OTP Sharing for KYC Update Scam — How to Identify & Stay Safe

INDIA — By BharatSecure Threat Intelligence Team ·

Severity: Critical | View Full Scam Details

OTP Sharing KYC Update Scam in India 2026: How Fake Bank Calls Are Draining Accounts in Minutes

Fraudsters posing as bank and telecom representatives are tricking Indians into sharing OTPs under the guise of urgent KYC updates — and victims are losing lakhs before they realise what happened. With over ₹300 crore reported lost to OTP-theft and phishing scams in the last fiscal year alone, this is one of the most dangerous active threats facing Indian mobile banking users today.


What Is the OTP Sharing for KYC Update Scam?

This scam involves callers impersonating representatives from trusted institutions — such as banks or telecom providers — who convince victims to read out a One-Time Password (OTP) sent to their phone. That single OTP hands the fraudster the keys to a victim's bank account, UPI wallet, or mobile number.

The scam targets everyday users during normal banking hours and especially after UPI transactions or QR code payments — moments when financial activity is high and users are already primed to engage with payment-related messages. Anyone with a bank account or smartphone is a potential target.

According to public complaints registered with the Ministry of Home Affairs (MHA) and India's Cybercrime Reporting Portal (cybercrime.gov.in), hundreds of such cases are reported every month. BharatSecure's threat-intelligence database has catalogued 38,282 phishing URLs and domains verified against CERT-In, RBI, and OpenPhish data — a significant portion of which are linked to fake KYC and OTP-harvesting campaigns.


Exactly How This Scam Works — Step by Step

  1. The call arrives. You receive a phone call or WhatsApp/SMS message from a number that appears to belong to your bank or telecom provider. Caller ID spoofing and official-looking names, logos, and language make it convincing.
  2. The threat is delivered. The caller claims your KYC details are incomplete. They say: "Your account will be blocked in the next 15 minutes unless you verify your KYC right now."
  3. Panic sets in. The urgency is deliberate. You're mid-transaction, or you've just received a real-looking SMS — and you're worried about losing access to your money or mobile service.
  4. An OTP lands on your phone. The scammer, who has already begun a transaction or SIM swap request on your account, tells you to check your phone for an OTP and read it aloud "to complete verification."
  5. You share the OTP. The moment you do, the fraudster completes the unauthorised UPI transaction, logs into your net banking, or initiates a SIM swap that redirects all future OTPs to their device.
  6. The damage compounds. With SIM swap control, the scammer can intercept every subsequent bank OTP, drain multiple accounts, and lock you out entirely — often within minutes.

Real Warning Signs (What to Watch For)


What Happens to Victims

The immediate financial damage is severe. Victims report unauthorised UPI transfers that clear within seconds — well before the RBI's chargeback window can be activated. Once a SIM swap is complete, the fraudster intercepts all subsequent OTPs, potentially draining every linked account. Losses in individual cases have reportedly reached several lakhs of rupees, and the collective impact across reported cases has crossed ₹300 crore in a single fiscal year.

Beyond money, the emotional toll is significant. Victims often experience anxiety, shame, and loss of trust in digital banking — sometimes abandoning UPI entirely. Recovery is slow: RBI guidelines require victims to report unauthorised transactions to their bank within three working days for maximum liability protection, but navigating the complaint process while in financial distress is genuinely difficult. Aadhaar-linked services can also be vulnerable if the compromised mobile number is tied to an Aadhaar OTP chain.


What RBI, CERT-In, and I4C Say

The Reserve Bank of India (RBI) has consistently and publicly warned that no bank will ever ask a customer to share an OTP, PIN, or password — by phone, SMS, or any other channel. RBI's customer protection guidelines place the burden of proof on banks when a customer reports an unauthorised transaction promptly.

CERT-In (cert-in.org.in), India's nodal cybersecurity agency, has issued repeated public advisories warning citizens about phishing calls exploiting KYC deadlines and UPI verification pretexts. CERT-In recommends verifying any "urgent" communication by calling your bank's official number directly.

I4C (Indian Cybercrime Coordination Centre), operating under MHA, runs the 1930 cybercrime helpline — the fastest way to report financial fraud and attempt a transaction freeze. The cybercrime.gov.in portal accepts formal complaints 24/7.

Under the IT Act 2000 and Bharatiya Nyaya Sanhita (BNS) 2023, OTP fraud and identity theft are cognisable offences. The Digital Personal Data Protection (DPDP) Act 2023 also places obligations on organisations to protect personal data — victims have a legal basis to escalate complaints.


How to Protect Yourself

  1. Never share an OTP with anyone — not a caller claiming to be from your bank, telecom, UIDAI, or any government body.
  2. Hang up immediately if a caller creates urgency around KYC, account blocking, or SIM issues.
  3. Call back on the official number printed on your debit card or the bank's verified website — not a number the caller gives you.
  4. Do not click links in SMS or WhatsApp claiming to be KYC update portals; go directly to your bank's app.
  5. Enable SIM swap alerts with your telecom provider so you're notified of any porting or swap request.
  6. Set a UPI transaction limit in your banking app to cap potential losses.
  7. Register your number on the DND registry (1909) to reduce unsolicited calls, and use TRAI's Sanchar Saathi portal to monitor SIM activity on your Aadhaar.

What to Do If You've Been Targeted

Act within the first 30 minutes — speed is everything.

For case-specific legal or financial guidance on recovery, consult a qualified advocate or certified financial adviser.


Frequently Asked Questions

Why does the scammer need my OTP if they're claiming to do a KYC update? They don't need it for KYC — that's the lie. Your OTP is the authentication token that authorises a real financial transaction or SIM swap already initiated by the fraudster on the back end. The "KYC update" is just the cover story to make you hand it over willingly.

Can I get my money back if I shared an OTP by mistake? Possibly, but speed is critical. RBI guidelines state that if you report an unauthorised transaction to your bank within three working days and it was not caused by your gross negligence, your liability may be limited. File with 1930 and your bank immediately — do not wait. Consult a lawyer or your bank's grievance officer for advice specific to your situation.

What is a SIM swap and why is it so dangerous in this scam? A SIM swap transfers your mobile number to a SIM card controlled by the fraudster. Once they have your number, every OTP your bank sends goes to them — not you. They can then access net banking, reset passwords, and drain accounts without any further interaction with you. You'll typically notice it when your own SIM loses signal suddenly.

How do I verify if a KYC request is real? Hang up or ignore the message. Open your bank's official app or call the number on the back of your debit card independently. Real KYC updates are done through verified in-app journeys or branch visits — never through an unsolicited phone call demanding an OTP.


Received a suspicious KYC call or message? Scan it for free at BharatSecure.app and report it to the 1930 cybercrime helpline right away — your report could protect the next potential victim.

Disclaimer: This article describes a pattern of fraud reported in public sources for public-safety awareness. It is not legal, financial, or medical advice. To request correction or removal of any content, write to hello@bharatsecure.app.

Related Scams in Our Database

Verify Any Suspicious Message

Check any suspicious message, link, or call for free at bharatsecure.app.