Bank Security Tip: Avoid APK File Scams to Stay Safe from Cyber Fraud
An 85-year-old retired engineer in Pune has allegedly lost ₹3 lakh to cyber fraudsters who deceived him by claiming to reactivate his net banking facility.
Case Study: The Pune Cyber Fraud Incident
Authorities reported that scammers created a counterfeit website mimicking a public sector bank’s official portal to target the victim. Posing as bank representatives, they transmitted a malicious APK file and persuaded him to disclose personal and financial information. Within hours of submitting the data, two unauthorized transactions drained ₹3 lakh from his account.
The Fraudulent Scheme Unveiled
The victim, a retired government agency engineer from Uttarakhand, resides in Pune’s Kharadi neighborhood. His online banking access, linked to a public sector bank account, had been suspended in December 2025, prompting him to seek restoration methods. During February 2026, while using a social media platform, the individual encountered a link appearing to connect to the bank’s official site.
After accessing the page, he received a call from an individual impersonating a bank employee. The caller assured rapid reactivation of services and requested completion of procedural steps. The fraudster allegedly sent a harmful APK file to the victim’s mobile device, instructing installation. Subsequently, the victim was prompted to share personal details, account information, and other required credentials.
Investigation and Forensic Analysis
Investigators suspect the stolen data enabled unauthorized access to the account, facilitating the two transactions. Upon detecting the irregularities, the victim reported the matter to Pune Cyber Police. Preliminary examinations of digital evidence and financial records by Kharadi Police revealed the fraudulent activities.
Authorities are examining whether the fake banking portal, malicious APK, and call center operations were part of a broader organized cybercrime scheme. Forensic teams are tracing the recipient bank accounts for the stolen funds and analyzing transaction patterns to identify potential suspects.
Expert Insights on APK-Based Scams
Criminals increasingly use deceptive tactics such as fake banking assistance, KYC updates, and net banking activation offers to entice victims into installing malicious software. Once installed, these applications can grant attackers control over devices, enabling extraction of sensitive data including banking credentials, one-time passwords (OTPs), and personal information.
A prominent cybercrime expert and former IPS officer, Prof. Triveni Singh, highlighted the rising prevalence of APK-based scams.
Preventive Measures and Public Awareness
Cybersecurity professionals have urged the public to verify the legitimacy of banking-related links before interacting with them and to avoid installing unverified applications. Officials emphasized that digital forensic analysis will be critical in determining the operation’s full scope.
