A caller knowing your bank, your name and the last digits of your card proves nothing. In an August 2025 case, Delhi Police said insiders at an authorised card-protection call centre in Gurugram siphoned SBI credit-card customer data, feeding a fraud of nearly ₹2.60 crore; 18 people were arrested. Never confirm or supply an OTP, CVV, PIN or card number on an inbound call. Hang up, dial the number printed on your card — then complain to the bank, because under RBI's outsourcing rules the bank remains answerable for its service providers.
The call sounds real because of what the caller already knows. Your full name. Which bank you're with. The last four digits of the card in your wallet. Most people draw the obvious conclusion — only my bank could know that, so this must be my bank — and then hand over an OTP.
That inference is the attack. It is the whole mechanism. And in India, the reason the caller knows those things is usually far more boring than hacking: someone your bank paid handed the list over.
1. The Gurugram case: the leak was inside an authorised vendor
On 16 August 2025, The Tribune reported a Delhi Police case in which, police said, insider moles inside an authorised Card Protection Plan call centre in Gurugram secretly siphoned off confidential SBI credit-card data — customer names, registered mobile numbers and partial card details.
What the syndicate then did with it is the part worth reading twice: the fraudsters posed as bank representatives, used the leaked details to sound legitimate, and induced cardholders to reveal OTPs and CVVs. The total came to nearly ₹2.60 crore, and 18 people were arrested. Reporting of the police account listed the roles in the syndicate as including "syndicate masterminds, orchestrators, strategists, account/cash handlers, Call Centre Insiders and data brokers."
Read that role list again. "Call Centre Insiders" and "data brokers" are separate job descriptions in a police account of one criminal operation. The leaking and the calling are not two unrelated worlds; they are two links in the same chain.
An important precision. The call centre was an authorised vendor providing card-protection services — not the bank's own staff. And these are police allegations against the individuals arrested, not findings against any company. The lesson for you is structural, not about one firm: you gave your details to your bank, and they left through a vendor you never chose and cannot see.
2. Police say this is the pattern, not the exception
This is not an isolated case that happened to involve a vendor. Speaking about a separate 2023 data-selling investigation, Cyberabad police told ThePrint that "in cases related to bank data theft, data is often leaked through third-party companies which banks hire to verify their customers' data."
In that same investigation, Business Today reported that Cyberabad police served notices on eleven organisations whose customer data had turned up — described as three banks, a social media giant, an IT services company, an online grocery seller, a digital payments app and an online insurance platform — asking them to explain how they maintained their databases, what procedures they followed and who could access the data.
No finding of liability against any of them was reported; that was an investigative step, not a verdict. The point is the ordinariness of the list. These are not shady websites. They are the apps on your phone. If you have ever wondered where your data is actually being sold, the answer usually starts at a company you willingly signed up with.
3. It isn't only banks — outsourced support is the exposure surface
In December 2025, BleepingComputer reported the arrest in Hyderabad of a former customer support agent, in connection with a breach at TaskUs — an outsourcing provider — that affected about 69,500 Coinbase customers.
Be clear about what that case does and does not show. Those affected were largely overseas customers, not Indian consumers. The India connection is simply where the insider sat — and that is exactly the useful lesson. Your data does not only live with the brand on the app. It lives with whoever that brand outsourced support, verification or collections to, and every one of those firms is staffed by people with a login.
4. Correct your mental model of the word "breach"
Most Indians picture a hacker in a hoodie. The law does not. The DPDP Act 2023, at section 2(u), defines a personal data breach as "any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data".
Accidental disclosure. Loss of access. A misconfigured server, a spreadsheet emailed to the wrong address, a vendor leaving a storage bucket open — all of it counts. So "we were not hacked" and "your data leaked from us" can both be true at once.
And you probably won't be told. Under directions issued in April 2022 (effective from June 2022), Indian companies must report cyber incidents — expressly including "Data Breach" and "Data Leak" — to CERT-In within six hours. That duty is owed to the government, not to you. The rule that will require a company to tell you sits in Rule 7 of the DPDP Rules 2025, which does not commence until roughly May 2027. Until then, silence from a company is not evidence that you were unaffected. Here's what to do if you find out you were in a breach.
