Differences
This shows you the differences between two versions of the page.
| — | fake-kyc-update-scam-india [2026/07/22 17:47] (current) – created - external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | ====== Fake KYC Update Scam India — How to Detect, Block, and Recover (2026) ====== | ||
| + | |||
| + | |||
| + | |||
| + | {{ : | ||
| + | |||
| + | <WRAP center round info 95%> | ||
| + | **Quick Reply:** Fake KYC update scam in India? Spot the SMS / link / call, block your account in 90 minutes via 1930, and recover money under RBI 2017 rules — full... | ||
| + | </ | ||
| + | |||
| + | {{htmlmetatags> | ||
| + | {{htmlmetatags> | ||
| + | |||
| + | **If you live abroad:** see the [[https:// | ||
| + | |||
| + | The "your KYC will expire in 24 hours, click here to update" | ||
| + | |||
| + | > **Citizen Crisis Response Network — 90-minute rule**\\ If you clicked a fake KYC link or shared an OTP: hang up → freeze your account through net-banking → call **1930** → file at **cybercrime.gov.in** → write to your bank within 24 hours. Most refunds depend on action inside the first 90 minutes. | ||
| + | |||
| + | ===== Direct answer (featured snippet) ===== | ||
| + | |||
| + | Genuine KYC updates in India are done **only** by visiting the bank branch, through the bank's verified app/website (no link in SMS), or via a video-KYC session that **you** initiate. A KYC update SMS that contains a link, a phone number, or threatens 24-hour account closure is a scam. If you have already clicked: change your net-banking password, call **1930**, file a complaint at [[https:// | ||
| + | |||
| + | ===== In this guide ===== | ||
| + | |||
| + | * [[#How the fake KYC scam runs|How the fake KYC scam runs]] | ||
| + | * [[#Six red flags in 30 seconds|Six red flags in 30 seconds]] | ||
| + | * [[#The first 90 minutes — what to do if you clicked|The first 90 minutes — what to do if you clicked]] | ||
| + | * [[#The next 24 hours — written complaints|The next 24 hours — written complaints]] | ||
| + | * [[# | ||
| + | * [[#Sample written complaint|Sample written complaint to your bank]] | ||
| + | * [[#What not to do|What not to do]] | ||
| + | * [[#Can compensation be claimed? | ||
| + | * [[# | ||
| + | |||
| + | ===== How the fake KYC scam runs ===== | ||
| + | |||
| + | The pattern is identical across operators. The **bait**, **trap**, and **drain** are three separate steps: | ||
| + | |||
| + | - **Bait** — An SMS, WhatsApp message, or call claims: "Dear customer, your [Bank] KYC will expire today / your account will be blocked. Update at [link] or call [number]." | ||
| + | - **Trap** — The link opens a near-perfect clone of your bank's net-banking page, or installs an APK that records the screen. You enter the user-id, password, debit-card details, and the OTP that the **real** bank sends because the attacker is **simultaneously** triggering a transaction at the bank's real site. | ||
| + | - **Drain** — Within seconds: UPI is added to a new device, a sweep of the savings is sent to multiple money-mule accounts (often layered through cryptocurrency), | ||
| + | |||
| + | The defining signature is **time pressure** ("24 hours" | ||
| + | |||
| + | ===== Six red flags in 30 seconds ===== | ||
| + | |||
| + | | Flag | What you'll see | Why it's a scam | | ||
| + | | **1. URL shortener or odd domain** | bit.ly/x, .xyz, kyc-sbi-update.in, | ||
| + | | **2. APK download** | " | ||
| + | | **3. Toll-free in SMS body** | "Call 8XXXXXXXXX urgently" | ||
| + | | **4. SMS sender ID is a 10-digit number** | sent from +91-9XX… | Bank SMSes come from registered DLT IDs (e.g., HDFCBN, ICICIB) | | ||
| + | | **5. Threat of account block** | " | ||
