KYC vishing scam — How to Identify & Stay Safe
INDIA — By BharatSecure Threat Intelligence Team ·
Severity: Critical | View Full Scam Details
KYC Vishing Scam India 2026: How Fake Bank Calls Are Draining Accounts in Minutes
Scammers impersonating SBI, HDFC Bank, and RBI officials are reportedly calling thousands of Indians every day, claiming their KYC is "expired" — and victims are losing life savings before they realise what hit them. With losses from KYC-related fraud contributing significantly to the ₹2,500 crore that the Ministry of Home Affairs reports Indians lost to cyber scams in a single recent year, this threat is as urgent as it gets.
What Is the KYC Vishing Scam?
"Vishing" means voice phishing — fraud carried out over a phone call. In the KYC vishing scam, callers claiming to be from banks or regulators trick victims into handing over OTPs, PINs, or remote access to their devices, all under the pretext of completing a mandatory KYC update.
This scam targets anyone with a bank account, UPI handle, or mobile wallet — which is to say, most of urban and semi-urban India. First-time smartphone users, senior citizens, and small business owners are especially at risk because they may be less familiar with what banks actually ask for on calls.
The Reserve Bank of India and CERT-In (cert-in.org.in) have both issued repeated public advisories warning that no bank or regulator will ever ask for OTPs, PINs, or remote access over the phone. The I4C (Indian Cybercrime Coordination Centre) tracks KYC fraud as one of the highest-volume cybercrime categories reported to the national helpline 1930.
Exactly How This Scam Works — Step by Step
Data harvesting. Fraudsters acquire your name, phone number, and partial account details from data breaches, social media profiles, or online forums — enough to sound convincingly real.
The call arrives. You receive a call from someone claiming to be a representative of a bank (often impersonating SBI, HDFC Bank, or similar institutions) or even the RBI. They greet you by name and may quote the last few digits of your account.
The false emergency. The caller warns that your account will be frozen within hours unless you update your KYC immediately. Urgent, scripted language is used to prevent you from thinking clearly or calling back on an official number.
Credential harvesting. You are asked to "verify your identity" by sharing an OTP sent to your registered mobile number, or to confirm your ATM PIN, Aadhaar number, or UPI MPIN.
Remote access trap. In more sophisticated cases, the caller instructs you to download an app (such as a screen-sharing or remote access tool) to "assist" with the KYC process. Once installed, the fraudster can see and control your screen.
Money gone. With your OTP, PIN, or device access, the fraudster authorises transfers — often via UPI — within seconds. By the time you realise, the money has moved through multiple accounts.
Real Warning Signs (What to Watch For)
- The caller creates extreme urgency: "Your account will be blocked in two hours."
- They already know your name, partial account number, or recent transaction — designed to build false trust.
- You are asked to share an OTP, PIN, MPIN, or Aadhaar OTP over the phone.
- The caller asks you to download any app to "resolve" the KYC issue.
- The call comes from a mobile number, not a bank's official landline.
- The caller discourages you from hanging up and calling the bank's official number back.
- They claim to be from the "RBI KYC Department" — no such department contacts customers directly.
What Happens to Victims
Financially, victims face immediate unauthorised UPI transfers and, in some cases, full account drains. UPI transactions are near-instant; the RBI's chargeback and grievance redressal process can take weeks, and recovery is not guaranteed — especially once money moves through mule accounts. Victims who shared Aadhaar OTPs face additional risks, including fraudulent SIM swaps that lock them out of their own accounts.
Beyond money, the psychological toll is severe. Many victims report shame, anxiety, and lasting distrust of legitimate banking calls — which itself becomes a barrier to getting help quickly.
What RBI, CERT-In, and I4C Say
- RBI has consistently stated through public communications that banks will never ask customers to share OTPs, PINs, or passwords over any channel — phone, SMS, or email. Customers are advised to report suspicious calls directly to their bank's official grievance channel.
