SBI Warns Customers of YONO App Deactivation Scam
Key Takeaways A widespread social engineering campaign is targeting State Bank of India (SBI) customers. Scammers are sending fake messages via SMS, WhatsApp, and email, falsely claiming the YONO...
Key Takeaways
- A widespread social engineering campaign is targeting State Bank of India (SBI) customers.
- Scammers are sending fake messages via SMS, WhatsApp, and email, falsely claiming the YONO banking app will be deactivated unless Aadhaar details are updated.
- The attacks aim to trick users into downloading malicious APK files, which can grant attackers full control over devices, enabling theft of banking credentials, OTPs, and personal data.
- SBI and government agencies have issued urgent warnings, emphasizing that official updates are never distributed via unofficial links or APK files.
- Users are advised to only download the YONO app from official app stores and report any suspicious communications.
Millions of State Bank of India (SBI) customers are currently being targeted by a sophisticated social engineering scheme. Threat actors are circulating deceptive messages, falsely notifying users that their YONO banking application will be deactivated unless they promptly update their Aadhaar identification details.
Table Of Content
These fraudulent communications are being disseminated through various channels, including SMS, WhatsApp, and unsolicited emails. The tactics employed leverage a strong sense of urgency and fear to manipulate unsuspecting individuals into taking actions that compromise their security. For additional context, a fraud alert provides details.
The attackers’ objective is to coerce victims into clicking malicious links or downloading unauthorized Android Package Kit (APK) files. These APK files, once installed, can grant threat actors complete control over a user’s device, enabling them to illicitly harvest sensitive information such as banking credentials, one-time passwords (OTPs), and other personal data, often without the user’s knowledge. This method, while simple, proves highly effective, particularly against individuals unfamiliar with the secure distribution channels for official banking applications. Business Standard has also reported on this scam.
Security analysts at SBI swiftly identified and publicly flagged this campaign through an official fraud alert. They unequivocally stated that these messages are fraudulent and should be disregarded. According to a report shared with Cyber Security News (CSN), SBI emphasized that the bank never requests customers to update their Aadhaar details via APK files or unofficial links. This crucial alert reached nearly one million individuals within hours of its posting on the bank’s official social media platforms.
This campaign is indicative of a broader surge in mobile-based phishing attacks, commonly referred to as “smishing,” which have proliferated across India in recent years. Cybercriminals are increasingly employing sophisticated techniques to mimic legitimate banking communications, making it challenging for average users to distinguish between authentic alerts and fraudulent ones. The strategic use of Aadhaar as a lure is particularly potent, given that linking Aadhaar to bank accounts is a well-known regulatory requirement that many customers are still in the process of fulfilling.
India’s Press Information Bureau (PIB) fact-checking unit, PIB Fact Check, also intervened to formally debunk the claims circulating in these fake messages, classifying them as deliberate fraud attempts designed to steal personal and financial information.
Understanding the YONO App Deactivation Scam
The fraudulent message typically arrives as an SMS or WhatsApp text, employing language designed to appear official and convey a sense of urgency. It informs the recipient that their YONO app faces imminent blocking or deactivation unless they update their Aadhaar information within a short timeframe. The message then provides a link or directly attaches an APK file for the user to download and install.
Upon installation of the fake application, attackers gain the ability to intercept OTPs, monitor banking sessions, and remotely access the compromised device to illicitly transfer funds. These counterfeit applications are meticulously designed to visually replicate the legitimate YONO interface, rendering detection extremely difficult for an average user. This technique, known as a fake banking app overlay attack, represents a recognized and dangerous form of mobile malware delivery. Further details on this scam are available in a document outlining the Yono Self-Kyc Scam Alert.
What You Should Do
- Download from Official Sources Only: Always download the official YONO app exclusively from the Google Play Store or Apple App Store. Never install applications via links received through SMS, email, or WhatsApp, regardless of how convincing the message appears.
- Verify All Communications: Be skeptical of any message that demands immediate action or threatens account deactivation. SBI will never ask for sensitive details like Aadhaar, passwords, PINs, CVV numbers, or OTPs via unofficial channels.
- Delete and Report Suspicious Messages: Immediately delete and ignore any suspicious messages. Do not click on any links or download any attachments.
- Report Phishing Attempts: Report any phishing attempts directly to SBI at [email protected].
- Report Cybercrime: For financial cybercrime, utilize the National Cyber Crime Reporting Portal at www.cybercrime.gov.in or call the national helpline at 1930.
- Monitor Account Activity: Regularly check your banking statements and transaction history for any unauthorized activity.
- If Compromised: If you suspect your device has been compromised, perform a full antivirus scan and immediately change all your banking and other important account passwords from a separate, trusted device.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.