To secure your demat account from hackers: enable SEBI-mandated two-factor authentication (2FA/TOTP), use a strong unique password changed periodically, never log in on public Wi-Fi or shared devices, turn on real-time SMS/email transaction alerts, protect your TPIN and never share OTPs, keep your device and trading app updated, and verify your broker's SEBI registration before sharing any information. If you notice unauthorised activity, call the national cybercrime helpline 1930 immediately.
You check your demat account one evening and your holdings show zero. The funds have moved to an account you don't recognise. It sounds like a nightmare scenario — and for a growing number of Indian investors, it isn't hypothetical. Indians lost an estimated ₹22,495 crore to cyber fraud in 2025 alone, with investment-related scams accounting for roughly three-quarters of that figure. As more first-time investors open demat accounts online, fraudsters have kept pace, using phishing links, impersonation calls, and fake trading apps to get in.
The good news: a demat account is one of the more defensible parts of your financial life, because SEBI, NSDL, and CDSL already mandate several layers of protection. Most breaches happen because an investor bypasses or is tricked around a safeguard — not because the safeguard failed. This guide covers how these frauds actually happen, the warning signs to watch for, seven SEBI-backed steps to lock your account down, and exactly what to do if you're hit.
What Is a Demat Account?
A demat (dematerialised) account is an electronic account that holds your shares, bonds, ETFs, and mutual fund units in digital form, maintained through a Depository Participant (DP) registered with NSDL or CDSL. It is linked to both a trading account (to buy and sell) and a bank account (to move funds) — which is exactly why it's a high-value target: compromising one login can expose all three.
How Do Demat Account Frauds Happen in India?
Most demat account fraud follows one of six patterns. Recognising the pattern is often the fastest way to avoid it.
● Phishing & smishing — fake emails or SMS messages with links that mimic your broker's login page and harvest your credentials.
● Vishing calls — a fraudster impersonates a broker, DP, or "SEBI official" by phone and asks for your password, OTP, or TPIN.
● SIM swap fraud — the fraudster gets your mobile number ported to a new SIM they control, so your OTPs go to them instead of you.
● Fake trading apps and unregistered "advisory" groups — Telegram/WhatsApp groups promising guaranteed returns that ask you to route trades through unofficial platforms.
● Remote-access app misuse — being talked into installing screen-sharing apps like AnyDesk or TeamViewer, which then expose your live session.
● Malware via attachments or cracked apps — links or downloads that quietly install keyloggers or credential-stealing malware.
Warning Signs: How to Spot Unauthorized Activity
Because every change to a demat account legally requires the account holder's authorisation, any of the following should be treated as a red flag and reported immediately:
● Transactions you did not initiate, however small.
● Holdings or fund balances that don't match your last check.
● Registered phone number, email address, or address changed without your action.
● Missing broker notifications for trades that did happen — a sign alerts may have been silently redirected.
● Account statements that don't arrive or don't match your records.
● An unfamiliar linked bank account or additional trading account you didn't add.
7 SEBI-Backed Tips to Secure Your Demat Account
1. Enable Two-Factor Authentication (2FA/TOTP)
2FA has been mandatory for all Indian demat accounts since October 1, 2022, following an NSE circular and SEBI's Cyber Security & Cyber Resilience framework for stockbrokers. Accounts without it activated cannot transact. Beyond the legal minimum, prefer app-based TOTP (time-based one-time password) over SMS OTP where your broker offers it — it's harder to intercept via a SIM swap.
2. Use a Strong, Unique Password — and Rotate It
Avoid birthdays, family names, or anything guessable from your social media. Use a long passphrase with a mix of case, numbers, and symbols, and don't reuse your demat password anywhere else. Change it periodically, and immediately if you suspect any exposure.
3. Never Access Your Account on Public Wi-Fi or Shared Devices
Public computers and open Wi-Fi networks (cafés, airports, co-working spaces) are easy points for credential-stealing malware and network snooping. Reserve demat/trading logins for your own device on a trusted network, and always log out fully rather than just closing the tab.
