Markets & Money News

ICICI Bank Net Banking Switches to a .bank.in Address and Adds CAPTCHA: What Customers Should Do

ICICI Bank's net banking now sits on a .bank.in web address and adds a CAPTCHA step, as reported by Livemint. Here is what customers should check, update and watch for.

Written by BankCreds Editorial Team

Reviewed by BankCreds Financial Experts

Published:

Updated:

ICICI Bank Net Banking Switches to a .bank.in Address and Adds CAPTCHA: What Customers Should Do

ICICI Bank has changed the web address of its net banking service to a .bank.in domain and added a CAPTCHA feature to the login flow, according to reporting by Livemint. For customers, the practical meaning is simple: the address you use to sign in is different, and you may see an extra verification step before you can enter your credentials.

If you bank with ICICI, do not rush to click anything sent to you about the change. Reach the site through the bank's official mobile app, a branch, or a bookmark you create yourself, and treat any message urging you to log in through a link as suspect.

The details of exactly which pages, apps and sub-services are covered are best confirmed with the bank directly, since this article relies only on the reported headline. What follows is standing background on why banks are adopting the .bank.in domain, how a CAPTCHA fits into login security, and what an ordinary customer should do.

Key takeaways

  • ICICI Bank's net banking now uses a .bank.in web address and adds a CAPTCHA feature, as reported by Livemint.
  • The .bank.in ending is meant to be reserved for banks, which makes lookalike fraud sites easier to spot for careful users.
  • A CAPTCHA is an anti-bot check; it does not protect you if you enter your password on a fake page.
  • Interest rates, EMIs, charges and account terms are not affected by a change of web address.
  • Update your bookmarks, avoid links in SMS, email or messaging apps, and log in via the official app or a self-typed address.
  • Transition periods attract phishing, so expect more scam messages than usual in the coming weeks.

What is the .bank.in domain and why are banks adopting it?

A web address ends in a domain extension: .com, .in, .co.in and so on. Most of these are open to anyone who pays a registration fee, which is why a fraudster can register a name that looks nearly identical to a bank's real one. The .bank.in extension is different in intent. As widely reported, the Reserve Bank of India directed banks to move to an exclusive .bank.in domain so that customers have one reliable signal that a site belongs to a genuine, regulated bank.

The idea is about trust at a glance. If every Indian bank's official site ends in .bank.in, and registration under that ending is restricted to verified banks, then a site ending in .com, .xyz or .in with a bank-like name stands out as unusual. Regulators in several countries have pursued similar restricted domains for the same reason.

For the customer, the benefit depends on behaviour. A restricted domain only helps if you actually look at the address, or better, avoid typing addresses at all and use the official app. Most phishing succeeds not because the fake page is perfect but because the victim never looks.

What changes for ICICI Bank net banking users?

Based on the reported headline, two things change: the address and the login experience. Everything else that the reporting may cover, such as the exact old and new addresses, dates of cut-over, or whether old links redirect, is not something this article can state, so check the bank's own communication for those specifics.

Here is a plain before-and-after view of what is likely to matter to you, framed as questions to verify rather than facts.

Area Before After (as reported) What you should check
Web address Earlier net banking address New .bank.in address Confirm the address via the official app or branch
Login step Existing login flow CAPTCHA feature added Expect an extra challenge before sign-in
Saved bookmarks Point to the old address May no longer be the preferred route Delete and recreate the bookmark
Interest rates and fees Unchanged by address Unchanged by address No action needed
Password and OTP Existing credentials Existing credentials continue to matter Never share them, whatever the page looks like

Notice that the last two rows are about things the change does not touch. Rates, EMIs and your credentials all stay in your control and outside the domain switch.

How does a CAPTCHA protect your account?

CAPTCHA stands for a test that separates humans from automated programs. It typically asks you to read distorted characters, tick a box or pick certain images. Its main job is to make it costly for bots to try thousands of username and password combinations against a login page, a technique known as credential stuffing.

That is useful, but narrow. A CAPTCHA does not tell you whether the page in front of you is genuine, and a criminal running a fake site can copy the CAPTCHA just as easily as the rest of the design. In fact, a convincing fake with a CAPTCHA may feel more trustworthy to an unwary user.

So think of the CAPTCHA as protection for the bank against bots, and the .bank.in address as protection for you against lookalikes. Neither replaces your own vigilance, your one-time password discipline, or the bank's transaction alerts.

