The Call Merge OTP Scam: How a Simple Phone Feature Is Draining Indian Bank Accounts
NPCI and MHA have issued urgent warnings about a scam where fraudsters trick victims into merging calls to steal OTPs in real time. Here's exactly how the call merge scam works and how to protect yourself in 2026.
A phone call from a stranger claiming to know a mutual friend feels harmless enough. An invitation to a social event or an exclusive opportunity feels flattering rather than threatening. A request to merge in a "friend" calling from another number feels like a completely ordinary favor. Each individual step in this scam feels reasonable in isolation which is exactly why call merging fraud has spread rapidly enough across India to prompt formal warnings from both the National Payments Corporation of India (NPCI) and the Ministry of Home Affairs.
This scam doesn't rely on malware, fake apps, or sophisticated technology. It exploits a completely standard, everyday phone feature the ability to merge two calls into one turning a routine convenience into a mechanism for stealing the one thing that's supposed to protect your bank account: your OTP.
How the Call Merge Scam Actually Works, Step by Step
Step 1: The Friendly, Unexpected Call
The scam begins with a call from an unfamiliar number. The caller claims to have gotten your number through a mutual friend, adopting a casual, friendly tone specifically designed to feel harmless and socially normal rather than suspicious.
Step 2: Building False Rapport
Once the initial contact feels comfortable, the caller often offers something appealing an invitation to an exclusive event, a social gathering, or a promising opportunity. This step exists specifically to build enough trust that the next request doesn't trigger suspicion.
Step 3: The Request to Merge Calls
The fraudster then claims that a mutual friend is trying to call from another number, and asks the victim to merge that incoming call into the current conversation. Since merging calls is a completely normal, everyday phone function, this request rarely raises any alarm.
Step 4: The Second Call Is Actually the Bank
What the victim doesn't realize is that the "second call" isn't actually a friend at all it's an automated call from their own bank, delivering a One-Time Password verification call, which the scammer has deliberately timed to arrive at precisely this moment. When the victim merges the calls, they unknowingly connect the scammer directly into their real, legitimate bank verification call.
Step 5: The OTP Is Captured in Real Time
With both calls merged, the scammer listens in silently as the automated banking system delivers the OTP. Because the victim believes this is simply part of their ongoing conversation with a "friend," they either read the OTP aloud without suspicion or fail to notice the scammer has captured it directly from the merged call itself.
Step 6: The Fraudulent Transaction Completes Instantly
Once the scammer has the OTP, they use it immediately to authorize a fraudulent transaction or account change, often draining a significant amount before the victim has any indication anything went wrong. In one documented case, a victim lost ₹50,000 within moments of merging what they believed was a simple personal call.
Why This Scam Is Different From Typical OTP Fraud
It Doesn't Require the Scammer to Ask for Anything Directly
Most OTP scams rely on directly asking the victim to read out or type in a code, which at least creates one moment where a cautious person might pause and question why they're being asked. The call merge scam bypasses this entirely the OTP is captured passively through the merged call itself, meaning the scammer never has to make a request that might trigger suspicion.
It Exploits a Completely Legitimate Bank Process
The OTP call the victim receives is entirely genuine it really is coming from their actual bank. This is precisely what makes the scam so effective: the victim isn't being tricked into trusting a fake source, they're being tricked into accidentally connecting a fraudster into a real, legitimate verification call they would otherwise have handled correctly on their own.
It Relies on Precise Timing, Not Just Deception
Unlike scams that unfold entirely through the scammer's own script, this fraud depends on the scammer already knowing, or triggering, that an OTP call is about to arrive meaning victims often report the fraudulent transaction attempt happens in close coordination with an otherwise unrelated banking action, suggesting a level of preparation beyond a purely improvised phone call.
The Scale of the Problem
The National Payments Corporation of India issued a direct public warning through its official channels, explicitly stating that scammers are using call mergers to trick people into revealing OTPs, and urging the public to stay alert. This warning came alongside broader findings that over a third of Indians have reportedly experienced some form of real-time payment scam, indicating call merge fraud is emerging within an already significant and growing wave of OTP-based financial crime. The Ministry of Home Affairs has separately flagged call merging fraud as a distinct, quietly spreading threat drawing increasing attention from cybersecurity authorities and financial regulators alike.
Why People Fall for This Even When They Know About OTP Scams
The Social Framing Disarms Normal Caution
Because the scam begins as a casual social interaction rather than an obvious financial request, it doesn't trigger the same defensive instincts that a direct call from "your bank" asking for an OTP typically would. Most OTP scam awareness specifically warns people not to share codes with anyone claiming to be a bank representative this scam sidesteps that warning entirely by never claiming to be the bank at all.
The Merge Request Feels Like an Ordinary Favor
Merging a call to connect a friend is a completely normal, everyday action that most phone users have done without a second thought. There's nothing about the request itself that resembles the red flags people are typically trained to watch for.
