Mumbai: A 66-year-old retired bank employee from Dadar allegedly lost ₹7.02 lakh after cyber fraudsters sent him an SMS impersonating the Election Commission and claimed that there was an error in his name on the electoral roll. The fraudsters allegedly directed him to contact a phone number for correction and subsequently shifted the communication to WhatsApp, where they sent files and instructed him to provide personal and banking details.
The victim, a resident of Hindu Colony in Dadar East and a retired Syndicate Bank employee, approached the police after discovering that money had been withdrawn from his bank account as well as a linked account belonging to his wife.
Fake Election Commission SMS Starts the Fraud
According to the complaint, the incident occurred around 6 pm on August 25 while the victim was at home. He received an SMS from an unknown number whose profile picture allegedly displayed the Election Commission. The message claimed that his name on the voter list was incorrect and asked him to contact the number mentioned in the message.
When the victim called the number, the person on the other end allegedly introduced himself as an Election Commission official based in Mumbai. He was then instructed to continue the verification and correction process through WhatsApp.
WhatsApp Link and File Used to Collect Personal Details
The victim subsequently received a file from another WhatsApp number and was allegedly instructed to open it and enter details such as his name, age and mobile number. He was then redirected to another page and asked to make a payment of ₹5.
Following the instructions, the victim entered his net-banking credentials. The fraudsters allegedly sent him an APK file shortly afterwards and instructed him to open it.
APK File Followed by Unauthorised Bank Transactions
Soon after the APK was opened, the victim began receiving messages indicating that money was being debited from his bank accounts. He realised that he had likely fallen victim to cyber fraud after four transactions resulted in a total loss of approximately ₹7.02 lakh.
Police said ₹4,65,627 was allegedly debited from the victim’s account, while another ₹2,36,383 was allegedly withdrawn from his wife’s linked account.
The sequence of events is now being examined by investigators to determine whether the APK facilitated unauthorised access to the device or whether the banking credentials entered by the victim were used to carry out the transactions.
How the Fake Election Commission Scam Worked
The alleged fraud combined government impersonation, social engineering, a fake correction request, a fraudulent payment page and a potentially malicious APK.
By claiming that the victim’s electoral-roll information required immediate correction, the fraudsters allegedly created a sense of urgency. The communication was then moved from SMS to WhatsApp, where the victim was allegedly persuaded to open files and provide information.
The case demonstrates how scammers can use the identity of trusted government institutions to make fraudulent communications appear genuine.
₹7.02 Lakh Routed From Two Linked Accounts
The police investigation is also focused on the financial trail. The alleged transactions involved both the victim’s account and his wife’s linked account, with a combined amount of ₹7.02 lakh reportedly withdrawn.
Investigators are examining the beneficiary accounts, transaction details and other banking records to determine where the money went after it was debited.
The phone numbers, WhatsApp accounts and digital files allegedly used by the fraudsters are also being examined to establish whether they are connected to other complaints.
Police Trace Digital and Financial Trail
The victim immediately contacted the national cybercrime helpline at 1930 and later filed a complaint through the Citizen Portal. Matunga Police are investigating the case and examining the phone numbers, WhatsApp accounts, payment trail and digital files allegedly used in the fraud.
Investigators are also expected to examine the APK file and determine whether it was designed to facilitate unauthorised access to the victim’s device or banking information. The money trail could help police identify the accounts and individuals allegedly involved in receiving or moving the stolen funds.
Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions
Why APK Files From Unknown Sources Are Risky
An APK, or Android Package Kit, is the file format used to install applications on Android devices. While APK files themselves are not inherently fraudulent, installing an application received from an unknown or unsolicited source can create security risks, particularly when the file is accompanied by requests for sensitive permissions.
Users should avoid installing APK files received through unexpected SMS or WhatsApp messages, especially when the sender claims to represent a government department, bank or other trusted organisation.
Cybercrime Expert Warns Against Government Impersonation
Renowned cyber crime expert and former IPS officer Prof. Triveni Singh said such scams exploit the victim’s trust in official institutions rather than relying only on technical vulnerabilities. He said people should not install APK files or enter banking credentials merely because a message claims to have been sent by a government department.
The case also underlines the danger of responding to unsolicited SMS messages that create a sense of urgency around voter records, bank accounts or government documents. Official departments generally provide established channels for verification, and any unexpected request involving payment, banking credentials or application installation should be treated with suspicion.
What to Do If You Receive a Fake Government SMS
People receiving unexpected messages claiming to be from the Election Commission or another government department should not call numbers provided in the message, open unknown links or install applications sent through WhatsApp.
If banking details have already been shared or money has been transferred, the incident should be reported immediately through 1930 and the National Cyber Crime Reporting Portal. The victim should also contact the concerned bank and preserve screenshots, phone numbers, messages, transaction IDs and other digital evidence.
Investigation Continues
Police are continuing to investigate the alleged fraud and trace the digital and financial trail. The probe will determine how the suspects obtained the victim’s details, where the fraudulent communications originated and whether the same network has targeted other people using fake Election Commission messages.
The investigation is also likely to focus on the movement of the ₹7.02 lakh allegedly withdrawn from the two linked accounts and the role of any intermediaries who may have helped transfer or withdraw the money.
The allegations remain subject to investigation, and the identities and roles of the persons behind the alleged fraud will be established through the police probe and subsequent legal proceedings.
About the author — Ananya Aradhya writes on cybercrime, fraud, scams, cybersecurity, digital safety, and emerging threats. Her work also covers major criminal cases, financial frauds, consumer scams, and stories that highlight risks affecting people in the real and digital world.