Skip to main content

The Call Merge OTP Scam: How a Simple Phone Feature Is Draining Indian Bank Accounts

The Call Merge OTP Scam: How a Simple Phone Feature Is Draining Indian Bank Accounts

NPCI and MHA have issued urgent warnings about a scam where fraudsters trick victims into merging calls to steal OTPs in real time. Here's exactly how the call merge scam works and how to protect yourself in 2026.

A phone call from a stranger claiming to know a mutual friend feels harmless enough. An invitation to a social event or an exclusive opportunity feels flattering rather than threatening. A request to merge in a "friend" calling from another number feels like a completely ordinary favor. Each individual step in this scam feels reasonable in isolation  which is exactly why call merging fraud has spread rapidly enough across India to prompt formal warnings from both the National Payments Corporation of India (NPCI) and the Ministry of Home Affairs.

This scam doesn't rely on malware, fake apps, or sophisticated technology. It exploits a completely standard, everyday phone feature  the ability to merge two calls into one  turning a routine convenience into a mechanism for stealing the one thing that's supposed to protect your bank account: your OTP.

How the Call Merge Scam Actually Works, Step by Step
Step 1: The Friendly, Unexpected Call
The scam begins with a call from an unfamiliar number. The caller claims to have gotten your number through a mutual friend, adopting a casual, friendly tone specifically designed to feel harmless and socially normal rather than suspicious.

Step 2: Building False Rapport
Once the initial contact feels comfortable, the caller often offers something appealing  an invitation to an exclusive event, a social gathering, or a promising opportunity. This step exists specifically to build enough trust that the next request doesn't trigger suspicion.

Step 3: The Request to Merge Calls
The fraudster then claims that a mutual friend is trying to call from another number, and asks the victim to merge that incoming call into the current conversation. Since merging calls is a completely normal, everyday phone function, this request rarely raises any alarm.

Step 4: The Second Call Is Actually the Bank
What the victim doesn't realize is that the "second call" isn't actually a friend at all  it's an automated call from their own bank, delivering a One-Time Password verification call, which the scammer has deliberately timed to arrive at precisely this moment. When the victim merges the calls, they unknowingly connect the scammer directly into their real, legitimate bank verification call.

Step 5: The OTP Is Captured in Real Time
With both calls merged, the scammer listens in silently as the automated banking system delivers the OTP. Because the victim believes this is simply part of their ongoing conversation with a "friend," they either read the OTP aloud without suspicion or fail to notice the scammer has captured it directly from the merged call itself.

Step 6: The Fraudulent Transaction Completes Instantly
Once the scammer has the OTP, they use it immediately to authorize a fraudulent transaction or account change, often draining a significant amount before the victim has any indication anything went wrong. In one documented case, a victim lost ₹50,000 within moments of merging what they believed was a simple personal call.

Why This Scam Is Different From Typical OTP Fraud
It Doesn't Require the Scammer to Ask for Anything Directly
Most OTP scams rely on directly asking the victim to read out or type in a code, which at least creates one moment where a cautious person might pause and question why they're being asked. The call merge scam bypasses this entirely  the OTP is captured passively through the merged call itself, meaning the scammer never has to make a request that might trigger suspicion.

It Exploits a Completely Legitimate Bank Process
The OTP call the victim receives is entirely genuine  it really is coming from their actual bank. This is precisely what makes the scam so effective: the victim isn't being tricked into trusting a fake source, they're being tricked into accidentally connecting a fraudster into a real, legitimate verification call they would otherwise have handled correctly on their own.

It Relies on Precise Timing, Not Just Deception
Unlike scams that unfold entirely through the scammer's own script, this fraud depends on the scammer already knowing, or triggering, that an OTP call is about to arrive  meaning victims often report the fraudulent transaction attempt happens in close coordination with an otherwise unrelated banking action, suggesting a level of preparation beyond a purely improvised phone call.

The Scale of the Problem
The National Payments Corporation of India issued a direct public warning through its official channels, explicitly stating that scammers are using call mergers to trick people into revealing OTPs, and urging the public to stay alert. This warning came alongside broader findings that over a third of Indians have reportedly experienced some form of real-time payment scam, indicating call merge fraud is emerging within an already significant and growing wave of OTP-based financial crime. The Ministry of Home Affairs has separately flagged call merging fraud as a distinct, quietly spreading threat drawing increasing attention from cybersecurity authorities and financial regulators alike.