| + | | **6. Asks for OTP / password / CVV** | "Share OTP to confirm KYC" | Banks **never** ask for OTP, full card number, CVV or password | | ||
| + | |||
| + | > **Citizen tip** — Before you act on any KYC SMS, log into your bank's app **directly** (not from the SMS link). If KYC is genuinely due, you'll see a banner inside the app. If the app shows nothing, the SMS is fake. | ||
| + | |||
| + | ===== The first 90 minutes — what to do if you clicked ===== | ||
| + | |||
| + | ==== 1. Disconnect from the internet and the call ==== | ||
| + | |||
| + | Pull data off if you installed an APK — the screen recorder cannot stream OTPs without internet. End the call. Do **not** answer the same number' | ||
| + | |||
| + | ==== 2. Change net-banking password from a different device ==== | ||
| + | |||
| + | Use a laptop / family member' | ||
| + | |||
| + | ==== 3. Block the debit card ==== | ||
| + | |||
| + | Most apps: **Cards → Manage → Block / Hot-list**. Or call the 24×7 card-block number printed on the card / the bank's IVR. | ||
| + | |||
| + | ==== 4. Disable UPI and add-on apps ==== | ||
| + | |||
| + | UPI: open the app → De-register / Remove account → confirm. Then revoke any device-binding shown under " | ||
| + | |||
| + | ==== 5. Call 1930 ==== | ||
| + | |||
| + | [[https:// | ||
| + | |||
| + | ==== 6. File the same complaint online ==== | ||
| + | |||
| + | Submit a structured complaint at cybercrime.gov.in (Financial Fraud → Online Banking / UPI / Net-banking). Upload the SMS screenshot, the APK file (if available), the bank statement entry, and any URL/ | ||
| + | |||
| + | ==== 7. Notify your bank in writing ==== | ||
| + | |||
| + | Email + the bank's online " | ||
| + | |||
| + | > **Emergency step** — If you installed an APK, **factory-reset** the phone after backing up only photos / contacts (no APK). Some KYC trojans persist after the app is uninstalled. | ||
| + | |||
| + | ===== The next 24 hours — written complaints ===== | ||
| + | |||
| + | - **Bank** — Branch visit + written letter; obtain stamped acknowledgement | ||
| + | - **Card issuer** — Separate dispute form for each unauthorized transaction | ||
| + | - **UPI** — NPCI dispute (your bank app → "Raise dispute" | ||
| + | - **Police FIR / e-FIR** — Citing **BNS, 2023 §319 (cheating)** + **§316 (cheating by personation)** + **§318 (cheating with property)** | ||
| + | - **TRAI** — File spam-DLT complaint at sancharsaathi.gov.in → Chakshu, attaching the SMS screenshot — this helps trace the registered telemarketer / DLT ID | ||
| + | |||
| + | Keep all reference numbers in one document. You will need them for the bank, the ombudsman, and any future consumer-court claim. | ||
| + | |||
| + | ===== Recovering money — RBI 2017 framework ===== | ||
| + | |||
| + | RBI's **Master Direction on Limiting Liability of Customers in Unauthorised Electronic Banking Transactions, | ||
| + | |||
| + | ^ Reporting delay ^ Customer liability (Savings) ^ Customer liability (Current) ^ | ||
| + | | **0–3 working days** | **Zero** (full refund) | Zero | | ||
| + | | 4–7 working days | ₹5,000 max | ₹10,000 max | | ||
| + | | Beyond 7 days | Per bank's board-approved policy | Per bank's board-approved policy | | ||
| + | |||
| + | The 90-day clock starts the day you report. The bank must: | ||
| + | * Provide **shadow / temporary credit** within 10 working days | ||
| + | * Resolve the dispute within 90 days | ||
| + | * If unresolved, **escalate to the RBI Banking Ombudsman**: | ||
| + | |||
| + | Refund probability is highest when (a) you reported within 3 working days, (b) you have a 1930 reference, (c) the bank cannot prove you shared the OTP intentionally with no scam pretext, and (d) the receiving account was lien-frozen before layering. | ||
