Fake SEBI KYC SMS Phishing Scam
INDIA — By BharatSecure Threat Intelligence Team ·
Verdict Summary
Fake SEBI KYC SMS Phishing Scam shows strong scam indicators common in fraud targeting Indian users. Do not share OTPs, passwords, or payments — verify the source independently.
Risk score: 8/10 · Severity: High · Verdict: Suspicious
Scam Intelligence: Fake SEBI KYC SMS Phishing Scam
Proprietary signals from BharatSecure's scam-tracking database.
| Top affected regions | Delhi, India, urban, general |
| Last reported | May 06, 2026 |
How Fake SEBI KYC SMS Phishing Scam Works
Overview: Scammers are pushing SMS and WhatsApp messages to Indian smartphone users claiming urgent SEBI-mandated KYC updates, threatening account suspension. The fraud appeals to those who fear penalties or account blocks and is dangerous as it tricks people into sharing sensitive data and one-time passwords (OTPs), resulting in fast financial theft or identity misuse. How It Works: The victim gets an SMS or WhatsApp: 'Your crypto wallet KYC is pending. Update now or wallet function will be suspended as per SEBI.' A link takes the person to a site nearly identical to a real KYC update form. The site collects Aadhaar, PAN, selfies, and asks to enter OTPs received by SMS. These details are used to hijack wallets, create fake accounts, or apply for loans using your identity. Some links even auto-install spyware that tracks banking apps, compounding losses. India Angle: This playbook is especially active after regulatory announcements that generate public confusion, such as recent cooperation talks between SEBI and international agencies. Many scams use Hindi, English, Marathi, or even Bengali. Residents of metro areas and those active in mobile banking and crypto activities are frequent targets. Real Examples: Messages like, 'SEBI Update: Last warning—complete your crypto wallet KYC at secure-sebilive[.]top to avoid freeze', or calls from 'SEBI support' asking for real-time OTP entry. Sometimes, the SMS sender ID is spoofed to look like an official bank or SEBI shortcode. Red Flags: 1. KYC messages received without you initiating a process. 2. Links to obscure or misspelled websites, not sebi.gov.in. 3. Promises of instant account unlocks after KYC update. 4. Requests for full personal details and real-time OTP over phone/SMS. Protective Measures: Never act on unexpected urgent KYC requests. Always start any KYC update by visiting official bank or SEBI channels directly. Never enter OTPs on calls or forms you did not initiate. Block and report unsolicited KYC SMSes to TRAI and cyber police. Enable SIM card security features and avoid downloading unknown files from these messages. If Victimised: Change passwords for all connected accounts, lock your SIM, and call your bank to freeze cards if needed. Report details of the phishing scam at cybercrime.gov.in, alert 1930, and notify your bank or payment app support to limit damage. Send a copy to RBI if you suspect data leaks through banking apps. Related Scams: Keep an eye out for similar KYC or PAN urgency phishing, fake income tax refund SMSes, and UPI id 'verification' scams using RBI's name.
How This Scam Works — Detailed Explanation
In the heart of India's digital economy, where Unified Payments Interface (UPI) and Aadhaar have transformed the way citizens interact with banking, a new threat emerges — the Fake SEBI KYC SMS Phishing Scam. Scammers are capitalizing on the anxiety surrounding Know Your Customer (KYC) regulations mandated by the Securities and Exchange Board of India (SEBI). They target unsuspecting victims primarily through SMS and WhatsApp messages that claim, 'Your crypto wallet KYC is pending. Update now or wallet function will be suspended.' These messages often find their way into smartphones, exploiting the pervasive usage of digital wallets and UPI services among Indians. The sheer simplicity of these platforms makes them attractive targets for scammers who are constantly devising new ways to deceive consumers.
These fraudsters rely heavily on psychological manipulation, appealing to the fears of potential penalties, account blocks, and the urgency imposed by the supposed 'SEBI mandates.' They know that many individuals dread the idea of losing access to their hard-earned money and will act quickly to prevent any such risk. The messages usually feature threats about immediate account suspension if the user fails to act, leading many to believe they must comply without questioning further. Scammers also employ tactics such as using logos and branding that closely resemble legitimate entities, making it increasingly difficult for potential victims to discern their authenticity.
Once a victim interacts with the message, they are usually directed to take specific actions. Initially, they are asked to click on a link to verify their KYC details, which directs them to a phishing site. From here, they are prompted to enter personal information, including their mobile number, Aadhaar details, and bank account information. Often, they are also coerced into providing OTPs that they receive on their phones. A real example of this occurred in 2022 when a group of individuals from Maharashtra lost nearly ₹10 crore collectively through similar scams, showing how quickly financial losses can mount. Victims typically find that within moments of sharing this sensitive data, fraudulent transactions are initiated through UPI, leading to severe financial and emotional distress.
