EPFO Cyber Fraud Alert 2026: PF Account Holders Warned Not to Share UAN, OTP or Bank Details
EPFO Cyber Fraud Alert 2026: The Employees' Provident Fund Organisation (EPFO) has warned provident fund subscribers about cybercriminals attempting to steal sensitive information through fake websites, fraudulent messages and suspicious links. Members have been advised to protect their Universal Account Number (UAN), passwords, OTPs, Aadhaar, PAN and banking details to prevent unauthorised access and potential financial fraud.
Millions of salaried employees across India rely on their Employees' Provident Fund (EPF) accounts to build retirement savings. With more PF-related services becoming available online, members can check their balances, update personal information and submit withdrawal claims digitally.
However, this convenience has also created opportunities for cybercriminals who impersonate EPFO officials and attempt to obtain confidential information.
According to a report published on October 8, 2026, EPFO has issued a security advisory through its official social media platform, X, urging members to remain cautious while accessing online PF services.
EPFO Issues Important Warning to PF Account Holders
The latest advisory highlights the risks associated with sharing sensitive account information through unverified communication channels.
Fraudsters may contact individuals through phone calls, WhatsApp messages, SMS, emails or social media platforms while pretending to represent EPFO.
These messages may claim that a PF account needs urgent verification, a withdrawal request is pending or an account will be blocked unless certain details are provided.
Such claims can pressure unsuspecting users into clicking malicious links or revealing confidential information.
EPFO has advised members to use only its official platforms for accessing provident fund services and to avoid responding to suspicious requests for personal details.
Importantly, receiving a suspicious message does not necessarily mean that an EPF account has been compromised. The primary concern is preventing fraudsters from obtaining information that could enable unauthorised activity.
Never Share These Details With Unknown People
EPFO has specifically cautioned subscribers against disclosing sensitive personal and financial information.
| Information |
Why It Must Be Protected |
|---|---|
| UAN (Universal Account Number) |
Identifies the member's EPF account |
| OTP (One-Time Password) |
Used to authorise verification and transactions |
| EPFO Login Password |
Protects access to online member services |
| Aadhaar Number |
Sensitive identity information that can be misused |
| PAN Details |
May be exploited in identity-related fraud |
| Bank Account Information |
Can be used in financial scams |
| PPO Number |
Sensitive pension-related identification information |
Members should enter necessary details only on verified official portals and should never disclose passwords or OTPs to callers, agents or unknown individuals.
EPFO Does Not Ask for OTP or Password Through Calls and Messages
One of the most important points in the advisory concerns fraudulent communication.
EPFO has clarified that it does not ask members to reveal personal credentials, passwords or OTPs through phone calls, WhatsApp, SMS, social media or emails.
Therefore, if someone claims to be an EPFO employee and asks for an OTP or login password, the request should be treated as suspicious.
Fraudsters may use convincing language, official-looking logos and fabricated identification details to appear genuine.
Some may even claim that a member's PF withdrawal will be rejected or that the account will be frozen unless immediate action is taken.
Members should not share confidential information simply because a caller appears to know their name, employer or UAN.
How Do EPFO Cyber Fraud Scams Work?
Cybercriminals may use different techniques to target PF subscribers.
1. Fake EPFO Websites
Scammers create websites resembling official EPFO portals. These pages may contain similar colours, logos and login forms.
When users enter their UAN, password or other personal details, the information may be captured by criminals.
2. Fraudulent SMS and WhatsApp Messages
Members may receive messages claiming that their PF balance is blocked or that an urgent KYC update is required.
Such messages often contain suspicious links designed to redirect users to fraudulent websites.
3. Fake PF Withdrawal Assistance
Some fraudsters promise quick PF withdrawals or faster claim approvals in exchange for personal information or advance payments.
Subscribers should be cautious of anyone offering guaranteed claim approval or asking for confidential credentials.
4. OTP and Identity Verification Scams
A scammer may pretend to verify a member's identity and request an OTP.
Sharing this code can allow criminals to complete an unauthorised verification or account-related action, depending on the service involved.
How to Protect Your EPF Account From Cyber Fraud
EPFO members can reduce their exposure to online scams by following these precautions:
-
Use the official EPFO website: Visit www.epfindia.gov.in for authentic information and access to official services.
-
Avoid suspicious links: Do not open unknown links received through SMS, WhatsApp, email or social media.
-
Protect your credentials: Never disclose UAN login passwords or OTPs to anyone.
-
Verify website addresses: Carefully check domain names before entering sensitive information.
-
Avoid sharing banking information: Do not provide bank account details to unverified individuals claiming to represent EPFO.
-
Monitor your PF account: Periodically review account information and claim activity through official channels.
-
Report suspicious activity: Inform the appropriate authorities if you encounter phishing attempts or fraudulent requests.
Members should also be cautious about downloading unofficial applications that claim to offer EPFO services.
How to Check Your PF Account Safely
EPFO subscribers can access official online services without relying on unknown third-party websites.
The general process is:
-
Open the official EPFO website.
-
Navigate to the relevant member service or official portal.
-
Verify that the website address belongs to the authorised EPFO domain.
-
Enter your credentials only on the legitimate login page.
-
Complete any required authentication without sharing the OTP with another person.
-
Review your account information and log out after finishing.
Members may also use supported services through the official UMANG application.
What Should You Do if You Have Already Shared Your OTP or Password?
If you suspect that your EPFO credentials have been exposed, immediate action can help reduce the risk of further misuse.
First, change your EPFO account password through the official member portal if you can still access the account.
Next, review your registered mobile number, bank details and recent claim activity for unexpected changes.
If banking credentials have also been compromised, contact your bank immediately to secure the affected services.
Victims of suspected cybercrime can report incidents through India's official National Cyber Crime Reporting Portal.
For urgent financial cyber fraud, individuals can also contact the national cybercrime helpline at 1930.
Members facing EPFO-related account issues can seek assistance through the organisation's official grievance portal, EPFiGMS.
Can Fraudsters Withdraw Your PF Money Using Only Your UAN?
Knowing someone's UAN alone does not ordinarily provide direct access to their PF savings.
EPFO services use additional authentication and verification measures for account access and eligible transactions.
However, a UAN combined with stolen passwords, OTPs, identity documents or other sensitive information may increase the risk of account misuse.
This is why EPFO encourages members to protect all confidential details rather than relying on a single security measure.
Final Reminder for PF Subscribers
EPFO's reported October 2026 advisory serves as an important reminder that retirement savings require digital security as well as financial planning.
Fraudsters may use fake EPFO websites, misleading messages and impersonation tactics to obtain confidential information from unsuspecting members.
The key warning is simple: EPFO does not ask subscribers to disclose OTPs, passwords or sensitive login credentials through phone calls, WhatsApp messages or social media.
PF account holders should rely on official websites, verify every suspicious communication and report attempted fraud promptly. Protecting personal information is one of the most effective ways to keep provident fund accounts secure.