A message or caller claims that your bank account, wallet, FASTag, PAN or SIM will be blocked unless KYC is updated immediately. A link, APK file or phone number is supplied.
Why it is dangerous
The link may open a fake login page. An APK file can install a malicious Android application that reads messages, steals credentials, captures the screen or enables remote control.
Warning signs
- Threats of immediate account suspension or loss of service.
- An APK file received through WhatsApp, SMS or email.
- A shortened, misspelled or unfamiliar website address.
- Requests for password, PIN, CVV, OTP or remote screen access.
Update KYC safely
Open the bank or service provider’s official app yourself, type its official website address, call the number printed on your card or statement, or visit the branch. Do not use a link or number supplied in an urgent message.
If you installed a suspicious app, disconnect the phone from the internet, contact your bank from another trusted device, change important passwords and seek qualified help before using the phone for payments again.
If money or account access is already lost
- Call your bank or payment provider immediately and ask them to block the transaction or account.
- Call the national cyber-fraud helpline 1930 as quickly as possible.
- File a report at cybercrime.gov.in.
- Preserve screenshots, phone numbers, UPI IDs, transaction references, emails and chat history.
Official reference
See the Reserve Bank of India’s 2026 KYC fraud-awareness material.