KYCKART
KYCKART Guide · August 2026Guide

KYC-Update SMS Scams: Why Smishing Attacks Surged 146% in Indian Banking

SMS-based “KYC update” scams surged 146% in Indian banking, per BioCatch’s 2026 fraud-trends report. How the scam actually works, the warning signs that separate a real bank message from a fake, and what it means for banks and NBFCs trying to stop it at the source.

calendar_monthAugust 2026
schedule12 min read
library_books16 Cited Sources
personBhanujeet Choudhary, Head of Compliance

Smishing is phishing delivered by text message instead of email: a fake link, a spoofed helpline number, or a direct request for an OTP, card detail, or UPI credential, sent as an SMS. SMS-based scams targeting Indian banking customers rose 146% comparing H2 2025-H1 2026 against the same period a year earlier, according to BioCatch, a fraud-detection and behavioral-biometrics vendor, in a report titled “2026 Digital Banking Fraud Trends in India,” published 22 July 2026 in Mumbai. One version of this scam impersonates a bank’s own KYC-update process, the fraud pattern the Reserve Bank of India (RBI) issued a public warning about in Press Release 2023-2024/1794 on 2 February 2024.

SMS-based scams in Indian banking rose 146% comparing H2 2025-H1 2026 against the same period a year earlier, per BioCatch’s July 2026 fraud-trends report.

This piece is a dedicated look at that one scam type. KYCKART’s bank fraud overview covers the wider landscape of fraud typologies hitting Indian banks. Here, the focus is narrower and deeper: how the KYC-update SMS scam actually works, how to tell a fake from a real bank message, and what it means institutionally for banks and NBFCs trying to stop it at the source.

01

The Scale of India's Smishing Surge

The same BioCatch report found the shift toward mobile-based fraud is broader than just SMS. Overall mobile fraud sessions rose 67% in that period, with an 86% increase on iOS devices and a 35% increase on Android devices, while web-browser-based fraud sessions declined 10%, a pattern also reported by the420.in. The report also found the total value of attempted fraud payments rose 35%, risky payment sessions doubled, median fraud-session length fell 32%, average call length (the voice-based social-engineering component) fell 31%, and the median transfer value per fraud session rose roughly 1.7x. Fraud attempts became fewer in number, but faster and higher-value per attempt.

BioCatch’s Director of Global Fraud Intelligence, Tom Peacock, said: “SMS scams are particularly effective because they exploit trusted communication channels, making fraudulent messages appear legitimate and prompting customers to act before they stop to question what they’re seeing.”

Separately, India’s overall cybercrime-incident volume also rose sharply in this broad period: total incidents registered on the National Cyber Crime Reporting Portal reached roughly 22.68 lakh (2,268,346) in 2024, a 42.08% increase over 2023. This figure covers cybercrime generally, not banking-specific smishing, and is drawn from secondary reporting that cites the National Cyber Crime Reporting Portal’s own data rather than a single primary source.

02

How the KYC-Update Smishing Scam Actually Works

RBI’s 2 February 2024 press releasedescribes the general pattern: an unsolicited phone call, SMS, or email manipulates the customer into revealing personal, account, or login details, or into installing an unauthorised app via a link, using false urgency and threats that the account will be frozen, blocked, or closed if the customer doesn’t act immediately. In practice, that plays out in two variants.

The link-based variantsends an SMS claiming the customer’s KYC has expired or is about to expire, with a link to “re-verify” or “update” details. Clicking the link leads to a fake page designed to harvest login credentials or OTPs.

The call-based variant goes further. Per one cybersecurity-advisory source, Cyber Secure India, a fraudster follows up by phone, posing as a bank representative or “KYC officer,” and talks the customer into installing a remote-access app, commonly AnyDesk or TeamViewer, to “resolve” the supposed KYC issue. Once the app is installed and permissions are granted, the fraudster can see the victim’s screen, capture credentials and OTPs, and initiate transactions directly from the victim’s own device. RBI has separately warned banks that fraudsters were using AnyDesk this way to drain customer accounts, per one source, CIO.inc; that report doesn’t name the advisory’s date or reference number, so this point is treated as a general, lower-confidence supporting detail rather than a precise regulatory citation.

Both variants rely on the same three levers RBI’s press release names: urgency, an unverified contact channel, and a threat of account disruption.

03

Warning Signs: Real Bank Message vs. Fake

RBI’s guidance recommends that anyone receiving a KYC-update request contact their bank or financial institution directly, using a phone number sourced only from the institution’s official website, not the number or link in the message itself, and never share login credentials, card details, PINs, passwords, or OTPs, and never click a suspicious or unverified link.

