OTP Sharing for KYC Update Scam

केवाईसी अपडेट के लिए ओटीपी साझा करने का घोटाला

INDIA — By BharatSecure Threat Intelligence Team ·

Dangerous Risk: 10/10 Severity: Critical BharatSecure Threat Intelligence

Category: Phishing

Evidence & AI transparency

Not yet assessed. This older record has not completed the new evidence-governance review.

This page includes AI-assisted analysis. AI assistance does not mean a person reviewed or approved this page.

Sources: 0 · Last automated validation: Not recorded

Evidence-backed facts: statements mapped to cited evidence by the automated validator. BharatSecure analysis: interpretation and safety guidance; it is not an official finding.

Automated analysis can contain errors. Confirm important information and decisions with official authorities.

Report an error or suggest a correction

Verdict Summary

OTP Sharing for KYC Update Scam is a confirmed scam. Do not engage — block the sender and report to 1930 (National Cyber Crime Helpline) immediately.

Risk score: 10/10 · Severity: Critical · Verdict: Dangerous

Scam Intelligence: OTP Sharing for KYC Update Scam

Proprietary signals from BharatSecure's scam-tracking database.

Last reportedAug 30, 2026
First documentedAug 30, 2026

How OTP Sharing for KYC Update Scam Works

  1. Send a call or SMS claiming KYC is incomplete or needs re-verification
  2. Ask the victim to share the OTP received on their phone
  3. Use the OTP to authorize fraudulent transactions or SIM swaps

How This Scam Works — Detailed Explanation

Scammers continuously exploit the trust of Indian citizens by posing as representatives from banks or telecom service providers, initiating contact through phone calls or SMS messages. Utilizing a variety of platforms such as WhatsApp and SMS, they cleverly disguise their communications to appear authentic, often using official-sounding names, logos, and even caller ID spoofing to look legitimate. These scammers target individuals during their regular banking hours or when they conduct transactions on UPI (Unified Payments Interface) systems after scanning QR codes. This method of engagement allows them to find a large pool of potential victims who are already engaged in financial transactions and might be more inclined to respond to fake KYC requests.

In terms of tactics, these scammers are trained manipulators, employing various psychological tricks to create a sense of urgency and fear among their targets. They may call victims, claiming their KYC (Know Your Customer) details are incomplete, thus threatening to block access to their bank accounts, mobile services, or even digital wallets unless immediate action is taken. Using phrases like "Your account will be blocked in the next 15 minutes unless you verify your KYC," they push victims into a panic. During the conversation, they often ask victims to check their phones for an OTP (One-Time Password) that has been sent to them, which they are ominously instructed to share with the caller to proceed with the KYC update.

Once a victim falls for this trick, the scammers proceed step-by-step to perpetrate their crime. For instance, after instructing the victim to share the OTP, they use this password to access bank accounts, initiate unauthorized UPI transactions, or even carry out a SIM swap to gain full control over the victim's number and thereby access any subsequent security codes sent by banks. Real incidents in India have reported losses ranging in crores, with victims losing money in scenarios of unauthorized transactions for services they never requested. The effectiveness of these scams greatly relies on the trust that victims place in the sheer authority and legitimacy of the impersonated entity, such as SBI or HDFC.

The impact of these scams in India is profound. The Ministry of Home Affairs (MHA) and the Reserve Bank of India (RBI) have constantly raised alarms about the rise of such phishing attacks, with hundreds of complaints registered monthly. Recently, over ₹300 crore was reported lost to cyber scams involving OTP theft and phishing in the last fiscal year alone. CERT-In (Computer Emergency Response Team) has also suggested several measures to protect consumers, yet the scams persist, causing profound financial harm and emotional distress to victims.

To differentiate between genuine communications and scams, individuals should be aware of a few key red flags. Legitimate bank or telecom communications will never ask you to share your OTP over the phone, nor will they threaten you with immediate account blocking without prior and formal notifications through secured channels. Additionally, individuals should know that genuine bank representatives would provide official communication through their registered email or account notifications. Always verify directly through your bank's official helpline, such as SBI's 1800-11-1109 or HDFC's 1800-202-6161 before taking any actions dictated over the phone.

Who Does OTP Sharing for KYC Update Scam Target?

Bank customers, mobile subscribers, and digital wallet users in India

Red Flags — How to Identify OTP Sharing for KYC Update Scam

  • Request to share OTP with caller or sender
  • Claims of account blocking unless immediate action is taken
  • Impersonation of bank or telecom staff

What To Do If You Encounter OTP Sharing for KYC Update Scam

  1. Report the incident immediately to the cybercrime helpline by calling 1930 or visiting cybercrime.gov.in.
  2. Contact your bank's customer service using official helplines to secure your account.
  3. Change passwords for your online banking and UPI applications immediately.
  4. Monitor your bank statements and transaction history for any unauthorized entries.
  5. Block your SIM card by contacting your telecom service provider if you suspect a SIM swap.
  6. Educate friends and family about this scam to prevent further incidents.

How to Report OTP Sharing for KYC Update Scam in India

  • Call 1930 — National Cyber Crime Helpline (24x7)
  • File a complaint at cybercrime.gov.in
  • Contact your bank immediately if money was lost
  • Call RBI helpline: 14440 for banking fraud

Frequently Asked Questions

What to do if I shared my OTP in a Phishing scam?
Immediately contact your bank using official helplines and report to cybercrime at 1930. Change your account passwords.
How do I identify an OTP Sharing for KYC Update Scam?
Look for requests to share your OTP over the phone or aggressive claims of immediate account blocking from unofficial sources.
How do I report this type of scam in India?
Report through the cybercrime helpline 1930 or file a complaint at cybercrime.gov.in and notify your bank of the fraudulent activity.
What steps should I take to recover money or protect my account after this scam?
Contact your bank urgently to block unauthorized transactions and make them aware of the scam incident to follow their protocol for further assistance.
🛡️

How This Scam Works — BharatSecure AI

Spreading fast

A plain-language breakdown based on 500 real reported scams of this type.

How they reach you Documented primary channels are AI-generated voice/video calls and messages delivered via WhatsApp, phone calls, social media DMs, email (BEC), and SMS, often using spoofed caller IDs. Victims are als
How they gain your trust Trust is established through AI voice/video deepfakes that convincingly impersonate trusted figures—family members, company executives (CEO/CFO), bank officials, or government authorities—leveraging a
How they take your money Most commonly observed rails are UPI and QR-code transfers, IMPS/bank wire transfers to mule or offshore accounts, and crypto payments; OTP extraction
Who they target Documented targets include urban professionals, finance/payroll staff and small-business employees (for BEC and executive-impersonation transfers), the elderly (via distress-call vishing), and job see
How they manipulate you
  • Authority bias (impersonating executives, police, bank/government officials)
  • Urgency and panic (emergencies, arrests, frozen accounts, digital arrest threats)
  • Familiarity/emotional trust (cloned voices of loved ones and known contacts)
Warning signs
  • Unexpected urgent request for money or OTP framed as an emergency, arrest, or account suspension
  • Voice or video call from a 'known' person or executive pressuring immediate confidential transfers
  • Payment demanded via UPI/QR code, crypto, or wire to unfamiliar accounts under time pressure
  • Links to 'verify identity' or login on portals reached via ads, DMs, or emails (cloned websites)
  • Deepfake indicators: slightly off video/audio sync, refusal to verify via a known secondary channel or shared secret

Related Scams in India

Verify Any Suspicious Message

Check any suspicious message, link, or call for free at bharatsecure.app. BharatSecure uses AI to detect scams in real-time and protect Indian users.