OTP Interception via Fake Customer Support — How to Identify & Stay Safe

INDIA — By BharatSecure Threat Intelligence Team ·

Severity: Critical | View Full Scam Details

OTP Interception via Fake Customer Support: How Indian Bank Accounts Are Being Drained in 2026

Fraudsters impersonating customer support agents are stealing OTPs to wipe out Indian bank accounts — sometimes within minutes of a single phone call. With cyber fraud losses from account takeovers reportedly exceeding ₹1,000 crore in a single financial year, this scam is one of the most dangerous threats facing Indian internet users today.


What Is OTP Interception via Fake Customer Support?

This scam involves callers posing as representatives from trusted institutions — banks like SBI or HDFC Bank, or e-commerce platforms like Amazon or Flipkart — to trick victims into handing over their One-Time Passwords (OTPs). Once the OTP is shared, attackers can authorise UPI transfers, reset net banking credentials, or access linked accounts entirely without the victim's further involvement.

The scam targets anyone with a bank account or UPI handle — salaried professionals, senior citizens, small business owners, and students alike. Reported losses in individual cases have ranged from ₹50,000 to multiple crores, confirming no demographic is immune. The Ministry of Home Affairs (MHA) has flagged a sharp rise in such phishing incidents. Both the Reserve Bank of India (RBI) and CERT-In have issued public advisories urging customers to never share OTPs over call or chat, under any circumstances.


Exactly How This Scam Works — Step by Step

  1. The Hook: You receive an unsolicited call, SMS, or WhatsApp message claiming to be from your bank's or a major brand's customer support team.
  2. The Scare: The caller alleges an urgent problem — "Your KYC is not updated," or "Your account will be suspended within 24 hours." This triggers immediate panic.
  3. False Legitimacy: The caller provides a fake employee ID and uses your name or partial account details to appear genuine.
  4. The OTP Request: They tell you an OTP will arrive on your phone "for verification." They ask you to read it aloud immediately.
  5. Remote Access Trap (Advanced Variant): In more aggressive cases, reported callers instruct victims to install AnyDesk or TeamViewer — framed as a "help tool" — giving fraudsters live screen access to banking apps.
  6. The Drain: The moment the OTP is shared (or the screen is visible), funds are transferred via UPI to unknown accounts. In one reported case, a victim lost ₹1.5 lakh from their SBI account within minutes of sharing a single OTP during what they believed was a KYC call.

Real Warning Signs (What to Watch For)


What Happens to Victims

Financial losses can be immediate and irreversible. UPI transactions are near-instant, and reversal windows are extremely narrow — typically requiring the receiving bank's cooperation, which is not guaranteed. Victims have reported losses from ₹50,000 to crores, with funds often routed through multiple mule accounts before they can be traced. If a remote access app was installed, attackers may also harvest stored Aadhaar numbers, PAN details, or saved passwords, compounding the damage into long-term identity theft.

The emotional toll is severe and underreported. Victims describe anxiety, shame, and disruption to daily financial life for months afterward. Restoring a compromised Aadhaar-linked profile or disputing fraudulent transactions through the RBI's Banking Ombudsman can take weeks or months, during which the victim bears the financial burden. Consulting a lawyer or registered financial advisor is strongly recommended for case-specific recovery steps.


What RBI, CERT-In, and I4C Say

The RBI has repeatedly stated in public communications that no bank will ever ask for an OTP, PIN, or CVV over the phone. Customers are advised to treat any such request as a red flag, regardless of how official the caller sounds.

CERT-In (cert-in.org.in), India's national cybersecurity agency, has issued advisories warning specifically about social engineering attacks that combine urgency tactics with OTP phishing. CERT-In advises users never to install remote access tools at the instruction of an unverified caller.

I4C (Indian Cyber Crime Coordination Centre) and the cybercrime.gov.in portal provide a centralised mechanism to report such fraud. The 1930 Cybercrime Helpline is the fastest first response channel — calling it immediately after an incident can help authorities attempt to freeze the destination account before funds are moved further.

The IT Rules 2021 and the Bharatiya Nyaya Sanhita (BNS) 2023 provide legal recourse for victims of financial fraud and identity theft. For personalised legal guidance, consult a qualified advocate.


How to Protect Yourself

  1. Never share an OTP with anyone — no legitimate bank, e-commerce platform, or government body will ever ask for it.
  2. Hang up immediately if a caller claims urgent KYC or account suspension — then call your bank's official number from the back of your card.
  3. Never install AnyDesk, TeamViewer, or any remote tool at the instruction of an inbound caller.
  4. Verify caller identity independently — don't use numbers provided by the caller; look up official helplines yourself.
  5. Enable UPI transaction limits in your banking app to cap single-transfer amounts.
  6. Register for SMS and email alerts on all accounts so you catch unauthorised activity in real time.
  7. Lock your Aadhaar biometrics via the UIDAI portal (myaadhaar.uidai.gov.in) to prevent misuse if your details are compromised.

What to Do If You've Been Targeted

  1. Call 1930 immediately — India's National Cybercrime Helpline. Speed is critical; early reporting can trigger a hold on receiving accounts.
  2. File a complaint at cybercrime.gov.in — keep your transaction reference number, timestamp, and caller number ready.
  3. Call your bank's official helpline and ask them to freeze your account or UPI handle pending investigation.
  4. Uninstall any remote access app (AnyDesk, TeamViewer) that was installed during the incident and run a security scan on your device.
  5. File a written complaint at your nearest police station under the IT Act and BNS 2023 — get a copy with a complaint number for your records.
  6. Contact the RBI Banking Ombudsman if your bank does not respond to your grievance within 30 days.
  7. Lock your Aadhaar via UIDAI if you suspect your biometric or demographic data was accessed.

Frequently Asked Questions

Can a bank ever legitimately ask for my OTP over a call? No. The RBI has clearly stated that no genuine bank employee, under any circumstances, will ask for your OTP, PIN, CVV, or net banking password over the phone, SMS, or WhatsApp. Any caller making this request — regardless of how convincingly they identify themselves — should be considered a fraud attempt.

I shared my OTP 10 minutes ago — is it too late to act? Not necessarily. Call 1930 immediately. Authorities can sometimes coordinate with receiving banks to place a hold on funds before they are withdrawn or further transferred. Simultaneously, call your bank to freeze your account. Every minute counts.

The caller knew my name and the last four digits of my account — how? Partial account details are often harvested from data leaks, social media, or purchased from underground data brokers. Fraudsters use this information specifically to build false credibility. Knowing your name or partial account number does not mean the caller is legitimate.

Can installing AnyDesk cause more damage than just losing money? Yes. Remote access tools give the operator live visibility of your entire screen. If your banking app, stored passwords, Aadhaar PDF, or PAN card image is visible during the session, all of that information can be captured. This can enable follow-on fraud including new loan applications, SIM swaps, and identity theft well after the initial incident.


Worried a message or call might be a scam? Scan it instantly at BharatSecure.app and report any cybercrime to the 1930 helpline — early reporting is your strongest protection.

Disclaimer: This article describes a pattern of fraud reported in public sources for public-safety awareness. It is not legal, financial, or medical advice. To request correction or removal of any content, write to hello@bharatsecure.app.

Related Scams in Our Database

Verify Any Suspicious Message

Check any suspicious message, link, or call for free at bharatsecure.app.