Demat account fraud and scams

Updated 16 August 2026 · 11 min read · Written and reviewed by the DematOpen team

The plain answer

Demat fraud almost never breaks the system; it breaks the person. The scams run on four stolen things: the OTP, the TPIN, remote access to your phone, and trust in a caller. Every scam in this page asks you to hand over one of those four, and every one of them collapses the moment you refuse.

The protection is not technical; it is two rules. Never share codes, and never install software for a caller. The rest of this page shows the scams those two rules defeat, the tells that expose each one, and the exact recovery sequence if one already landed.

Why these scams work

The scams succeed because they borrow three powers that legitimate processes actually have. Authority: the caller speaks as the broker, the depository or the regulator, and the vocabulary is right. Urgency: the caller’s story always has a deadline, a suspended account or an expiring KYC, because urgency is what stops the mark from hanging up and checking. Knowledge: the caller knows your name, and sometimes your holdings, because data leaks and data brokers supply exactly that.

The borrowed powers are all fake. Genuine brokers do not reach you through cold calls; they reach you in the app and at your registered email. Genuine processes have timelines, not five-minute deadlines. And knowing your name proves only that the caller bought a list, not that they represent anyone. The scams work on the gap between how authority feels and how it actually behaves, and closing that gap is the whole skill this page teaches.

One more mechanic explains the success rate: each scam asks for a small thing first. An OTP is six digits. Installing an app is one click. The small thing is the whole scam, because the small thing is the credential, and the credential is the account. Refusing the small thing ends the scam at its first step.

The scam list

ScamHow it worksThe tell
OTP theft by callA “support” caller claims an issue needs your OTPReal support never asks for OTPs
Remote-access fraudA caller walks you through installing AnyDesk or similarNo genuine broker uses remote-access apps
Fake support numbersSearch results show a paid number that connects to fraudstersThe only safe number is on the broker’s website
TPIN phishingA “verification” call asks for your 6-digit TPINThe TPIN is entered only by you, in the app, at a debit
KYC-expired phishingA link or PDF claims your KYC is suspendedThe link harvests credentials; KYC issues come in the app
Tip-group schemesA WhatsApp or Telegram group offers “sure” calls or returnsRegistered advisers publish credentials; groups do not

The OTP scam is the most common and the cheapest to run. The caller claims to be from the broker, mentions a real-sounding problem, a failed debit or a security check, and asks you to read back the OTP that just arrived. The OTP is the second factor that authorises the action; handing it over is signing the transfer the scammer is entering in parallel on their screen.

Remote-access fraud is the most damaging per incident, because it hands over the whole device, not one code. The caller poses as support for a refund, an account upgrade or a technical fix, and walks you through installing a screen-sharing or device-control app. From there the scammer reads the OTPs as they arrive, changes passwords and clears the account, all while the legitimate screen confirms their actions.

The remaining rows are variations on one pattern. Fake support numbers harvest search-engine users who type “broker customer care” into a search box and call the first paid result, which rings a fraudster with the broker’s name on the line. TPIN phishing asks for the demat authorisation code instead of the login OTP. KYC-expiry phishing pushes a link or a PDF that claims the account is frozen, and the link harvests the credentials that the app would never ask for over a message. Tip-group schemes skip the account entirely and ask for money: a WhatsApp or Telegram group with a “premium” channel whose sure-shot calls exist to dump stocks on the group.

The tells that give them away

Every scam on the list carries at least one of four tells, and recognising a single tell is enough to end the call. The first is urgency: real processes have timelines, scammers have deadlines. A genuine freeze, dispute or verification never expires in the five minutes the caller grants you.

The second is the ask. A request for an OTP, TPIN, password or remote-access install is never legitimate, in any combination and under any claimed reason. No genuine institution needs you to reveal an authorisation code, because the entire design of those codes is that only you enter them.

The third is the channel. Genuine brokers reach you through the app and your registered email; cold calls, WhatsApp forwards and paid search results are the scammer’s mediums. The fourth is the payment path: a request to send money to a personal account, a wallet or a “verification transfer” is the endgame of every scheme, because legitimate fees are debited from the trading account, never routed through a stranger’s UPI ID.

One tell is enough to end the conversation; two make it a certainty. The skill is not scepticism of everyone; it is knowing that genuine institutions never need the four things scammers ask for.

