Legal information notice: this article provides general information and isn't a substitute for advice from a qualified lawyer.
Cash was withdrawn or a purchase was made using your debit card and PIN — but you never entered it, and you’re now facing the uncomfortable question your bank will also ask: how did someone else know your PIN? The answer to that question genuinely shapes your recovery odds. Here’s how to think through it and respond.
A PIN-based unauthorized withdrawal generally traces back to one of a few sources: a skimming device that captured both your card data and PIN (via a hidden camera or keypad overlay) — this is third-party breach, not negligence; shoulder-surfing, where someone observed you entering it; someone with legitimate prior access to your card and a PIN you’d written down or shared at some point; or, less commonly, a PIN that was genuinely easy to guess (a birthdate, a repeated digit sequence) combined with physical access to your card.
Do this immediately through your banking app, net banking, or helpline — this stops further unauthorized use of the same card and PIN combination right away.
This is the single most important internal question — a skimmed PIN is a clear third-party breach; a PIN you wrote down and someone found, or shared at some point with someone who misused it, is a more complicated negligence question.
Provide your genuine understanding of how this happened, even if it’s not flattering to your own PIN-handling habits — an honest account, even one with some fault, gets handled better than a story that later turns out to be incomplete.
Where the withdrawal involved a specific individual with prior access (rather than an anonymous skimming operation), a formal police complaint may be necessary, particularly for larger amounts.
The bank will assess whether this was third-party breach or negligence based on the specific facts — cooperate fully, since a transparent, well-documented account tends to support a fairer outcome.
It’s worth being realistic here: if you genuinely wrote your PIN on the card itself, saved it in an obviously labeled phone note, or told it to someone for a one-time favor that they then misused, a bank can reasonably argue this contributed to the loss — this is exactly the kind of “customer negligence” the RBI framework distinguishes from third-party breach. Being honest about this from the start, rather than having it discovered during investigation, generally leads to a better outcome.
On the other hand, if you’ve never shared or written down your PIN and there’s no reasonable explanation other than a skimming device or a hidden camera, this is squarely third-party breach — report within 3 working days and you’re entitled to zero liability, with the burden on the bank to prove otherwise, not on you to prove your innocence.
Going forward, a few basic habits meaningfully reduce this specific risk: never write your PIN anywhere near your card, shield the keypad with your hand when entering it in public, and change your PIN periodically, especially after using it at an unfamiliar ATM or terminal.
| How the PIN Was Likely Known | Legal Classification |
|---|---|
| Skimming device with hidden camera/overlay | Third-party breach — report within 3 days for zero liability |
| Someone observed you entering it (shoulder-surfing) | Generally third-party breach, not negligence |
| You wrote it down or shared it with someone | Likely negligence — be upfront about this with your bank |
| Genuinely unclear how it was known | Report honestly and let the investigation determine this |
Report to your bank immediately. File a police complaint where a specific individual with prior access is involved, and report on cybercrime.gov.in for a skimming-related case.
Reporting to your bank, filing a police complaint, and the cybercrime portal are all free.
A clear third-party breach case (skimming, no PIN-sharing) can often be handled directly with the bank. A situation involving a known individual, or where your bank disputes your account of how the PIN was compromised, benefits from legal guidance.
Need professional legal help with this?
Find a Lawyer on VidyodayFor the complete liability framework underlying this decision, see our pillar guide on RBI rules on unauthorized electronic transactions. If this involved a cloned card rather than a known PIN, our guide on debit card cloned covers that specific scenario.
Report your honest best understanding — the bank’s investigation will also look at the specific transaction pattern and location, which can help establish what actually happened independent of your memory.
Not changing a PIN periodically isn’t the same as sharing or exposing it — this alone shouldn’t be treated as negligence sufficient to deny a legitimate third-party breach claim.
This supports a third-party breach explanation (likely skimming with the data used elsewhere) rather than negligence — mention this specifically in your report.
The underlying liability principles are the same regardless of whether the PIN was used at an ATM or a point-of-sale terminal — what matters is how the PIN itself was compromised.
This is a genuinely difficult, sensitive situation — report it honestly to your bank, and where the amount and circumstances warrant it, a police complaint remains an option regardless of the relationship.
Yes — since the burden of proof is on the bank, you’re entitled to understand the specific basis for any negligence finding they make against you.
This is worth mentioning specifically — a very recent PIN change followed quickly by unauthorized use can suggest the new PIN was also compromised through the same method as before, which is useful investigative context.
Many banks provisionally credit the disputed amount within about 10 working days pending the full investigation, consistent with the standard RBI framework timeline.
This article is for general information only and does not constitute legal advice. Liability determinations depend heavily on the specific facts of each case — consult a cyber law lawyer for guidance specific to your situation.