Fake Customer Care Numbers: How to Check One Before You Call
Never call a customer care number you found in search results, a comment section or a random online directory. Fake customer care numbers are placed there on purpose, they rank well, and the person who picks up will sound completely professional. Take the number from the company's own app or its official website instead. If money has already left your account, call 1930 immediately.
This is not a rare scam, and it is old enough to have a paper trail. On 14 August 2019, Zomato filed a complaint with the cyber crime police in Gurugram about fake websites and phone numbers posing as its support team. The complaint pointed out something most people never realise: Zomato does not have a customer care phone number at all. Two months earlier a customer in Bengaluru had found one of these numbers online and called about a refund of ₹89. She was told the money could come to her instantly on Google Pay, and asked to install an app so the agent could help. Her entire bank balance was debited. An FIR was registered against unidentified persons.

What a fake customer care number scam actually looks like
The call feels ordinary. There is hold music sometimes, a reference number, a polite voice that repeats your complaint back to you. Nothing about it feels like fraud, and that is the whole design.
Then the request comes, and it is always dressed up as a step in the refund process. Install this small app so I can guide you. Approve this request of ₹1 for verification of your account. Read out the OTP so I can confirm your identity.
Every one of those steps hands over control. The "small app" is a remote access tool like AnyDesk, TeamViewer QuickSupport or RustDesk. RBI's cyber security cell warned banks about exactly this in February 2019: the app generates a nine digit code on your phone, the caller asks you to read it out, and from that moment they can see your screen and operate your device. Bengaluru cyber police registered 25 such cases in two months, with losses running from ₹15,000 to ₹2 lakh.
The ₹1 verification is a UPI collect request, which takes money out and never brings it in. The OTP is the last lock on your account.
What makes this work is the moment you are in. Your food order got cancelled, your recharge failed, a payment is stuck, so you are already irritated and you want it solved fast. Whoever is running a fake customer care number knows that people searching for helpline at 11 pm are not in a mood to verify anything.
How fake customer care numbers reach the top of your search results
Search engines rank pages, not truth. If a page is well built and matches what you typed, it can rank, and nobody at Google is checking whether the phone number on it belongs to the company it claims. That is the whole gap, everything else follows from it.
The set of routes used to push a fake customer care number in front of you are mostly free, which is why they keep working:
Cloned support websites. A page that copies the brand's logo, colours and layout, with one phone number changed. Some of these have been sitting in the results since long, and they often rank for specific queries like "swiggy refund complaint number".
Business listing edits. On some map and directory listings, anyone can suggest a change to the phone number. If nobody notices, the edit stays live for days.
Comment sections. YouTube videos about a bank, app or portal collect dozens of comments saying "helpline number 9XXXXXXXXX, call for fast solution". They look like other users helping out.
Social media replies. You tweet a complaint at a brand, and within minutes a lookalike account replies asking you to DM a number.
Paid ads. Sometimes the fake number sits in a sponsored result, above every genuine link on the page.

There is one more reason these listings survive. Many Indian companies, particularly the newer app-first ones, do not run a public phone helpline at all. They handle support entirely in-app. So when you search for their customer care number, there is no genuine number for Google to show you, and the gap gets filled by whoever wants to fill it.

