Stand Against Crime

Emerging Scams · India

The “KYC Update” Scam

“Your KYC has expired — account will be blocked in 2 hours.” It’s the most common banking scam in India right now. Here’s the one fact that defeats it, and what to do if you already clicked.

Updated Aug 2026 · 6 min read

KYC-Update Scam · India

SMS · “Your Bank”

“Your KYC has expired. Account blocked in 2 hrs — update: bit.ly/…”

Fake — banks never do this

The message lands with a countdown: your KYC has expired, and your account will be frozen in two hours unless you click the link and “update” it now. It feels official and urgent — so people click. That single tap starts a chain that can empty a bank account in minutes.

The “your KYC will expire” SMS is India’s most common banking scam of 2026, and it has evolved: today it doesn’t just want your password — it wants your whole phone.

The one fact that ends every KYC scam

No bank, wallet, or the RBI ever asks you to update KYC by clicking a link, installing an app, or over a call — and never asks for your OTP, PIN, or screen access.

Real KYC happens only inside your bank’s official app, at a branch, or via a video-KYC link from the bank’s verified website. Anything else is a scam.

How the scam works

1

The message

An SMS, WhatsApp, or email that looks like it's from your bank (or Paytm/PhonePe/Google Pay): “Your KYC has expired — your account will be blocked in 2 hours. Update now.” The countdown is deliberate; panic is the point.

2

The phishing link

The link opens a page that looks exactly like your bank's and asks for your login, card, or Aadhaar details. Everything you type goes straight to the scammer.

3

The “KYC officer” call

Minutes later, someone calls saying the update “didn't go through” and asks you to install a “verification app” — almost always a screen-sharing tool like AnyDesk or TeamViewer — and share the access code.

4

The drain

With your screen shared, they read the OTPs as they arrive, open your banking or UPI app, and transfer your money while you watch. Victims have lost lakhs within minutes.

The warning signs

  • Any message saying your KYC has “expired” and your account will be “blocked” in a few hours.
  • A link to “update KYC” — real KYC never happens through an SMS, WhatsApp, or email link.
  • A caller asking you to install AnyDesk, TeamViewer, QuickSupport, or any “verification/helper” app.
  • A request for your OTP, UPI PIN, card number, CVV, or password.
  • Pressure and urgency — “do it right now or lose access.”
Free tool · runs in your browser

Got a “KYC update” link? Check it first.

Paste the link into our checker before you tap it. It flags fake bank pages, lookalike domains, and hidden destinations — the exact tricks behind KYC phishing messages.

Open the link checker →

How to stay safe

  • Never click a KYC link in an SMS, WhatsApp, or email. Open your bank's official app or website directly, or visit a branch.
  • Never install a screen-sharing or remote app because a “bank” or “support” caller told you to.
  • Never share an OTP, PIN, CVV, or password — no bank or RBI process ever needs them.
  • If unsure, call the number printed on the back of your card — not the number that contacted you.

If you clicked or shared something

  1. If you installed a screen-sharing app, turn on airplane mode, uninstall the app, and disconnect from the internet.
  2. Freeze or block your account and cards immediately via your bank's app or 24×7 helpline.
  3. Change your net-banking and UPI passwords/PINs from a different, safe device.
  4. Report: call 1930 and file at cybercrime.gov.in, and write to your bank within 24 hours — prompt reporting can limit your liability under RBI rules.

Where to report — wherever you are

In India, freeze your account via your bank's app/helpline first, then call 1930 and file at cybercrime.gov.in — and write to your bank within 24 hours to protect your liability. Reporting fast gives the best chance of freezing the money before it’s gone. Then file with your national authority:

Anywhere else: contact your bank and local police right away, and search “report a scam” plus your country. For cross-border cases, econsumer.gov collects international complaints. Beware anyone who later offers to “recover” your money for an upfront fee — that is a second scam.

Frequently asked questions

Do banks ever ask you to update KYC by SMS, link, or call?

No — never. The RBI has stated repeatedly that KYC is done only inside your bank's app, at a branch, or via an official video-KYC link from the bank's verified website. Any link, app, or call asking you to “update KYC” is a scam.

A “KYC officer” asked me to install AnyDesk. Is that safe?

No. No genuine bank or KYC process ever asks you to install a screen-sharing app or share an access code. Doing so hands the scammer full view and control of your phone — including your OTPs and banking apps.

I clicked the link or shared an OTP — what now?

Act fast: freeze your account, change your passwords from another device, and report to 1930 and cybercrime.gov.in, and to your bank, within 24 hours. Prompt reporting can limit how much you're liable for.

How do I actually update my KYC if it's genuinely due?

Only through your bank's official app, net-banking, a branch visit, or a video-KYC link from the bank's verified website — never a link someone sent you or a number that called you.

Sources: Reserve Bank of India public awareness alerts on KYC-updation fraud; Indian Cyber Crime Coordination Centre (I4C); 2026 case reporting. General information only — verify against primary sources.

Warn someone — share this