Keep RTI Wiki Free for Every Citizen 🇮🇳
Hosting, servers, and content cost ₹50,000+ per month. Your support keeps this resource alive.
Fake KYC Update Scam India — How to Detect, Block, and Recover (2026)
Quick Reply: Fake KYC update scam in India? Spot the SMS / link / call, block your account in 90 minutes via 1930, and recover money under RBI 2017 rules — full…
If you live abroad: see the NRI bank account frozen guide for the KYC, NRE, NRO and dormant-account rescue path.
The “your KYC will expire in 24 hours, click here to update” SMS is the single biggest banking scam in India today. RBI has clarified — repeatedly — that no bank ever asks customers to update KYC by clicking a link, by installing an app, or over a call. This page explains exactly how the scam runs, how to spot it in 30 seconds, how to lock the account if you've already clicked, and how to claim a refund under the RBI customer-liability framework.
Citizen Crisis Response Network — 90-minute rule
If you clicked a fake KYC link or shared an OTP: hang up → freeze your account through net-banking → call 1930 → file at cybercrime.gov.in → write to your bank within 24 hours. Most refunds depend on action inside the first 90 minutes.
Direct answer (featured snippet)
Genuine KYC updates in India are done only by visiting the bank branch, through the bank's verified app/website (no link in SMS), or via a video-KYC session that you initiate. A KYC update SMS that contains a link, a phone number, or threatens 24-hour account closure is a scam. If you have already clicked: change your net-banking password, call 1930, file a complaint at cybercrime.gov.in, freeze your debit card, and email a written complaint to your bank within 24 hours quoting the reference numbers — RBI's 2017 framework can give you a full refund if you reported within 3 working days.
In this guide
How the fake KYC scam runs
The pattern is identical across operators. The bait, trap, and drain are three separate steps:
- Bait — An SMS, WhatsApp message, or call claims: “Dear customer, your [Bank] KYC will expire today / your account will be blocked. Update at [link] or call [number].”
- Trap — The link opens a near-perfect clone of your bank's net-banking page, or installs an APK that records the screen. You enter the user-id, password, debit-card details, and the OTP that the real bank sends because the attacker is simultaneously triggering a transaction at the bank's real site.
- Drain — Within seconds: UPI is added to a new device, a sweep of the savings is sent to multiple money-mule accounts (often layered through cryptocurrency), and a fake “registered mobile changed” alert is suppressed by the screen-recording app.
The defining signature is time pressure (“24 hours”) and out-of-channel contact (you didn't initiate). Banks never threaten time-bound closures by SMS link.
Six red flags in 30 seconds
| Flag | What you'll see | Why it's a scam |
| 1. URL shortener or odd domain | bit.ly/x, .xyz, kyc-sbi-update.in, sbi-kyc.online | Real banks use only their root domain (sbi.co.in, hdfcbank.com) |
| 2. APK download | “Install this app to update KYC” | Real KYC never requires a third-party APK |
| 3. Toll-free in SMS body | “Call 8XXXXXXXXX urgently” | Banks publish only their published toll-free numbers |
| 4. SMS sender ID is a 10-digit number | sent from +91-9XX… | Bank SMSes come from registered DLT IDs (e.g., HDFCBN, ICICIB) |
| 5. Threat of account block | “Account suspension in 24 hours” | RBI prohibits coercive language in genuine KYC reminders |
| 6. Asks for OTP / password / CVV | “Share OTP to confirm KYC” | Banks never ask for OTP, full card number, CVV or password |
Citizen tip — Before you act on any KYC SMS, log into your bank's app directly (not from the SMS link). If KYC is genuinely due, you'll see a banner inside the app. If the app shows nothing, the SMS is fake.
The first 90 minutes — what to do if you clicked
1. Disconnect from the internet and the call
Pull data off if you installed an APK — the screen recorder cannot stream OTPs without internet. End the call. Do not answer the same number's redial.
2. Change net-banking password from a different device
Use a laptop / family member's phone. Login → Profile → Change Password. If the password was already changed by the attacker, use Forgot Password with debit-card details + OTP to your registered number (assuming the SIM is still in your control — if SIM is gone too, run the stolen-SIM playbook in parallel).
3. Block the debit card
Most apps: Cards → Manage → Block / Hot-list. Or call the 24×7 card-block number printed on the card / the bank's IVR.