If you are already a victim

The recovery sequence is the same for every scenario, and the order matters, because damage continues while credentials remain in the scammer’s hands.

StepActionWhy this order
1Reset the login password from the app, on your own deviceCuts session access
2Reset the TPIN the same wayCuts the ability to move shares
3Ask the broker to freeze trading and debitsStops further movement during the investigation
4Review holdings and the ledger for unauthorised activityBuilds the timeline the complaint needs
5Report to the broker’s grievance channel the same dayStarts the broker lane and the escalation clock
6If money moved, call 1930 and file on cybercrime.gov.inStarts the police lane that can freeze the money trail

The police lane deserves its own detail, because it is where money actually gets frozen. 1930 is the National Cyber Crime Helpline, run by the Ministry of Home Affairs around the clock. Calling it immediately lets the Citizen Financial Cyber Fraud Reporting and Management System alert the banks involved, which can freeze the receiving account before the money is withdrawn. File the full complaint on the cybercrime.gov.in portal and keep the acknowledgement number; the earlier both steps happen, the better the odds on the money trail.

The financial lanes run in parallel, not in sequence. Report the unauthorised transactions to the broker’s grievance channel, and escalate to the depository or SEBI SCORES if the response is unsatisfactory. The broker lane can freeze and in some cases reverse within the system; the police lane chases what left it. Both lanes only move once informed, which is why steps five and six come on day one, not after the audit is comfortable.

Why regulators keep warning

SEBI and the exchanges run repeated investor-awareness campaigns on exactly these scams, because the loss pattern is constant: credentials handed over voluntarily, positions liquidated, money gone before the victim opens the app. The regulator can mandate two-factor authentication and TPIN authorisation; it cannot mandate refusal. The campaigns exist because the human layer is the only layer the system cannot patch.

The regulator’s enforcement history also explains why the broker-side rules keep tightening. The Karvy episode of 2019, where client securities were pledged without authorisation, and similar cases after it, led SEBI and the exchanges to harden the client asset rules: client funds now upstream to the clearing corporation daily, and securities pay out directly to client demat accounts. The institutional side has been patched, repeatedly. The credential side cannot be patched by regulation, which is why the warnings keep pointing at the same two habits.

Treat every warning as the same sentence in different clothes: the regulator protects what you hold, the exchanges guarantee what you trade, and only you control what you reveal. The scams on this page are the only remaining attack surface, and they require your cooperation to work.

What people usually get wrong

The depository system can be hacked through my account

The institutional layers hold. The breach path is the credential: what you share, what you install, what you type on a caller’s instruction.

Smart people do not fall for these

The scams exploit urgency and authority, not intelligence. Doctors, engineers and bankers populate the complaint files.

Reporting after a loss is pointless

The report starts the reversal and the investigation. The broker, the depository, SCORES and the police each have a lane, and the lanes only move when informed.

The caller knew my details, so they were genuine

Names, numbers and holding values circulate through leaks and data brokers. Verification runs in one direction only: you call the broker’s published number, never the number that called you.

Questions people ask

Never. OTPs authorise actions and are for you to enter, not to speak. Any caller asking for an OTP, a TPIN or a remote-access app install is a scam in progress, whatever they claim the reason is.

Act in this order: reset the login password and the TPIN from the app on your own device, check the holdings and ledger for anything you did not authorise, and report the incident to the broker’s grievance channel the same day. If money moved, also call the cybercrime helpline 1930 and file on cybercrime.gov.in. Speed is the only recovery tool that works.

Hang up and call the number published on the broker’s website. Genuine support is reachable in the app and on the official site; incoming calls are the scammer’s medium. The number that called you proves nothing, and the details the caller knows about you prove even less.

No. No genuine broker support requires AnyDesk, TeamViewer or screen sharing to help you. A request to install remote-access software is the strongest single signal of fraud in this entire list.

1930 is the National Cyber Crime Helpline, run 24 hours a day by the Ministry of Home Affairs. Call it immediately after any financial fraud; the system alerts your bank and the receiving bank to freeze the flow of money. Then file the details on the cybercrime.gov.in portal and keep the acknowledgement number.

Partially, in parallel lanes. The broker, the depository and SEBI SCORES can freeze and investigate what passed through the trading system, while the police cybercrime lane pursues the money trail. Reporting to all of them, fast, is what gives recovery its chance; money that moved out of the banking system weeks ago is far harder to trace.

Sources