5. The one rule that survives all of this
If you remember nothing else from this page, remember this:
Knowledge of your details proves nothing
A caller reciting your bank, your name, your city or your card's last four digits has demonstrated that a leak occurred — not that they work for your bank. Treat accurate information as a warning sign, not a credential.
Never supply or confirm an OTP, CVV, PIN or card number on an inbound call
Not "just to verify". Not partially. Not even to say "yes, that's right". In the Gurugram case, police said this was exactly the step the fraudsters needed — the leaked data got them credibility, and the victim supplied the rest.
Hang up and call back on a number you found yourself
Use the number printed on the back of your card or shown inside your bank's own app. Never a number the caller gives you, never a number from a search result, never "press 1 to be connected". The same discipline defeats the "digital arrest" scam, which runs on the identical trick of quoting real details to manufacture panic.
6. Your escalation route — and be precise about it
Complaining to the caller is pointless; they are three hops down a chain. Complain to the institution that is answerable.
A 2006 RBI circular on outsourcing puts that duty squarely on the bank. It requires that "the bank should seek to ensure the preservation and protection of the security and confidentiality of customer information in the custody or possession of the service provider", that service-provider staff access customer information strictly on a need-to-know basis, and that banks notify RBI of any leakage of confidential customer information.
In other words: the vendor may have leaked, but the bank chose the vendor and remains responsible for it. That is your lever.
| Your situation | Where it goes | What it can realistically do |
|---|---|---|
| Money already gone | Helpline 1930 / cybercrime.gov.in — same hour | Fastest route to freezing a transaction; do this before anything else |
| Suspicious call, nothing lost | Chakshu on Sanchar Saathi | Feeds a national pattern; DoT has said it uses this crowd-sourced data for analysis rather than acting on individual reports |
| Your details leaked / the bank's vendor exposed you | Bank's grievance officer in writing → RBI's banking ombudsman | The only channel where the accountable party is actually on the hook |
| You want the data deleted | Written erasure request to the company holding it | Creates the dated record; full statutory teeth arrive around May 2027 (see below) |
On the government reporting channel: in a written reply to the Rajya Sabha on 5 February 2026, the Minister of State for Communications said citizen inputs through Sanchar Saathi had led to 39.43 lakh mobile connections being disconnected, 2.27 lakh handsets blacklisted and 1.31 lakh SMS templates blocked, as reported by The Tribune. Reporting is not theatre — but it is aggregate, so treat your report as one vote in a pattern rather than a personal remedy.
7. Two legal routes most people never hear about
These are worth knowing because they exist today, unlike most of the DPDP Act.
Compensation, via a route that is closing. Section 43A of the IT Act 2000 — the provision under which a person can claim compensation from a company whose negligence with sensitive personal data caused them wrongful loss — is omitted by DPDP section 44(2)(a). But that sub-section sits in the Act's eighteen-month commencement bucket, so section 43A is still alive until roughly May 2027. Claims go to an Adjudicating Officer under section 46 of the IT Act — an administrative forum, not a civil court, with jurisdiction up to ₹5 crore. Separately, section 43(b) covers the person who copied or extracted the data without permission, and is not being repealed.
The criminal provision aimed exactly at this scenario. Section 72A of the IT Act punishes a person who, "while providing services under the terms of lawful contract", secured access to material containing someone's personal information and then disclosed it without consent or in breach of that contract, with intent to cause or knowledge of likely wrongful loss or gain — up to three years' imprisonment, or a fine up to ₹5 lakh, or both. That is the insider-at-an-outsourced-vendor situation, described in a statute. Its limit is the contract requirement: it does not reach a stranger who scraped your data with no relationship to anyone.
Be realistic about the criminal route. NCRB data reported by The Tribune shows 1.67 lakh cybercrime cases registered across 28 states between 2020 and 2022, against 2,706 persons convicted — roughly 1.6%. File the complaint; it matters. But build your own paper trail in parallel rather than waiting on a conviction.
8. Ask your bank in writing — four questions
Send this by email, from the address registered with the bank, so the date is provable. Address it to the bank's grievance officer or nodal officer.
- Which third parties and service providers have received my name, registered mobile number and card details, and for what purpose?
- On what basis do they hold it, and for how long?
