security scan) and reconsider any other accounts where you reused the same or similar passwords — credential compromise from one source frequently gets tried against other accounts too.

Need Immediate Legal Help?

Get Legal Help from ApniLaw Sponsored

Common Compromise Methods and What They Mean

How This Likely Happened

MethodWhat It Suggests
Phishing email/SMS with a fake login pageThird-party deception — not customer negligence
Vishing call posing as bank staffA sophisticated scam — worth reporting specifically as such
Malware/keylogger on your deviceTechnical compromise — get a full security scan done
Screen-sharing app for 'support'A well-recognised fraud pattern — state this explicitly

Where Do You File?

Report to your bank immediately, and file a parallel report on cybercrime.gov.in or via 1930. Escalate liability disputes to the RBI Ombudsman.

Does It Cost Anything?

All these channels — bank complaint, cybercrime portal, and RBI Ombudsman escalation — are completely free.

Can You Handle This Without a Lawyer?

Most cases are resolved directly with the bank and, if needed, the RBI Ombudsman. A lawyer becomes useful specifically where the bank disputes your account of how the compromise happened and denies liability on that basis.

What Happens After You Report?

  • Your bank investigates the compromise method and the pattern of unauthorized transactions
  • Zero or limited liability applies based on when you reported and whether it was a genuine third-party breach
  • Your cybercrime portal report supports law enforcement efforts to trace and potentially freeze funds
  • A wrongly denied claim can be independently reviewed by the RBI Ombudsman

Need professional legal help with this?

Find a Lawyer on Vidyoday

For the broader signs and general immediate response to a compromised account, see our guide on bank account hacked. For the full range of options across different fraud types, our guide on net banking fraud money recovery covers the complete picture.

Key Takeaways

  • Internet banking fraud usually traces back to phishing, vishing, malware, or a screen-sharing “support” scam — identifying which one matters for your bank’s liability investigation.
  • Being deceived by a convincing, sophisticated scam is not the same as negligence — push back if your bank frames it that way to deny liability.
  • Check your full recent transaction history, not just the transaction you first noticed — credential compromise often enables multiple transactions.
  • Reconsider any other accounts sharing the same or similar password — a single compromise is often tried against multiple accounts.

Frequently Asked Questions

This is common — describe your best understanding of recent suspicious calls, messages, or app installations, and your bank’s technical investigation can sometimes identify the specific vector even if you’re not certain.

A password change combined with enabling additional security features (like login alerts) is usually sufficient — permanently closing access is rarely necessary unless your bank specifically recommends it during an active investigation.

This is a serious escalation — report it immediately as a priority, since it can block your own alerts and further compromise your account; your bank has specific emergency procedures for this scenario.

This depends on your bank’s specific response — some temporarily restrict access during investigation, others allow continued use once your password is changed; confirm directly with your bank.

Mention this in your report, since it can be relevant to understanding how malware or phishing might have reached the device, though it doesn’t change your individual liability assessment.

The same RBI zero/limited liability framework applies across electronic banking channels generally, though the specific compromise method can differ between mobile apps and web-based platforms.

Ask your bank about additional verification — checking for any unfamiliar registered devices, active sessions, or linked payment methods — to confirm nothing else was set up during the compromise.

This varies by complexity, but many banks provisionally credit disputed amounts within about 10 working days pending the full investigation outcome.

Vidyoday
Vidyoday Editorial Team
Cyber Law & Banking Fraud
Reviewed and published by Vidyoday.
Disclaimer:

This article is for general information only and does not constitute legal advice. Liability determinations depend on the specific facts of each case — consult a cyber law lawyer for guidance specific to your situation.

Leave a Comment