Six Hyderabad Residents Lose Over ₹23 Lakh To Fake APK Apps In Two Days: How Are Fraudsters Using Bills And Bank Updates To Empty Accounts?

Six Hyderabad-area residents lost roughly ₹23.2 lakh after installing malicious Android APK files or following fake app-update instructions in a burst of cyber fraud reported over two days. The victims, several of them retired employees, were approached with believable hooks: a water-bill update, a pension card, a bank-app upgrade, a credit-card limit increase and even a Facebook advertisement. Hyderabad, Cyberabad and Malkajgiri cyber crime police registered cases after complaints were filed on August 6 and 7. The episode shows how quickly a routine-looking WhatsApp file or banking message can turn into direct access to money.

How Did Six Hyderabad Residents Lose More Than ₹23 Lakh?

The biggest reported loss was ₹6 lakh. A 67-year-old retired employee from Gunfoundry was contacted by a person posing as an IndusInd Bank representative and offered a lifetime-free senior citizen pension card. He downloaded an APK sent through WhatsApp. Three unauthorised transactions followed on August 6.

A retired railway officer, 82, from Kondapur lost ₹3.7 lakh after clicking a Facebook advertisement claiming to update the Union Bank app. A caller then guided him over video call and got a fake APK installed. Four transactions were made on August 4 and 5.

The other cases followed the same broad pattern. A Moulali businessman lost ₹3 lakh after a supposed RBL Bank representative offered a credit-card limit increase. A Jiyaguda retiree lost ₹4.6 lakh; police later found “RTO Challan” and “RTO m-Wallet” apps on his phone. Another retiree in Himayatnagar lost ₹4 lakh after installing “HMWSSB Bill Update.apk” received from a relative’s WhatsApp number. A Boduppal resident lost ₹1.9 lakh through a fake SBI pension-card APK. The six-case breakdown was reported by the Times of India.

Why Are Fake Bills And Bank Updates So Effective?

The bait works because it arrives dressed as a task people already expect to complete. A pending bill, KYC check, pension-card offer or mobile-banking update creates urgency without sounding unusual. Fraudsters may also use familiar branding, social-media advertisements, compromised contacts or callers pretending to be bank staff.

Once an Android user installs an APK outside an official app store and grants powerful permissions, malicious software may read messages, capture OTPs, collect banking details or help criminals operate the device remotely. In March 2026, CERT-In warned about an RTO and e-Challan Android malware campaign using files such as “RTO Challan.apk” and “MParivahan.apk”.

The scale is not limited to Hyderabad. In July, Surat police arrested an 18-year-old accused of building fake banking and company apps for cybercriminal groups; investigators said some versions could relay OTPs and banking information to an admin app in real time. The case was detailed by NDTV.

What Warning Signs Should Android Users Watch For?

Hyderabad Cyber Crime had already warned residents about fake HMWSSB water-bill links and malicious APKs sent through SMS, WhatsApp and phone calls. The official Cyber Crimes Unit Hyderabad post on X is especially relevant because one of the latest victims installed an HMWSSB-themed file.

Watch for these red flags:

  • An APK arrives directly through WhatsApp, SMS, Telegram or email.
  • A caller asks you to install an “update” instead of using the official app store.
  • A bill message threatens quick disconnection unless you act immediately.
  • Someone asks for screen-sharing, accessibility access, OTPs, PINs or card details.
  • A banking advertisement leads to a download page outside the bank’s verified website.

A genuine-looking logo is not proof. Open the bank, utility or government website yourself rather than using the message link.

What Should A Victim Do Immediately After Installing A Fake APK?

Speed can affect the chance of stopping further transfers. Disconnect mobile data and Wi-Fi, contact the bank through its verified number, block cards or digital banking where necessary, and change credentials from a clean device. The Reserve Bank of India advises customers to notify their bank immediately about unauthorised electronic transactions.

Financial cyber fraud should also be reported immediately on the National Cyber Crime Reporting Portal or by calling 1930. The portal also offers tools for reporting suspicious phone numbers, URLs, WhatsApp handles and other identifiers. Keep screenshots, transaction IDs, phone numbers and the suspicious message instead of deleting everything before filing the complaint.

FAQs

What is an APK fraud?


It uses a malicious Android installation file to steal data, OTPs or banking access remotely.

Can a fake bill APK empty a bank account?


Yes, malicious permissions can expose banking credentials, messages and OTPs used for unauthorised financial transactions.

Should banks send APK files through WhatsApp?


Customers should avoid WhatsApp APKs and download banking apps only through verified official app stores.

What number should cyber-fraud victims call in India?


Call 1930 immediately for financial cyber fraud and file the complaint on cybercrime.gov.in without delay.

Can uninstalling the fake APK stop the fraud?


Uninstalling helps, but victims should disconnect the internet, contact banks and change credentials from another device.

Related Articles