OTP Sharing for KYC Update Scam — How to Identify & Stay Safe
INDIA — By BharatSecure Threat Intelligence Team ·
Severity: Critical | View Full Scam Details
OTP Sharing KYC Update Scam in India 2026: How Fake Bank Calls Are Draining Accounts in Minutes
Fraudsters posing as bank and telecom representatives are tricking Indians into sharing OTPs under the guise of urgent KYC updates — and victims are losing lakhs before they realise what happened. With over ₹300 crore reported lost to OTP-theft and phishing scams in the last fiscal year alone, this is one of the most dangerous active threats facing Indian mobile banking users today.
What Is the OTP Sharing for KYC Update Scam?
This scam involves callers impersonating representatives from trusted institutions — such as banks or telecom providers — who convince victims to read out a One-Time Password (OTP) sent to their phone. That single OTP hands the fraudster the keys to a victim's bank account, UPI wallet, or mobile number.
The scam targets everyday users during normal banking hours and especially after UPI transactions or QR code payments — moments when financial activity is high and users are already primed to engage with payment-related messages. Anyone with a bank account or smartphone is a potential target.
According to public complaints registered with the Ministry of Home Affairs (MHA) and India's Cybercrime Reporting Portal (cybercrime.gov.in), hundreds of such cases are reported every month. BharatSecure's threat-intelligence database has catalogued 38,282 phishing URLs and domains verified against CERT-In, RBI, and OpenPhish data — a significant portion of which are linked to fake KYC and OTP-harvesting campaigns.
Exactly How This Scam Works — Step by Step
- The call arrives. You receive a phone call or WhatsApp/SMS message from a number that appears to belong to your bank or telecom provider. Caller ID spoofing and official-looking names, logos, and language make it convincing.
- The threat is delivered. The caller claims your KYC details are incomplete. They say: "Your account will be blocked in the next 15 minutes unless you verify your KYC right now."
- Panic sets in. The urgency is deliberate. You're mid-transaction, or you've just received a real-looking SMS — and you're worried about losing access to your money or mobile service.
- An OTP lands on your phone. The scammer, who has already begun a transaction or SIM swap request on your account, tells you to check your phone for an OTP and read it aloud "to complete verification."
- You share the OTP. The moment you do, the fraudster completes the unauthorised UPI transaction, logs into your net banking, or initiates a SIM swap that redirects all future OTPs to their device.
- The damage compounds. With SIM swap control, the scammer can intercept every subsequent bank OTP, drain multiple accounts, and lock you out entirely — often within minutes.
Real Warning Signs (What to Watch For)
- A caller claims your KYC is incomplete and your account will be blocked within minutes
- You're asked to share an OTP over the phone — no legitimate bank or telecom ever does this
- The message or call arrives just after a UPI transaction or QR code scan
- The caller uses official-sounding names, logos, or spoofed numbers to appear authentic
- Contact comes via WhatsApp — not an official bank app or verified email
- You feel an overwhelming sense of urgency or fear designed to stop you from thinking clearly
- The caller asks you to "stay on the line" while you check your phone for the OTP
What Happens to Victims
The immediate financial damage is severe. Victims report unauthorised UPI transfers that clear within seconds — well before the RBI's chargeback window can be activated. Once a SIM swap is complete, the fraudster intercepts all subsequent OTPs, potentially draining every linked account. Losses in individual cases have reportedly reached several lakhs of rupees, and the collective impact across reported cases has crossed ₹300 crore in a single fiscal year.
Beyond money, the emotional toll is significant. Victims often experience anxiety, shame, and loss of trust in digital banking — sometimes abandoning UPI entirely. Recovery is slow: RBI guidelines require victims to report unauthorised transactions to their bank within three working days for maximum liability protection, but navigating the complaint process while in financial distress is genuinely difficult. Aadhaar-linked services can also be vulnerable if the compromised mobile number is tied to an Aadhaar OTP chain.
What RBI, CERT-In, and I4C Say
The Reserve Bank of India (RBI) has consistently and publicly warned that no bank will ever ask a customer to share an OTP, PIN, or password — by phone, SMS, or any other channel. RBI's customer protection guidelines place the burden of proof on banks when a customer reports an unauthorised transaction promptly.
