
The Employees' Provident Fund Organisation (EPFO) has issued a public warning to its members regarding online security threats. According to reports from Business Standard, EPFO posted on X on 9 August 2026, urging all members to stay vigilant online and avoid fake links, verify URLs, and protect their personal information at all times. The organisation emphasized the importance of thinking before clicking on links, particularly given the increasing digital adoption of PF services. As reported by NDTV Profit, EPFO has specifically advised members to never provide anyone access to their UAN, password, OTP, PAN, Aadhaar, or bank information because the EPFO never asks for private information over the phone or over digital messages.
According to Business Standard, a common fraud method involves sending messages that appear to come from EPFO and ask members to click links to update KYC, activate UAN, check PF balance, or resolve account-related issues. The link may take users to websites that look similar to the genuine EPFO portal, with the objective of persuading users to enter their UAN, password, Aadhaar, PAN, bank details, or OTP. Members should never click on unverified links received through SMS, email, or social media and instead open the official EPFO website directly. As reported by NDTV Profit, the safer approach is to independently check the official EPFO website rather than depending on links received via emails or texts before using services.
According to Business Standard, fraudsters can copy the design of government websites and use web addresses that resemble genuine ones, making fake websites difficult to identify at first glance. Members should check the complete URL before entering their credentials, looking for misspellings, unusual domain names, extra words or characters in the URL, links that redirect to another website, and pages asking for information that EPFO normally does not request through such links. The organisation emphasizes that any links received via unknown messages, emails, or other unverified sources should be treated with caution, particularly if they ask users to provide sensitive information such as ATM PINs or OTPs. EPFO stresses the importance of checking website authenticity and creditworthiness before proceeding to avoid falling victim to phishing attempts.
As reported by Business Standard, EPFO has established six key guidelines for members to protect their personal information. The information that needs protection includes UAN and password, Pension Payment Order (PPO) details, Aadhaar number, PAN details, bank account information, and OTPs received during transactions or authentication. According to NDTV Profit, members should independently check the official EPFO website rather than depending on links they get via emails or texts before using services. EPFO's official fraud-prevention guidance states that its staff do not ask members for such information through calls, messages, WhatsApp, social media, or similar channels. The EPFO passbook portal carries a warning that members should not respond to calls asking for Aadhaar, PAN, bank details, or OTPs, and the organisation does not call members to ask them to deposit money.
As reported by Business Standard, members can report suspicious websites, messages, or phishing attempts through appropriate cybercrime or EPFO channels. The official member portal currently lists 14470 as the EPFO helpdesk number for assistance. EPFO has established clear reporting protocols for suspicious activities and emphasizes that it never asks for OTPs, personal information, or login credentials via phone calls, SMS, WhatsApp, social media, or email. Members can protect themselves from phishing scams by first verifying the website's legitimacy and trustworthiness before providing any personal information, treating OTPs as the final authentication step for transactions.