loaderimg
image
Cyber Law

Bank Account Hacked After Clicking a Suspicious Link? What to Do Immediately

Share this article WhatsApp Facebook X

Legal information notice: this article provides general information and isn't a substitute for advice from a qualified lawyer.

You clicked a link — maybe in an SMS about a “failed delivery,” an email about a “KYC update,” or a message that looked like it came from your bank — and now something’s clearly wrong with your account. What happens after that click matters as much as the click itself. Here’s exactly what to do, starting right now.

What to Do Immediately

  • Disconnect the device from the internet — turn off Wi-Fi/mobile data if you suspect malware may still be active
  • Do not enter any more credentials on that device until you’ve confirmed it’s clean
  • Call your bank from a different, trusted device to report the suspicious link and freeze/block access as needed
  • Report on the cybercrime portal or call 1930 immediately, and preserve the original suspicious message (screenshot it, don’t delete it yet)

What Actually Happens When You Click

A malicious link typically does one of a few things: takes you to a fake login page designed to capture your credentials the moment you enter them, silently installs malware (a keylogger or remote-access tool) in the background, or redirects you through a chain that eventually asks for information under a false pretext. Not every click results in compromise — but you should assume it might have until you’ve confirmed otherwise.

Securing Your Account and Device: Process at a Glance

01
Isolate the Device
Disconnect from the internet
02
Secure Your Banking From a Clean Device
Change password, freeze if unsure
03
Scan and Clean the Compromised Device
Full security scan, factory reset if needed
04
Report Every Unauthorized Transaction
With dates and reference numbers
05
File on the Cybercrime Portal
cybercrime.gov.in or 1930
Step 1: Isolate the Device You Clicked the Link On

Turn off its internet connectivity — this stops any malware that may have been installed from communicating further or capturing more of your activity.

Step 2: Secure Your Banking Access From a Different, Clean Device

Change your net banking password and PIN from a device you’re confident wasn’t affected, and consider asking your bank to temporarily freeze access if you’re not certain the compromise is contained.

Step 3: Thoroughly Clean the Compromised Device

Run a full security/antivirus scan, and if you have any doubt about whether it caught everything, a factory reset (after backing up unaffected data) is the most reliable way to be certain the device is genuinely clean.

Step 4: Report Every Unauthorized Transaction to Your Bank

List each transaction with its date, amount, and reference number — this feeds directly into your liability claim under the RBI’s protection framework.

Step 5: File on the National Cybercrime Portal

Report at cybercrime.gov.in or call 1930, and keep the original suspicious message as evidence rather than deleting it immediately.

Need Legal Help? Get expert legal help from experienced professionals with ApniLaw legal services across India. Advertisement

This is squarely a “third-party breach” under the RBI’s liability framework, not customer negligence — being deceived by a convincing fake message, even one you clicked on, isn’t the same as knowingly handing over your credentials. Report within 3 working days of your bank’s transaction alert and you’re entitled to zero liability for any resulting unauthorized transaction, provided your bank can’t show you were actually negligent beyond simply clicking the link.

Keep the original phishing message itself rather than just describing it — the specific sender number/email, the exact wording, and the URL it linked to are all genuinely useful evidence both for your bank’s investigation and the cybercrime portal report, and this evidence tends to degrade quickly once messages get deleted or apps get uninstalled.

If you’re not entirely sure whether the device is clean even after a scan, err toward caution — reset it, or at minimum avoid using it for banking until you’re confident. The cost of extra caution here is small compared to the cost of a second compromise from residual malware.

Need Immediate Legal Help?

Get Legal Help from ApniLaw Sponsored

Common Outcomes of a Malicious Link

What HappenedWhat It Means
Fake login page you entered credentials intoYour credentials are compromised — change them immediately
Nothing visible happened after clickingMalware may still be silently installed — scan the device anyway
You entered OTP/personal details on the linked pageTreat as a confirmed compromise, act with urgency
You closed the page immediately without entering anythingLower risk, but still worth a precautionary scan

Where Do You File?

Report to your bank immediately through a trusted device. File a parallel report on cybercrime.gov.in or via 1930.

Does It Cost Anything?

Reporting to your bank and the cybercrime portal are both free. A security scan or device reset may involve your own time but typically no direct cost using built-in device security tools.

Can You Handle This Without a Lawyer?

Most cases resolve directly with the bank once reported promptly and clearly as a third-party breach. A lawyer becomes useful if the bank wrongly attributes the compromise to your negligence and denies your claim on that basis.

What Happens After You Report?

  • Your bank investigates the pattern of unauthorized activity following the link click
  • Being deceived by phishing is treated as third-party breach, not negligence, supporting a zero-liability claim if reported promptly
  • Your cybercrime portal report, including the preserved original message, supports law enforcement efforts to trace the source
  • A wrongly denied claim can be escalated per the standard RBI liability framework process

Need professional legal help with this?

Find a Lawyer on Vidyoday

For the complete liability framework this situation falls under, see our pillar guide on RBI rules on unauthorized electronic transactions. For the broader signs and response to a compromised account regardless of cause, our guide on bank account hacked covers that generally.

Key Takeaways

  • Isolate the device from the internet first — this stops any silently installed malware from communicating further while you secure your accounts elsewhere.
  • Being deceived by a convincing phishing link is third-party breach, not negligence — report within 3 working days for zero liability.
  • Preserve the original suspicious message rather than deleting it — it’s genuinely useful evidence for both your bank and law enforcement.
  • When in doubt about whether a device is fully clean, a factory reset is the most reliable way to be certain before resuming banking on it.

Frequently Asked Questions

Some malware operates silently for a period before being used — it’s still worth running a security scan and monitoring your accounts closely even without an obvious sign of compromise yet.

Banks generally don’t ask you to click a link to “verify” or “update” sensitive details urgently — when in doubt, go directly to your bank’s official app or website rather than clicking any link in a message.

Yes — most telecom providers have a mechanism to report and block spam/phishing numbers, which is worth doing alongside your bank and cybercrime portal reports.

The same principles apply regardless of the messaging platform — isolate the device, don’t enter further credentials, and report through the same channels.

In some cases, yes — certain malicious links can trigger a “drive-by” download or exploit without you entering anything, which is exactly why a precautionary scan is worthwhile even if you didn’t type anything in.

Change it everywhere, not just for banking — a compromised password reused across accounts extends the risk well beyond just your bank.

A thorough security scan from a reputable tool is often sufficient, but a factory reset is the more certain option if you have any lingering doubt, especially for a device used for sensitive banking activity.

Ask them to specifically check for new registered devices, changed contact details, or new beneficiaries — these are common downstream signs of a compromise that a general account check might miss.

Vidyoday
Vidyoday Editorial Team
Cyber Law & Banking Fraud
Reviewed and published by Vidyoday.
Disclaimer:

This article is for general information only and does not constitute legal advice. Device security and liability outcomes depend on the specific facts of each case — consult a cyber law lawyer for guidance specific to your situation.

Leave a Comment