KBC digipass reply YES: scam or real?

First assess what is being requested, which channel was used and what has already happened. Do not use the received link or imposed phone number as the verification channel.

Information updated : 2026-09-10

Critical risk - Point de vigilance : The fraudster is trying to capture a sensitive validation.

Editorial Trust

Last update
2026-09-10
Sources checked
2026-09-17
Content status
information published with visible sources and clear limits
Official sources cited
5
Editorial responsibility
StopArnaques

StopArnaques is an independent Belgian service. It is not a public authority and does not speak on behalf of the organisations cited.

Report a correction

Analysis of the case described

  • Replying YES or using a digipass is not a harmless formality. The code produced can authorise a login or an operation prepared by a third party.
  • The KBC name and the reader wording do not make it possible to know where the message came from; control must come from the app and the official numbers.

How the scam works

  • Bank impersonation combines an alarming alert and an immediate instruction: reply, call back, log in or confirm an operation.
  • The number or name shown can be copied; the validation requested can authorise the very operation the fraudster claims to be cancelling.

Why it is dangerous

  • The fraudster is trying to capture a sensitive validation.

Warning signs

  • Digipass or reader
  • Reply YES
  • Urgent block or transfer

What a legitimate service would do

  • The request is checked after hanging up, in the banking app or using the official number.
  • A bank does not ask you to move your savings to a safe account or to share a secret code.

Verification protocol

  • Do not reply and do not generate any code. Open the KBC app yourself.
  • Call the bank using the number published on its card or website and describe the wording you received.

What to do now

  • Do not send any code or validation.
  • Check in the KBC app or via kbc.be typed in manually.

If I already clicked

  • Contact the bank using the official number.
  • Watch for transfers and device confirmations.

What this sheet allows us to say

  • The wording "KBC digipass reply YES" is a search clue, not enough proof by itself. The number, domain, beneficiary and requested action must be checked together.
  • This sheet describes a defensive method. It does not attribute a message to a person or organisation without verified evidence.

How to use the sources on this sheet

  • The references selected for "KBC digipass reply YES" cover the method, the service being claimed and the protection steps. They should be read for the procedure they document, not as automatic proof that every similar message belongs to a confirmed campaign.
  • For the alert "KBC digipass reply YES", the first three references are: Febelfin - Phishing ; Febelfin - Fake bank technical support fraud ; Bancontact Payconiq Company - Together against payment fraud. Each link is checked separately and an inaccessible source must be removed or replaced.

What would confirm or weaken the risk

  • The risk is stronger if several signs come together: digipass or reader; reply yes; urgent block or transfer. An irreversible action, an external domain or an unknown beneficiary carry more weight than a simple language mistake.
  • For "KBC digipass reply YES", the risk is weaker if the same request, with the same reference and the same action, is found in the official space opened manually. This match must be checked without using the link, number or QR code received.

Limits of this page

  • This page does not prove that a message is safe and does not replace your bank, the police, Safeonweb, a platform or a public service.
  • A scam may be new, very well written or described with too little context. Use the result as decision support, not as absolute certainty.
  • Before taking a final action, checking through the official channel matters more than the appearance of the received message.

Check through an official channel

  • Type the service address yourself or open the official app. Do not use a phone number, link or QR code from the suspicious message to verify the situation.
  • When money, card details, a code or account access are involved, the safety action comes first. The analysis can then help organise the evidence.

How to read the result

  • A low number of signals does not mean that everything is safe. It only means that this page or analysis did not find decisive evidence with the information available.
  • Focus on the requested action: paying, sharing a code, installing an app, approving a bank action or leaving an official platform. That action matters more than a logo, sender name or polished wording.
  • If the situation feels urgent, step away from the received message first. Then check calmly through a channel you already trusted before the message arrived.

Belgian reading of this situation

  • For this kbc digipass reply yes situation, focus on the relevant Belgian next step: open the official channel yourself, contact the bank, use Safeonweb or preserve evidence.
  • The right decision for this kbc digipass reply yes situation depends on what has already happened. Reading a message is not the same as clicking, paying, sharing a code or granting remote access.

Frequently asked questions

Does the bank name prove that the message is genuine?

No. Sender names, phone numbers and banking terms can be imitated. Open the banking app yourself or call the number printed on your card.

Should I use my card reader or digipass to cancel the fraud?

Not when instructed by an unexpected message or caller. A generated code may actually approve a login or transaction.

What should I do after sharing a code or approving an action?

Call your bank immediately through its official number. Ask it to review and, where necessary, block access, devices, beneficiaries and transactions.

Am I safe if no debit appears yet?

Not necessarily. Ask the bank to check new beneficiaries, devices and pending approvals as well.

Useful official sources

Test another suspicious message

Search for similar campaigns