Three things a real support agent will never ask you to do
Learn these three, and you have covered nearly every version of this fraud.
1. Install a screen-sharing or remote access app. No bank, wallet, food delivery app or government helpline will ever need to see or operate your phone to process a refund. Not once. If this comes up, the call is fake, hang up straightaway.
2. Enter your UPI PIN to receive money. This one traps the most people, so read it twice. You enter your UPI PIN only when money is going out of your account. Receiving money never needs a PIN. Any "refund" that asks you to approve a request and enter your PIN is a payment you are making to the fraudster.
3. Share an OTP, CVV, card PIN or full card number. Bank staff do not ask for these, and they have no reason to. The OTP message itself usually carries a line saying not to share it with anyone. RBI has said the same thing in a public notice on safe digital banking, which names vishing, phishing and remote access as the three methods to watch for.
A fourth signal, less absolute but still useful: a genuine helpline is almost always a toll free 1800 number, a short code like 121 or 139, or a landline with an STD code. A 10-digit mobile number claiming to be a bank's customer care is worth doubting immediately.
How to check a customer care number in under a minute
You do not need to be able to spot a fake customer care number. You only need a habit that never puts you in front of one. Do this in order, and the first source that gives you a number is the one to use.
Open the app. Nearly every banking, payments and delivery app has support built into it, under Help, Support or Contact Us. This is the safest route because there is no search result in between.
Type the official website address yourself. Not a search, an actual typed URL. Then look for the contact page. For government services check the domain ends in
gov.inornic.in.Check the physical objects you already have. The back of your debit or credit card, your passbook, your policy document, your last account statement. These carry the real number and nobody can edit them.
Check your SMS history. Alerts from your bank often carry the official helpline at the end of the message.
Only then, use a directory, and only one that says where the number came from and when it was last checked.
One thing you should not do: dial the number that appears in a search snippet without opening the page and confirming the domain. The snippet is where a lot of these numbers live.
What to do if you have already called a fake number
Speed decides the outcome here, more than anything else. Money moves through mule accounts quickly, and a lien can only be placed on funds that are still sitting somewhere.
Within the first few minutes:
If you installed a remote access app, put the phone in airplane mode and uninstall the app.
Call your bank on a number taken from the back of your card and ask them to block the affected channel: card, net banking, UPI, or the account.
Call 1930, the national cyber crime helpline. It runs 24x7, is operated by the Indian Cyber Crime Coordination Centre under the Ministry of Home Affairs, and replaced the older 155260 number. Have your transaction reference number, the amount, the time, and the fraudster's phone number ready.
File a complaint at cybercrime.gov.in under Report Other Cyber Crime, then Financial Fraud. Download the acknowledgement PDF and keep it safe.
Within the same week:
Give your bank a written complaint at the branch, with the cyber crime acknowledgement attached, and get it stamped.
Report the phone number on the Chakshu facility at Sanchar Saathi, run by the Department of Telecommunications, so the number itself can be acted on. Complaints filed within 30 days are investigated.
Do not delete the call log, the SMS alerts or the app. That is your evidence. You could also save screenshots of those call logs, SMS and app screens.
What the rules say about getting your money back
You have more protection than most people realise, and it depends heavily on how fast you report.
Two frameworks matter, because one is being replaced by the other:
Rule till 31 December 2026 | Rule from 1 January 2027 | |
|---|---|---|
Source | RBI circular dated 6 July 2017 on limiting customer liability | RBI Responsible Business Conduct Third Amendment Directions, 2026, for commercial banks, issued 24 June 2026 |
Zero liability window, third party breach | Report within 3 working days of the bank's alert | Report within 5 calendar days of the fraud, to the bank and to 1930 or cybercrime.gov.in |
Reported late | 4 to 7 working days: liability capped at ₹5,000, ₹10,000 or ₹25,000 depending on account or card type | Compensation assessed under the new framework rather than a fixed cap |
Small value fraud relief | Not available | Loss up to ₹50,000: 85% of net loss or ₹25,000, whichever is lower. Once in a lifetime. |
Provisional credit | Within 10 working days of notification | Credit card complaints: shadow reversal within 5 calendar days |
Burden of proof | On the bank | On the bank |
Sources: RBI circular DBR.No.Leg.BC.78/09.07.005/2017-18 dated 6 July 2017, and the RBI (Commercial Banks) Responsible Business Conduct Third Amendment Directions, 2026 dated 24 June 2026. Direct RBI notification link for the 2026 directions: Notification, Press release, [PDF].
Two points worth holding on to. The burden of proving that you were negligent sits with the bank, not with you, and courts have declined to accept the argument that an OTP was generated so the transaction must have been authorised. And the new rules do not apply to anything that happens before 1 January 2027, so if you are defrauded this month, the 2017 timelines are the ones that govern your case.
If your bank does not resolve the complaint in 30 days, you can escalate to the RBI Ombudsman under the Integrated Ombudsman Scheme, free of cost, through RBI's complaint management portal at https://cms.rbi.org.in/. This is general information and not legal advice.
Why we put a date on every helpline number
We built the helpline directory on this site for one reason only. The gap between "a number that ranks" and "a number that is real" is where this entire fraud lives, and somebody has to close it.
So every number carries the month we last verified it, and a line saying numbers can change and to confirm on the official site. We say where the number came from, and we link out to how we verify.
There is a second check on top of ours, and it is the part we trust most. Under each number there is a simple question: did this number work for you? Readers tap Yes, it connected or No, it didn't. When enough recent answers come back positive, the page says so plainly, "Works for most people who tried recently". That is not us claiming the number is good. That is people who dialled it this week telling you it rang.

It cuts both ways, which is the point. If a number stops working, the answers turn and we go and re-verify it. A directory that only ever tells you numbers are fine is a directory nobody is checking. We also say when a company has no phone helpline at all, instead of inventing one to fill the page, and if something on our site is wrong, write to us and we will fix it.

None of this replaces your own check. Before you dial anything about money, open the app or type the website address yourself. It takes twenty seconds, and it is the single habit that stops this scam from working.