What should you do now? A simple checklist

You do not need to change your password or panic. A few habits are enough.

  1. Open the official ICICI Bank mobile app, or ask at a branch, to confirm the correct web address.
  2. Delete old bookmarks and browser shortcuts for net banking, then create a fresh one after typing the confirmed address yourself.
  3. Check the padlock and the address bar every time you sign in, and read the full address rather than the first few letters.
  4. Turn on SMS and email alerts for every debit, so an unauthorised transaction is visible within minutes.
  5. Stop using links from SMS, email, WhatsApp or social media to reach your bank, even if the sender claims to be the bank explaining the change.
  6. Keep your device updated and avoid net banking on public or shared computers.

If you also use net banking to pay loan instalments, it is a good moment to review what you actually owe. Our EMI calculators can help you confirm the monthly figure you should see leaving your account, so an unexpected debit stands out.

Why transitions attract phishing, and how to spot it

Whenever a bank changes an address, fraudsters use the confusion. The typical script is a message saying your net banking is being upgraded, your account will be blocked, or you must re-register at a new link. The message creates urgency, and urgency is what makes people click.

A useful rule: a genuine bank does not ask for your full password, card PIN, CVV or OTP by phone, email or message, and it does not need you to click a link to keep your account alive. If a message says otherwise, it is a scam regardless of how official it looks.

Signs of a fake page include:

  • An address that does not end in the bank's official domain, or that adds extra words, hyphens or numbers.
  • A request for your card number, PIN and OTP on one page, which real login flows do not combine.
  • Spelling errors, low-quality logos, or a page that loads after you tapped a link from a message.
  • Pressure to act within minutes.

The same caution applies to fraudulent loan offers that copy bank branding. If you are comparing borrowing options, use only regulated lenders and our guides on instant loans to understand what genuine offers look like.

A worked example: what a phishing loss can look like

Consider a hypothetical customer with ₹1,20,000 in a savings account who receives a message about the new address and enters credentials on a fake page. If the fraudster drains the account, the loss is the full ₹1,20,000. If the customer notices the debit alert quickly and reports it, the outcome changes considerably.

Under RBI's customer protection framework for unauthorised electronic transactions, a customer's liability can be zero where the fraud arises from a third-party breach and the customer reports it within three working days of receiving the communication from the bank. Where the customer's own negligence, such as sharing credentials, is the cause, the customer typically bears the loss until the bank is informed. The exact limits depend on the account type and the circumstances, so always read the current RBI rules or ask your bank.

The lesson is not to memorise the rule, but to act on the timing. Speed of reporting is the single biggest factor within your control, which is why alerts and a habit of checking them matter more than any address change.

Who is affected and who is not?

The change is most relevant to people who use ICICI Bank net banking on a computer or browser. Customers who use only the mobile app may notice little, though it depends on how the app is built and what the bank communicates.

Less directly affected are people who hold accounts with other banks. That said, the RBI's push toward .bank.in means other banks are expected to follow, so the same habits will apply to you soon.

Not affected at all are your deposits, loan terms and rates. If you are shopping for a loan or reviewing your borrowing costs, current figures live on our interest rates page, and none of them shift because of a URL change.

Common mistakes to avoid

The most frequent errors are predictable. People keep using an old bookmark that may eventually stop working and then search for the bank on a search engine, where a sponsored fake result can appear above the real one. Others reply to a message that looks like a notification about the change. Some assume that a CAPTCHA or a padlock icon proves a site is genuine, when neither does.

Another mistake is to ignore the transition entirely and assume it is only technical. It is a good prompt to review your security basics: unique passwords, a locked phone, alerts on, and a habit of reporting anything odd immediately. For news on other banking and regulatory developments as they are reported, visit our news hub.

Frequently asked questions

Is ICICI Bank's new net banking address safe to use?

According to reporting by Livemint, the bank has moved its net banking to a .bank.in address, an ending intended for regulated banks. Confirm the exact address through the bank's app or a branch and type it yourself instead of following links. That is the safest way to reach any bank site.

Do I need to change my password because of the new URL?

A change of web address on its own does not require a new password. However, if you have entered your credentials on any page reached through a message or link, change your password at once and contact the bank. Never share your password or OTP with anyone, however official they sound.

Will the CAPTCHA make net banking slower?

