A young man from Balkeshwar Colony allegedly lost ₹1.98 lakh from two credit cards after a fraudster posing as a Union Bank employee sent him an APK file on WhatsApp in the name of cancelling an unwanted insurance service.
The victim, Saurabh Singh, told police that he received the call at around 1 pm on August 31. The caller introduced himself as Ankit Tinga from Union Bank’s credit card department and claimed that an insurance plan had been activated on Singh’s card.
The caller allegedly warned that ₹3,000 would be deducted every month unless the service was cancelled.
When Singh agreed to cancel it, the fraudster sent an APK file to his WhatsApp number and asked him to open it.
Within minutes, unauthorised transactions began appearing on his cards.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
₹1.49 Lakh Taken From One Card, ₹48,905 From Another
According to the complaint, multiple transactions totalling ₹1,49,950 were made from Singh’s Union Bank credit card.
Another ₹48,905 was then allegedly charged to his State Bank of India credit card.
The combined loss came to ₹1,98,855.
Singh immediately reported the transactions to the national cybercrime helpline at 1930.
Kamla Nagar Police have registered a case and begun examining the number used for the call, the WhatsApp communication, the suspicious application and the route through which the stolen money was spent or transferred.
The case is another example of fraudsters using a believable banking problem to persuade victims to install software outside official app stores.
What Is an APK and How Can It Become Dangerous?
APK stands for Android Package Kit.
It is simply the file format Android uses to install applications. Genuine applications also use APK files, so the format itself is not malicious.
The danger comes when criminals create a harmful app and send the APK directly through WhatsApp, SMS, email or a website.
Once installed, such an application may ask for permissions to read SMS messages, view notifications, access contacts or interact with other parts of the phone.
A banking Trojan can then potentially steal credentials, display fake login pages or send information back to servers controlled by criminals.
The Indian Cyber Crime Coordination Centre has warned that banking malware can create backdoor access to a device or imitate legitimate financial login pages to steal confidential information.
That is why saying an APK “hacks” a phone merely by existing on it is not technically precise.
The major risk generally begins when the user installs the app and gives it permissions it should never need.
Fake Banking Problems Are a Common Entry Point
The fraudster in the Agra case allegedly used an invented insurance charge to create urgency.
The method is effective because the victim believes he is preventing a future deduction rather than authorising a dangerous download.
Similar scams use KYC updates, electricity bills, gas connections, traffic challans or reward points.
In Chandigarh, police recently arrested a Jamtara resident accused of posing as an Adani Gas representative and sending malicious APK files to customers after threatening disconnection over supposedly unpaid bills. Investigators alleged that compromised phones were later used for unauthorised debit-card, credit-card and UPI transactions.
The similarity is important.
In both cases, the criminal did not begin by asking for an OTP or card number.
The attacker first created a believable service problem, then offered a convenient “solution” through an unofficial application.
Malicious APK Fraud Is Now Operating at Scale
Recent investigations suggest these scams are becoming industrialised.
In August, Surat Cyber Crime Police said they uncovered 336 malicious APK files connected with more than 31,000 installations and 5,613 compromised devices.
Police linked those files to alleged fraud worth around ₹125.39 crore across India.
A separate Surat investigation in July led to the arrest of an 18-year-old accused of developing fake banking APKs.
Police alleged that 121 malicious apps created by him had been installed on more than 21,000 phones and were linked to fraud exceeding ₹64 crore.
The Agra case is much smaller in financial value, but the method follows the same pattern.
The attacker impersonates a trusted institution, creates urgency and moves the victim outside official banking channels.
For investigators, the suspicious APK itself may now become one of the most useful pieces of evidence. Its code, server connections and permissions could show whether it was linked to a broader malware network.
What this means for you:
A bank will not normally ask you to install an APK received through WhatsApp to cancel insurance, update KYC or fix a card problem. If an unknown caller sends an app file, stop the conversation and contact the bank through its official app, website or customer-care number. If money is stolen, report it immediately to 1930; the government says rapid reporting has helped stop thousands of crores from being siphoned away.