This SMS has probably reached your phone in some form, regardless of which bank you actually use:

Dear Customer, your A/C has been TEMPORARY SUSPENDED due to KYC not updated. Update within 24 Hrs to avoid permanent block. Click: hxxp://sbi-ekyc-update.info/verify

It gets sent in bulk, untargeted, to millions of numbers regardless of which bank — or whether the recipient even has an account there. It works on volume: send it to enough people and some percentage will bank with whoever the message names, and a smaller percentage of those will panic and click.

Breaking the message down, line by line

1. "TEMPORARY SUSPENDED" — broken grammar, deliberately urgent capitals

Real bank SMS templates go through legal and compliance review. They don't contain grammatical errors, and they don't use random capitalisation for emphasis. Poor grammar is one of the most reliable tells in Indian phishing SMS, because many campaigns are run by non-native English speakers using templates translated or reused across countries.

2. "within 24 Hrs" — manufactured urgency

Legitimate KYC update requirements from RBI-regulated banks come with weeks of notice, multiple channels of communication (SMS, email, app notification, sometimes physical mail), and never a 24-hour ultimatum threatening account suspension over SMS alone.

3. The link itself

Look at the domain, not the words around it: sbi-ekyc-update.info is not a State Bank of India domain. Indian banks operate on their own registered domains (for example, the real SBI's domains end in .sbi or onlinesbi.sbi) — a domain that merely contains a bank's name, followed by a generic extension like .info, .xyz, or a shortened URL, is not affiliated with that bank. Anyone can register anything-sbi-anything.info.

The core trick

Phishing domains are built to be glanced at, not read. "sbi-ekyc-update.info" is designed so your eye catches "sbi" and "kyc" and stops parsing there. Banks' real domains are short, well-known, and don't need to spell out what the page is for in the URL itself.

What happens if you click

The link opens a page built to be a pixel-for-pixel clone of a real net-banking login screen. It asks for your customer ID, password or PIN, and often a "verification" OTP. Every field you fill in is captured directly by the scammer — there is no real bank system behind that page. Within minutes, that captured login is used to log into your actual account or add the scammer as a payee.

How to verify a KYC message is real, in under a minute

Do this instead
  • Never tap the link in the message. Open your bank's app directly, or type the bank's known website address yourself.
  • Call the number printed on the back of your physical debit/credit card, or the number listed on the bank's official website — not any number given in the SMS.
  • Check your bank's verified social media or official app for any real KYC campaign notices — these are always mirrored across multiple channels, not sent as a single lone SMS.
  • Remember: your KYC status is always visible inside your bank's app or net banking portal. If you're unsure, check there directly instead of reacting to the SMS at all.

Why banks are an especially common lure

Phishing campaigns default to banks, UPI apps, and government services (Aadhaar, income tax, electricity boards) because these are the accounts where fear of "losing access" produces the fastest, least-questioned reaction. The message doesn't need to be convincing on close inspection — it only needs to trigger a reflexive tap before you inspect it at all.