Cybercriminals have grown so brazen that they are increasingly targeting high-profile financial leaders alongside ordinary citizens. Nilesh Shah, the managing director of Kotak Mahindra AMC who oversees a massive fund exceeding six lakh crore rupees, recently came close to becoming a victim of a cyber fraud attempt. Thanks to his timely alertness and presence of mind, Shah managed to evade the trap, successfully protecting his bank account and personal data from being compromised.
Nilesh Shah shared the entire incident on the social media platform X. The episode revolves around a sophisticated USSD code-based call forwarding scam. In this type of fraudulent activity, scammers trick users into dialing a specific code that diverts all incoming calls from the victim's phone to the fraudsters' number, ultimately giving them unauthorized access to bank accounts and private information.
Recounting his personal experience, Shah revealed that he initially received two missed calls followed by an unknown message. The message contained a 15-digit number (*21*8969849428#) and instructed him to call back immediately. Shortly after receiving this text, the fraudsters called him again, aggressively pushing him to dial the exact same number on his phone right away.
Sensing that something was amiss, Shah decided to investigate the matter rather than blindly following instructions. When he searched the number and format on the internet, the reality that came to light was shocking. Had he gone ahead and dialed that code, it could have resulted in severe financial damage.
How the Call Forwarding Service Operates
If Shah had mistakenly dialed that code, unconditional call forwarding would have instantly activated on his mobile device. Consequently, every single call landing on his number, including voice OTPs from banks, WhatsApp verification codes, and other sensitive communications, would have been directly transferred to the hackers. Utilizing this exploit, malicious actors can easily take over personal messaging apps and banking portals.
Precautions to Avoid Call Forwarding Scams
The most effective defense against such cyber frauds is to completely ignore unknown messages and suspicious calls, while avoiding any links sent by unverified numbers. If you or someone you know has inadvertently dialed such a code, immediately open your phone dialer and enter ##002#. This action will instantly deactivate all active call forwarding services on the device. To verify whether call forwarding is currently enabled on your phone without your knowledge, you can simply dial *#21# to check the current status.



















