Every few months, millions of Indians receive a text message: "Your bank account KYC is pending. Your account will be blocked within 24 hours. Click the link to update." The message looks official. The sender ID looks like your bank. The urgency is real.

It is a scam โ€” almost every time. And unlike most scams, it works because KYC updates are a genuine, regular requirement from Indian banks. Scammers exploit this familiarity to make their fake messages believable.

Your bank will never send you a link to update KYC via SMS or WhatsApp.

KYC updates happen only at a branch in person, through the bank's official app, or on the bank's official website that you navigate to yourself โ€” never through a link someone sends you.

What Is KYC โ€” and Why Scammers Use It

KYC stands for Know Your Customer. It is a regulatory requirement from the Reserve Bank of India (RBI) that banks must verify the identity of their account holders periodically โ€” using documents like Aadhaar, PAN, and address proof.

Banks do legitimately send KYC reminders from time to time. Scammers know this. They send fake KYC messages designed to look identical to real bank communications, counting on you to act without verifying. The goal is to get you onto a phishing website that captures your banking credentials, Aadhaar number, OTP, and UPI PIN.

How the KYC Update Scam Works โ€” Step by Step

  1. 1 You receive an SMS or WhatsApp message from what appears to be your bank (SBI, HDFC, ICICI, Axis, etc.) saying your KYC is pending and your account will be blocked unless you update it immediately.
  2. 2 The message contains a link โ€” usually a shortened URL (bit.ly, tinyurl) or a fake domain like sbi-kyc-update.in or hdfc-verify-kyc.com. These look convincing in a glance.
  3. 3 You click the link and land on a fake website that looks exactly like your bank's login page. It may even have the bank's logo, color scheme, and layout.
  4. 4 The fake site asks for your details โ€” customer ID, password, account number, debit card number, CVV, expiry date, and often your Aadhaar number and registered mobile number.
  5. 5 An OTP is sent to your real phone by your actual bank (triggered by the scammer using the credentials you just entered). The fake site asks you to enter this OTP to "verify your identity."
  6. 6 The scammer now has full access to your bank account. Money is transferred immediately โ€” often within minutes of you sharing the OTP.

โš ๏ธ The OTP your bank sends in step 5 is a real transaction OTP. By entering it on the fake site, you are approving a money transfer โ€” not completing a KYC verification.

Real Examples of Fake KYC Messages

๐Ÿ“ฑ SMS โ€” Fake SBI
Dear SBI Customer, Your KYC verification is pending. Your account will be blocked within 24 hours. Update immediately: http://sbi-kyc-update.in/verify โ€” SBI Bank
๐Ÿ“ฑ SMS โ€” Fake HDFC
ALERT: HDFC Bank account linked to Aadhaar number requires KYC update. Failure to update will result in account suspension. Click here: https://bit.ly/hdfc-kyc-2026
๐Ÿ’ฌ WhatsApp โ€” Fake Bank Officer
Hello, I am Priya Sharma calling from SBI Customer Care. Your KYC is due for renewal as per RBI guidelines. I am sending you a link on WhatsApp. Please fill in your details and OTP to complete verification. It will take only 2 minutes.
๐Ÿ“ž Phone call โ€” Fake Bank Agent
"Sir, your bank account will be permanently deactivated tonight due to incomplete KYC. Please share your Aadhaar number and the OTP you just received so I can update it from my side."

6 Red Flags of a Fake KYC Message

๐Ÿšฉ Extreme urgency โ€” "24 hours", "tonight", "immediately". Real KYC reminders from banks give you weeks or months to comply. If a message says your account will be blocked within hours, it is engineered to panic you.
๐Ÿšฉ A link in the SMS or WhatsApp message. Your bank's official SMS communications will never contain a clickable link directing you to fill in personal details. Official KYC notices tell you to visit a branch or log into your bank's app yourself.
๐Ÿšฉ The website domain is not the bank's official domain. SBI's real website is sbi.co.in. HDFC's is hdfcbank.com. Any variation โ€” sbi-kyc.in, hdfc-update.com, sbi.co.in.kyc-verify.net โ€” is fake. Check the full URL before entering anything.
๐Ÿšฉ Asks for debit card number, CVV, or UPI PIN. KYC updates require identity documents (Aadhaar, PAN, photo). They never require your debit card details, CVV, expiry date, or UPI PIN. Any form asking for these is a fraud attempt.
๐Ÿšฉ Asks you to enter an OTP to "verify" your KYC. OTPs are transaction authorization codes โ€” they confirm a money transfer, not an identity verification. If any step asks for an OTP, a real money movement is being authorized without your knowledge.
๐Ÿšฉ Someone calls you to "help" complete the KYC. No bank will call you, send you a link, and then guide you through entering your details over the phone. This is a social engineering attack. Hang up immediately.

How Your Bank Actually Does KYC Updates

Understanding the legitimate process makes it easy to spot the fake one. Here is how real KYC verification works in India:

๐Ÿ’ก The key difference: in a legitimate KYC process, you initiate the session by going to the bank's official platform yourself. In a scam, someone sends you a link and tells you to go there.

The Fake Sender ID Problem

You may notice that the SMS sender ID looks exactly like your bank's โ€” "VM-SBIBNK", "AM-HDFCBK", or even just "SBI". This is called SMS spoofing. Scammers can make their messages appear in the same conversation thread as your real bank messages on your phone.

This is why you cannot trust an SMS just because it appears in the same thread as your bank's previous messages. The only thing that matters is the link inside โ€” if there is a link asking you to enter credentials, it is a scam regardless of how official the sender looks.

What to Do If You Already Clicked the Link

  1. 1 If you only clicked but did not enter any details: Close the tab immediately. Change your banking app login password as a precaution. You are likely safe โ€” phishing sites need your input to steal credentials.
  2. 2 If you entered your customer ID and password: Log into your bank's official app or website immediately and change your password. Also change your UPI PIN on your payment app. Call your bank's helpline to flag the login as potentially compromised.
  3. 3 If you entered your debit card number, CVV, or expiry date: Call your bank immediately and ask them to block your debit card. Request a replacement card. Report the fraud at 1930.
  4. 4 If you entered an OTP: A transaction has likely already been authorized. Call 1930 (Cyber Crime Helpline) immediately and ask to freeze the transaction. File a complaint at cybercrime.gov.in. Time is critical โ€” the faster you act, the better the chance of recovery.
  5. 5 Report the phishing site: Forward the SMS to 1909 (the National Anti-Phishing helpline for telecom fraud) and report the fake website to cybercrime.gov.in so others are protected.

How to Protect Yourself โ€” 4 Rules

โœ… Never click a KYC link sent to you. If your bank needs a KYC update, open the bank's official app yourself or visit a branch. Ignore any link sent via SMS or WhatsApp.
โœ… Check the domain before entering anything. SBI is sbi.co.in. HDFC is hdfcbank.com. If the URL is anything else โ€” no matter how similar โ€” close the tab.
โœ… Never share an OTP for KYC. OTPs authorize money transfers. If any KYC process asks for an OTP, stop immediately and call your bank's official helpline.
โœ… When in doubt, call the bank directly. Use the number on the back of your debit card or on your bank's official website โ€” not a number given to you in the suspicious message.

๐Ÿ“ž Cyber Crime Helpline: 1930  |  Report online: cybercrime.gov.in
Act within 24 hours of fraud for the best chance of recovery.