Loading...

Home >> Blog >> Demat Account Security: 7 Tips to Stop Hackers (2026)

Demat Account Security: 7 Tips to Stop Hackers (2026)

   


Summary

  • 2FA is mandatory for every Indian demat account. Make sure you use app-based TOTP instead of relying only on SMS.
  • Never share your TPIN or OTP with anyone, including people claiming to be from your broker or SEBI.
  • Keep real-time alerts enabled, as they are your earliest warning system.
  • If you suspect fraud, act immediately by calling 1930 or reporting it at cybercrime.gov.in within the first hour.
  • Always verify SEBI registration before trusting any broker, app, or "guaranteed return" advisory group.

To secure your demat account from hackers: enable SEBI-mandated two-factor authentication (2FA/TOTP), use a strong unique password changed periodically, never log in on public Wi-Fi or shared devices, turn on real-time SMS/email transaction alerts, protect your TPIN and never share OTPs, keep your device and trading app updated, and verify your broker's SEBI registration before sharing any information. If you notice unauthorised activity, call the national cybercrime helpline 1930 immediately.

You check your demat account one evening and your holdings show zero. The funds have moved to an account you don't recognise. It sounds like a nightmare scenario — and for a growing number of Indian investors, it isn't hypothetical. Indians lost an estimated ₹22,495 crore to cyber fraud in 2025 alone, with investment-related scams accounting for roughly three-quarters of that figure. As more first-time investors open demat accounts online, fraudsters have kept pace, using phishing links, impersonation calls, and fake trading apps to get in.

The good news: a demat account is one of the more defensible parts of your financial life, because SEBI, NSDL, and CDSL already mandate several layers of protection. Most breaches happen because an investor bypasses or is tricked around a safeguard — not because the safeguard failed. This guide covers how these frauds actually happen, the warning signs to watch for, seven SEBI-backed steps to lock your account down, and exactly what to do if you're hit.

What Is a Demat Account?

A demat (dematerialised) account is an electronic account that holds your shares, bonds, ETFs, and mutual fund units in digital form, maintained through a Depository Participant (DP) registered with NSDL or CDSL. It is linked to both a trading account (to buy and sell) and a bank account (to move funds) — which is exactly why it's a high-value target: compromising one login can expose all three.

How Do Demat Account Frauds Happen in India?

Most demat account fraud follows one of six patterns. Recognising the pattern is often the fastest way to avoid it.

●       Phishing & smishing — fake emails or SMS messages with links that mimic your broker's login page and harvest your credentials.

●       Vishing calls — a fraudster impersonates a broker, DP, or "SEBI official" by phone and asks for your password, OTP, or TPIN.

●       SIM swap fraud — the fraudster gets your mobile number ported to a new SIM they control, so your OTPs go to them instead of you.

●       Fake trading apps and unregistered "advisory" groups — Telegram/WhatsApp groups promising guaranteed returns that ask you to route trades through unofficial platforms.

●       Remote-access app misuse — being talked into installing screen-sharing apps like AnyDesk or TeamViewer, which then expose your live session.

●       Malware via attachments or cracked apps — links or downloads that quietly install keyloggers or credential-stealing malware.

 

Warning Signs: How to Spot Unauthorized Activity

Because every change to a demat account legally requires the account holder's authorisation, any of the following should be treated as a red flag and reported immediately:

●       Transactions you did not initiate, however small.

●       Holdings or fund balances that don't match your last check.

●       Registered phone number, email address, or address changed without your action.

●       Missing broker notifications for trades that did happen — a sign alerts may have been silently redirected.

●       Account statements that don't arrive or don't match your records.

●       An unfamiliar linked bank account or additional trading account you didn't add.

 

7 SEBI-Backed Tips to Secure Your Demat Account

1. Enable Two-Factor Authentication (2FA/TOTP)

2FA has been mandatory for all Indian demat accounts since October 1, 2022, following an NSE circular and SEBI's Cyber Security & Cyber Resilience framework for stockbrokers. Accounts without it activated cannot transact. Beyond the legal minimum, prefer app-based TOTP (time-based one-time password) over SMS OTP where your broker offers it — it's harder to intercept via a SIM swap.

2. Use a Strong, Unique Password — and Rotate It

Avoid birthdays, family names, or anything guessable from your social media. Use a long passphrase with a mix of case, numbers, and symbols, and don't reuse your demat password anywhere else. Change it periodically, and immediately if you suspect any exposure.

3. Never Access Your Account on Public Wi-Fi or Shared Devices

Public computers and open Wi-Fi networks (cafés, airports, co-working spaces) are easy points for credential-stealing malware and network snooping. Reserve demat/trading logins for your own device on a trusted network, and always log out fully rather than just closing the tab.

4. Turn On Real-Time SMS and Email Transaction Alerts

SEBI requires brokers to send real-time alerts for trades and fund movement. Keep these enabled — don't mute broker notifications — and treat every alert as something to actually read, not dismiss. An alert for a trade you didn't place is your earliest possible warning.

5. Protect Your TPIN and Never Share OTPs

NSDL and CDSL require a TPIN (Transaction PIN) to authorise sell-side transactions, separate from your login password. No genuine broker, DP, or "SEBI representative" will ever call and ask for your TPIN, OTP, or password — treat any such request as fraud, whatever the caller claims.

6. Keep Devices, Apps, and Browsers Updated

Security patches close the exact vulnerabilities malware relies on. Keep your phone's OS, your broker's app, and your browser current, and run reputable antivirus/anti-malware on the device you trade from. Clear stored cookies and review app permissions periodically.

