New Delhi: Sending sensitive documents such as PAN cards, Aadhaar cards and bank statements over WhatsApp may appear convenient, particularly when a bank, financial adviser, broker, employer or service provider asks for documents for verification. However, sharing such information without checking who is requesting it and how it will be stored can expose people to privacy breaches, unsolicited financial scams and even identity theft.

The concern becomes more serious because these documents contain information that can be used to establish a person’s identity and, when combined with other details, potentially facilitate fraudulent activity. The scale of financial fraud in India underlines why consumers need to be particularly cautious when sharing KYC documents digitally.

The Reserve Bank of India’s Annual Report for 2024-25 recorded 23,953 banking fraud cases involving ₹36,014 crore, highlighting the financial risks facing consumers.

Why PAN and Aadhaar documents are sensitive

A PAN card contains a person’s name, photograph, date of birth and Permanent Account Number. Aadhaar contains identity information linked to an individual’s Aadhaar number.

Individually, these documents are important identification records. When combined with other information such as a mobile number, address, bank details or financial statements, however, they can provide a much more comprehensive profile of an individual.

This is why consumers should avoid treating a request for a PAN or Aadhaar copy as an ordinary document-sharing exercise.

Before sending anything, it is important to establish who is requesting the document, why it is required and whether there is a safer official channel for submitting it.

Bank statements reveal more than account balances

Bank statements can be particularly sensitive because they contain information about a person’s financial activity.

Depending on the statement, it can reveal account details, transaction dates, payment recipients, merchants, salaries, loan repayments and other spending patterns.

A scammer who obtains a bank statement along with identity documents could potentially use the information to make fraudulent approaches appear more convincing.

For example, someone possessing details of a recent transaction could pose as a bank representative or financial service provider and use that information to make a fraudulent call or message appear legitimate.

WhatsApp is convenient but not automatically a secure document portal

WhatsApp is widely used in India for communication and file sharing. Its convenience can make it tempting to send KYC documents through a chat window.

However, the key question is not simply whether a messaging platform offers encryption. The bigger concern is what happens to the document after it reaches the recipient.

Once a copy of a PAN card, Aadhaar card or bank statement has been sent, the sender may have limited control over where that file is stored, whether it is forwarded, how long it is retained or who ultimately gets access to it.

That is why consumers should distinguish between communicating with a trusted contact and submitting sensitive documents through an organisation’s official, controlled KYC process.

Verify who is asking for the documents

One of the most important precautions is to independently verify the identity of the person or organisation requesting the information.

A message saying that documents are urgently required should not automatically be trusted.

If someone claiming to represent a bank, lender, broker or financial company asks for KYC documents through WhatsApp, customers should contact the organisation through its official website, app or customer-care channel and confirm the request.

This is particularly important when the message contains pressure tactics such as:

  • “Send the documents immediately.”
  • “Your account will be blocked.”
  • “Your KYC will expire today.”
  • “Your loan will be cancelled.”
  • “Your investment account will be suspended.”

Urgency is frequently used to discourage people from verifying a request.

Be careful with unsolicited WhatsApp messages

An unexpected WhatsApp message asking for identity or financial documents should be treated with caution.

Fraudsters can impersonate banks, insurance companies, investment platforms, loan providers and government agencies.

A professional-looking profile picture or company logo does not establish that the person is genuine.

Consumers should avoid clicking unfamiliar links sent along with such requests and should independently locate the organisation’s official website or application rather than using a link provided by an unknown sender.

Identity theft is a major concern

Personal information can become valuable to criminals because it can be combined with information obtained from other sources.

The consequences can range from targeted scam calls and phishing attempts to more serious forms of identity fraud.

A person who has access to several documents may know enough about a potential victim to make a fraudulent communication appear legitimate.

For this reason, sharing sensitive documents should be based on necessity and verification, rather than convenience.

Do not send unnecessary documents

Another useful precaution is to ask whether the requested document is actually necessary.

If an organisation asks for multiple documents, consumers can ask why each one is required and whether an alternative form of verification is available.

There is little reason to provide additional sensitive information simply because it has been requested.

The principle should be simple: share the minimum information necessary for the legitimate purpose.

Add a watermark before sharing copies

When a document copy genuinely needs to be shared, consumers can consider adding a visible watermark indicating the intended purpose.

For example, a copy could be marked with text such as “For KYC verification only – [organisation name] – [date]”.

A watermark does not make a document impossible to misuse, but it can make unauthorised reuse more difficult and clearly communicate the original purpose of the copy.

Consumers should ensure that the watermark does not obscure essential information needed for legitimate verification.

Never share OTPs or passwords along with documents

A legitimate KYC process may require identity documents, but consumers should be extremely cautious if someone simultaneously asks for an OTP, PIN, password or other authentication credential.

These credentials are fundamentally different from identification documents.

An OTP is designed to authenticate a transaction or login and should not be disclosed to another person merely because they claim to be helping with KYC.

The same applies to debit-card PINs, internet-banking passwords and other account credentials.

Check the destination before pressing send

A common mistake is sending a document to the wrong WhatsApp contact.

Before sharing a file, users should check the recipient’s phone number and confirm that it belongs to the intended organisation or person.

This is particularly important when multiple contacts have similar names.

A sensitive PDF or photograph sent to the wrong person can be difficult to recover.

What to do if you have already shared the documents

If sensitive documents have already been sent to a suspicious or unverified contact, the person should not panic but should act quickly.

The first step is to establish exactly what information was shared and with whom.

If banking information may have been compromised, the individual should contact the bank through its official channels and monitor the account for unusual activity.

Any suspicious calls, messages, payment requests or account activity should be treated seriously.

People should also avoid providing additional information if the recipient subsequently contacts them asking for OTPs, passwords or money.

Financial fraud remains a serious concern

The RBI’s banking-fraud figures provide an important backdrop to the warning.

The 23,953 fraud cases involving ₹36,014 crore during 2024-25 demonstrate the scale at which financial fraud affects the banking ecosystem.

Not every fraud involves stolen identity documents, and sharing a document over WhatsApp does not automatically mean that a person will become a victim.

However, limiting unnecessary exposure of personal and financial information is an important part of reducing the opportunities available to scammers.

Convenience should not come before security

Digital communication has made KYC and financial paperwork much faster.

Documents that once had to be photocopied and physically submitted can now be sent within seconds.

But that convenience also makes it easier for sensitive information to be shared without sufficient verification.

Consumers should therefore pause whenever a request involves PAN, Aadhaar, bank statements or other financial records.

A few minutes spent verifying the recipient can be far less costly than dealing with the consequences of identity or financial fraud.

Conclusion

PAN cards, Aadhaar cards and bank statements contain highly sensitive personal and financial information, so consumers should think carefully before sending copies through WhatsApp or other informal channels. The concern is not simply the messaging platform itself, but also the identity of the recipient, how the documents will be stored and whether they could subsequently be misused.

The safest approach is to verify the request independently, use an organisation’s official KYC or document-upload channel whenever available, share only what is necessary and never disclose OTPs, PINs or passwords.

With the RBI recording 23,953 banking fraud cases involving ₹36,014 crore in 2024-25, protecting personal information has become an increasingly important part of financial security.