Two consumer-safety sources add detail worth flagging, with appropriate caution since each is a single source rather than independently corroborated. Billcut states that legitimate Indian banks never send clickable KYC links via SMS, directing customers instead to the official app or a branch visit, without a hard countdown deadline. RBI’s own language doesn’t go this far. It cautions against clicking suspicious links and recommends independent verification, but doesn’t itself state that banks categorically never use any link in a genuine SMS. ScanTotal describes typical fraudulent wording, including same-day deactivation threats and 24-hour re-verification deadlines, and notes such messages typically arrive from a plain 10-digit mobile number rather than a registered sender header; that specific detail about 10-digit numbers is sourced only to ScanTotal.

The one warning sign that is independently verifiable, not just consumer-blog reporting, is the sender ID format itself. A properly registered SMS header run through India’s telecom Distributed Ledger Technology (DLT) platform takes a fixed structure: two operator/circle-identifying characters, a hyphen, and a six-character alphanumeric code identifying the registered sender (for example, a format like “AM-HDFCBK”). That structure is different from an unregistered plain 10-digit mobile number. Since 6 May 2025, TRAI has also required every registered header to carry a category suffix: -P for promotional, -S for service, -T for transactional, -G for government, visible before the message content is even opened. TRAI’s own notification number for these header-format and header-suffix rules doesn’t appear in the secondary sources that document them here or elsewhere in this piece (Message Central, SMS Alert’s knowledge base, SS Rana & Co.); each documents the requirements by title and effective date rather than a specific regulation number.

SignalGenuine Bank KYC CommunicationFraudulent KYC-Update SMS
Sender formatRegistered alphanumeric header (e.g. AM-HDFCBK) with a category suffix, per the sourcing note aboveOften a plain 10-digit mobile number, per one consumer-safety source
Verification methodRBI advises contacting the bank using a number from its official website, not the message itselfDirects the customer to click an embedded link or call a number given in the message
Deadline languageNo hard countdown deadline, per one consumer-safety sourceSame-day deactivation or 24-hour re-verification threats
Requested actionDirects to the official app or a branch visit, per one consumer-safety sourceAsks for OTP/credentials via link, or a follow-up call requesting a remote-access app install
04

Consumer Protection: Who's Targeted and Where to Report

Any bank customer receiving an SMS is a potential target: RBI’s advisory is addressed to the general public rather than a specific demographic. If a customer clicks a suspicious link, enters credentials, or installs a remote-access app in response to one of these messages, RBI’s press release directs them to file a complaint on the National Cyber Crime Reporting Portal (cybercrime.gov.in) or call the national cybercrime helpline, 1930, immediately.

There’s a second reporting channel worth knowing about, aimed specifically at the suspicious message itself rather than a completed fraud. India’s Department of Telecommunications runs a citizen-facing portal, Sanchar Saathi, which includes a facility called Chakshu for reporting suspected fraudulent calls, SMS, or WhatsApp messages, with “KYC update” explicitly listed as one of its reportable fraud categories, alongside impersonation of government agencies or customer service, and fake lottery, loan, or job offers. Per a government statement on the facility, citizens have filed roughly 7.7 lakh suspected-fraud-communication reports since Chakshu’s launch, including over 5.19 lakh in 2025 alone, with KYC- and payment-related fraud among the largest categories reported; based on these reports, DoT has disconnected 39.43 lakh mobile connections, blacklisted 2.27 lakh handsets, and blocked 1.31 lakh SMS templates. These figures rely on The Tribune’s reporting of that statement rather than a direct read of the Sanchar Saathi portal itself.

These reporting channels do produce measurable outcomes at scale. Per a written reply in the Rajya Sabha by the Minister of State for Home Affairs, Bandi Sanjay Kumar, reported February 2026, India’s Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS), accessible via 1930 and cybercrime.gov.in, saved more than ₹8,189 crore across over 23.61 lakh complaints between 2021 and 2025. The same reply states that as of 31 December 2025, more than 12.21 lakh SIM cards and 3.03 lakh IMEIs had been blockedas part of the government’s cyber-fraud response.

The KYC-update lure specifically impersonates a legitimate, recurring bank process, periodic re-KYC. Customers who understand what a genuine re-KYC request actually requires are better positioned to spot a fake one; see KYCKART’s KYC/AML glossary for that entry.

05

What This Means for Banks, NBFCs, and Compliance Teams

The consumer-facing warning signs above only work if genuine bank communication is itself distinguishable from a fake. That is why the institutional side of this problem is a telecom and messaging-infrastructure question as much as a customer-awareness one.

