Kerala Police have warned of a growing cyber fraud in which people searching online for hospital appointments are being redirected to fake phone numbers and then tricked into installing malicious Android applications.
The scam targets patients looking for OP appointments or contact details of well-known hospitals. Fraudsters allegedly place or promote fake phone numbers in Google search results and pose as hospital staff when victims call.
They then send an APK file over WhatsApp with names such as “hospital appointment booking” and ask the victim to install it.
Once installed, the malicious application can expose confidential information, OTPs and UPI-related details, potentially allowing unauthorised financial transactions.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Search results are being used as the first trap
The fraud begins before the victim downloads anything.
A patient may simply search online for the phone number of a hospital or an appointment desk. If the number shown in search results is fake, the victim can unknowingly contact the scammer directly.
The fraudster then behaves like a hospital employee and uses the urgency of securing a medical appointment to gain trust.
That makes this scam especially dangerous because people seeking medical help may be less likely to question instructions that appear to come from a hospital.
Police have advised users to verify hospital phone numbers through the hospital’s official website or verified social-media pages before calling or making any payment.
Kerala already has an official eHealth system through which patients can create a health ID and book appointments at participating government hospitals. The state Health Department says users can log in through the official eHealth portal, choose a hospital and department, and select available appointment tokens.
What the fake APK can do after installation
An APK is the file format used to install applications on Android phones.
There is nothing inherently suspicious about APK files. Legitimate Android applications also use them.
The risk arises when a file is sent through WhatsApp, SMS or an unknown website and asks for permissions that an appointment-booking app should not need.
Kerala Police said malicious files used in these scams can compromise the phone and expose SMS messages, notifications, OTPs and UPI information.
They may also allow fraudsters to misuse existing UPI applications or install additional payment apps without the user’s knowledge.
Users should therefore be suspicious if a so-called hospital application asks for access to SMS, contacts, notifications or phone functions.
A hospital appointment does not normally require an unknown app sent privately through WhatsApp.
UPI Lite users face an extra risk
Police have issued a specific warning to people using UPI Lite.
UPI Lite allows certain low-value payments to be made more quickly, and some transactions within the permitted limit may not require a separate OTP.
That means a compromised phone may be used for a series of small unauthorised payments without each transaction appearing dramatic on its own.
Kerala Police said users should not ignore repeated transactions below ₹1,000 simply because the amounts are small.
This is important because fraudsters often split stolen money into smaller transfers to delay detection.
Victims may notice only after several transactions have already gone through.
Hospital appointment fraud is appearing in other states too
The method is not limited to Kerala.
Police in Belagavi, Karnataka, warned in August that fraudsters were impersonating health-service representatives and extracting OTPs or banking details from people while they were trying to book hospital appointments.
A separate case reported from Sonipat earlier this year also involved fraud under the pretext of arranging a hospital appointment, alongside other online financial scams.
The common pattern is urgency combined with trust.
People tend to assume that a hospital contact displayed online is genuine, particularly when they are already worried about getting an appointment quickly.
Fraudsters are exploiting exactly that behaviour.
What to do if you installed a suspicious hospital app
Kerala Police have advised anyone who suspects that they installed a malicious APK to immediately disconnect the phone from the internet.
They should then contact their bank or UPI service provider to secure the account.
Victims who have lost money should report the incident through the cybercrime helpline 1930 or the National Cyber Crime Reporting Portal.
The safest prevention remains simple: do not install appointment, KYC or refund applications received privately over WhatsApp.
Download applications only from trusted stores such as Google Play, and verify hospital contact information through official channels before sharing any personal or financial details.
What this means for you: Never install a hospital “appointment” APK sent over WhatsApp, even if the caller sounds genuine. Verify the hospital’s number independently and watch for unexplained small UPI transactions, especially if you use UPI Lite.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics