I entered details on a fake link

A link from an SMS, WhatsApp or email opened a page that looked like your bank, and you entered your login or card details there.

Do this now

  1. Step 1.

    Within 5 minutes

    Call 1930 right now. It is the national cyber-crime helpline and runs 24 hours. The sooner the complaint is on record, the better the chance the bank can freeze the money — the first hour matters most.

    Call 1930
  2. Step 2.

    Within 15 minutes

    Call your bank on its official number — the one printed on the card or passbook — report the transaction as disputed and get the account or card frozen. Note the complaint number. Under the RBI circular, if the breach was a third party's and the deficiency lay neither with the bank nor with you, reporting within three working days of the bank's intimation leaves your liability at zero. But if you passed on the OTP, PIN or password yourself, you bear the entire loss until you report it — and the bank bears any loss after that. Which is why every hour of delay adds to the amount.

  3. Step 3.

    Within 20 minutes

    Change whatever password you typed into that page — and everywhere else you used the same password. Turn on two-step verification on every important account.

  4. Step 4.

    Within 45 minutes

    Remove any file or app that the link downloaded, and run a full scan on the device.

  5. Step 5.

    Within the first hour

    File the written complaint at cybercrime.gov.in and save the acknowledgement number. The phone complaint lands on the same portal, but only you can add the written account and the documents.

    File at cybercrime.gov.in
  6. Step 6.

    Within 24 hours

    Go to the nearest police station or cyber cell, give a written complaint and take the acknowledgement. A cyber-crime FIR can be registered at any police station — you cannot be turned away on the ground that it is not their jurisdiction.

Do not do this

  • Do not open the link again to 'check' it, and do not forward it to anyone.
  • Never share an OTP, UPI PIN, CVV or password with anyone — including someone claiming to be from your bank, the police or a 'cyber cell'. No real official ever asks.
  • Do not delete the chat, call log, email or messages — not even out of anger. That is your evidence, and it does not come back.
  • Do not pay another rupee to 'release your refund' or 'close the case'. Anyone who asks for money to get your money back is running a second fraud.

Preserve this evidence

  • The full URL of the website or link you opened — copied from the address bar, not retyped from memory.
  • Screenshot every screen with the date and time visible — the chat, the payment screen, the email, the profile.
  • The sender's phone number, UPI ID, email address, WhatsApp profile, and the link to any social-media account they contacted you from.
  • The UTR or reference number of every transaction, the amount, the time, and the full details of the account or UPI ID the money went to.
  • Leave the original messages, mails and files exactly where they are — the original counts as evidence alongside the screenshot. Delete nothing.

Similar cases

  • Phishing

    KYC phishing: the 'update today or your account will be blocked' message

    This is a composite illustration built from the near-identical complaints every bank receives daily, not the record of one real case; the amount only shows the typical order of magnitude, while the method, the warning signs and the sections cited are real. The basic point is that a bank never asks you to complete KYC through a link, and never asks for an OTP, PIN or CVV. One more thing is worth remembering: reporting within three working days of the bank's intimation gives the customer zero liability under the RBI customer protection framework.

    Amount lost
    ₹85,000
    Not recovered

National helplines

State cyber cells

This is educational information, not legal advice. For anything serious, speak to an advocate.