Why People Fall for This Even When They Know About OTP Scams
The Social Framing Disarms Normal Caution
Because the scam begins as a casual social interaction rather than an obvious financial request, it doesn't trigger the same defensive instincts that a direct call from "your bank" asking for an OTP typically would. Most OTP scam awareness specifically warns people not to share codes with anyone claiming to be a bank representative  this scam sidesteps that warning entirely by never claiming to be the bank at all.

The Merge Request Feels Like an Ordinary Favor
Merging a call to connect a friend is a completely normal, everyday action that most phone users have done without a second thought. There's nothing about the request itself that resembles the red flags people are typically trained to watch for.

The Victim Genuinely Believes the OTP Call Is Unrelated
Because the actual banking OTP call arrives disguised as the promised "friend calling from another number," victims often don't consciously register that they're even on a call with their bank at all, let alone one that requires the same caution they'd apply to a direct OTP request.

Warning Signs to Watch For
An unexpected call from someone claiming mutual friend connections, particularly when the relationship or context feels vague or difficult to verify

Any request to merge in a second incoming call, especially when it arrives at a moment coinciding with expected banking activity or account communication

Invitations to exclusive events or opportunities from unfamiliar callers, used specifically to build enough rapport to make the merge request feel natural

A second call that sounds automated or robotic once merged, which may actually be a genuine OTP delivery call rather than the promised friend

Any OTP-related notification arriving during or immediately after an unrelated personal call, which deserves independent verification before assuming it's unconnected


How to Protect Yourself From Call Merge Fraud
Never Merge Calls From Unknown or Unverified Numbers
The single most effective protection is a simple behavioral rule: decline any request to merge an unfamiliar caller's "friend" into an ongoing conversation, particularly from someone you don't already know well and haven't independently verified.

Treat Any OTP You Receive During an Active Call With Suspicion
If an OTP arrives while you're on a call, especially one that began with an unfamiliar caller, pause before assuming it's unrelated. Hang up and independently verify directly through your bank's official app or number before taking any further action.

Never Read an OTP Aloud During Any Phone Call
Regardless of who you believe you're speaking with, treat OTPs as information that should never be spoken aloud during a call under any circumstance  legitimate banking processes never require this.

Verify Unfamiliar Callers Independently Before Engaging Further
If someone claims to know you through a mutual friend, verify that connection directly with the friend in question through a separate channel before continuing the conversation, rather than taking the claim at face value.

Report Suspicious OTP Activity Immediately
If you receive an OTP for a transaction you didn't initiate, or suspect a call merge attempt has occurred, contact your bank immediately and call India's national cybercrime helpline at 1930 without delay.

What to Do If You've Already Fallen for This Scam
Contact your bank immediately to report the fraudulent transaction and request an emergency freeze on your account.

Call the national cybercrime helpline at 1930 as quickly as possible, since faster reporting significantly improves the chances of freezing stolen funds before they're moved further.

File a formal complaint through the National Cyber Crime Reporting Portal at cybercrime.gov.in, including any details about the caller, the merged number, and the transaction itself.

Change your banking app passwords and PIN as a precaution, particularly if you're unsure exactly what information may have been exposed during the call.

Monitor your account closely over the following days and weeks, since some fraud attempts involve multiple follow-up transactions rather than a single incident.

Why Awareness Remains the Most Effective Defense
Because this scam exploits a completely legitimate phone feature and a genuinely real banking process, no app setting or security software can fully prevent it  the vulnerability lies entirely in the social engineering moment where a victim agrees to merge an unfamiliar call. This makes simple awareness of the pattern itself the most reliable protection available: understanding that any unsolicited request to merge in an unknown caller, particularly one arriving alongside banking activity, deserves the same caution as a direct, obvious OTP request.

