A message saying your electricity connection will be disconnected tonight is designed to make you act before you think. In India, electricity-related scam messages have been documented in which fraudsters claimed a bill was unpaid, pushed victims to call a number on WhatsApp, and attempted to move the conversation toward malicious apps or payments. The Department of Telecommunications has specifically documented an electricity KYC-update scam and encouraged citizens to report suspected fraud communications through Sanchar Saathi’s Chakshu facility.

Why the electricity disconnection message works

The scam combines three powerful triggers: urgency, authority and a familiar service. A message may mention your consumer account, a late bill, a meter or KYC, then give a short deadline. The goal is not necessarily to steal money in the first SMS. The message is often the opening step that gets you to call a fraudster, install an APK, share an OTP or make a payment.

Free Resume Builder ATS-ready Banner 750x90

What a suspicious message usually looks like

  • A threat of immediate or same-day disconnection.
  • A request to call a mobile number instead of using your electricity provider’s official support channel.
  • A shortened or unfamiliar payment URL.
  • A request to install an APK or remote-access application.
  • Pressure to share an OTP, UPI PIN, card information or screen access.
  • Claims about KYC that you cannot verify inside the provider’s official app or website.

How to verify the bill without using the message

  1. Do not call the number in the SMS. Open your electricity provider’s known website or official app independently.
  2. Check the bill status there. Use your consumer number or account details through the normal login/payment flow.
  3. Compare the official contact details. If WhatsApp support is offered, start it from the provider’s own website rather than from the message.
  4. Never install an APK sent by a supposed electricity officer. The DoT’s documented electricity scam included malicious mobile applications.
  5. Never share a UPI PIN or OTP. A PIN authorizes transactions; it is not a tool for receiving a refund or verifying a bill.

How to verify an official WhatsApp Business account

A WhatsApp business label alone should not be treated as proof that a contact is your electricity provider. The safer test is independent verification: find the provider’s official website or app, open its support/contact section, and follow the WhatsApp link or number listed there. Compare the business identity, website and phone number before starting a conversation.

Also look at what the account asks you to do. A genuine support workflow may help you check a bill, raise a complaint or navigate an official payment process. A scammer is more likely to push urgency, ask you to move to another number, send an APK, request remote access or ask for security credentials.

What to do if you already clicked or called

  • Stop communicating with the number and do not follow further instructions.
  • If you installed an unfamiliar app, disconnect it from sensitive permissions and remove it; then review your banking and account activity from a trusted device if possible.
  • Change passwords that you disclosed and enable two-factor authentication.
  • If money was transferred because of cyber fraud, report it immediately through India’s cybercrime reporting channels and call 1930.
  • Report suspicious SMS or WhatsApp communications through the Sanchar Saathi Chakshu facility.

A 30-second verification checklist

Question Safe answer
Did the message give you a phone number? Ignore it and find the provider’s official number independently.
Does it demand immediate payment? Check the account in the official app/site first.
Does it ask for an APK? Do not install it.
Does it request an OTP or UPI PIN? Never share it.
Is WhatsApp the only verification channel? Verify the account from the provider’s official website.

Related PURSHOLOGY resources

For more practical security guidance, see our articles on fake UPI Collect requests, fake software update fraud, and SSH security mistakes.

Sources