4. Disable UPI and add-on apps
UPI: open the app → De-register / Remove account → confirm. Then revoke any device-binding shown under “Linked devices.”
5. Call 1930
National Cyber Crime Reporting Portal — call 1930 within the golden hour. The operator generates a complaint number. The portal then issues a lien on the receiving account at the destination bank, which is the only mechanism that can claw back funds before they layer.
6. File the same complaint online
Submit a structured complaint at cybercrime.gov.in (Financial Fraud → Online Banking / UPI / Net-banking). Upload the SMS screenshot, the APK file (if available), the bank statement entry, and any URL/screenshot of the cloned page.
7. Notify your bank in writing
Email + the bank's online “Report Unauthorized Transaction” form. Include: time of click, time of debit, 1930 reference, cybercrime portal reference, screenshot of the SMS. Demand temporary credit pending investigation — RBI requires 90-day resolution.
Emergency step — If you installed an APK, factory-reset the phone after backing up only photos / contacts (no APK). Some KYC trojans persist after the app is uninstalled.
The next 24 hours — written complaints
- Bank — Branch visit + written letter; obtain stamped acknowledgement
- Card issuer — Separate dispute form for each unauthorized transaction
- UPI — NPCI dispute (your bank app → “Raise dispute” against the UTR)
- Police FIR / e-FIR — Citing BNS, 2023 §319 (cheating) + §316 (cheating by personation) + §318 (cheating with property)
- TRAI — File spam-DLT complaint at sancharsaathi.gov.in → Chakshu, attaching the SMS screenshot — this helps trace the registered telemarketer / DLT ID
Keep all reference numbers in one document. You will need them for the bank, the ombudsman, and any future consumer-court claim.
Recovering money — RBI 2017 framework
RBI's Master Direction on Limiting Liability of Customers in Unauthorised Electronic Banking Transactions, 2017 governs every such fraud:
| Reporting delay | Customer liability (Savings) | Customer liability (Current) |
|---|---|---|
| 0–3 working days | Zero (full refund) | Zero |
| 4–7 working days | ₹5,000 max | ₹10,000 max |
| Beyond 7 days | Per bank's board-approved policy | Per bank's board-approved policy |
The 90-day clock starts the day you report. The bank must:
- Provide shadow / temporary credit within 10 working days
- Resolve the dispute within 90 days
- If unresolved, escalate to the RBI Banking Ombudsman: cms.rbi.org.in
Refund probability is highest when (a) you reported within 3 working days, (b) you have a 1930 reference, © the bank cannot prove you shared the OTP intentionally with no scam pretext, and (d) the receiving account was lien-frozen before layering.
Sample written complaint
To, The Branch Manager, [Bank Name], [Branch], [City] Subject: Unauthorised debit / Fake KYC fraud — A/C [last 4 digits] — request for refund under RBI Master Direction 2017 Sir / Madam, I, [Full name], holder of Savings A/C [number], wish to report unauthorised debit(s) totalling ₹[amount] on [date] at approximately [time], arising from a fake KYC update SMS / call that I responded to in the belief that it was from your bank. The transactions are itemised below: [Date] [Time] [UTR / Ref] [Amount] [Beneficiary] ... I have already (a) blocked my debit card, (b) changed net-banking credentials, (c) filed a complaint at 1930 and cybercrime.gov.in (Reference No. _______, _______), and (d) reported the SMS at Chakshu (Reference No. _______). Per the RBI Master Direction on Limiting Liability of Customers in Unauthorised Electronic Banking Transactions, 2017, since I have reported the loss within ___ working day(s) of debit, my liability is [Zero / capped at ₹5,000]. I request you to: 1. Provide temporary / shadow credit within 10 working days. 2. Resolve the dispute within 90 days. 3. Issue a written reply with the result of investigation. Yours faithfully, [Signature, Name, Date] [Phone, Email, Aadhaar last 4]
What not to do
- Do not call back the number in the SMS — it leads to a “verification” agent who will harvest more.
- Do not install any “bank update” app from outside the official Play Store / App Store.
- Do not share OTP, CVV, debit-card grid, or net-banking password with anyone — including someone claiming to be the bank.
- Do not run AnyDesk, TeamViewer, QuickSupport, RustDesk, or any remote-access app on a banker's instructions — this is the second-stage trojan.
