The Reserve Bank of India (RBI) has issued a fresh warning about cyber fraud carried out in the name of KYC updates. The central bank has advised customers to remain cautious of WhatsApp messages and phone calls that threaten to block their bank accounts unless they immediately complete a KYC update. Fraudsters may use such messages to persuade victims to click suspicious links, share sensitive banking information or download malicious applications.
The RBI has urged people not to panic when they receive such messages and instead follow its ‘Stop, Think and Act’ safety rule. According to the central bank, users should not immediately follow instructions received through unexpected messages or calls, particularly when fraudsters create urgency by claiming that an account will be blocked within a specified period.
‘Stop’ Means Do Not Act Immediately
The first step in the RBI’s three-part safety message is ‘Stop’. Customers should not immediately respond to calls, SMS messages or WhatsApp communications from unknown individuals. If someone claims to be a bank official and asks the customer to update KYC to prevent account blocking, the request should first be independently verified.
The second step is ‘Think’. The RBI has specifically warned that banks and Non-Banking Financial Companies (NBFCs) do not send suspicious links asking customers to complete KYC updates. Therefore, any link accompanied by a warning that an account will be blocked should be treated as a major red flag.
The third step is ‘Act’. Customers should never click on suspicious KYC links or share sensitive banking information such as OTPs, PINs and passwords. If a KYC update is genuinely required, customers should contact their bank or NBFC through its official website, mobile application or authorised customer-care channel.
The RBI has also highlighted the principle that an ‘Unknown Link’ represents an ‘Unknown Risk’. Such links can potentially expose users to malicious applications, credential theft and unauthorised access to sensitive banking information.
KYC Scams Can Give Fraudsters Access to Bank OTPs
Cyber criminals using KYC scams are increasingly adopting methods that go beyond simply collecting banking details. In some cases, victims are persuaded to download APK files that appear to be legitimate banking applications.
In a recent case, Noida Police busted an alleged cyber fraud call centre where suspects reportedly posed as bank representatives and contacted credit card users regarding KYC updates and reward points. According to the investigation, some victims were persuaded to download a malicious APK file.
The application allegedly had the capability to capture sensitive information entered by users and intercept OTPs sent to their mobile phones. Investigators alleged that stolen card details and OTPs were subsequently used to make purchases, including gold and silver coins.
Gurugram Man Allegedly Loses ₹1.28 Lakh
In another case, a Gurugram man was allegedly targeted by a caller who claimed that his KYC was incomplete. The caller reportedly posed as an Axis Bank official and sent the victim a link. After the victim interacted with the link, ₹1.28 lakh was allegedly withdrawn from his bank account.
Such incidents highlight the risks associated with responding to unsolicited KYC requests. Customers should not use links or phone numbers provided in suspicious messages, even when the sender claims to represent a bank or financial institution.
Instead, customers should independently visit their bank’s official website or mobile application, or contact its authorised customer-care service to verify whether a KYC update is actually required.
If a person becomes a victim of KYC-related financial fraud, the bank should be informed immediately so that the affected account or card can be secured. The incident should also be reported promptly through the appropriate cybercrime reporting channels.
Early reporting can improve the chances of tracing the transaction and preventing the defrauded funds from being transferred further.