The one-time password (OTP) is the last lock on your money. Almost every large online fraud in India comes down to one thing: the victim was tricked into revealing an OTP or approving a request. Here’s how it happens and how to shut it down.
How OTP fraud works
- Fake urgency: "Your KYC/electricity/account will be blocked in 2 hours." Panic makes people act without thinking.
- Impersonation: the caller claims to be from your bank, a wallet, or a delivery company.
- The ask: they push you to "verify" by reading an OTP, or to tap "approve" on a payment request.
- Remote apps: some convince victims to install screen-sharing apps so they can watch the OTP directly.
The golden rules
- No genuine bank or company will EVER ask for your OTP, PIN or CVV. Anyone who does is a scammer.
- Receiving money never needs a PIN. If an app asks for your UPI PIN to "receive" a payment, stop.
- Read the SMS: an OTP message usually says what it authorises. If it says "to pay ₹X", you are sending money, not receiving it.
- Never install remote-access apps because a caller told you to.
FAQ
Can someone steal money with just my OTP?
Often yes — combined with your card or UPI details, an OTP can authorise a payment. That’s why sharing it is so dangerous.
My bank is calling to verify an OTP. Is it safe?
No. Banks never ask you to share OTPs. Hang up and call the number on the back of your card.
I already shared an OTP. What now?
Call 1930 and your bank immediately, block the account/card, and file at cybercrime.gov.in.

