I clicked a phishing link and entered my bank details, what should I do now?

I received a fake bank/courier email or SMS and entered my card or net-banking details on a lookalike site. I have been reading conflicting things online and I would like to understand what Indian law actually says about this, which Act and Section applies, what the realistic timelines and costs are, and what I should be doing right now to protect my position. If the matter can be resolved without litigation I would prefer that route, but I want to know what my rights are before I agree to anything or sign any document.

I clicked a phishing link and entered my bank details, what should I do now? is governed in India primarily by Information Technology Act, 2000 – Section 66, Information Technology Act, 2000 – Section 66D and Information Technology Act, 2000 – Section 43. The short answer is set out below, followed by the practical steps most people in this situation need to take. Read it alongside the specific provisions named, because the exact relief available to you turns on the facts you can prove on paper.

Section 66 of the IT Act covers computer-related offences including dishonestly obtaining data through phishing, punishable with up to 3 years imprisonment or fine up to Rs 5 lakh, or both.

Immediately block your card/net-banking access through your bank's app or helpline to prevent further unauthorised debits, since every minute matters once credentials are compromised.

Change passwords for any other account where you reused the same password, since phishing kits often test stolen credentials across multiple sites.

Report the phishing URL to Google Safe Browsing and to CERT-In (cert-in.org.in) so the malicious site can be taken down and other users protected.

If money is already debited, follow the RBI zero-liability process by reporting to your bank within 3 working days in addition to filing at cybercrime.gov.in.

What to do next: 1) Block your card/net-banking immediately via the bank helpline; 2) Change passwords for that and any reused accounts; 3) Report the phishing link to CERT-In and the bank's fraud department; 4) File a complaint on cybercrime.gov.in or call 1930.

If the other side has already issued a notice, filed a case or set a deadline, treat the matter as time-sensitive — most remedies under Information Technology Act, 2000 – Section 66 carry limitation periods, and a delay you cannot explain weakens an otherwise strong case. You can post the details on the MyVakeel forum for a practising advocate to review, or book a paid consultation with a Bar Council verified lawyer in this practice area.

Disclaimer: This information is for general awareness and does not constitute legal advice. Statutes and their interpretation change, and outcomes depend on the facts of your case. Please consult a qualified advocate before acting on it.