Legal information notice: this article provides general information and isn't a substitute for advice from a qualified lawyer.
Not one transaction — several, in quick succession, draining your account before you’ve even had time to process what’s happening. Multiple unauthorized transactions in a short window is a genuinely different, more urgent situation than a single fraudulent charge, and it needs a faster, more coordinated response. Here’s exactly what to do.
With multiple transactions happening rapidly, the single biggest priority is stopping any further loss — freezing access matters more, in the first few minutes, than having a perfectly complete list of every transaction. Once access is secured, you can methodically go through your statement to compile the full picture without the fraud continuing to worsen while you do it.
Block your cards, freeze net banking and mobile banking access, and disable UPI through your app if you’re at all unsure whether the fraud has stopped — this is the single highest-priority action.
Call your bank’s dedicated fraud helpline (not general customer service) the moment you notice the first unauthorized transaction — don’t wait until you’ve identified every single one, since every minute of delay risks another transaction going through.
With access secured, methodically go through your statement or app to list every unauthorized transaction — date, time, amount, and reference number for each.
Report at cybercrime.gov.in or call 1930, providing as complete a list as you can — a pattern of multiple rapid transactions is itself significant evidence for the investigation.
Each individual transaction’s zero/limited liability determination generally runs from when you were alerted to that specific transaction — keep your documentation organized transaction-by-transaction, not just as one combined total.
A rapid sequence of multiple transactions is, in itself, strong evidence of a serious, active compromise — not a one-off error or an isolated dispute — and this pattern generally works in your favour when establishing a third-party breach rather than negligence. Banks and investigators recognize this pattern well, since it’s a hallmark of an automated or actively-controlled fraud in progress, not something a customer would plausibly cause through a single lapse.
Given the volume involved, organize your evidence clearly from the start — a simple table of date, time, amount, and reference number for each transaction, rather than scattered screenshots, makes both your bank’s investigation and any cybercrime portal report considerably faster to process and act on.
If some transactions in the sequence are smaller “test” amounts followed by larger ones, mention this pattern specifically — it’s a well-recognized fraud technique (testing whether a card/account works before attempting a larger transaction) and helps establish the deliberate, third-party nature of what happened.
| Aspect | Multiple Transactions |
|---|---|
| Priority action | Freeze everything first — documentation comes second |
| Evidence value | The pattern itself supports third-party breach, not negligence |
| Reporting approach | Report immediately, add details as you compile them |
| Liability assessment | Generally per-transaction, tracked from each alert |
Call your bank’s fraud helpline immediately. File on cybercrime.gov.in or via 1930 without delay.
Freezing your accounts, reporting to your bank, and filing on the cybercrime portal are all free.
Most cases, once access is frozen and reported promptly, are handled directly with the bank. A lawyer becomes useful where the total amount is substantial or the bank disputes liability across multiple transactions.
Need professional legal help with this?
Find a Lawyer on VidyodayFor the complete liability framework governing each transaction, see our pillar guide on RBI rules on unauthorized electronic transactions. If your bank has now blocked your account as a precaution following your report, our guide on bank account blocked after reporting fraud explains what happens next.
File one combined report describing the full sequence — banks and the cybercrime portal are equipped to handle multiple related transactions within a single case, which is also more efficient than several disconnected reports.
Report all of them together, regardless of individual size — the full pattern, including smaller “test” transactions, is relevant evidence even if some individual amounts seem too minor to matter on their own.
Yes, temporarily — this is an expected tradeoff during an active fraud response; you can typically resume normal transactions once your bank confirms the account is secure.
Report the full mixed pattern as one connected incident — this actually suggests a broader compromise (like stolen credentials) affecting multiple channels, which is important context for the investigation.
Fraud helplines are generally prioritized for faster response than general customer service, precisely because of situations like this — but exact response times vary by bank.
Your bank statement will show the precise timestamps — don’t rely on memory for the sequence; pull the actual transaction log once you’re compiling your complete list.
Generally, liability is assessed per transaction based on when you were alerted to that specific one — reporting the full pattern promptly protects your position across the whole sequence.
Contact your bank immediately again — this suggests either the freeze wasn’t fully effective or a different channel/account is also compromised, and needs urgent, direct escalation.
This article is for general information only and does not constitute legal advice. Liability determinations depend on the specific facts of each transaction — consult a cyber law lawyer for guidance specific to your situation.