4. Turn On Real-Time SMS and Email Transaction Alerts
SEBI requires brokers to send real-time alerts for trades and fund movement. Keep these enabled — don't mute broker notifications — and treat every alert as something to actually read, not dismiss. An alert for a trade you didn't place is your earliest possible warning.
5. Protect Your TPIN and Never Share OTPs
NSDL and CDSL require a TPIN (Transaction PIN) to authorise sell-side transactions, separate from your login password. No genuine broker, DP, or "SEBI representative" will ever call and ask for your TPIN, OTP, or password — treat any such request as fraud, whatever the caller claims.
6. Keep Devices, Apps, and Browsers Updated
Security patches close the exact vulnerabilities malware relies on. Keep your phone's OS, your broker's app, and your browser current, and run reputable antivirus/anti-malware on the device you trade from. Clear stored cookies and review app permissions periodically.
7. Verify Your Broker's SEBI Registration Before Trusting Any Platform
Before acting on investment tips or opening an account with a new platform, confirm the intermediary is SEBI-registered via the SEBI website, and check any grievance against them on the SEBI SCORES portal. Unregistered "advisory" channels on Telegram or WhatsApp promising guaranteed returns are a leading source of fraud losses in 2025.
Fraud Type vs. Warning Sign vs. Immediate Action
|
Fraud Type |
Typical Warning Sign |
Immediate Action |
|
Phishing/Smishing |
Unexpected link asking you to "verify" your login |
Don't click; type the broker's URL manually; report the message |
|
Vishing (impersonation call) |
Caller asks for OTP/TPIN/password |
Hang up; call your broker back on their official number |
|
SIM swap |
Sudden loss of mobile network signal/OTPs stop arriving |
Contact your telecom operator and broker immediately |
|
Fake advisory group |
"Guaranteed returns" via Telegram/WhatsApp |
Verify SEBI registration before acting; do not transfer funds |
|
Remote-access misuse |
Asked to install AnyDesk/TeamViewer for "support" |
Refuse; never share your screen during a live trading session |
What to Do If Your Demat Account Is Hacked
Speed matters more than anything else here — funds are typically moved through layered accounts within hours, so reporting within the first hour meaningfully improves the odds of a freeze and recovery.
● Call the national cybercrime helpline 1930 immediately, or file a complaint at cybercrime.gov.in.
● Notify your broker and Depository Participant (NSDL/CDSL) to freeze the account and block further transactions.
● Change your password and TPIN from a different, trusted device.
● File a police complaint / FIR and preserve all evidence — screenshots, SMS alerts, emails.
● If you suspect broker or DP negligence, file a grievance on SEBI's SCORES portal.
● Review and revoke any unfamiliar linked accounts, devices, or standing instructions.
Conclusion
A hacked demat account is frightening precisely because it touches your holdings, your trading account, and your bank account all at once — but it's also one of the more preventable forms of financial fraud, because the regulatory groundwork is already in place. SEBI's 2FA mandate, NSDL/CDSL's TPIN requirement, and mandatory real-time alerts mean the system is built to stop most attacks before they reach your money. What decides the outcome is usually the investor's own habits: a password never shared, an OTP never given to a caller, a login never attempted on a café's Wi-Fi.
Treat the seven steps in this guide as a checklist, not a one-time read — revisit your 2FA setting, your alert preferences, and your broker's SEBI registration periodically, especially after any device change. And if something does go wrong, remember that the single biggest factor in recovering your money is speed: call 1930 or report at cybercrime.gov.in within the first hour, don't wait to see if it "resolves itself." Small, consistent security habits are what keep decades of disciplined investing safe from a five-minute scam call.
DISCLAIMER: This blog is NOT any buy or sell recommendation. No investment or trading advice is given. The content is only for educational purposes. Always discuss with your SEBI-registered financial advisor for investment-related decisions.
Follow this WhatsApp Channel for the latest updates directly on WhatsApp.