Under TRAI’s DLT framework, any business sending bulk commercial or transactional SMS, including OTPs, must register as a “Principal Entity” (submitting KYC documents such as PAN, GSTIN, or CIN) and register its SMS sender IDs (“Headers”) on the DLT platform. Non-compliant senders, those bypassing header or template registration, risk disconnection of all their telecom resources for up to two years. As with the header-format and header-suffix rules noted earlier, TRAI’s own notification number for this DLT registration and Principal Entity requirement doesn’t appear in the secondary sources cited here (Message Central, SMS Alert’s knowledge base, SS Rana & Co.); each documents the requirements by title and effective date rather than a specific regulation number, unlike the RBI circulars cited below.

RBI has gone further for its own regulated entities. Circular RBI/2024-25/105, dated 17 January 2025, “Prevention of Financial Frauds Perpetrated Using Voice Calls and SMS, Regulatory Prescriptions and Institutional Safeguards,” applies to banks, NBFCs, Housing Finance Companies, Payment Aggregators, and Credit Information Companies. It directs regulated entities to use the “1600xx” telecom numbering series for transactional or service voice calls, reserving “140xx” only for promotional calls; to register SMS headers and message templates via the DLT platform; and to include only whitelisted URLs, APKs, OTT links, or callback numbers in customer-facing SMS, without URL-shortening services that obscure the sender’s identity. The same circular requires regulated entities to clean customer contact databases against DoT’s Mobile Number Revocation List and publish verified customer-care numbers on Sanchar Saathi. Full compliance was required by 31 March 2025.

Separately, RBI’s revised Master Directions on Fraud Risk Management, issued 15 July 2024 for banks and All India Financial Institutions (circular DOS.CO.FMG.SEC.No.5/23.04.001/2024-25) and for NBFCs and HFCs (circular RBI/DOS/2024-25/120, DOS.CO.FMG.SEC.No.7/23.04.001/2024-25), require regulated entities to maintain a board-level oversight committee for fraud monitoring, an Early Warning Signals (EWS) framework with real-time transaction monitoring, and dedicated Data Analytics and Market Intelligence Units. This is the institutional infrastructure a real-time anomaly following a smishing-linked login (a new device, an unusual location, a rapid high-value transfer shortly after a customer-service-style call) would feed into as a fraud-detection signal. No source states that “smishing-linked activity” is itself a named category within the EWS framework; that connection describes how the general infrastructure could apply, not an established regulatory category.

Read together, the sender-ID infrastructure (DLT registration, the 1600xx/140xx numbering split, whitelisted URLs) and the Fraud Risk Management Master Directions’ EWS requirement point to two separate control layers. The DLT and numbering rules work at the prevention stage: a genuine registered header has a fixed, checkable format that a plain 10-digit number can’t replicate, which makes a convincing spoofed sender identity structurally harder to produce in the first place. The EWS and transaction-monitoring requirement works at the detection stage. Even though no source names “smishing-linked activity” as a specific EWS category, that general monitoring infrastructure is what would need to flag the behavioral aftermath of a successful smishing attack, such as an unusual device, location, or transfer pattern following contact that looked like customer service, if it is going to catch it at all. A bank that invests only in the prevention layer stays exposed to the call-based, remote-access-app variant, since that path runs on a phone call and a customer being talked into installing software, and never touches a spoofed SMS header at all. The practical implication for compliance and fraud teams is to check coverage against both layers independently when evaluating smishing defenses, since header and DLT compliance alone doesn’t address the call-based path.

verified

How KYCKART Helps

KYCKART’s fraud intelligence platform flags the behavioral anomalies a successful smishing attack leaves behind, an unfamiliar device, location, or transfer pattern, so the detection layer still catches what a spoofed sender header alone can’t stop.

Frequently Asked Questions

person

Bhanujeet Choudhary

Head of Compliance, KYCKART

Published August 27, 2026

Disclaimer: This piece summarizes publicly available regulatory guidance (RBI, TRAI/DLT documentation, Government of India statements) and third-party reporting for informational purposes. It is not legal or compliance advice. Institutions should confirm current regulatory requirements directly with the relevant regulator, and individuals should verify any KYC-related communication directly with their bank before acting on it.

KYCKART Intelligence

Catch What a Spoofed Header Can’t Stop

KYCKART’s fraud intelligence platform spots the behavioral aftermath of a smishing attack, not just the message itself, so the call-based, remote-access-app variant doesn’t slip through.

Explore Fraud Intelligencearrow_forward