| + | |||
| + | ===== Sample written complaint ===== | ||
| + | |||
| + | < | ||
| + | To, | ||
| + | The Branch Manager, | ||
| + | [Bank Name], [Branch], [City] | ||
| + | |||
| + | Subject: Unauthorised debit / Fake KYC fraud — A/C [last 4 digits] — | ||
| + | request for refund under RBI Master Direction 2017 | ||
| + | |||
| + | Sir / Madam, | ||
| + | |||
| + | I, [Full name], holder of Savings A/C [number], wish to report | ||
| + | unauthorised debit(s) totalling ₹[amount] on [date] at approximately | ||
| + | [time], arising from a fake KYC update SMS / call that I responded to | ||
| + | in the belief that it was from your bank. | ||
| + | |||
| + | The transactions are itemised below: | ||
| + | |||
| + | [Date] [Time] [UTR / Ref] [Amount] [Beneficiary] | ||
| + | ... | ||
| + | |||
| + | I have already (a) blocked my debit card, (b) changed net-banking | ||
| + | credentials, | ||
| + | (Reference No. _______, _______), and (d) reported the SMS at Chakshu | ||
| + | (Reference No. _______). | ||
| + | |||
| + | Per the RBI Master Direction on Limiting Liability of Customers in | ||
| + | Unauthorised Electronic Banking Transactions, | ||
| + | reported the loss within ___ working day(s) of debit, my liability is | ||
| + | [Zero / capped at ₹5,000]. I request you to: | ||
| + | |||
| + | 1. Provide temporary / shadow credit within 10 working days. | ||
| + | 2. Resolve the dispute within 90 days. | ||
| + | 3. Issue a written reply with the result of investigation. | ||
| + | |||
| + | Yours faithfully, | ||
| + | [Signature, Name, Date] | ||
| + | [Phone, Email, Aadhaar last 4] | ||
| + | </ | ||
| + | |||
| + | ===== What not to do ===== | ||
| + | |||
| + | * Do **not** call back the number in the SMS — it leads to a " | ||
| + | * Do **not** install any "bank update" | ||
| + | * Do **not** share OTP, CVV, debit-card grid, or net-banking password with anyone — including someone claiming to be the bank. | ||
| + | * Do **not** run AnyDesk, TeamViewer, QuickSupport, | ||
| + | * Do **not** write off the loss. Even small " | ||
| + | |||
| + | ===== Can compensation be claimed? ===== | ||
| + | |||
| + | Yes. Three independent paths: | ||
| + | |||
| + | - **Bank refund** — RBI 2017 framework (above). If denied, escalate to the **RBI Banking Ombudsman** at [[https:// | ||
| + | - **Consumer court** — If the bank's negligence is established (e.g., it ignored unusual-pattern alerts), file at the **District Consumer Disputes Redressal Commission** under the Consumer Protection Act, 2019. Typical award includes refund + ₹25, | ||
| + | - **Telecom / DLT trace** — If the SMS came from a fake DLT, TRAI / DoT may impose penalties on the telemarketer; | ||
| + | |||
| + | Use the **1930 reference + bank acknowledgement + ombudsman number** as the audit trail across all three. | ||
| + | |||
| + | ===== What to do in the next 30 minutes (printable card) ===== | ||
| + | |||
| + | - **0–10 min** — Pull data off; change net-banking password from another device | ||
| + | - **10–20 min** — Block debit card; de-register UPI; revoke linked devices | ||
| + | - **20–35 min** — Call **1930**; note complaint number | ||
| + | - **35–60 min** — File at cybercrime.gov.in; | ||
| + | - **60–90 min** — Email bank's " | ||
| + | - **+24 h** — Visit branch with stamped letter; get written acknowledgement | ||
| + | - **+3 working days** — RBI window — your liability is zero if reported | ||
| + | |||
| + | ===== Long-tail keywords this page targets ===== | ||
| + | |||