The Victim Genuinely Believes the OTP Call Is Unrelated
Because the actual banking OTP call arrives disguised as the promised "friend calling from another number," victims often don't consciously register that they're even on a call with their bank at all, let alone one that requires the same caution they'd apply to a direct OTP request.
Warning Signs to Watch For
An unexpected call from someone claiming mutual friend connections, particularly when the relationship or context feels vague or difficult to verify
Any request to merge in a second incoming call, especially when it arrives at a moment coinciding with expected banking activity or account communication
Invitations to exclusive events or opportunities from unfamiliar callers, used specifically to build enough rapport to make the merge request feel natural
A second call that sounds automated or robotic once merged, which may actually be a genuine OTP delivery call rather than the promised friend
Any OTP-related notification arriving during or immediately after an unrelated personal call, which deserves independent verification before assuming it's unconnected
How to Protect Yourself From Call Merge Fraud
Never Merge Calls From Unknown or Unverified Numbers
The single most effective protection is a simple behavioral rule: decline any request to merge an unfamiliar caller's "friend" into an ongoing conversation, particularly from someone you don't already know well and haven't independently verified.
Treat Any OTP You Receive During an Active Call With Suspicion
If an OTP arrives while you're on a call, especially one that began with an unfamiliar caller, pause before assuming it's unrelated. Hang up and independently verify directly through your bank's official app or number before taking any further action.
Never Read an OTP Aloud During Any Phone Call
Regardless of who you believe you're speaking with, treat OTPs as information that should never be spoken aloud during a call under any circumstance legitimate banking processes never require this.
Verify Unfamiliar Callers Independently Before Engaging Further
If someone claims to know you through a mutual friend, verify that connection directly with the friend in question through a separate channel before continuing the conversation, rather than taking the claim at face value.
Report Suspicious OTP Activity Immediately
If you receive an OTP for a transaction you didn't initiate, or suspect a call merge attempt has occurred, contact your bank immediately and call India's national cybercrime helpline at 1930 without delay.
What to Do If You've Already Fallen for This Scam
Contact your bank immediately to report the fraudulent transaction and request an emergency freeze on your account.
Call the national cybercrime helpline at 1930 as quickly as possible, since faster reporting significantly improves the chances of freezing stolen funds before they're moved further.
File a formal complaint through the National Cyber Crime Reporting Portal at cybercrime.gov.in, including any details about the caller, the merged number, and the transaction itself.
Change your banking app passwords and PIN as a precaution, particularly if you're unsure exactly what information may have been exposed during the call.
Monitor your account closely over the following days and weeks, since some fraud attempts involve multiple follow-up transactions rather than a single incident.
Why Awareness Remains the Most Effective Defense
Because this scam exploits a completely legitimate phone feature and a genuinely real banking process, no app setting or security software can fully prevent it the vulnerability lies entirely in the social engineering moment where a victim agrees to merge an unfamiliar call. This makes simple awareness of the pattern itself the most reliable protection available: understanding that any unsolicited request to merge in an unknown caller, particularly one arriving alongside banking activity, deserves the same caution as a direct, obvious OTP request.
Frequently Asked Questions (FAQs)
Q1: How does the call merge scam actually steal my OTP?
Scammers trick victims into merging a call from an unfamiliar "friend" that is actually a genuine, automated OTP verification call from their own bank, allowing the scammer to listen in and capture the OTP directly without ever asking for it.
Q2: Why doesn't this scam feel suspicious like typical OTP fraud?
Because the scammer never directly claims to be your bank or asks for the OTP outright the request to merge calls feels like an ordinary social favor, which bypasses the usual caution people apply to direct banking-related requests.
Q3: What should I do if someone asks me to merge an unfamiliar call?
Decline the request unless you can independently verify the caller's identity and connection to you, particularly if the request comes from someone you don't already know well.
Q4: Is it safe to merge calls in general?
Merging calls between people you know and trust is completely normal; the risk specifically arises when merging in an unfamiliar or unverified caller, particularly one introduced through a vague "mutual friend" framing.
Q5: What should I do immediately if I've shared an OTP through a merged call?
Contact your bank immediately to freeze your account and report the fraudulent transaction, then call India's national cybercrime helpline at 1930 as quickly as possible to improve the chances of recovering any stolen funds.
Conclusion
The call merge scam demonstrates how effectively fraudsters can weaponize a completely ordinary phone feature by combining it with precise timing and genuine banking processes, rather than relying on obvious deception. Because the scam exploits a real OTP call rather than a fake one, standard advice about never trusting callers claiming to be your bank doesn't fully apply here the actual vulnerability is the innocent-seeming request to merge in an unfamiliar caller. Declining call merge requests from unverified numbers, treating any OTP received during a call with independent verification, and reporting suspicious activity immediately remain the most reliable protections against a scam that NPCI and India's Ministry of Home Affairs have both flagged as an active, spreading threat.
Comments
Post a Comment