- Do not write off the loss. Even small “₹2,000 was taken” cases are eligible for refund and tracked through 1930.
Can compensation be claimed?
Yes. Three independent paths:
- Bank refund — RBI 2017 framework (above). If denied, escalate to the RBI Banking Ombudsman at cms.rbi.org.in (no fee, online).
- Consumer court — If the bank's negligence is established (e.g., it ignored unusual-pattern alerts), file at the District Consumer Disputes Redressal Commission under the Consumer Protection Act, 2019. Typical award includes refund + ₹25,000–₹2,00,000 compensation for harassment.
- Telecom / DLT trace — If the SMS came from a fake DLT, TRAI / DoT may impose penalties on the telemarketer; you can claim as the affected consumer.
Use the 1930 reference + bank acknowledgement + ombudsman number as the audit trail across all three.
What to do in the next 30 minutes (printable card)
- 0–10 min — Pull data off; change net-banking password from another device
- 10–20 min — Block debit card; de-register UPI; revoke linked devices
- 20–35 min — Call 1930; note complaint number
- 35–60 min — File at cybercrime.gov.in; upload SMS + APK
- 60–90 min — Email bank's “report unauthorised transaction” with all references
- +24 h — Visit branch with stamped letter; get written acknowledgement
- +3 working days — RBI window — your liability is zero if reported
Long-tail keywords this page targets
fake KYC update scam India 2026, KYC SMS scam how to recover, RBI fake KYC link, KYC update scam refund, 1930 KYC fraud complaint, fake KYC APK, bank KYC link fraud, SBI KYC scam SMS, HDFC KYC fake link, ICICI KYC update scam
If the formal channel fails, escalate via RTI
If this complaint isn't resolved through the regular complaint route, you can file an RTI to force the public authority to either act or explain in writing why they haven't. The fee is ₹10 (free if you're BPL).
- Draft your application: AI RTI Drafter
- Calculate timelines: Timeline Calculator
- If PIO doesn't reply in 30 days: Deemed refusal first appeal
- If PIO rejects without reason: S.8 rejection appeal
- Sample applications: Sample RTI library
Internal cross-links
Government & authority references
- RBI Master Direction on Limiting Liability of Customers, 2017 — the entire compensation framework
- MHA — National Cyber Crime Reporting Portal: cybercrime.gov.in · Helpline 1930
- RBI Banking Ombudsman: cms.rbi.org.in
- DoT — Sanchar Saathi → Chakshu (report fraud SMS / call)
- TRAI — DLT regulations on commercial communication
- CERT-In advisories on banking phishing
- BNS, 2023 §316 (personation), §318 (cheating with property), §319 (cheating)
- Consumer Protection Act, 2019 — district / state / national commission
FAQ
Is "video KYC" through a link safe?
Only if you initiate it from the bank's official app. A link sent over SMS / WhatsApp / email — even one that says “video KYC” — is a phishing vehicle.
I got a call asking to download AnyDesk for KYC verification. Is it ever genuine?
Never. RBI has prohibited remote-screen-sharing apps in any banking process. End the call.
My bank says I "voluntarily" gave OTP, so no refund. What now?
Quote RBI's 2017 framework — it specifically allows refund where the customer was “deceived.” File the Banking Ombudsman complaint and consumer-court complaint in parallel.
Should I share the SMS forensics with my bank?
Yes. The DLT sender ID and the URL help the bank's fraud-monitoring unit blacklist the originator. It also strengthens your refund case.
Can the police actually trace the receiving account?
Yes — the 1930 lien mechanism freezes the destination account within minutes (across banks). Tracing the human is harder, but getting your money back doesn't depend on tracing them.
Myth vs reality
| Myth | Reality |
|---|---|
| “RBI sends KYC SMSes.” | RBI never contacts customers. Banks do, and never with a link. |
| “If I gave OTP, I have no recovery.” | RBI 2017 framework allows refund when reported within 3 working days. |
| “1930 is just for emergencies.” | 1930 is the only way to lien the receiving account before money layers. Use it always. |
| “APK from a 'bank' must be safe.” | No bank distributes APK files directly. Always Play Store / App Store. |
| “Banks update KYC by phone call.” | All KYC happens at branch, in-app, or via initiated video-KYC. |
Reader signal
Was this article useful?
Tap once if it helped you. These counters show other citizens which pages are worth reading.