Frequently Asked Questions (FAQs)
Q1: How does the call merge scam actually steal my OTP?
Scammers trick victims into merging a call from an unfamiliar "friend" that is actually a genuine, automated OTP verification call from their own bank, allowing the scammer to listen in and capture the OTP directly without ever asking for it.
Q2: Why doesn't this scam feel suspicious like typical OTP fraud?
Because the scammer never directly claims to be your bank or asks for the OTP outright  the request to merge calls feels like an ordinary social favor, which bypasses the usual caution people apply to direct banking-related requests.
Q3: What should I do if someone asks me to merge an unfamiliar call?
Decline the request unless you can independently verify the caller's identity and connection to you, particularly if the request comes from someone you don't already know well.
Q4: Is it safe to merge calls in general?
Merging calls between people you know and trust is completely normal; the risk specifically arises when merging in an unfamiliar or unverified caller, particularly one introduced through a vague "mutual friend" framing.
Q5: What should I do immediately if I've shared an OTP through a merged call?
Contact your bank immediately to freeze your account and report the fraudulent transaction, then call India's national cybercrime helpline at 1930 as quickly as possible to improve the chances of recovering any stolen funds.

Conclusion
The call merge scam demonstrates how effectively fraudsters can weaponize a completely ordinary phone feature by combining it with precise timing and genuine banking processes, rather than relying on obvious deception. Because the scam exploits a real OTP call rather than a fake one, standard advice about never trusting callers claiming to be your bank doesn't fully apply here  the actual vulnerability is the innocent-seeming request to merge in an unfamiliar caller. Declining call merge requests from unverified numbers, treating any OTP received during a call with independent verification, and reporting suspicious activity immediately remain the most reliable protections against a scam that NPCI and India's Ministry of Home Affairs have both flagged as an active, spreading threat.

Comments

Popular posts from this blog

AI Job Scams in 2026: 7 Red Flags Every Job Seeker Must Know Before It's Too Late

AI Job Scams in 2026: 7 Red Flags Every Job Seeker Must Know Before It's Too Late AI-powered job scams have pushed losses past $500 million as deepfake recruiters and fake offer letters flood LinkedIn and email inboxes. Here are the 7 red flags that still expose them in 2026, and what to do if you've already been targeted. For years, job seekers were told that bad grammar and awkward phrasing were the easiest way to spot a fake recruiter. That advice no longer holds. Generative AI can now produce outreach messages, offer letters, and even live video interviewers that are functionally indistinguishable from the real thing. Reported losses from job search fraud jumped from $90 million in 2020 to more than $500 million in 2024, and industry researchers project that by 2028, roughly one in four candidate profiles circulating online will be entirely fake. This isn't a distant future risk  it's actively reshaping how hiring works right now, targeting new graduates...

The New UPI Scam That's Draining Bank Accounts in Seconds: How It Works and How to Spot It

The New UPI Scam That's Draining Bank Accounts in Seconds: How It Works and How to Spot It UPI fraud has surged as scammers exploit fake customer care numbers, QR codes, and screen-sharing apps. Here's exactly how India's most common UPI scams work in 2026, real cases, and the 3-day rule that could save your money. A Bihar grocer lost ₹58,000 from his bank account without clicking a single link or receiving a single call. A Chennai user complained about a failed transaction on Twitter and had ₹1.8 lakh drained from his SBI account within minutes, after a fake "Paytm Care" account responded to his post and talked him into installing a screen-sharing app. A Jaipur street vendor scanned a QR code a "customer" sent him to receive payment  and instead authorized a debit. None of these victims were reckless. All of them fell for scams built around a simple, unchanging truth about UPI: the system is instant, irreversible, and requires the victim...

AI-Generated Investment Scams: How Fake Crypto Platforms Are Stealing Billions in 2026

AI-Generated Investment Scams: How Fake Crypto Platforms Are Stealing Billions in 2026 Every year, artificial intelligence gets better at doing useful things  writing code, analyzing data, generating images. Unfortunately, scammers have been paying just as much attention to these advances as legitimate businesses have, and in 2026, they've turned AI into the most effective fraud tool the financial world has ever seen. What used to be obvious, badly-written scam emails have evolved into polished trading platforms with real-looking dashboards, AI-generated "proof" of returns, and even deepfake videos of celebrities and CEOs vouching for products that don't exist. The result is a wave of losses running into the billions of dollars, hitting everyone from retirees to tech-savvy young professionals who assumed they were too smart to fall for it. Understanding exactly how these scams work  not just that they exist  is the difference between recognizing one in the...