Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
OpenAI Expands GPT-3.5 Access With Unlimited Chats for All Users
August 7, 2026
SilverFox Hijacks Drivers to Disable Security Tools
August 7, 2026
Critical Rockwell Automation Flaw Exposes Water Systems to Cyberattacks
August 6, 2026
Home/Threats/SBI Warns Customers of YONO App Deactivation Scam
Threats

SBI Warns Customers of YONO App Deactivation Scam

Key Takeaways A widespread social engineering campaign is targeting State Bank of India (SBI) customers. Scammers are sending fake messages via SMS, WhatsApp, and email, falsely claiming the YONO...

Jennifer sherman
Jennifer sherman
May 28, 2026 4 Min Read
70 0

Key Takeaways

  • A widespread social engineering campaign is targeting State Bank of India (SBI) customers.
  • Scammers are sending fake messages via SMS, WhatsApp, and email, falsely claiming the YONO banking app will be deactivated unless Aadhaar details are updated.
  • The attacks aim to trick users into downloading malicious APK files, which can grant attackers full control over devices, enabling theft of banking credentials, OTPs, and personal data.
  • SBI and government agencies have issued urgent warnings, emphasizing that official updates are never distributed via unofficial links or APK files.
  • Users are advised to only download the YONO app from official app stores and report any suspicious communications.

Millions of State Bank of India (SBI) customers are currently being targeted by a sophisticated social engineering scheme. Threat actors are circulating deceptive messages, falsely notifying users that their YONO banking application will be deactivated unless they promptly update their Aadhaar identification details.

Table Of Content

  • Key Takeaways
  • Understanding the YONO App Deactivation Scam
  • What You Should Do

These fraudulent communications are being disseminated through various channels, including SMS, WhatsApp, and unsolicited emails. The tactics employed leverage a strong sense of urgency and fear to manipulate unsuspecting individuals into taking actions that compromise their security. For additional context, a fraud alert provides details.

The attackers’ objective is to coerce victims into clicking malicious links or downloading unauthorized Android Package Kit (APK) files. These APK files, once installed, can grant threat actors complete control over a user’s device, enabling them to illicitly harvest sensitive information such as banking credentials, one-time passwords (OTPs), and other personal data, often without the user’s knowledge. This method, while simple, proves highly effective, particularly against individuals unfamiliar with the secure distribution channels for official banking applications. Business Standard has also reported on this scam.

Security analysts at SBI swiftly identified and publicly flagged this campaign through an official fraud alert. They unequivocally stated that these messages are fraudulent and should be disregarded. According to a report shared with Cyber Security News (CSN), SBI emphasized that the bank never requests customers to update their Aadhaar details via APK files or unofficial links. This crucial alert reached nearly one million individuals within hours of its posting on the bank’s official social media platforms.

This campaign is indicative of a broader surge in mobile-based phishing attacks, commonly referred to as “smishing,” which have proliferated across India in recent years. Cybercriminals are increasingly employing sophisticated techniques to mimic legitimate banking communications, making it challenging for average users to distinguish between authentic alerts and fraudulent ones. The strategic use of Aadhaar as a lure is particularly potent, given that linking Aadhaar to bank accounts is a well-known regulatory requirement that many customers are still in the process of fulfilling.

India’s Press Information Bureau (PIB) fact-checking unit, PIB Fact Check, also intervened to formally debunk the claims circulating in these fake messages, classifying them as deliberate fraud attempts designed to steal personal and financial information.

Understanding the YONO App Deactivation Scam

The fraudulent message typically arrives as an SMS or WhatsApp text, employing language designed to appear official and convey a sense of urgency. It informs the recipient that their YONO app faces imminent blocking or deactivation unless they update their Aadhaar information within a short timeframe. The message then provides a link or directly attaches an APK file for the user to download and install.

Upon installation of the fake application, attackers gain the ability to intercept OTPs, monitor banking sessions, and remotely access the compromised device to illicitly transfer funds. These counterfeit applications are meticulously designed to visually replicate the legitimate YONO interface, rendering detection extremely difficult for an average user. This technique, known as a fake banking app overlay attack, represents a recognized and dangerous form of mobile malware delivery. Further details on this scam are available in a document outlining the Yono Self-Kyc Scam Alert.

What You Should Do

  • Download from Official Sources Only: Always download the official YONO app exclusively from the Google Play Store or Apple App Store. Never install applications via links received through SMS, email, or WhatsApp, regardless of how convincing the message appears.
  • Verify All Communications: Be skeptical of any message that demands immediate action or threatens account deactivation. SBI will never ask for sensitive details like Aadhaar, passwords, PINs, CVV numbers, or OTPs via unofficial channels.
  • Delete and Report Suspicious Messages: Immediately delete and ignore any suspicious messages. Do not click on any links or download any attachments.
  • Report Phishing Attempts: Report any phishing attempts directly to SBI at [email protected].
  • Report Cybercrime: For financial cybercrime, utilize the National Cyber Crime Reporting Portal at www.cybercrime.gov.in or call the national helpline at 1930.
  • Monitor Account Activity: Regularly check your banking statements and transaction history for any unauthorized activity.
  • If Compromised: If you suspect your device has been compromised, perform a full antivirus scan and immediately change all your banking and other important account passwords from a separate, trusted device.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarephishingSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Critical FortiClientEMS CVE-2023-48788 exploited to deploy EKZ malware

Next Post

Silent Ransom Group Targets Law Firms via IT Support Impersonation

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Best Intrusion Detection & Prevention (IDS/IPS) Tools for 2026
August 6, 2026
Critical WSUS Vulnerability Lets Attackers Compromise Enterprise Endpoints
August 6, 2026
Critical Paperclip Flaws Let Attackers Gain Admin Access
August 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us