A 67-year-old accountant residing in the Ellisbridge area of Ahmedabad has allegedly been defrauded of ₹3.20 crore after opening a malicious Android Application Package (APK) file received via WhatsApp under the pretext of the Pradhan Mantri Awas Yojana. The complaint, registered with the Cyber Cell of the Ahmedabad Crime Branch, indicates that unauthorized access gained through the mobile device resulted in hundreds of immediate payment service (IMPS) transactions siphoning capital from three linked bank accounts.
Deceptive Message Leads to Device Compromise
The incident began on September 10 when Dilipbhai Chinubhai Shah received a message from the mobile number of an acquaintance operating a garage. The communication claimed that Shah had been designated as a beneficiary under the central government’s housing scheme and included an attached APK file. Shah opened the file, but when no interface or activity appeared on the display, he closed it. Investigators suspect that launching the application provided the perpetrators covert administrative or remote access to the smartphone, allowing them to capture banking credentials and bypass security protocols tied to the registered mobile number.
Bounced Cheques Expose Massive Depletion of Funds
The unauthorized transactions remained undetected until September 19, when Shah’s son, Jainam, attempted to deposit two separate cheques. These included a cheque for ₹2.21 lakh drawn on Shah’s Punjab National Bank account and another for ₹1.99 lakh drawn on his mother Shilpa’s Bank of Baroda account. Both instruments were promptly returned by the banks citing insufficient balances. Upon inspecting their balances via mobile banking applications, Shah discovered only around ₹10,000 left in his account, while his wife’s balance had fallen to just ₹635.
Realising that his contact number was also linked to a Bank of India account belonging to his friend Pravin Chandra Patel, Shah alerted him to verify his funds. Almost simultaneously, an alert arrived indicating a deduction of ₹10,000 from Patel’s account. Subsequent verification confirmed that Patel’s account had also been compromised, prompting the family to formally notify the authorities.
Police Trace Digital Trail Across Beneficiary Accounts
Official transaction statements compiled in the formal complaint show that the illicit transfers occurred systematically between September 12 and September 21. The perpetrators executed rapid IMPS transactions valued from ₹1,000 to ₹99,999 across a wide network of recipient accounts. A large portion of the withdrawals involved repeated transactions of ₹10,000, ₹15,000, ₹20,000, and ₹30,000 alongside several larger transfers, ultimately draining a cumulative ₹3.20 crore across the three linked accounts.
The Ahmedabad Crime Branch Cyber Cell has launched an extensive technical investigation to track the money trail, freezing the recipient accounts and identifying the secondary layers where the stolen funds were routed. Cyber forensic experts are analyzing the digital route of the APK file to determine its code architecture, device compromise mechanism, and distribution infrastructure. Police officials noted that establishing the identities of the individuals operating the beneficiary accounts and tracing the originating devices remain central to uncovering the wider network orchestrating the operation.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics