Every few months, millions of Indians receive a text message: "Your bank account KYC is pending. Your account will be blocked within 24 hours. Click the link to update." The message looks official. The sender ID looks like your bank. The urgency is real.
It is a scam โ almost every time. And unlike most scams, it works because KYC updates are a genuine, regular requirement from Indian banks. Scammers exploit this familiarity to make their fake messages believable.
Your bank will never send you a link to update KYC via SMS or WhatsApp.
KYC updates happen only at a branch in person, through the bank's official app, or on the bank's official website that you navigate to yourself โ never through a link someone sends you.What Is KYC โ and Why Scammers Use It
KYC stands for Know Your Customer. It is a regulatory requirement from the Reserve Bank of India (RBI) that banks must verify the identity of their account holders periodically โ using documents like Aadhaar, PAN, and address proof.
Banks do legitimately send KYC reminders from time to time. Scammers know this. They send fake KYC messages designed to look identical to real bank communications, counting on you to act without verifying. The goal is to get you onto a phishing website that captures your banking credentials, Aadhaar number, OTP, and UPI PIN.
How the KYC Update Scam Works โ Step by Step
- 1 You receive an SMS or WhatsApp message from what appears to be your bank (SBI, HDFC, ICICI, Axis, etc.) saying your KYC is pending and your account will be blocked unless you update it immediately.
- 2 The message contains a link โ usually a shortened URL (bit.ly, tinyurl) or a fake domain like sbi-kyc-update.in or hdfc-verify-kyc.com. These look convincing in a glance.
- 3 You click the link and land on a fake website that looks exactly like your bank's login page. It may even have the bank's logo, color scheme, and layout.
- 4 The fake site asks for your details โ customer ID, password, account number, debit card number, CVV, expiry date, and often your Aadhaar number and registered mobile number.
- 5 An OTP is sent to your real phone by your actual bank (triggered by the scammer using the credentials you just entered). The fake site asks you to enter this OTP to "verify your identity."
- 6 The scammer now has full access to your bank account. Money is transferred immediately โ often within minutes of you sharing the OTP.
โ ๏ธ The OTP your bank sends in step 5 is a real transaction OTP. By entering it on the fake site, you are approving a money transfer โ not completing a KYC verification.
Real Examples of Fake KYC Messages
6 Red Flags of a Fake KYC Message
How Your Bank Actually Does KYC Updates
Understanding the legitimate process makes it easy to spot the fake one. Here is how real KYC verification works in India:
- Branch visit: Your bank may send a physical letter or registered SMS asking you to visit the nearest branch with your original Aadhaar and PAN card. No link is provided.
- Video KYC (V-CIP): Some banks offer video-based KYC where a bank employee calls you on a scheduled video call. You show your original documents on camera. No website login is required during this call.
- Official banking app: Banks like SBI (YONO), HDFC (HDFCBank App), ICICI (iMobile) have KYC update sections inside their official apps. You navigate to these yourself โ the bank does not send you a link.
- Bank's own website: You type the URL yourself (sbi.co.in, hdfcbank.com). You are never redirected through a link someone else sent you.
๐ก The key difference: in a legitimate KYC process, you initiate the session by going to the bank's official platform yourself. In a scam, someone sends you a link and tells you to go there.
The Fake Sender ID Problem
You may notice that the SMS sender ID looks exactly like your bank's โ "VM-SBIBNK", "AM-HDFCBK", or even just "SBI". This is called SMS spoofing. Scammers can make their messages appear in the same conversation thread as your real bank messages on your phone.
This is why you cannot trust an SMS just because it appears in the same thread as your bank's previous messages. The only thing that matters is the link inside โ if there is a link asking you to enter credentials, it is a scam regardless of how official the sender looks.
What to Do If You Already Clicked the Link
- 1 If you only clicked but did not enter any details: Close the tab immediately. Change your banking app login password as a precaution. You are likely safe โ phishing sites need your input to steal credentials.
- 2 If you entered your customer ID and password: Log into your bank's official app or website immediately and change your password. Also change your UPI PIN on your payment app. Call your bank's helpline to flag the login as potentially compromised.
- 3 If you entered your debit card number, CVV, or expiry date: Call your bank immediately and ask them to block your debit card. Request a replacement card. Report the fraud at 1930.
- 4 If you entered an OTP: A transaction has likely already been authorized. Call 1930 (Cyber Crime Helpline) immediately and ask to freeze the transaction. File a complaint at cybercrime.gov.in. Time is critical โ the faster you act, the better the chance of recovery.
- 5 Report the phishing site: Forward the SMS to 1909 (the National Anti-Phishing helpline for telecom fraud) and report the fake website to cybercrime.gov.in so others are protected.
How to Protect Yourself โ 4 Rules
๐ Cyber Crime Helpline: 1930 | Report online: cybercrime.gov.in
Act within 24 hours of fraud for the best chance of recovery.