A retired RBI employee in Hyderabad lost ₹3.25 lakh after falling for a fake Election Commission verification scam involving a malicious APK file and WhatsApp video calls.

Fake Election Commission Verification Scam: Retired RBI Official Swindled of ₹3.25 Lakh

The420 Web Correspondent
6 Min Read

In a troubling cyber fraud incident demonstrating the evolving tactics of digital extortion, a retired Reserve Bank of India (RBI) employee residing in the Ameerpet area of Hyderabad was defrauded of ₹3.25 lakh. The cybercriminals executed the scam by impersonating officials from the Election Commission of India (ECI), deploying a multi-stage deception that combined artificial urgency, a staged WhatsApp video call, and a malicious Android Application Package (APK) file to breach the victim’s banking security.

The case highlights an alarming operational model where fraudsters utilize micro-transactions to disarm a victim’s natural caution before siphoning large sums of money. Following a formal complaint, the Hyderabad Cybercrime Police registered a case and initiated technical analysis to trace the digital footprint, banking channels, and communication endpoints used by the criminal network.

Elaborate Impersonation and Artificial Urgency

The fraudulent scheme began when the retired central bank official received an unexpected SMS message claiming that his voter registration records required immediate verification within 48 hours. The communication warned that failure to complete the process would lead to the suspension or deletion of his electoral records. Because the Election Commission of India is a trusted constitutional body, the urgency conveyed in the message bypassed the victim’s initial skepticism, leading him to treat the notice as an authentic government directive.

Shortly after the SMS was delivered, a fraudster contacted the victim via WhatsApp, posing as an official representative from the ECI customer support division. The caller offered personalized guidance to help the senior citizen complete the mandatory verification process without visiting an electoral office. By adopting a professional tone and referencing official-sounding administrative procedures, the fraudster systematically established rapport and earned the victim’s trust over the course of the conversation.

Malicious APK Deployment and Video Call Manipulation

To facilitate the verification exercise, the fraudster instructed the victim to download a specific utility file sent over WhatsApp, disguised as an official document titled “ECI-Customer Support (PDF)”. Unbeknownst to the victim, the downloaded file was actually a malicious Android Application Package containing remote-access spyware. Once installed on the device, the spyware granted the perpetrators administrative privileges, enabling them to track keystrokes, capture banking credentials, and read incoming SMS notifications including One-Time Passwords.

To further solidify credibility and eliminate any lingering doubt, the criminals initiated a WhatsApp video call. During the visual interaction, the fraudster presented themselves as an Election Commission official operating from an administrative setting. This sophisticated visual staging completely disarmed the victim, convincing him that he was interacting with legitimate constitutional personnel and providing a false sense of security while the spyware operated silently in the background of his mobile phone.

The Micro-Transaction Trap and Device Compromise

With the spyware active on the device, the fraudster instructed the victim to pay a nominal processing fee of ₹4 to finalize the electoral verification. The victim completed the small transaction using his regular online banking portal. Shortly afterward, the fraudster claimed that the initial payment had failed due to a temporary gateway error and requested a second transfer of ₹5. Believing the explanation, the victim executed the second payment as requested.

These micro-payments served as a tactical trap designed to lower the victim’s suspicion while capturing active banking credentials and transaction PINs in real time. Because transfers of ₹4 and ₹5 appeared completely harmless, the victim did not suspect financial foul play. Once the spyware captured the required authorization data, the fraudsters initiated unauthorized high-value debits, siphoning a total of ₹3.25 lakh across two linked bank accounts before the victim realized he had been duped.

Expert Warning and Safeguards Against APK Scams

Commenting on the incident, former IPS officer and cybercrime expert Prof. Triveni Singh noted that cybercriminals increasingly weaponize the reputation of respected public institutions to manipulate targets. Prof. Singh explained that fraudsters rely on authority bias to bypass common sense, convincing victims to perform seemingly trivial actions like installing files or making nominal payments that ultimately compromise their entire digital identity and financial ecosystem.

Cybersecurity authorities and police agencies have issued strict advisories warning citizens against side-loading APK files delivered through messaging platforms, social media, or SMS links. Official government agencies never distribute application installers through unofficial channels or demand administrative fees via chat apps. Citizens are urged to verify all electoral and civic requirements through official government portals such as eci.gov.in and immediately report suspicious financial debits to the national cybercrime helpline at 1930.

Stay Connected