Legal information notice: this article provides general information and isn't a substitute for advice from a qualified lawyer.
You clicked a link — maybe in an SMS about a “failed delivery,” an email about a “KYC update,” or a message that looked like it came from your bank — and now something’s clearly wrong with your account. What happens after that click matters as much as the click itself. Here’s exactly what to do, starting right now.
A malicious link typically does one of a few things: takes you to a fake login page designed to capture your credentials the moment you enter them, silently installs malware (a keylogger or remote-access tool) in the background, or redirects you through a chain that eventually asks for information under a false pretext. Not every click results in compromise — but you should assume it might have until you’ve confirmed otherwise.
Turn off its internet connectivity — this stops any malware that may have been installed from communicating further or capturing more of your activity.
Change your net banking password and PIN from a device you’re confident wasn’t affected, and consider asking your bank to temporarily freeze access if you’re not certain the compromise is contained.
Run a full security/antivirus scan, and if you have any doubt about whether it caught everything, a factory reset (after backing up unaffected data) is the most reliable way to be certain the device is genuinely clean.
List each transaction with its date, amount, and reference number — this feeds directly into your liability claim under the RBI’s protection framework.
Report at cybercrime.gov.in or call 1930, and keep the original suspicious message as evidence rather than deleting it immediately.
This is squarely a “third-party breach” under the RBI’s liability framework, not customer negligence — being deceived by a convincing fake message, even one you clicked on, isn’t the same as knowingly handing over your credentials. Report within 3 working days of your bank’s transaction alert and you’re entitled to zero liability for any resulting unauthorized transaction, provided your bank can’t show you were actually negligent beyond simply clicking the link.
Keep the original phishing message itself rather than just describing it — the specific sender number/email, the exact wording, and the URL it linked to are all genuinely useful evidence both for your bank’s investigation and the cybercrime portal report, and this evidence tends to degrade quickly once messages get deleted or apps get uninstalled.
If you’re not entirely sure whether the device is clean even after a scan, err toward caution — reset it, or at minimum avoid using it for banking until you’re confident. The cost of extra caution here is small compared to the cost of a second compromise from residual malware.
| What Happened | What It Means |
|---|---|
| Fake login page you entered credentials into | Your credentials are compromised — change them immediately |
| Nothing visible happened after clicking | Malware may still be silently installed — scan the device anyway |
| You entered OTP/personal details on the linked page | Treat as a confirmed compromise, act with urgency |
| You closed the page immediately without entering anything | Lower risk, but still worth a precautionary scan |
Report to your bank immediately through a trusted device. File a parallel report on cybercrime.gov.in or via 1930.
Reporting to your bank and the cybercrime portal are both free. A security scan or device reset may involve your own time but typically no direct cost using built-in device security tools.
Most cases resolve directly with the bank once reported promptly and clearly as a third-party breach. A lawyer becomes useful if the bank wrongly attributes the compromise to your negligence and denies your claim on that basis.
Need professional legal help with this?
Find a Lawyer on VidyodayFor the complete liability framework this situation falls under, see our pillar guide on RBI rules on unauthorized electronic transactions. For the broader signs and response to a compromised account regardless of cause, our guide on bank account hacked covers that generally.
Some malware operates silently for a period before being used — it’s still worth running a security scan and monitoring your accounts closely even without an obvious sign of compromise yet.
Banks generally don’t ask you to click a link to “verify” or “update” sensitive details urgently — when in doubt, go directly to your bank’s official app or website rather than clicking any link in a message.
Yes — most telecom providers have a mechanism to report and block spam/phishing numbers, which is worth doing alongside your bank and cybercrime portal reports.
The same principles apply regardless of the messaging platform — isolate the device, don’t enter further credentials, and report through the same channels.
In some cases, yes — certain malicious links can trigger a “drive-by” download or exploit without you entering anything, which is exactly why a precautionary scan is worthwhile even if you didn’t type anything in.
Change it everywhere, not just for banking — a compromised password reused across accounts extends the risk well beyond just your bank.
A thorough security scan from a reputable tool is often sufficient, but a factory reset is the more certain option if you have any lingering doubt, especially for a device used for sensitive banking activity.
Ask them to specifically check for new registered devices, changed contact details, or new beneficiaries — these are common downstream signs of a compromise that a general account check might miss.
This article is for general information only and does not constitute legal advice. Device security and liability outcomes depend on the specific facts of each case — consult a cyber law lawyer for guidance specific to your situation.