
Scam watch
The fake APK on WhatsApp: how one file empties a bank account
· 5 min read
Reviewed by Adv. Mahir Gupta, Advocate, Delhi High Court ·
On 5 October 2026, PTI reported that the Mumbai Crime Branch had arrested a 36-year-old software developer from Madhya Pradesh. Police allege that he built 2,805 malicious Android application files (APKs) and sold them to cybercriminal gangs. The accused has not been convicted, and the case is still under investigation.
The numbers in the police account are large. Officials put the identified loss at about ₹15.75 crore. They linked the files to at least 9,673 people across India. Analysis of complaints on the national helpline 1930 tied the apps to 1,074 complaints, including 143 in Maharashtra, and 88 cases have been registered across the country so far. Police also say they suspect the true loss may be far higher, but that is an investigative estimate and not a traced figure.
The case began with one complaint. A 72-year-old resident of Byculla lost ₹5.62 lakh on 13 August. A caller posing as a senior bank official sent a file named "Senior Citizen Card Verification.apk" on WhatsApp, saying it was needed to issue a card for the elderly. The victim was then pressed to enter personal details and debit card information.
This is the pattern to understand. The fraud does not begin with a hack. It begins with a phone call or message that creates a reason to act: a card to be issued, a bill to be cleared, a document to be verified. The file that follows is presented as the official way to do it.
An APK is the installation file for an Android app. Phones normally install apps from the Google Play Store, which screens them. A file received on WhatsApp bypasses that screening, and Android asks the user to allow installation from an unknown source. Once the user agrees, the app can ask for sensitive permissions.
The Indian Cyber Crime Coordination Centre (I4C), under the Ministry of Home Affairs, has issued a related warning. In an advisory issued on 26 August 2026 by its National Cybercrime Threat Analytics Unit, about malicious Android apps promoted on social media (the advisory concerned apps disguised as adult content, not this case), it said such apps may request accessibility permissions. With those permissions, the app can gain control of the device and enable unauthorised financial transactions. The same warning applies to any APK received from an unknown source.
The warning signs are consistent. The caller or message creates urgency, such as a disconnection, a blocked account or a deadline. The sender asks you to install a file rather than open an official app or website. The file arrives on WhatsApp, SMS or Telegram, not from a store. Its name sounds official, for example a verification, a card or a pension document. After installing, the app asks for accessibility permission, or asks you to enter card details or an OTP.
Some simple habits break the chain. Install apps only from the Google Play Store or another trusted store. Never install an APK sent to you, whatever the reason given. Never grant accessibility permission to an app you do not recognise. If a message claims to come from a bank, gas company or government office, close it and open the organisation's own app or website yourself, or call the number printed on your bill or card. Keep Google Play Protect switched on, and review your installed apps from time to time.
If you have already tapped install, treat the first hour as the most important. First, call 1930, the National Cyber Crime Helpline, and then file a complaint at cybercrime.gov.in. Reporting quickly gives the authorities a chance to ask banks to hold the money, though no one can promise that any amount will be recovered. In the 2025 figures reported by ThePrint from MHA data, Indians lost at least ₹22,495 crore to cybercrime across 28.15 lakh cases.
Second, call your bank on its official number and ask it to block the cards, UPI and net banking linked to that phone. Third, disconnect the phone from mobile data and Wi-Fi, so that a remote controller loses access. Fourth, from a different, clean device, change the passwords of your email, banking and UPI apps. Fifth, do not factory-reset the phone yet. Take screenshots of the file, the chat, the caller's number and any messages from your bank, because they are evidence.
On the law, the conduct described here falls under several provisions. Cheating is defined in BNS S. 318(1). Where the cheating dishonestly induces a person to hand over property, BNS S. 318(4) provides imprisonment of up to seven years and a fine. Pretending to be someone else, such as a bank official, is cheating by personation under BNS S. 319, punishable with imprisonment of up to five years, a fine, or both. Using a communication device or computer resource to cheat by personation is also an offence under IT Act S. 66D, with imprisonment of up to three years and a fine of up to ₹1 lakh. Which sections apply in a particular case is for the police and the courts to decide.
For families, the people most often targeted are older relatives. The Byculla case began with a "senior citizen card", which was chosen to sound routine and official. A short conversation at home helps: a genuine bank, gas company or government office does not ask you to install a file sent on WhatsApp. If someone does, the correct response is to stop and call a family member or 1930.
For small businesses, one infected phone can hold the UPI app, the email account and the WhatsApp used for customers. Staff who handle payments should be told the same rule, and company phones should not allow installation from unknown sources.
Codesnag × VirtualVakil works on cyber protection and response in India. If you suspect an infected phone, the steps above come first, and 1930 and the police are always the first call.
This article reports allegations made by the police and reported by the press. It is general information, not legal advice, and no victim is identified.
Sources
- ThePrint (PTI): Software developer held from MP in Rs 15.75 crore nationwide cyber fraud
- The420.in: Mumbai Crime Branch APK fraud ecosystem (updated 5 October 2026)
- Asianet Newsable: I4C advisory on malicious Android apps promoted on social media (26 August 2026)
- ThePrint: Cybercrime saw 24% spike in 2025, Indians lost Rs 22,495 crore
- Devgan: BNS Section 318 (cheating)
- Devgan: BNS Section 319 (cheating by personation)
- LawX: IT Act Section 66D
Need help with a cyber crime? Cyber Surety is a cyber-safety membership by Codesnag × VirtualVakil: ethical hackers and lawyers on your case, 24×7 on WhatsApp. Or read how to file a cyber crime complaint.