- Please confirm deletion by your processors and vendors — not only from your own systems. This is the sentence most people forget, and it is the one that matters, because the leak in the cases above happened downstream of the bank.
- Has any leakage of my information been reported to RBI, as required under the outsourcing circular?
Keep the reply. If they ignore you, here's what to do when a company ignores a deletion request, and here's the fuller DPDP erasure request guide.
9. Honest note on timing — and why to do it anyway
Saaph is a privacy company, so we have every commercial reason to tell you the DPDP Act is a magic wand today. It isn't, and you should be suspicious of anyone who says otherwise.
The DPDP Rules were notified in November 2025 with, per the government's own explainer, an eighteen-month period for phased compliance. That puts the erasure right (section 12), the requirement to answer access, correction and erasure requests within a maximum of ninety days, and the penalty Schedule at around May 2027. Three further caveats worth stating plainly:
- The forum isn't staffed yet. Writing on 1 August 2026, Dr. Raghvendra Kumar Chaudhary of CHRIST (Deemed to be University) noted in a LiveLaw opinion piece that the Data Protection Board "has no appointed Chairperson and no appointed Members" — it exists "only as a statutory possibility". Appointments can be made at any time, but as of writing, that is the position.
- The erasure right has a boundary. Section 12 covers personal data you gave the company — by consent or voluntarily. It is a weak instrument against someone who bought or scraped your data and never had any relationship with you.
- The famous fines are not yours. The Schedule allows penalties of up to ₹250 crore for failing to take reasonable security safeguards and up to ₹200 crore for failing to notify a breach. Those are ceilings, imposed by the Board — and section 34 credits every rupee to the Consolidated Fund of India, not to you.
So today this is a grievance-and-record-building exercise. Do it anyway. The dated written request is what every later escalation depends on — the ombudsman complaint, the adjudication claim, the Board complaint in 2027. People who start the paper trail this year will be a year ahead of people who start it when the deadline lands.
Find out which companies are still holding your details
Saaph scans Indian platforms and known breaches for your name, email and number, shows you what's exposed, and sends DPDP erasure requests to the companies holding it. It can't recall data that has already leaked, and it won't stop a fraud call — what it does is shrink the number of places your details sit, and give you a dated record for every request.
Run a free exposure scan →FAQ
How does the caller already know my bank and the last four digits of my card?
Usually because a company that legitimately held your details leaked them. In August 2025, The Tribune reported that Delhi Police alleged insiders at an authorised card-protection call centre in Gurugram siphoned SBI credit-card customer data — names, registered mobile numbers and partial card details — feeding a fraud of nearly ₹2.60 crore, with 18 arrests. Cyberabad police have said that in bank data theft cases the data is often leaked through third-party companies banks hire to verify customer details.
Does a caller knowing my details prove they are from my bank?
No. It proves a leak happened. Never confirm or supply an OTP, CVV, PIN or full card number on a call you did not place — hang up and dial the number printed on your card.
My bank says it was not hacked. Can my data still have leaked from them?
Yes. The DPDP Act defines a personal data breach to include accidental disclosure, sharing, alteration and even loss of access — and data commonly leaves through outsourced verification agencies, sales agents and support vendors rather than through an attack on the bank itself.
Can I force my bank to delete my data under the DPDP Act right now?
Not in enforceable terms yet. The Rules were notified in November 2025 with an eighteen-month phased compliance period, putting the erasure right, the 90-day response requirement and the penalty Schedule at around May 2027. Send the written request anyway — it is dated, and it is the record every later escalation depends on.
Where do I complain if money has already gone?
Call 1930 or report at cybercrime.gov.in immediately. For a suspicious call with no loss, use the Chakshu facility on Sanchar Saathi. For the leak itself, write to your bank's grievance officer and then escalate to RBI's banking ombudsman — not to the agent who called.
General information as of August 2026. Saaph.in is a privacy technology platform, not a law firm, and this is not legal advice — confirm specifics with a qualified professional, and note that commencement dates under the DPDP Act and Rules can change. Police cases described above are allegations against the individuals arrested, reported by the outlets linked; they are not findings against any company. For cyber emergencies, contact the National Cyber Crime Helpline on 1930.