Stories

FlexiLoans’ Unsolicited “Loan Approved” SMS: Harassment That Breaches RBI And TRAI Rules

FlexiLoans’ Fake “Loan Approved” SMS: How an RBI-Registered NBFC Harasses Customers and Breaks the Rules

A man receives a text message on his phone. It says his loan application has been approved for ₹27 lakh. He checks his records and finds he has applied for no loan recently. Confused and disturbed, he calls the company. The agent confirms there is no active approved application. The message, the agent suggests, might have been a “proposal” SMS that the company does send to people. Now, imagine you being that customer, who is suddenly thrown in an unsolicited SMS, offering you a 27 lakh loan. This is nothing but violation of RBI guidelines. 

This is not an isolated incident. It is a pattern that thousands of Indians encounter from digital lenders, like FlexiLoans, an RBI-registered Non-Banking Financial Company. Unsolicited SMS messages declaring that a loan has been “approved” arrive without any recent application, without explicit consent for marketing, and often on numbers registered under the Do Not Disturb (DND) facility. These messages are not ‘just’ harmless promotions. They are a form of harassment that breaches clear rules laid down by the Reserve Bank of India and the Telecom Regulatory Authority of India.

Under the joint Digital Consent Acquisition framework of the RBI and TRAI, financial entities must obtain explicit, verifiable and revocable digital consent before sending promotional content. A customer cannot be assumed to have given blanket permission simply because they once interacted with the company or filled an old form. Every marketing communication requires specific consent that the customer can review and withdraw. When FlexiLoans or similar lenders broadcast “loan approved” texts without that consent, they are operating outside the regulatory framework.

The violation becomes more serious when the recipient’s number is on the National Customer Preference Register (NCPR), commonly known as DND. TRAI’s Telecom Commercial Communications Customer Preference Regulations, 2018, prohibit promotional SMS and calls to registered DND numbers. Sending marketing messages about loans or credit products to a DND-registered customer is a direct legal breach and attracts corporate penalties. Yet customers continue to report receiving FlexiLoans messages on numbers they deliberately registered for protection. The system designed to shield citizens from commercial spam is being ignored.

These messages are frequently misleading in content as well as unsolicited in delivery. The RBI Fair Practices Code requires transparency and honesty in the offering of financial products. A text that announces a loan as “approved” without any current application, KYC process or formal request creates a false impression of legitimacy and urgency. Regulators have identified such formats as deceptive bait tactics. The recipient is pushed to click a link, share personal details or enter a lending funnel they never sought. For many people the sudden appearance of an approval message triggers anxiety, the fear that their data has been compromised, or the temptation to engage out of confusion.

Technical rules are also routinely sidestepped. The RBI has directed regulated institutions to separate marketing communications from transactional ones. Promotional SMS and calls must use the 140xx number series. Service and transactional messages must use the 1600xx series. When messages arrive from non-compliant identifiers, accountability is further diluted and reporting becomes harder.

r/IsThisAScamIndia - I got this sms on loan approval from flexi loan amount of 2500000!

Similar experiences appear regularly on public forums. Reddit threads show users receiving identical “loan approved” texts from FlexiLoans and asking whether the messages are genuine or a scam. Many report that they never applied, that their numbers are on DND, or that previous interactions were limited and long past. The common thread is the absence of consent and the presence of pressure tactics dressed up as good news.

FlexiLoans is an RBI-registered entity. That status brings obligations, not exemptions. Registration does not grant permission to ignore consent requirements, DND registrations or the Fair Practices Code. When an NBFC sends unsolicited “loan approved” messages, it is not innovating in customer outreach. It is breaching the rules written precisely to prevent this behaviour.

Customers are not powerless. Those receiving such messages on DND numbers can file complaints through the TRAI DND app or portal, attaching screenshots and sender details. Complaints can also be escalated to the RBI’s consumer education and protection mechanisms. Persistent violations by regulated entities are supposed to attract scrutiny and penalties. The continued volume of reports, however, suggests that enforcement remains uneven and that the practice continues with limited consequence.

The deeper problem is cultural as much as regulatory. Too many digital lenders treat customer data as a free marketing resource and treat consent as an optional formality. The result is an environment in which ordinary people cannot protect their own phone numbers from commercial bombardment. When even DND registration fails to stop the messages, the privacy safeguards that citizens rely on are shown to be porous.

r/IsThisAScamIndia - I got this sms on loan approval from flexi loan amount of 2500000!

Unsolicited “loan approval” SMS from FlexiLoans and similar players are illegal under the combined RBI-TRAI framework when sent without explicit consent. They violate DND protections. They often use misleading language prohibited by the Fair Practices Code. And they frequently arrive through technical channels that the RBI has restricted. For the recipients, the experience is intrusive, unsettling and a reminder that their personal space is still being treated as fair game. Until regulators enforce the existing rules with real consequences, the unwanted messages will keep coming — and the privacy and peace of mind of ordinary customers will continue to be breached one SMS at a time.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button