| + | fake KYC update scam India 2026, KYC SMS scam how to recover, RBI fake KYC link, KYC update scam refund, 1930 KYC fraud complaint, fake KYC APK, bank KYC link fraud, SBI KYC scam SMS, HDFC KYC fake link, ICICI KYC update scam | ||
| + | |||
| + | ===== If the formal channel fails, escalate via RTI ===== | ||
| + | |||
| + | <WRAP center round info 100%> | ||
| + | If this complaint isn't resolved through the regular complaint route, you can file an **RTI** to force the public authority to either act or explain in writing why they haven' | ||
| + | |||
| + | * Draft your application: | ||
| + | * Calculate timelines: [[https:// | ||
| + | * If PIO doesn' | ||
| + | * If PIO rejects without reason: [[https:// | ||
| + | * Sample applications: | ||
| + | </ | ||
| + | |||
| + | ===== Internal cross-links ===== | ||
| + | |||
| + | * [[scammed-on-upi-recovery-steps|UPI fraud recovery]] | ||
| + | * [[block-lost-stolen-sim-card-india|Block lost / stolen SIM]] | ||
| + | * [[fake-aadhaar-update-website-fraud|Fake Aadhaar update fraud]] | ||
| + | * [[social-media-hacked-recovery|Social media hijack recovery]] | ||
| + | * [[banking-ombudsman-complaint-guide-india|Banking Ombudsman complaint guide]] | ||
| + | * [[rbi-complaint-against-bank-india|RBI complaint against bank]] | ||
| + | * [[recover-money-wrong-bank-account-india|Money sent to wrong account]] | ||
| + | * [[atm-fraud-recovery|ATM fraud recovery]] | ||
| + | * [[pan-aadhaar-fraud-recovery|PAN-Aadhaar fraud recovery]] | ||
| + | |||
| + | ===== Government & authority references ===== | ||
| + | |||
| + | * **RBI Master Direction on Limiting Liability of Customers, 2017** — the entire compensation framework | ||
| + | * **MHA — National Cyber Crime Reporting Portal**: cybercrime.gov.in · Helpline **1930** | ||
| + | * **RBI Banking Ombudsman**: | ||
| + | * **DoT — Sanchar Saathi → Chakshu** (report fraud SMS / call) | ||
| + | * **TRAI — DLT regulations on commercial communication** | ||
| + | * **CERT-In** advisories on banking phishing | ||
| + | * **BNS, 2023** §316 (personation), | ||
| + | * **Consumer Protection Act, 2019** — district / state / national commission | ||
| + | |||
| + | ===== FAQ ===== | ||
| + | |||
| + | ==== Is "video KYC" through a link safe? ==== | ||
| + | |||
| + | Only if **you** initiate it from the bank's official app. A link sent over SMS / WhatsApp / email — even one that says "video KYC" — is a phishing vehicle. | ||
| + | |||
| + | ==== I got a call asking to download AnyDesk for KYC verification. Is it ever genuine? ==== | ||
| + | |||
| + | Never. RBI has prohibited remote-screen-sharing apps in any banking process. End the call. | ||
| + | |||
| + | ==== My bank says I " | ||
| + | |||
| + | Quote RBI's 2017 framework — it specifically allows refund where the customer was " | ||
| + | |||
| + | ==== Should I share the SMS forensics with my bank? ==== | ||
| + | |||
| + | Yes. The DLT sender ID and the URL help the bank's fraud-monitoring unit blacklist the originator. It also strengthens your refund case. | ||
| + | |||
| + | ==== Can the police actually trace the receiving account? ==== | ||
| + | |||
| + | Yes — the 1930 lien mechanism freezes the destination account within minutes (across banks). Tracing the human is harder, but **getting your money back** doesn' | ||
| + | |||
| + | ===== Myth vs reality ===== | ||
| + | |||
| + | ^ Myth ^ Reality ^ | ||
| + | | "RBI sends KYC SMSes." | ||
| + | | "If I gave OTP, I have no recovery." | ||
| + | | "1930 is just for emergencies." | ||
| + | | "APK from a ' | ||
| + | | "Banks update KYC by phone call." | All KYC happens at branch, in-app, or via initiated video-KYC. | | ||
| + | |||
| + | {{tag> | ||