Fake SEBI KYC SMS Phishing Scam — How to Identify & Stay Safe

INDIA — By BharatSecure Threat Intelligence Team ·

Severity: High | View Full Scam Details

🛡️ Want to check if you've received this scam?

Check This Scam on BharatSecure →

Beware in 2026: The Fake SEBI KYC SMS Phishing Scam Targeting Indian UPI and Crypto Users

A rising cyber threat in India involves fake SMS and WhatsApp messages claiming urgent SEBI KYC updates for crypto wallets, designed to steal money through UPI and digital wallets.

What Is the Fake SEBI KYC SMS Phishing Scam?

This scam exploits the widespread use of Unified Payments Interface (UPI) and digital wallets in India by sending fraudulent SMS and WhatsApp messages claiming to be from SEBI (Securities and Exchange Board of India). The messages warn users that their "crypto wallet KYC is pending" and urge immediate action to avoid suspension of wallet functionality.

Targeting urban and semi-urban digital payment users — especially those involved in cryptocurrency trading or investments — scammers play on fears created by India's stringent KYC norms. These messages falsely link SEBI's regulatory authority with crypto wallets to seem convincing.

While exact figures on the scam’s reach are still emerging, cybercrime complaints received by India’s I4C (Indian Cyber Crime Coordination Centre) and CERT-In (Indian Computer Emergency Response Team) indicate a sharp rise in reported incidents in early 2026. Many victims report losing money directly from their UPI-linked bank accounts or wallet apps after responding to such phishing attempts.

Official cyber agencies, including CERT-In, have issued general alerts warning users against responding to unexpected messages about KYC or crypto wallets, stressing that SEBI does not communicate KYC requirements via SMS or WhatsApp.

How This Scam Works — Step by Step

  1. Initial Contact: The victim receives an SMS or WhatsApp message stating, “Your crypto wallet KYC is pending. Update now or wallet function will be suspended.” The message often appears to come from a short-code number or a name resembling SEBI or related regulatory bodies.

  2. Clicking the Link: The message contains a clickable link that directs the user to a fake but convincing website mimicking official SEBI or wallet platforms. This fake site requests Aadhaar details, bank information, UPI PIN, or asks to install a third-party app.

  3. Data Capture: When the victim enters sensitive information, scammers capture Aadhaar data or UPI credentials. In some cases, victims are asked to authenticate payments through UPI using a QR code or deep-link.

  4. Unauthorized Transactions: Using the stolen UPI credentials, fraudsters initiate transactions—usually small at first to avoid suspicion—and progressively transfer larger sums from the victim’s linked bank accounts or digital wallets.

  5. Account Suspension Threat: As a psychological tactic, messages warn that the wallet or account will soon be suspended if “KYC” is not updated, creating urgency and panic, which push victims to act impulsively.

  6. Aftermath: Victims often realize too late their money has been drained. Attempts to reverse UPI transactions are complicated as many happen via ‘collect requests’ or apps that don’t offer direct transaction reversals.

Real Warning Signs to Watch For

What Happens to Victims

Victims often endure significant financial losses, as funds are transferred out of their UPI-linked bank accounts or digital wallets without their consent. The misuse of Aadhaar data can also lead to identity theft complicating recovery.

In India’s payment ecosystem, UPI transactions once authorized cannot be reversed easily, especially if done through fraudulent collect requests. Victims face emotional distress from the sudden loss of savings, coupled with frustration over slow police or bank procedures.

Some also suffer from unauthorized SIM swaps following Aadhaar data exposure, allowing scammers to bypass two-factor security. This cascade of fraud can severely damage trust in digital financial services.

What RBI and CERT-In Say

RBI and CERT-In have long advised users to be cautious about unsolicited communications demanding sensitive information. While there is no SEBI advisory specifically on this fake KYC scam, their overall guidance warns against sharing UPI PINs, OTPs, Aadhaar details, or installing apps from unknown sources.

CERT-In and I4C encourage victims to immediately report suspicious messages to the 1930 cybercrime helpline and file complaints on cybercrime.gov.in. RBI’s chatbot and customer service numbers advise users to regularly check bank statements and keep mobile SIM secure.

These agencies emphasize that SEBI does not mandate KYC updates via SMS or WhatsApp notifications — official KYC processes require direct interaction on secured platforms only.

How to Protect Yourself

  1. Do not click on links or download apps from unsolicited SMS or WhatsApp messages about KYC updates.
  2. Verify any KYC requirements independently by visiting official SEBI or wallet service websites directly.
  3. Never share your UPI PIN, OTPs, Aadhaar number, or bank details via SMS, WhatsApp, or calls.
  4. Use biometric or app-based authentication instead of PIN where possible for added security.
  5. Regularly update your mobile number’s KYC with your bank and wallet providers through official apps only.
  6. Be skeptical of urgent or threatening language demanding immediate action.
  7. Install security software on your phone and keep your operating system updated.

What to Do If You've Been Targeted

Frequently Asked Questions

Q: Can SEBI send SMS or WhatsApp messages asking me to update my crypto wallet KYC?
A: No, SEBI does not request KYC updates via SMS or WhatsApp. Official protocols involve secure, authenticated channels only. Beware of messages claiming otherwise.

Q: What should I do if I accidentally shared UPI PIN or Aadhaar details responding to a message like this?
A: Immediately block your UPI ID and associated bank accounts by contacting your bank. Report the incident to cybercrime.gov.in and the 1930 helpline to seek official assistance.

Q: Are UPI transactions reversible if done through phishing or fraud?
A: UPI transactions authorized by the user normally cannot be reversed easily, especially those using collect requests. Early reporting to the bank and cyber authorities increases chances of mitigation.

Stay vigilant — if you receive suspicious KYC messages related to crypto wallets or digital payments, always cross-check before responding. Report any fraud promptly to help protect yourself and others.

Verify suspicious messages at BharatSecure.app and report fraud at the 1930 cybercrime helpline without delay.

Disclaimer: This article describes a pattern of fraud reported in public sources for public-safety awareness. It is not legal, financial, or medical advice. To request correction or removal of any content, write to hello@bharatsecure.app.

Related Scams in Our Database

Verify Any Suspicious Message

Check any suspicious message, link, or call for free at bharatsecure.app.