Common Scam Call Scripts in India — and the Personal Data Behind Each One
TL;DR: India's most common phone scams follow recognizable scripts — and each one relies on a specific type of personal data to sound convincing. Knowing the pattern, and what feeds it, makes them easier to spot before they work.
Scam calls in India aren't random — they cluster into a handful of recurring formats, each refined over time because it works often enough to keep being used. Here's a breakdown of the most common ones, and specifically what personal data makes each one convincing.
The "digital arrest" scam
A caller claims to be from police, customs, or a central investigating agency, alleging you're implicated in a serious crime (often parcel-related or financial), and pressures you to stay on a video call — sometimes for hours — while transferring money to "clear" your name. This scam relies less on specific personal data upfront and more on psychological pressure and impersonation of authority, though scammers often open with a real detail (your name, sometimes your city) obtained cheaply from a leaked database to establish initial credibility before the pressure tactics begin.
The fake KYC update scam
A call or SMS claims your bank account, UPI, or SIM will be blocked unless you "update your KYC" immediately, often directing you to click a link or share an OTP. This one relies specifically on knowing which bank or service you actually use — information that often comes from a breach at that exact service, or from a data broker listing that includes your financial app usage patterns, making the impersonation far more targeted than a random guess.
The courier / customs scam
A call claims a parcel addressed to you is stuck in customs, contains illegal items, or requires a fee to release — often escalating into the digital arrest format described above. This depends on your phone number being flagged as active and reachable, and sometimes on genuine order history data (from a breached e-commerce or delivery account) to reference a plausible recent purchase.
The fake bank fraud alert
A caller claims suspicious activity was detected on your account and asks you to "verify" by sharing an OTP or card details to "secure" it — inverting the actual purpose of an OTP to extract it instead. This relies on knowing which bank you use, sometimes down to partial account or card details obtained from a prior breach, which makes the caller sound like they already have some legitimate access rather than being a cold, generic attempt.
The lottery / prize scam
A message or call claims you've won a prize, lottery, or cashback reward, requiring an upfront "processing fee" or your bank details to release it. This one relies on very little personal data — often just a phone number pulled from a bulk broker list — which is part of why it's usually easier to recognize as suspicious than the more targeted scripts above.
The job offer / work-from-home scam
An unsolicited message offers an easy, high-paying remote job (often "product review" or "liking videos" tasks), eventually asking for an upfront deposit or personal banking details to "activate" the account. This typically relies on nothing more specific than an active phone number and general demographic targeting, rather than any detailed personal profile.
What ties all of these together
The scripts differ, but the underlying pattern is consistent: the more specific and accurate a detail the caller has — your bank, your recent purchase, your actual name — the more that detail came from somewhere real: a breach, a broker listing, or a leaked database, rather than genuine account access. Recognizing that a caller "knowing" something about you doesn't mean they have real access is the single most useful mental model across every script above.
What actually protects you against all of these
- Never share an OTP over a call — no legitimate bank, agency, or service will ever ask for one verbally.
- Verify independently — hang up and call your bank or the agency back using their official number, never one provided by the caller.
- Be skeptical of urgency — every script above relies on pressuring you to act before you have time to think it through.
- Report serious attempts — India's National Cyber Crime Helpline (1930) and cybercrime.gov.in exist specifically for this.
- Check your own exposure — knowing what data of yours is already circulating helps you gauge how targeted a given call is likely to be, rather than reacting purely on instinct.
This last point is where Scan My Shadow is useful — checking your phone number and email across 1,500+ sources shows you what data a scammer targeting you would actually have access to, turning a vague sense of risk into something concrete.
FAQs
Is it true that just answering a scam call puts me at more risk?
It can slightly increase future targeting, since it confirms your number is active and monitored — letting unfamiliar numbers go to voicemail is a reasonable default habit.
Can scammers actually freeze my bank account remotely, as some scripts claim?
No — genuine account actions require your active participation (sharing an OTP, making a transfer) or direct access to your credentials. The threat itself is part of the pressure tactic, not a real independent capability.
What should I do immediately if I've already shared an OTP or made a payment to a scammer?
Contact your bank immediately to report it and block further transactions, then file a report at cybercrime.gov.in or call 1930 — acting quickly meaningfully improves the chances of recovering funds or limiting further damage.
Curious what's already out there about you? Scan My Shadow checks your phone number and email across 1,500+ sources and sends you a clear report — no guesswork, just facts. Start your scan.
Comments
Post a Comment