A CAPTCHA adds a short step at login, usually a few seconds. Its purpose is to block automated bot attempts, not to inconvenience genuine customers. If you have trouble completing it, contact the bank's official support rather than a number from a search result.

Do interest rates or EMIs change with the new address?

No. A web address and a login feature have no effect on loan interest, deposit rates, EMIs or charges. Those are set by the bank's product terms and market conditions, not by its domain.

What should I do if I get a message about the change asking me to click a link?

Do not click it. Open the bank's official app or type the confirmed address yourself, and report the message to the bank. If you have already entered details, change your password and inform the bank immediately, since reporting quickly protects your position.

BankCreds analysis

The headline sounds like a big security event, but for most account holders it is a small change with one real benefit and one real risk. The benefit is that a .bank.in address is reserved for regulated banks, so a customer who types or checks that ending gets a cleaner signal than the old, crowded .com space offered. The risk is the transition itself: whenever a bank changes its address, fraudsters send messages saying your net banking is being shifted, click here to continue. That message is now more believable than it was last month.

A worked example

Take a salaried household paying a ₹28,000 home loan EMI and a ₹6,500 credit card bill through net banking every month, about ₹34,500 in total. Nothing about the payment amounts, due dates or interest changes because of a new URL. The only exposure is the moment the customer types the address or taps a link. A single successful phishing login could expose that whole monthly flow plus any balance in the account. So the change matters less for your wallet and more for your habits.

What it does not mean

A CAPTCHA does not make an account unhackable. It mainly slows automated login attempts by bots; it does nothing against a customer who voluntarily enters their password on a fake page, and it does not replace the one-time password step. Nor does the change alter any loan rate, deposit rate, fee or charge.

This week, the useful actions are small: replace your saved bookmark with the address you reach from the bank's official app or a branch, delete old shortcuts, and ignore every message that asks you to log in through a link. Those three steps cost five minutes and remove most of the risk. Beyond that, this is a housekeeping story rather than a financial one.

This section is BankCreds' own assessment of what the development means for Indian borrowers and savers. It is independent commentary, not part of the source reporting above.

Sources & references

  1. Livemint — originating report https://www.livemint.com/money/personal-finance/icici-bank-changes-net-banking-url-new-bank-in-address-captcha-feature-what-customers-need-to-know-11789816727068.html
  2. RBI notifications and circulars — RBI's directions on the exclusive .bank.in domain for banks and on limiting customer liability in unauthorised electronic transactions https://www.rbi.org.in/Scripts/NotificationUser.aspx
  3. Reserve Bank of India — Regulator of banks in India and source of customer-protection guidance https://www.rbi.org.in/

Source links are shown as plain text, not clickable links. Copy a URL into your browser to read the original report.

Editorial note & disclaimer

How this was reported. The development above is attributed to the source or sources listed. BankCreds does not independently verify a third party's reporting; where a figure or a regulatory position is stated as fact, it is either attributed or drawn from the regulator's own published material. Everything under "BankCreds analysis" is our own assessment.

Rates and figures. Interest rates, per-gram values and premium bands quoted here are indicative, move daily, and differ by borrower profile, city and lender policy. Confirm the final number with the institution before you act on it — the sanction letter or policy schedule governs, not a news report.

Not financial advice. This article is general information for an Indian audience. It is not investment, tax, credit or insurance advice, takes no account of your circumstances, and BankCreds is not a lender, broker, distributor or advisor. Consider speaking to a SEBI-registered investment adviser or a qualified professional before acting.

Editorial policy · Fact-checking policy · Corrections policy · Our authors · About BankCreds · Contact us

Spotted an error? Corrections are published, not quietly edited — write to us via the contact page and see our corrections policy.

Never miss a rate move — get free alerts

Choose what you care about — every category, one loan type, or a daily gold-rate alert — and we deliver it to your inbox or phone.

Free forever, unsubscribe anytime. We only send what you pick — no spam, no sharing of your contact details.

Disclaimer: BankCreds.com is a loan comparison platform and does not directly lend, disburse, or provide any financial products. We aggregate and display loan offers from RBI-registered banks and NBFCs to help you make an informed decision. All loan applications are processed directly by the respective lender. Interest rates, charges, eligibility, and terms shown are indicative and subject to the lender's final assessment. Please read the lender's terms and conditions carefully before applying.