- CERT-In (cert-in.org.in) has flagged vishing as a critical and growing vector of financial fraud targeting Indian mobile users, urging users not to install unverified apps based on phone instructions.
- I4C / cybercrime.gov.in maintains the national 1930 cybercrime helpline specifically for financial fraud. Calling 1930 within the first few hours of a fraud gives investigators the best chance of freezing mule accounts before money is withdrawn.
- The IT (Intermediary Guidelines and Digital Media Ethics) Rules, 2021 and the DPDP Act 2023 create a legal framework requiring platforms and organisations to report breaches — but individual vigilance remains the first line of defence.
How to Protect Yourself
- Never share OTPs, PINs, or MPINs with anyone on a call — not even someone claiming to be from your bank or the RBI.
- Hang up and call back on the number printed on your bank card or the bank's official website — never use a number the caller gives you.
- Do not download any app at a caller's request, especially screen-sharing or remote-access tools.
- Verify KYC requests by visiting your bank branch in person or logging into your bank's official app directly.
- Enable UPI transaction limits and daily caps in your bank or UPI app to reduce exposure.
- Register for SMS/email alerts on all transactions so you catch unauthorised activity immediately.
- Treat urgency as a red flag — legitimate banks give you time; scammers do not.
- Check haveibeenpwned-style breach alerts and be extra cautious if your data has been exposed.
What to Do If You've Been Targeted
- Call 1930 immediately — the national cybercrime helpline. Report within the first hour for the best chance of a hold on mule accounts.
- File a complaint at cybercrime.gov.in — the I4C portal accepts online FIRs for financial fraud.
- Call your bank's 24×7 fraud helpline and request an immediate freeze on your account and UPI handle.
- Block your SIM with your telecom provider if you suspect a SIM swap has occurred or is imminent.
- Change all banking passwords and UPINs from a secure, uncompromised device.
- Screenshot everything — call logs, SMS alerts, transaction IDs — and preserve them for your police complaint.
- For Aadhaar misuse concerns, visit uidai.gov.in to lock your Aadhaar biometrics.
Frequently Asked Questions
Can my bank account really be frozen for not updating KYC over the phone? No. While banks are required by RBI regulations to periodically update customer KYC, they do this through written notices, official app prompts, or in-branch visits — never by demanding instant action on an unsolicited phone call. A caller threatening immediate account freezing unless you share an OTP is almost certainly attempting fraud.
I gave the caller my OTP but no money has gone yet — am I safe? Not necessarily. Call your bank's fraud helpline and the 1930 helpline right away. An OTP can be used within a short validity window; acting quickly may allow your bank to block the transaction before it completes. Do not wait.
Why does the caller already know my name and account details — does that mean they're legitimate? No. Partial personal data — names, phone numbers, last few account digits — is widely available from data breaches and social media. Fraudsters use this information specifically to build trust. A real bank representative knowing your name does not confirm the call is genuine. Always call back on the official number.
What if I downloaded the remote access app they asked for? Uninstall the app immediately, turn on flight mode to cut the connection, and then call your bank and 1930. Change all passwords and PINs from a different device. Consider a factory reset of the affected device after backing up essential data, and consult a cybersecurity professional for case-specific guidance.
If you received a suspicious call or message claiming to be about KYC, scan it at BharatSecure.app to check it against known scam patterns. If you have already lost money, call 1930 right now — every minute counts.
Disclaimer: This article describes a pattern of fraud reported in public sources for public-safety awareness. It is not legal, financial, or medical advice. To request correction or removal of any content, write to hello@bharatsecure.app.
Related Scams in Our Database
- SBI KYC Update Fraud — Severity: CRITICAL
- SBI KYC Update Fraud — Severity: CRITICAL
- Bank KYC Update Fraud — Severity: CRITICAL
Verify Any Suspicious Message
Check any suspicious message, link, or call for free at bharatsecure.app.