Banks Warn: Avoid WhatsApp APK Scams – Mumbai Credit Card Scam Alert
A 70-year-old individual from Khar fell victim to a cyber fraud scheme involving a deceptive offer of a premium credit card, resulting in the unauthorized transfer of ₹6.7 lakh.
The Incident
A 70-year-old individual from Khar fell victim to a cyber fraud scheme involving a deceptive offer of a premium credit card, resulting in the unauthorized transfer of ₹6.7 lakh. The incident underscores the importance of recognizing and avoiding unsolicited requests for APK file installations, as such tactics are frequently exploited by cybercriminals. The victim, identified as KM Raju, received a call from an individual claiming to represent a bank’s credit card department. The caller promoted a high-tier credit card with a joining and annual fee of ₹12,500, along with applicable taxes.
Scammer’s Tactics
Following this discussion, the scammer sent a fraudulent APK file to Raju’s account, falsely attributing it to the bank. The file was presented as a necessary step to complete the application process. Once the malicious application was installed, the fraudster gained control of Raju’s mobile device, enabling unauthorized access to his banking accounts. Within an hour of the initial contact, eight fraudulent transactions were executed across multiple accounts linked to Raju, including those of his wife, sister, and daughter.
Authorities’ Response
Investigators noted that joint family accounts facilitated the transfer of funds from several sources after the device was compromised. The victim’s mobile phone reportedly shut down automatically during the incident, prompting him to suspect foul play. Upon discovering the unauthorized activity, Raju contacted the cybercrime helpline at 1930 and reported the case. Law enforcement officials notified the relevant banks and initiated measures to freeze the accounts where the illicit funds were allegedly transferred.
Cybersecurity Warnings
Authorities have emphasized that financial institutions do not require customers to install third-party APK files for credit card applications. The scam exploited the victim’s trust by leveraging the promise of exclusive financial products to justify the installation of malicious software. Cybercrime investigators are currently assessing whether the perpetrator is linked to a broader network of fraudsters and whether additional victims may have been targeted using similar methods.
Conclusion
The case highlights the increasing prevalence of APK-based attacks, where cybercriminals impersonate legitimate entities to trick users into downloading harmful applications. These tools often grant attackers access to sensitive data and financial systems, enabling rapid exploitation. Police have reiterated warnings to the public to refrain from installing APK files received via unverified sources, including messages or calls from unknown individuals. They also advised users to immediately report any suspicious transactions to their banks and the cybercrime helpline to maximize the likelihood of recovering stolen funds. The incident serves as a stark reminder of the evolving tactics employed by cybercriminals and the critical need for vigilance when engaging with unsolicited communications. Financial institutions continue to emphasize that legitimate processes for account management or product applications do not involve the distribution of unapproved software.
