Just in:
LatAm gushers and possible Venezuela exit a nightmare for Opec // Schnabel urges programmable central bank money on-chain // Hong Kong Science and Technology Parks Corporation Kicks Off 25th Anniversary Prelude “Innovation. Next by Nature.” // WisPaper Introduces TrueCite to Help Researchers Verify AI-Generated Academic References // Ingdan, Inc. (400.HK) Announces 2026 Interim Results // What Shein’s $27bn IPO means for Mubadala // SCX Corporation Accelerates SC Group’s Recurring-Income Businesses // Adobe widens Saudi AI access with $4 billion programme // Best Mart 360 Reports Interim Revenue Growth to HK$1.45 billion // Apple raises evidence-destruction claims against OpenAI // Apical Provides Free Health Screenings and Treatment for Lubuk Gaung Residents // Macao Economic, Trade and Tourism Investment Promotion Seminar Held in Singapore, Deepening Multi-Domain Cooperation to Empower Regional Growth // Amicura X1 Max Smart Cat Litter Box:AliExpress France Official Warehouse, Litter Box at One Click // Haldwani purification row: Caste back on political centre-stage // Chinese researchers engineer self-contracting muscle grafts // Russia brings cryptocurrency market law into force // InnoHK R&D Centres Establish Base at Science Park to Drive Emerging Industries and Pioneer Future Innovation // India plans own orbital space outpost, second after China // Jordan downs eight missiles as Iran targets US bases // US-Iran strikes revive confrontation across Hormuz and Jordan //

SBI alerts customers over YONO phishing

State Bank of India has warned customers against a phishing campaign that falsely claims its YONO app will be deactivated unless Aadhaar details are updated through a shared link or APK file.

The country’s largest lender has said the messages are fraudulent and should be ignored. Customers have been advised not to download files received through SMS, WhatsApp, email or social media, and not to share account details, Aadhaar numbers, passwords, PINs or one-time passwords with anyone. The warning follows the circulation of messages designed to create panic by suggesting that digital banking access will be blocked unless users act immediately.

The fraudulent message typically tells customers that their YONO account or app will be suspended because Aadhaar information has not been updated. It then directs them to install an APK file or open a link that imitates an official banking process. Cybersecurity specialists regard this pattern as a classic phishing and malware tactic, in which attackers use the name of a trusted institution to persuade users to install unauthorised software or enter sensitive credentials.

SBI has clarified that it does not ask customers to download APK files for Aadhaar updates or account verification. Banking updates are carried out through official channels, branches, internet banking portals or verified applications downloaded from trusted app stores. Customers who receive such messages have been asked to report them to the bank’s phishing reporting channel and to the national cybercrime helpline if money has been lost.

The campaign has gained attention because YONO is central to SBI’s digital banking strategy. The platform has more than 8.7 crore registered customers and is used for savings accounts, fund transfers, loans, cards, insurance, investments and cash withdrawal services. SBI has also been expanding its digital infrastructure through YONO 2.0, aiming to increase mobile banking adoption and reduce dependence on branch-based transactions.

Fraudsters are exploiting that shift. As more customers move to mobile banking, attackers are increasingly using fake app updates, Know Your Customer warnings, Aadhaar-linked messages and account-freeze threats to trigger hurried responses. The technique relies less on sophisticated hacking and more on social engineering, where fear of losing access to banking services pushes victims to click first and verify later.

The use of APK files has become a particular concern. APKs are installation packages for Android apps and can bypass the protections offered by official app stores when users install them from unknown sources. Once installed, malicious software can seek permissions to read SMS messages, intercept OTPs, access contacts, overlay fake login screens or monitor device activity. This gives criminals a route to both credentials and transaction authentication codes.

Digital payment growth has widened the attack surface. More than 18,000 crore digital payment transactions were recorded during 2024-25, with UPI and mobile banking playing a central role in everyday financial activity. That expansion has improved access and convenience, but it has also made banks, payment apps and telecom-linked authentication systems attractive targets for organised fraud networks.

Banking fraud data points to the same risk environment. Card and internet-related frauds account for a large share of reported fraud cases by number, even though higher-value frauds are often linked to loans and advances. Cyber fraud complaints have also grown sharply through the national reporting system, with victims reporting losses running into tens of thousands of crore rupees across online investment scams, payment fraud, remote-access app misuse, courier impersonation and fake customer-care operations.

Regulators have responded by strengthening authentication norms, encouraging risk-based checks and pushing banks to improve fraud monitoring. The Reserve Bank of India’s updated digital payment security framework gives regulated entities room to deploy additional verification where transaction risk appears high. Banks have also stepped up customer-awareness campaigns, warning users that OTPs, passwords and card details must never be shared, even with callers claiming to represent official institutions.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Dubai hotel provides free public co-working space // Qatar economy contracts 7% as energy output slumps // Gulf AI uptake outpaces measurable returns // Apical Provides Free Health Screenings and Treatment for Lubuk Gaung Residents // Best Mart 360 Reports Interim Revenue Growth to HK$1.45 billion // What Shein’s $27bn IPO means for Mubadala // Hong Kong Science and Technology Parks Corporation Kicks Off 25th Anniversary Prelude “Innovation. Next by Nature.” // Ingdan, Inc. (400.HK) Announces 2026 Interim Results // LatAm gushers and possible Venezuela exit a nightmare for Opec // InnoHK R&D Centres Establish Base at Science Park to Drive Emerging Industries and Pioneer Future Innovation // Inovatif Media Asia Sets Regional Ambitions in Motion with Tun Ahmad Fuzi as Strategic Advisor // Apple raises evidence-destruction claims against OpenAI // Putin holds talks with Pezeshkian in Bishkek // Macao Economic, Trade and Tourism Investment Promotion Seminar Held in Singapore, Deepening Multi-Domain Cooperation to Empower Regional Growth // Jungheinrich Marks 25 Years In Singapore, Leading APAC Strategic Hub And Electrification In The Market // Schnabel urges programmable central bank money on-chain // Amicura X1 Max Smart Cat Litter Box:AliExpress France Official Warehouse, Litter Box at One Click // SCX Corporation Accelerates SC Group’s Recurring-Income Businesses // Venezuela defends sovereignty after Trump oil control claim // Alpha Dhabi lifts MICAD commitment to $1 billion //