If your account is compromised

Updated 16 August 2026 · 11 min read · Written and reviewed by the DematOpen team

The plain answer

A compromised account follows a fixed recovery sequence: reset the login password, reset the TPIN, ask the broker to freeze trading and debits, audit the ledger against the depository’s CAS, and report through the broker, SEBI SCORES and the cybercrime channels in parallel. The order exists because damage continues for as long as the intruder holds credentials.

Every minute spent wondering instead of resetting is a minute the intruder can still act. The two resets together cut session access and asset movement, which is why they come before everything else, including before you contact anyone. Reporting follows evidence, and evidence follows security.

How you know the account is compromised

The signs arrive in two forms: alerts you did not trigger and activity you did not authorise. An OTP you never requested, an email about a login from a device you do not own, an app that logs you out mid-session, a support message confirming a change you never asked for. Each one is the system telling you someone else holds credentials.

The second form is ledger activity. An order you did not place, a debit in the transaction list, a payout request, or a CAS movement that does not match your own trades. The CAS is the depository’s independent record, and when it disagrees with your memory, treat the difference as an intruder until proven otherwise.

  • An OTP, login alert or password-change email you did not request.
  • The app showing an order, debit or payout request you did not place.
  • A login from a device or location the app lists as unfamiliar.
  • A CAS entry that does not match any trade you made.
  • A broker or "support" call asking you to share an OTP or PIN.

The recovery sequence

  1. Reset the login password from your own device
  2. Reset the TPIN to block share movement
  3. Ask the broker to freeze trading and debits
  4. Audit the app ledger against the CAS
  5. Report to the broker, SCORES and cybercrime
The recovery sequence: security first, evidence second, reporting third.

The first two steps cut access. The login password guards the door; the TPIN guards the assets. Both resets run through your registered mobile and email, and each one works even if the intruder changed the other. Do both, in that order, from your own device, before you spend time on anything else.

The third step, the freeze, stops movement while you investigate. The fourth, the audit, builds the evidence. The fifth, reporting, starts the recovery and investigation lanes. Reversing the order means collecting evidence while the intruder is still inside, which collects more damage instead of more proof.

StepActionWhy it comes at this point
1Reset the login passwordCuts session access and locks the door
2Reset the TPINCuts the ability to move shares out
3Ask the broker to freeze trading and debitsStops further movement during the investigation
4Audit the ledger and the CASBuilds the timeline of what happened
5Report through broker, SCORES and policeStarts the recovery and investigation lanes

Asking the broker to freeze

The freeze is the circuit breaker. You ask the broker to block trading and debit movement temporarily, state that you suspect compromise, and keep the request in writing. A freeze does not close the account and does not stop credits: dividends and corporate actions continue to arrive while the hold is on.

SEBI’s January 2024 direction requires brokers to offer a voluntary freeze option, and most brokers expose it in the app’s account services section with OTP confirmation. Where the app does not show it, the support or grievance channel does the same job. The freeze is yours to lift once the account is secured, typically within a working day or two of your request.

Freezing before auditing matters because the intruder may still hold a live session or a linked app. The freeze makes the current state the final state, so the audit you run afterwards describes a stopped event, not a moving one. That fixed state is what the dispute process needs.

Auditing what happened

The audit has three sources, and the truth is the difference between them. Pull each one and compare them line by line for the period you were not in control.

  • The app ledger. Every order, debit, payout request and, where the app shows it, login event with timestamps. Filter it to the period you were not in control, and export or screenshot every entry you did not authorise.
  • The depository CAS. Every demat movement, from the depository’s own record. The independent mirror that confirms or corrects the app’s ledger. Anything the app hides, the CAS still shows.
  • Your own record. List the trades and fund transfers you actually made. The difference between your list and the two system lists is the intruder’s activity, and that list, with dates and amounts, is the complaint.

Check the account’s configuration while you are there: the registered mobile and email, the linked bank account for payouts, the nominee on record, and any enrolled biometric or second-factor devices. An intruder who held the account may have changed these, and each change you reverse now is one you do not dispute later.