CERT-In (cert-in.org.in), India's nodal cybersecurity agency, has issued repeated public advisories warning citizens about phishing calls exploiting KYC deadlines and UPI verification pretexts. CERT-In recommends verifying any "urgent" communication by calling your bank's official number directly.
I4C (Indian Cybercrime Coordination Centre), operating under MHA, runs the 1930 cybercrime helpline — the fastest way to report financial fraud and attempt a transaction freeze. The cybercrime.gov.in portal accepts formal complaints 24/7.
Under the IT Act 2000 and Bharatiya Nyaya Sanhita (BNS) 2023, OTP fraud and identity theft are cognisable offences. The Digital Personal Data Protection (DPDP) Act 2023 also places obligations on organisations to protect personal data — victims have a legal basis to escalate complaints.
How to Protect Yourself
- Never share an OTP with anyone — not a caller claiming to be from your bank, telecom, UIDAI, or any government body.
- Hang up immediately if a caller creates urgency around KYC, account blocking, or SIM issues.
- Call back on the official number printed on your debit card or the bank's verified website — not a number the caller gives you.
- Do not click links in SMS or WhatsApp claiming to be KYC update portals; go directly to your bank's app.
- Enable SIM swap alerts with your telecom provider so you're notified of any porting or swap request.
- Set a UPI transaction limit in your banking app to cap potential losses.
- Register your number on the DND registry (1909) to reduce unsolicited calls, and use TRAI's Sanchar Saathi portal to monitor SIM activity on your Aadhaar.
What to Do If You've Been Targeted
Act within the first 30 minutes — speed is everything.
- Call 1930 (National Cybercrime Helpline) immediately to report the fraud and request a transaction freeze.
- Call your bank's official 24x7 helpline to block your account and reverse any pending transactions.
- File a formal complaint on cybercrime.gov.in with transaction details, the caller's number, and any screenshots.
- Visit your nearest bank branch and submit a written complaint; request a certified copy of all recent transactions.
- Contact your telecom operator if you suspect a SIM swap — report it immediately and get your SIM re-issued.
- Keep all evidence: call logs, SMS screenshots, transaction IDs, and UPI reference numbers for use in police and bank investigations.
For case-specific legal or financial guidance on recovery, consult a qualified advocate or certified financial adviser.
Frequently Asked Questions
Why does the scammer need my OTP if they're claiming to do a KYC update? They don't need it for KYC — that's the lie. Your OTP is the authentication token that authorises a real financial transaction or SIM swap already initiated by the fraudster on the back end. The "KYC update" is just the cover story to make you hand it over willingly.
Can I get my money back if I shared an OTP by mistake? Possibly, but speed is critical. RBI guidelines state that if you report an unauthorised transaction to your bank within three working days and it was not caused by your gross negligence, your liability may be limited. File with 1930 and your bank immediately — do not wait. Consult a lawyer or your bank's grievance officer for advice specific to your situation.
What is a SIM swap and why is it so dangerous in this scam? A SIM swap transfers your mobile number to a SIM card controlled by the fraudster. Once they have your number, every OTP your bank sends goes to them — not you. They can then access net banking, reset passwords, and drain accounts without any further interaction with you. You'll typically notice it when your own SIM loses signal suddenly.
How do I verify if a KYC request is real? Hang up or ignore the message. Open your bank's official app or call the number on the back of your debit card independently. Real KYC updates are done through verified in-app journeys or branch visits — never through an unsolicited phone call demanding an OTP.
Received a suspicious KYC call or message? Scan it for free at BharatSecure.app and report it to the 1930 cybercrime helpline right away — your report could protect the next potential victim.
Disclaimer: This article describes a pattern of fraud reported in public sources for public-safety awareness. It is not legal, financial, or medical advice. To request correction or removal of any content, write to hello@bharatsecure.app.
Related Scams in Our Database
- Deepfake Voice OTP Scam — Severity: CRITICAL
- Remote Access Trojan OTP Fraud — Severity: CRITICAL
- Malicious APK OTP Theft — Severity: CRITICAL
Verify Any Suspicious Message
Check any suspicious message, link, or call for free at bharatsecure.app.