The impact has been staggering across India. In recent years, it has been reported that individuals have lost upwards of ₹500 crore to various phishing scams, including the Fake SEBI KYC SMS Phishing Scam. According to the Ministry of Home Affairs (MHA), the rise in reported cases of identity theft and bank fraud has prompted increased awareness and the issuance of alerts by the Reserve Bank of India (RBI) and CERT-In. The lack of cybersecurity awareness among the general populace significantly exacerbates the issue, leading many to fall prey to these deceptive tactics. Reports indicate that more than 60% of the victims were unaware of the evolving nature of digital scams targeting UPI and Aadhaar platforms, further emphasizing the urgent need for increased cybersecurity education.
Identifying legitimate communications versus scams can be challenging in this context. Genuine messages from SEBI or other financial institutions will never ask for your private information or OTP via unsolicited SMS or third-party apps. Always verify the source's authenticity by visiting official websites such as sebi.gov.in. Watch for the website addresses; any URLs that do not contain this domain are suspect. Additionally, legitimate institutions will not threaten you with abrupt account suspension without prior notice. When in doubt, reach out directly to your bank using trusted helplines (like SBI at 1800-11-1109 or HDFC at 1800-202-6161) to inquire about any alleged KYC requirements.
Visual Intelligence:
BharatSecure's AI has identified this as a used in scams targeting Indian users.
Who Does Fake SEBI KYC SMS Phishing Scam Target?
General public across India
Red Flags — How to Identify Fake SEBI KYC SMS Phishing Scam
- Unsolicited KYC links requesting personal info/OTPs
- Websites using suspicious domains, not sebi.gov.in
- Threats of suspension or penalties for not updating KYC
- Requests to enter OTP sent to your phone
- Poor grammar or odd sender IDs
What To Do If You Encounter Fake SEBI KYC SMS Phishing Scam
- Report the scam immediately by calling the cybercrime helpline at 1930 or visit cybercrime.gov.in.
- Do not click on any links provided in the SMS or WhatsApp message.
- Contact your bank using verified helpline numbers to report any unauthorized transactions.
- Change your account passwords and enable two-factor authentication to enhance security.
- Monitor your financial accounts regularly for any unusual activity.
- Educate friends and family about this scam to prevent further victimization.
How to Report Fake SEBI KYC SMS Phishing Scam in India
- Call 1930 — National Cyber Crime Helpline (24x7)
- File a complaint at cybercrime.gov.in
- Contact your bank immediately if money was lost
- Call RBI helpline: 14440 for banking fraud
Frequently Asked Questions
- What to do if I shared my OTP in a UPI scam?
- Immediately contact your bank’s helpline at 1800-11-1109 or 1800-202-6161 to halt any further transactions and report the incident.
- How can I identify this specific scam?
- Look for unsolicited KYC requests and threats of account suspension. Legitimate organizations never ask for sensitive information through unsolicited messages.
- How can I report this type of scam in India?
- Report any phishing attempts by calling the cybercrime helpline at 1930 or visiting cybercrime.gov.in. You should also inform your bank.
- How can I recover money or protect my accounts after this scam?
- Contact your bank immediately to freeze your accounts, and report the scam to the cybercrime helpline at 1930. Follow their guidance on recovery and protective measures.
How This Scam Works — BharatSecure AI
Spreading fastA plain-language breakdown based on 100 real reported scams of this type.
| How they reach you | Observed primary contact occurs via unsolicited phone calls, WhatsApp/SMS messages, and social media/dating platforms, where fraudsters impersonate bank officials, customer support, government agents, |
| How they gain your trust | Trust is reportedly established through impersonation of authority (banks, RBI, PM-Kisan, army officers) or emotional bonding (love-bombing, family/friend impersonation), often reinforced by AI deepfa |
| How they take your money | UPI is the dominant rail across all records, primarily via disguised 'collect/request money' notifications tricking victims into entering their PIN, d |
| Who they target | Documented targets span the general population but concentrate on the elderly and digitally inexperienced (often via caregiver dependency), urban professionals, students, homemakers, small business ow |
- authority bias (impersonating banks/government/officials)
- urgency and scarcity (account frozen, limited-time offer, emergency)
- trust/reciprocity exploitation (familiar voices, love-bombing, small initial payouts)
- Receiving a UPI 'collect/request money' notification and being asked to enter your PIN to 'receive' funds (PIN is never needed to receive money)
- Unsolicited calls/messages claiming account freeze, KYC expiry, or suspicious transaction, pressuring you to share OTP, UPI PIN, or click a link
- Requests to install remote-access/screen-sharing apps (AnyDesk, TeamViewer) for 'support' or 'refund' assistance
- Mismatched or misleading recipient names/VPAs (e.g., 'Verified Merchant', 'Bank Refund Dept') or slightly altered UPI IDs
- Pressure via emotional urgency, deepfake voice/video of familiar people, forged payment screenshots, or too-good-to-be-true offers (free recharge, prizes, grants, loans, high-return investments)
Related Scams in India
Verify Any Suspicious Message
Check any suspicious message, link, or call for free at bharatsecure.app. BharatSecure uses AI to detect scams in real-time and protect Indian users.