APK File Downloads Trigger ₹24 Lakh Cyber Fraud in Noida, Three Victims Targeted

The420.in Staff
6 Min Read

Cyber fraudsters allegedly posing as bank employees, tax-related service providers and IGL officials cheated three people in Noida of a combined ₹24 lakh by persuading them to download APK files on their mobile phones. The victims were approached with offers or information related to credit cards, Income Tax Form 16 and gas bills. After the files were downloaded, money was transferred from their bank accounts. The three victims have reported the incidents to the cyber crime police and the National Cyber Crime Reporting Portal. Police are now investigating the transactions and the bank accounts used to receive the money.

The first case involves 69-year-old Rajesh, a cloth trader living in Sector 61. According to his complaint, he received a call on May 18, 2025, from a person claiming to be a bank employee. The caller offered to arrange a credit card from home and collected personal information while allegedly helping him complete an online application.

During the conversation, the caller sent an APK file through WhatsApp and instructed Rajesh to download it. After the file was installed, the caller allegedly told him that the application had been successfully submitted and that the credit card would soon be delivered to his home.

FCRF Launches Flagship Certified Cyber Security Auditor (CCSA) Program for Next-Generation Cyber Auditors

The next day, Rajesh received four messages informing him that money had been deducted from his bank account. A total of ₹8 lakh had been withdrawn or transferred. He subsequently realised that the person who had claimed to be a bank employee was allegedly a cyber fraudster.

Investigators are examining whether the APK file enabled unauthorised access to the device or banking-related information. Police are also tracing the accounts into which the stolen money was transferred.

Form 16 Search Leads to ₹9 Lakh Fraud

The second case involves 61-year-old Hemant, a retired railway employee from Sector 107. On July 3, he searched Google for information about Income Tax Form 16. During this period, he allegedly received a call from a person claiming to be able to provide the required form.

The caller reportedly offered to help him obtain the document and persuaded him to download an APK file. After the file was downloaded, the fraudster allegedly gained access to information linked to his bank account. Around ₹9 lakh was subsequently transferred from his account through multiple transactions.

Hemant realised that he had been defrauded after receiving banking alerts on his mobile phone. Police are examining the digital trail and the accounts that received the money.

IGL Bill Pretext Used to Steal ₹7 Lakh

The third case concerns 67-year-old Rajendra, a resident of Sector 31. On February 6, he allegedly received a call from a person claiming to be an IGL employee. The caller told him that an outstanding gas bill was pending.

Rajendra reportedly said that the bill had already been paid. The caller then allegedly offered to show him the outstanding bill and sent an APK file for the purpose. After Rajendra downloaded the file, the accused allegedly obtained access to information connected with his bank account.

Around ₹7 lakh was subsequently transferred from the account. The victim realised what had happened after the money was debited.

APK Files Emerging as a Common Fraud Tool

Although the three victims were approached using different pretexts, investigators found a similar pattern in all three cases. The alleged fraudsters first established credibility by referring to essential services such as banking, taxation or utility payments. They then persuaded the victims to download APK files, after which unauthorised transactions allegedly took place.

Cyber police are investigating whether the incidents were connected to the same organised group or whether different criminals were using a similar method. Investigators are also examining the beneficiary accounts and transaction trails to identify the people involved.

A Researcher at Algoritha Security said downloading an APK file at the request of an unknown caller can expose both the device and financial information to serious security risks. Even when someone claims to represent a bank, government department or service provider, users should independently verify the request through the organisation’s official website or helpline.

Police have advised people not to download unknown files received through WhatsApp or other messaging platforms. APK files received from unverified sources should be treated with particular caution. Users should never share banking credentials, OTPs, PINs or passwords with unknown callers.

In case of an unauthorised transaction, victims should immediately inform their bank and report the incident to the cyber crime authorities. Early reporting can improve the chances of tracing or freezing the movement of fraudulent funds.

Stay Connected