7. Verify Your Broker's SEBI Registration Before Trusting Any Platform

Before acting on investment tips or opening an account with a new platform, confirm the intermediary is SEBI-registered via the SEBI website, and check any grievance against them on the SEBI SCORES portal. Unregistered "advisory" channels on Telegram or WhatsApp promising guaranteed returns are a leading source of fraud losses in 2025.

 

Fraud Type vs. Warning Sign vs. Immediate Action

Fraud Type

Typical Warning Sign

Immediate Action

Phishing/Smishing

Unexpected link asking you to "verify" your login

Don't click; type the broker's URL manually; report the message

Vishing (impersonation call)

Caller asks for OTP/TPIN/password

Hang up; call your broker back on their official number

SIM swap

Sudden loss of mobile network signal/OTPs stop arriving

Contact your telecom operator and broker immediately

Fake advisory group

"Guaranteed returns" via Telegram/WhatsApp

Verify SEBI registration before acting; do not transfer funds

Remote-access misuse

Asked to install AnyDesk/TeamViewer for "support"

Refuse; never share your screen during a live trading session

 

 

What to Do If Your Demat Account Is Hacked

Speed matters more than anything else here — funds are typically moved through layered accounts within hours, so reporting within the first hour meaningfully improves the odds of a freeze and recovery.

●       Call the national cybercrime helpline 1930 immediately, or file a complaint at cybercrime.gov.in.

●       Notify your broker and Depository Participant (NSDL/CDSL) to freeze the account and block further transactions.

●       Change your password and TPIN from a different, trusted device.

●       File a police complaint / FIR and preserve all evidence — screenshots, SMS alerts, emails.

●       If you suspect broker or DP negligence, file a grievance on SEBI's SCORES portal.

●       Review and revoke any unfamiliar linked accounts, devices, or standing instructions.

 

 

 

Conclusion

A hacked demat account is frightening precisely because it touches your holdings, your trading account, and your bank account all at once — but it's also one of the more preventable forms of financial fraud, because the regulatory groundwork is already in place. SEBI's 2FA mandate, NSDL/CDSL's TPIN requirement, and mandatory real-time alerts mean the system is built to stop most attacks before they reach your money. What decides the outcome is usually the investor's own habits: a password never shared, an OTP never given to a caller, a login never attempted on a café's Wi-Fi.

Treat the seven steps in this guide as a checklist, not a one-time read — revisit your 2FA setting, your alert preferences, and your broker's SEBI registration periodically, especially after any device change. And if something does go wrong, remember that the single biggest factor in recovering your money is speed: call 1930 or report at cybercrime.gov.in within the first hour, don't wait to see if it "resolves itself." Small, consistent security habits are what keep decades of disciplined investing safe from a five-minute scam call.

 

DISCLAIMER: This blog is NOT any buy or sell recommendation. No investment or trading advice is given. The content is only for educational purposes. Always discuss with your SEBI-registered financial advisor for investment-related decisions.

Follow this WhatsApp Channel for the latest updates directly on WhatsApp.



Author

Dr Mukul Agrawal - Stock Market Expert

Founder & Market Analyst, Finowings

Dr. Mukul Agrawal is the Founder of Finowings and a stock market mentor, trader, and investor with over 23+ years of real market experience. He is a Guinness World Record holder and has trained thousands of investors in stock market strategies, IPO analysis, and wealth creation.

He specializes in IPO research, fundamental analysis, and helping beginners understand how to invest safely in the stock market. Dr. Agrawal has also authored multiple books on investing and regularly shares insights on IPOs, market trends, and long-term wealth building.


Frequently Asked Questions

+
It's the electronic account holding your shares and securities, linked to your trading and bank accounts — compromising one login can expose all three, which makes it a high-value target.
+
Yes. SEBI and NSE have mandated 2FA for all demat accounts since October 1, 2022; accounts without it enabled cannot transact.
+
A TPIN (Transaction PIN) is a separate PIN required by NSDL/CDSL to authorise sell-side transactions, distinct from your login password — an extra layer no login-only breach can bypass.
+
Watch for transactions you didn't initiate, mismatched holdings, changed contact details, or missing broker alerts — any of these warrants an immediate check.
+
Call the 1930 cybercrime helpline or file at cybercrime.gov.in right away, then notify your broker/DP to freeze the account and change your password and TPIN from a different device.
+
Recovery is possible but time-sensitive — funds reported within the first hour have a meaningfully higher chance of being frozen before they're moved through layered accounts.
+
Phishing uses email, smishing uses SMS, and vishing uses phone calls — all three aim to trick you into revealing login credentials, OTPs, or your TPIN.
+
Check the intermediary's registration on the official SEBI website, and search for any investor grievances against them on the SEBI SCORES portal before opening an account or acting on advice.
+
No — public Wi-Fi and shared/public computers are common vectors for credential theft. Use your own device on a trusted network, and always log out completely.
+
SCORES is SEBI's online platform for filing complaints against SEBI-registered brokers, DPs, and intermediaries — use it if you suspect broker negligence contributed to unauthorised access.


Liked What You Just Read? Share this Post:




Any Question or Suggestion

Post your Thoughts

Your email address will not be published. Required fields are marked *


Finance

Related Blogs

Click here for a Chance to Learn Free Technical Analysis
Subscribe on
YouTube
Follow us on
Instagram
Follow Us on
X
Like Us on
Facebook