Skip to Content
Join the Network with Us — Join Membership


RBI Says STOP Before You Update KYC: One Wrong Click Could Expose Your Bank Account

August 20, 2026

The Reserve Bank of India has issued a fresh warning about a familiar but still-effective scam: fraud carried out in the name of KYC updates. The central bank is urging customers to be wary of WhatsApp messages and phone calls threatening to block their bank accounts unless a KYC update is completed immediately, messages that are frequently designed to pressure people into clicking suspicious links, sharing sensitive banking details, or downloading malicious apps.

RBI's Rule: Stop, Think, Act

Rather than reacting to the panic these messages are designed to create, the RBI is urging people to follow a simple three-step approach.

Stop. Don't respond immediately to unexpected calls, SMS, or WhatsApp messages from unknown senders. If someone claiming to be a bank official asks you to update your KYC to avoid account blocking, verify the request independently before doing anything else.

Think. The RBI has been direct about this: banks and NBFCs do not send links asking customers to complete KYC updates. Any message pairing a link with a threat that your account will be blocked should be treated as an immediate red flag.

Act. Never click on a suspicious KYC link, and never share OTPs, PINs, or passwords, no matter how convincing the message sounds. If a KYC update is genuinely needed, go directly to your bank or NBFC's official website, mobile app, or verified customer-care channel instead.

The RBI summed up the underlying principle simply: an "Unknown Link" is an "Unknown Risk," one that can expose users to malicious apps, credential theft, and unauthorised access to their banking information.

How These Scams Actually Steal OTPs

KYC scams have evolved well beyond simply asking for banking details over a call. In some cases, victims are talked into downloading APK files disguised as legitimate banking apps.

In one recent case, Noida Police busted a fraudulent call centre where suspects posed as bank representatives, contacting credit card users about KYC updates and reward points. Investigators found that some victims were convinced to download a malicious APK, one capable of capturing information entered on the device and intercepting OTPs sent to the victim's phone. Police alleged the stolen card details and OTPs were then used to make purchases, including gold and silver coins.

A Gurugram Man's ₹1.28 Lakh Loss

In another case, a Gurugram resident was targeted by a caller claiming his KYC was incomplete. The caller reportedly posed as an Axis Bank official and sent a link; after the victim interacted with it, ₹1.28 lakh was allegedly withdrawn from his bank account.

Cases like these are a reminder of why unsolicited KYC requests deserve real skepticism. Customers should never use links or phone numbers provided directly in suspicious messages, even when the sender claims to represent a well-known bank, and should instead independently visit the official website or app, or contact verified customer care, to check whether a KYC update is actually needed.

What to Do If You've Already Been Targeted

If someone does fall victim to KYC-related fraud, the priority is speed: inform the bank immediately so the affected account or card can be secured, and report the incident promptly through the appropriate cybercrime reporting channels. Early reporting genuinely improves the odds of tracing the transaction and stopping defrauded funds before they're moved further along.

FAQs

Q1. What does RBI's "Stop, Think, Act" rule mean?

Stop means not reacting immediately to unexpected calls or messages; Think means recognising that banks don't send KYC-update links; Act means never clicking suspicious links or sharing OTPs, PINs, or passwords.

Q2. How can a fake KYC link actually steal OTPs?

In some cases, victims are persuaded to download malicious APK files disguised as banking apps, which can capture entered information and intercept OTPs sent to the phone.

Q3. How much did the Gurugram victim lose, and how?

₹1.28 lakh was allegedly withdrawn after he interacted with a link sent by a caller posing as an Axis Bank official over a fake KYC update.

Q4. What should you do if you're a victim of KYC fraud?

Inform your bank immediately to secure the account or card, and report the incident promptly through official cybercrime reporting channels to improve the chances of recovery.

in News
Share this post
Archive