How to Stay Safe from “Mobile Number Change” Banking Fraud: An SBI-Style Caution Guide
What Is the “Mobile Number Change” Fraud?
In this scam, criminals attempt to switch the mobile number linked to your bank account with their own. Once they succeed, they can intercept alerts, OTPs and reset credentials to carry out unauthorised transactions. The most common method is social engineering — they create urgency by implying account blockage, pending PPO/KYC, or pension delays and then coax you into clicking a link or sharing sensitive data.
- Calls or SMS that threaten account blockage or delayed pension unless you act immediately.
- Links urging instant PPO/KYC verification or “faster processing”.
- Requests for OTP, ATM PIN, passwords, or screenshots of messages.
- Unknown WhatsApp numbers posing as bank staff or convincing callers who ask for codes.
- Shortened or misspelled URLs and unfamiliar domains.
How the Trap Is Set
Fraudsters typically call or send an SMS that sounds legitimate—mentioning PPO, pension, or KYC. They create urgency and provide a link or request an OTP to “verify.” If you comply, they use those details to change your registered number and take control of alerts and transactions. Sometimes they push a malicious app or remote-access tool to the victim’s phone.
The Golden Rule: Banks Never Ask for Sensitive Data
A genuine bank will never ask you for your OTP, ATM PIN, internet banking password, CVV, or full card number on a call, SMS, email or WhatsApp. They will not force you to click unverified links or install third-party apps for verification. Treat any such request as fraudulent.
- Install/update banking apps only from Google Play Store or Apple App Store.
- Type your bank’s web address manually; avoid links received by SMS/WhatsApp/email.
- Read SMS/email alerts carefully — treat unexpected messages with suspicion.
- Contact your branch or official customer care number (from passbook/app), not numbers provided in suspicious messages.
- Save the national cybercrime helpline 1930 on your phone.
- Never share OTPs, ATM PINs, passwords, CVV or card details — even if requested by someone claiming to be the bank.
- Never click suspicious links or install unknown apps for “verification”.
- Never grant remote access to your phone/computer to strangers.
- Never ignore unusual login or transaction alerts — investigate immediately.
A Realistic Scenario — and the Right Response
Example: you get an SMS saying “Your PPO verification is pending. Click to confirm or your pension may be delayed.” A caller then offers “faster processing” and reads an OTP. Correct response: hang up, delete the message, and call the bank using the number from your passbook or official app. If you clicked or shared anything, block cards via the app, change passwords, and report to the cybercrime helpline.
Practical Safety Habits
- Use strong, unique passwords for banking and email; enable multi-factor authentication.
- Keep your phone number private where possible to reduce phishing risk.
- Lock your SIM with a PIN and notify your telecom provider immediately if the device is lost.
- Check alerts daily and act fast on unfamiliar activity.
- Educate family members, especially seniors, about OTP and link-based scams.
- National Cybercrime Helpline: 1930
- Your bank’s official customer care numbers (from passbook/app)
- Nearest branch contact details
What to Do If You Suspect a Compromise
- Freeze quickly: Block your card and disable online banking via the official app if available.
- Change credentials: Update internet banking and email passwords; review connected devices.
- Alert your branch: Inform them of the attempted mobile number change and ask for an account note.
- Report the crime: Call 1930 and document date/time, numbers, and messages.
- Monitor statements: Check recent transactions and raise disputes for unfamiliar activity.
Myth: If the caller knows my account details, they must be genuine.
Fact: Details can be scraped or leaked. Always verify via the official app or branch — never by returning a stranger’s call.
Myth: Clicking a link is harmless if I don’t fill anything.
Fact: Malicious links can trigger downloads or harvest data silently. Avoid them completely.
Share & Safeguard
Share this guidance with family groups and housing societies. Encourage everyone to save 1930 and their bank’s verified numbers. A minute of caution can prevent lengthy damage control later. Treat your registered mobile number like a key — keep it secure and private.
- Save 1930 and your bank’s official customer care numbers.
- Enable app lock and SIM PIN on your phone.
- Update your banking app from the official store.
- Turn on SMS/email alerts and review them daily.
- Educate at least one family member about OTP/link scams today.