What this category covers
Bank-impersonation fraud remains the single most damaging category of telephone scam in India, the UK, the US and the Gulf. Reserve Bank of India quarterly disclosures show that the average successful banking-impersonation scam in India now costs the victim more than ₹1.6 lakh — typically because the fraudster gets full account access through a combination of OTPs and remote-access app installs, then drains both the savings account and any pre-approved overdraft or credit limit.
Banks across the world repeat the same rule because it is the only one that matters: a bank will never ask you for your OTP, CVV, internet-banking password, UPI PIN or to install an app on a call. Any caller who breaks this rule is a fraudster, regardless of how convincing their accent, hold music, or knowledge of your last four digits sounds.
Red flags
- “Your debit card is blocked. We need to verify your details to reactivate it.”
- “Your reward points expire in two hours. Press 1 to redeem.”
- “Your KYC is incomplete. Your account will be frozen by 5 PM today.”
- “We see a suspicious transaction. Read the OTP we just sent you to cancel it.”
- “For faster verification, please install QuickSupport / AnyDesk / RustDesk on your phone.”
What to do
- Hang up the moment any of the above phrases appear. Do not engage, do not ask follow-up questions — fraudsters are trained to overcome objections.
- Dial your bank back on the number printed on the back of your physical debit card, never on a number the caller offered.
- If you have already shared an OTP or installed an app, switch off mobile data and Wi-Fi, call the bank from another phone, freeze your debit card and UPI through the bank app or IVR.
- Call 1930 within the first hour and file a complaint at cybercrime.gov.in — fund recovery is realistic only if you report fast.
Real-world examples
Credit-card reward-points expiry
Caller from “HDFC rewards desk” says you have 14,500 unredeemed points that expire today. They send a link to redeem, which is a fake bank login page that captures your net-banking credentials and OTP.
Locker rent KYC update
Caller from your branch claims your safe-deposit locker rent KYC has expired and walks you through installing AnyDesk ‘to update from the bank’s side’, then watches as you log in to net banking and silently captures your OTPs.
Official helplines & portals
- Bank fraud helpline: Printed on the back of every debit and credit card. Save it under your bank’s name in your phone.
- 1930 Cyber Helpline: Call within the golden hour for the best chance of freezing the receiving account.
- RBI Sachet portal: https://sachet.rbi.org.in for systemic banking-impersonation reporting.
Frequently asked questions
The caller knew my full name, my last four digits and my branch. How?
Bank-data leaks from third-party recovery agents, courier KYC envelopes and breached e-commerce sites are widely sold on Telegram. Knowing your details does not validate the caller — only the bank’s outbound IVR + your dialing-back-on-the-card-number does.
If a fraudster has my CVV but not the OTP, can they spend?
Yes, on international merchants that do not enforce 3-D Secure / OTP. Block the card the moment a fraudster has the CVV, regardless of whether the OTP was shared.
Related help & guides
See our guides on reporting a fraud number, spotting bank-call scams, the 1930 cybercrime helpline and DND registration. Browse all categories or read the latest scam analysis on our blog.