I clicked a phishing link and entered my bank details, what should I do immediately?

I received an email that looked like it was from my bank asking me to verify my account, and I entered my login details on the linked page. I have been reading conflicting things online and I would like to understand what Indian law actually says about this, which Act and Section applies, what the realistic timelines and costs are, and what I should be doing right now to protect my position. If the matter can be resolved without litigation I would prefer that route, but I want to know what my rights are before I agree to anything or sign any document.

I clicked a phishing link and entered my bank details, what should I do immediately? is governed in India primarily by Information Technology Act, 2000 – Section 66, Information Technology Act, 2000 – Section 66D and RBI Circular on Customer Liability in Unauthorised Electronic Transactions, 2017. The short answer is set out below, followed by the practical steps most people in this situation need to take. Read it alongside the specific provisions named, because the exact relief available to you turns on the facts you can prove on paper.

Phishing (creating a fake site to steal credentials) constitutes hacking/data theft under Section 66 and cheating by personation under Section 66D of the IT Act, both carrying up to 3 years imprisonment.

Immediately change your net-banking password/PIN and inform your bank so they can flag your account for suspicious activity monitoring, even before any unauthorised transaction occurs.

If a transaction does occur, the RBI's zero-liability circular protects you if reported within 3 working days, since the compromise arose from a third-party phishing attack rather than your own fraud.

Report the phishing email/website to your bank's fraud team and to CERT-In (cert-in.org.in), which can get the phishing site taken down and alert other potential victims.

Enable two-factor authentication and never click links in unsolicited banking emails; always navigate to your bank's site directly by typing the URL.

What to do next: 1) Change your net-banking credentials immediately and inform the bank; 2) Monitor your account and report any unauthorised transaction within 3 working days; 3) Report the phishing email/site to CERT-In and cybercrime.gov.in; 4) Enable two-factor authentication and avoid clicking links in unsolicited emails going forward.

If the other side has already issued a notice, filed a case or set a deadline, treat the matter as time-sensitive — most remedies under Information Technology Act, 2000 – Section 66 carry limitation periods, and a delay you cannot explain weakens an otherwise strong case. You can post the details on the MyVakeel forum for a practising advocate to review, or book a paid consultation with a Bar Council verified lawyer in this practice area.

Disclaimer: This information is for general awareness and does not constitute legal advice. Statutes and their interpretation change, and outcomes depend on the facts of your case. Please consult a qualified advocate before acting on it.