cardkhata

How credit card statement passwords work in India

Why the PDF is locked in the first place

Every Indian card issuer emails a monthly statement, and every one of those emails carries the statement as a password-protected PDF rather than a plain attachment. Email is not a vault — it sits in an inbox that might be shared, synced across devices, or eventually accessed by someone other than the cardholder. Encrypting the PDF means the statement is useless to anyone who opens the email but doesn't know the password, without asking you to set one up yourself.

That last part is the useful bit: you never choose this password and you never have to store it anywhere new. It's derived, every month, from a fixed formula applied to details the issuer already has on file for you. Once you know the formula for your card, you can open any statement from it without looking anything up.

The password is built from your own details

The exact formula is different for every issuer, and issuers change theirs from time to time without much notice, so this post won't tell you "your bank uses X" — that's exactly the kind of specific claim that goes stale and then wastes your time. What's stable is the shape these formulas take. Most fall into one of a few patterns:

  • Name fragments plus date of birth — for example, the first few letters of your first or last name, followed by your birth date in DDMM or DDMMYYYY format.
  • Card number digits plus date of birth — a handful of digits from the card number (never the full number) combined with a birth date.
  • Customer ID or account number based — some issuers key it entirely off an internal customer or relationship number rather than anything on the card itself.
  • Mobile number fragments — the last few digits of the registered mobile number, sometimes combined with another field.

A single issuer can also use different formulas for different card products, and can switch formulas after a re-issue or a systems migration. The only reliable source for your card is the statement email itself — the password hint is almost always printed right there in the email body, just above or below the attachment, and it's worth reading in full the first time a card arrives rather than guessing.

Actually opening the file

A few things trip people up more often than a wrong formula:

  • Case and spacing matter. Most PDF readers treat the password as an exact string — stray capitalisation or an extra space typed at the end will fail silently rather than telling you what's wrong.
  • Date format is the most common mismatch. If the hint says "date of birth," try both the 4-digit (DDMM) and 8-digit (DDMMYYYY) forms before assuming it's wrong — issuers aren't always precise about which one they mean in the hint text.
  • Check which cardholder's details apply. On an add-on or supplementary card, the password is sometimes built from the primary cardholder's details, not the person named on the add-on card.
  • If you've recently changed your registered mobile number or had the card reissued, the password may have changed too, even if the visible hint text in the email looks the same as always.

If none of that works, the fastest fix is usually the issuer's customer care line or app — they can read out or reset the exact scheme for your account in a couple of minutes, which beats guessing combinations against a PDF reader that only tells you "wrong password" with no further detail.

Why this is worth getting right

A locked statement is minor friction once, but multiply it by every card you hold and every month of the year, and it adds up to a real reason people stop opening their statements at all — which is exactly when a fee or an EMI instalment goes unnoticed. It's also the first step in checking things like whether you're on track for an annual fee waiver, since that means reading back through statements you might otherwise leave unopened. cardkhata exists to read what's inside these statements once they're unlocked, so the password is the only manual step left in the process.