In a poignant case highlighting the growing menace of search engine cyber fraud in Madhya Pradesh, a homemaker in Gwalior was cheated of ₹49,997 after attempting to book a medical appointment online. The stolen funds represented months of personal savings accumulated meticulously from government welfare disbursements, including the State Government’s flagship Mukhyamantri Ladli Behna Yojana and LPG gas cylinder subsidies.
The incident underscores a sophisticated social engineering trend across urban centers, where cybercriminals manipulate search engine optimization (SEO) algorithms to list fake customer care numbers for private clinics, hospitals, and essential service providers.
Malicious APK Deployment via Search Engine Manipulation
The victim, identified as Priyanka Gupta, a resident of Mahavir Ganj in Gwalior’s Morar area, sought an online appointment with an ear, nose, and throat (ENT) specialist for her elderly relative. Lacking the direct contact number for the clinic, she performed an internet search for the specialist’s medical practice in the Govindpuri area.
Unbeknownst to her, the mobile contact retrieved from the top search results was controlled by a cybercriminal network. Upon calling the listed number, an unidentified individual impersonating a clinic receptionist instructed her to complete a token registration fee of ₹1.
To facilitate the booking, the fraudster forwarded a Android Package Kit (.APK) file directly to her mobile device under the guise of an official appointment application. Once downloaded and installed, the malicious application granted the perpetrators remote access control and keystroke logging permissions on her smartphone. Although the initial token transaction failed, the background application had already captured her device security parameters.
Unauthorized Withdrawals and Financial Investigations
Over the subsequent days, the cybercriminals leveraged the compromised device credentials to execute three consecutive unauthorized bank transactions, draining a total of ₹49,997 from her savings account. The victim discovered the fraudulent withdrawals upon receiving transaction alerts from her banking institution, following which her spouse immediately approached the bank to freeze the compromised account.
According to preliminary investigative findings provided by the Morar Police Station and the local Cyber Cell, the illicit funds were swiftly routed through a chain of beneficiary accounts registered under individuals named Neha Kumari and Sujeet Chaurasia, alongside an account held with Jupiter neo-banking services.
A formal case has been registered under relevant cyber crime provisions at the Morar police station, with law enforcement tracking the digital transaction trail, Internet Protocol (IP) logs, and beneficiary account locations across state lines.
Vulnerabilities Surrounding Welfare Direct Benefit Transfers
The case reflects broader systemic security concerns regarding digital financial literacy among recipients of Direct Benefit Transfer (DBT) welfare schemes. State social security programs, such as the Ladli Behna Yojana, transfer monthly financial stipends directly into bank accounts, providing critical safety nets for millions of women across Madhya Pradesh.
However, as rural and semi-urban citizens retain accumulated welfare subsidies in digital savings accounts, cybercriminals are increasingly targeting them through remote access tools, fake search listings, and phishing applications. The Union Ministry of Home Affairs and cybersecurity agencies have consistently warned citizens against downloading third-party .APK files or trusting unverified contact details published on public search engines.
