I clicked a phishing link and entered my bank details, what should I do immediately?
I received an email that looked like it was from my bank asking me to verify my account, and I entered my login details on the linked page. I would like to understand which provision governs this, what it entitles me to, and how long I have before the remedy lapses. I also want to know whether I need a lawyer for this or can do it myself.
In India, the answer to "I clicked a phishing link and entered my bank details, what should I do immediately?" turns on Information Technology Act, 2000 – Section 66, Information Technology Act, 2000 – Section 66D and RBI Circular on Customer Liability in Unauthorised Electronic Transactions, 2017. The points below set out the position and then what to do about it, in the order it should be done.
Phishing (creating a fake site to steal credentials) constitutes hacking/data theft under Section 66 and cheating by personation under Section 66D of the IT Act, both carrying up to 3 years imprisonment.
Immediately change your net-banking password/PIN and inform your bank so they can flag your account for suspicious activity monitoring, even before any unauthorised transaction occurs.
If a transaction does occur, the RBI's zero-liability circular protects you if reported within 3 working days, since the compromise arose from a third-party phishing attack rather than your own fraud.
Report the phishing email/website to your bank's fraud team and to CERT-In (cert-in.org.in), which can get the phishing site taken down and alert other potential victims.
Enable two-factor authentication and never click links in unsolicited banking emails; always navigate to your bank's site directly by typing the URL.
What this means for you: 1) Change your net-banking credentials immediately and inform the bank; 2) Monitor your account and report any unauthorised transaction within 3 working days; 3) Report the phishing email/site to CERT-In and cybercrime.gov.in; 4) Enable two-factor authentication and avoid clicking links in unsolicited emails going forward.
Where the facts are disputed, what usually decides a phishing email bank fraud matter is the paper trail — dated complaints, acknowledgments and written replies under Information Technology Act, 2000 – Section 66. You can post the details on the MyVakeel forum for a practising advocate to review, or book a paid consultation with a Bar Council verified lawyer in cyber law.
Disclaimer: This information is for general awareness and does not constitute legal advice. Statutes and their interpretation change, and outcomes depend on the facts of your case. Please consult a qualified advocate before acting on it.