What is Bank Phishing?

Phishing is when a scammer impersonates your bank — via email, SMS, or phone call — to trick you into giving up your account details, passwords, or OTPs. It is the most common form of banking fraud in India.

Key rule: Your bank will NEVER ask for your PIN, password, or full card number over phone, SMS, or email — ever.

Red Flags in SMS & Emails

  • Urgent language: "Your account will be blocked in 24 hours!"
  • Links that don't end in the bank's official domain (e.g., sbi.gov.in, hdfcbank.com)
  • Requests to "verify your account" or "update KYC immediately"
  • Generic greetings like "Dear Customer" instead of your name
  • Spelling errors or odd formatting

How to Verify a Message is Real

  • Never click links in SMS — go directly to your bank's website by typing the URL
  • Check the sender ID — official bank SMS comes from alphanumeric IDs (e.g., HDFCBK), not 10-digit mobile numbers
  • Call your bank's official helpline (printed on your card) to verify
  • Log in through the official app or website, not through any link
If you receive a suspicious call: Hang up and call your bank directly using the number on their official website or the back of your card.

What to Do If You're Targeted

  • Do NOT click any links or share any details
  • Report the SMS/email to your bank's fraud helpline
  • Forward suspicious SMS to 1909 (TRAI's spam reporting number)
  • File a complaint at cybercrime.gov.in if you've already shared details