What is Bank Phishing?
Phishing is when a scammer impersonates your bank — via email, SMS, or phone call — to trick you into giving up your account details, passwords, or OTPs. It is the most common form of banking fraud in India.
Key rule: Your bank will NEVER ask for your PIN, password, or full card number over phone, SMS, or email — ever.
Red Flags in SMS & Emails
- Urgent language: "Your account will be blocked in 24 hours!"
- Links that don't end in the bank's official domain (e.g., sbi.gov.in, hdfcbank.com)
- Requests to "verify your account" or "update KYC immediately"
- Generic greetings like "Dear Customer" instead of your name
- Spelling errors or odd formatting
How to Verify a Message is Real
- Never click links in SMS — go directly to your bank's website by typing the URL
- Check the sender ID — official bank SMS comes from alphanumeric IDs (e.g., HDFCBK), not 10-digit mobile numbers
- Call your bank's official helpline (printed on your card) to verify
- Log in through the official app or website, not through any link
If you receive a suspicious call: Hang up and call your bank directly using the number on their official website or the back of your card.
What to Do If You're Targeted
- Do NOT click any links or share any details
- Report the SMS/email to your bank's fraud helpline
- Forward suspicious SMS to 1909 (TRAI's spam reporting number)
- File a complaint at cybercrime.gov.in if you've already shared details