Reporting through the channels

The reporting lanes run in parallel, and each has its own job. The broker investigates inside the system. SEBI SCORES enforces the broker’s response. The cybercrime channel chases the money and the criminal. None of the three waits for the others, so file all of them.

  • The broker. Write to the grievance channel with the list of unauthorised transactions, dates and amounts. The broker can freeze, investigate, and in some cases reverse movement within the system. Keep every written response.
  • SEBI SCORES. If the broker’s response is missing or unsatisfactory, register on scores.sebi.gov.in with your PAN and file against the broker. SCORES 2.0 auto-routes the complaint and the broker must respond within 21 calendar days. You can request a first-level review within 15 days and a second-level review after that.
  • The cybercrime channel. Call 1930, the round-the-clock helpline for financial fraud, and file a complaint on cybercrime.gov.in with the transaction details and screenshots. Save the complaint ID. The portal connects to the banks through the national fraud reporting system, and the complaint converts into an FIR through the local police.

After the dust settles

Once the account is secured and the reports are filed, verify the account’s configuration one more time: registered email and mobile are yours, the linked bank account is yours, the nominee is unchanged, and no unknown device or biometric remains enrolled. Where the broker offers two-factor or biometric login, switch it on.

Then review the habits that opened the door. A password reused across sites, an OTP spoken on a call, a remote-access app installed for a stranger, a screen shared during a "support" session. The institutional layers held; the entry point was behavioural, and the same door stays open until the habit changes.

Watch the CAS every month after the incident. The intruder knows more about you now than they did before: your holdings, your PAN, your registered contact. A second attempt often arrives weeks later, and the monthly CAS glance is the cheapest alarm you can install.

What people usually get wrong

I should figure out who did it before reporting

Investigation is the channels’ job. Reporting early preserves evidence and starts the clock, and the who emerges from the process.

A password reset is enough

The TPIN reset is equally urgent: the password guards the door, the TPIN guards the assets. Both must be reset before anything else.

The broker will handle everything once I call

The broker is one lane. SEBI SCORES and the cybercrime channels each have roles, and the strongest recoveries run all lanes in parallel.

A police complaint is pointless for small amounts

The 1930 helpline is built for exactly these reports, and the reporting system works with banks to stop fraudulent transfers. Amount does not gate the complaint.

Questions people ask

Reset the login password and then the TPIN, in that order, from the app on your own device. Both resets run through your registered mobile and email, and together they cut the intruder’s session access and their ability to move shares. If the intruder changed the registered mobile or email, call the broker with your identity proof before anything else. Everything else on this page follows from these two resets.

Yes. Contact the broker’s support or grievance channel and ask for a temporary freeze of trading and debits, and state that you suspect compromise. Brokers must offer a voluntary freeze option, usually in the app’s account services section with OTP confirmation, under SEBI’s January 2024 direction. The freeze stops further damage while the investigation runs, and you lift it yourself once the account is secured.

Report to the broker first, in writing, with the list of transactions you did not authorise. If the broker does not resolve it, escalate to SEBI SCORES, which auto-routes the complaint to the broker for a response within 21 calendar days. In parallel, report the financial fraud to the cybercrime channel: the 1930 helpline or cybercrime.gov.in. The three lanes run independently and feed each other.

Money that never left is secured by the freeze and the resets. Money that left through unauthorised debits becomes a dispute: reported to the broker, escalated through SCORES, and reported to the police as cybercrime, where the national reporting system works with banks to freeze fraudulent destinations. Recovery depends on how quickly each channel was informed, which is why speed is the first instruction on this page.

The app ledger lists every order, debit and payout request with timestamps, and the depository’s CAS lists every demat movement. Compare both against your own record of trades and funding. The difference between the lists is the intruder’s activity, and that list, with dates and amounts, is the evidence the broker, SCORES and the police each need.

For financial fraud, yes, and the first contact is the 1930 helpline, which operates around the clock and connects you to the Citizen Financial Cyber Fraud Reporting and Management System. You also file a complaint on cybercrime.gov.in and keep the complaint ID. Complaints above ₹10 lakh made through the helpline or portal are being auto-converted into FIRs under a scheme that began in Delhi in May 2025 and is being extended to other states.

Sources