Legal information notice: this article provides general information and isn't a substitute for advice from a qualified lawyer.
Your net banking credentials — user ID, password, sometimes even your transaction PIN — ended up in a fraudster’s hands, and they used your own login to move money out. This is different from a single unauthorized transaction slipping through; your entire net banking access was compromised. Here’s exactly how to respond and recover.
Internet banking fraud typically traces back to one of a few sources: a phishing email or SMS with a fake bank login page, a vishing call (a fraudster posing as bank staff, talking you through “verification” steps that actually hand over your credentials), malware on your device capturing keystrokes or screen activity, or a screen-sharing app installed under the guise of “technical support.” Identifying which one happened to you matters for both your bank’s investigation and preventing it from happening again.
Change your password from a device you’re confident is clean, and consider asking your bank to temporarily freeze net banking access entirely if you’re not certain the compromise is contained.
List each fraudulent transaction with its date, amount, and reference number — credential compromise often enables multiple transactions in quick succession, so check your full recent history, not just the first one you noticed.
Report at cybercrime.gov.in or call 1930 — given multiple transactions are often involved, prompt reporting improves the odds of funds still being traceable.
Your bank will assess how the credentials were likely compromised — be specific about any suspicious call, message, or app you interacted with recently, since this directly affects the liability determination.
If the bank denies your zero/limited liability claim without adequate basis, escalate through the RBI’s Complaint Management System.
The distinction between “third-party breach” and “customer negligence” gets contested most often in exactly this scenario — a bank might argue you were negligent for entering credentials on a phishing page, while you were, in reality, the target of a genuinely sophisticated, convincing scam. Being deceived isn’t the same as being careless; this is worth pressing on directly if your bank tries to shift full liability onto you based on a technically-true-but-misleading framing.
If you installed a screen-sharing app because someone claiming to be from your bank or a payment app’s “support team” asked you to, be specific about this in your complaint — this is a well-documented, extremely common fraud pattern, and banks and law enforcement are generally familiar with recognising it as third-party deception rather than negligence.
Once your immediate situation is secured, review your device for malware (a full security scan) and reconsider any other accounts where you reused the same or similar passwords — credential compromise from one source frequently gets tried against other accounts too.
| Method | What It Suggests |
|---|---|
| Phishing email/SMS with a fake login page | Third-party deception — not customer negligence |
| Vishing call posing as bank staff | A sophisticated scam — worth reporting specifically as such |
| Malware/keylogger on your device | Technical compromise — get a full security scan done |
| Screen-sharing app for 'support' | A well-recognised fraud pattern — state this explicitly |
Report to your bank immediately, and file a parallel report on cybercrime.gov.in or via 1930. Escalate liability disputes to the RBI Ombudsman.
All these channels — bank complaint, cybercrime portal, and RBI Ombudsman escalation — are completely free.
Most cases are resolved directly with the bank and, if needed, the RBI Ombudsman. A lawyer becomes useful specifically where the bank disputes your account of how the compromise happened and denies liability on that basis.
Need professional legal help with this?
Find a Lawyer on VidyodayFor the broader signs and general immediate response to a compromised account, see our guide on bank account hacked. For the full range of options across different fraud types, our guide on net banking fraud money recovery covers the complete picture.
This is common — describe your best understanding of recent suspicious calls, messages, or app installations, and your bank’s technical investigation can sometimes identify the specific vector even if you’re not certain.
A password change combined with enabling additional security features (like login alerts) is usually sufficient — permanently closing access is rarely necessary unless your bank specifically recommends it during an active investigation.
This is a serious escalation — report it immediately as a priority, since it can block your own alerts and further compromise your account; your bank has specific emergency procedures for this scenario.
This depends on your bank’s specific response — some temporarily restrict access during investigation, others allow continued use once your password is changed; confirm directly with your bank.
Mention this in your report, since it can be relevant to understanding how malware or phishing might have reached the device, though it doesn’t change your individual liability assessment.
The same RBI zero/limited liability framework applies across electronic banking channels generally, though the specific compromise method can differ between mobile apps and web-based platforms.
Ask your bank about additional verification — checking for any unfamiliar registered devices, active sessions, or linked payment methods — to confirm nothing else was set up during the compromise.
This varies by complexity, but many banks provisionally credit disputed amounts within about 10 working days pending the full investigation outcome.
This article is for general information only and does not constitute legal advice. Liability determinations depend on the specific facts of each case — consult a cyber law lawyer for guidance specific to your situation.