Legal information notice: this article provides general information and isn't a substitute for advice from a qualified lawyer.
“Your Paytm KYC will expire in 24 hours — update now or your wallet and payments will be blocked.” A message like this creates instant panic, and that panic is the entire point. The Paytm KYC update scam relies on urgency to get you to hand over sensitive details or install an app that hands over control of your account. Here’s exactly how it works and what to do if you’ve responded to one.
Paytm never asks for your UPI PIN, OTP, or full card details through a link, message, or unsolicited call to “complete” a KYC update. Genuine KYC updates happen within the official app or through RBI-mandated processes at your bank, not through urgent third-party links.
Delete the message and avoid clicking any embedded link, calling any number in it, or replying.
Open Paytm directly (not through the message’s link) and check your KYC status in the app’s own settings — this tells you the real situation, independent of the message.
Use the “24×7 Help” section within the app to report the fraud attempt, specifically selecting the phishing or fraud category.
If you entered details that led to an unauthorized transaction, call India’s cyber fraud helpline immediately to request an urgent freeze.
If money was lost or sensitive details were shared, file on cybercrime.gov.in under “Report Financial Fraud” for a trackable record.
KYC scams work especially well because KYC deadlines are, in fact, a real and periodic requirement under RBI rules — so the message doesn’t sound implausible on its own. The giveaway is always in the mechanism: a genuine KYC update never needs your UPI PIN, your full card number and CVV, or a screen-sharing app. It’s handled through document upload or verification within the official app itself, or occasionally in person at an authorized point, never through a link texted to you claiming urgency.
If you’re ever unsure whether your KYC genuinely needs attention, the safest path is to open the Paytm app directly and check, rather than trusting any link, however official it looks.
If you’ve already shared details or lost money, here’s where to take it next:
| Channel | Role |
|---|---|
| Paytm's In-App Support | Reports the phishing attempt and can flag the fraudulent link or number |
| 1930 Helpline | Requests an urgent freeze if money was actually lost |
| Your Bank | Where liability determination and refund decisions happen, if a transaction occurred |
No — reporting within Paytm, calling 1930, and filing on cybercrime.gov.in are all completely free.
Yes, for reporting and the initial recovery attempt if money was lost. A lawyer becomes relevant mainly for large losses or if your bank denies liability protection despite prompt reporting.
Need professional legal help with this?
Find a Lawyer on VidyodayIf the scam involved a fake screen-sharing “verification” leading to an actual payment, that mechanism is the same one covered in our guide on the UPI collect request scam. For the general Paytm, Google Pay, and PhonePe fraud reporting process beyond KYC scams specifically, see our guide on reporting fraud on these apps.
Yes — periodic KYC verification is a genuine RBI-mandated requirement for wallets and payment accounts. The scam exploits this real requirement, but the verification mechanism used by scammers is always fake.
Open the official Paytm app directly (not through any link) and check the KYC or profile section — this shows your actual, current status.
Contact your bank immediately to block the card and monitor for unauthorized transactions, then report the phishing attempt via cybercrime.gov.in.
Be cautious — verify independently through the official app or Paytm’s verified support channels before allowing any in-person “verification,” and never share your PIN or OTP with anyone in person either.
No — ignoring a fake message has no effect on your actual account. Only your real KYC status, checked within the official app, determines your account’s standing.
It depends on the circumstances and how quickly you reported — RBI’s liability rules are designed to evaluate exactly this kind of case, so report immediately.
The same pretext is used against Google Pay, PhonePe, and directly against bank account holders too, just with the platform name swapped — the underlying mechanics are identical.
Uninstall it immediately, then change your UPI PIN, net banking password, and any other credentials that may have been visible during the session.
This article is for general information only and does not constitute legal advice. App features and fraud patterns can change — consult a cyber lawyer for guidance specific to your case.