A Bareilly man allegedly lost ₹5.06 lakh after installing an APK sent over WhatsApp while trying to book an online doctor appointment.

Bareilly Man Loses ₹5.06 Lakh After Downloading Fake Doctor Appointment APK

The420 Web Correspondent
6 Min Read

A Bareilly resident allegedly lost ₹5.06 lakh after downloading an APK file sent by a cyber fraudster while trying to book a doctor’s appointment online.

The victim, Sarvesh Sharma of IFFCO Colony, had searched Google for the contact number of an ear, nose and throat specialist near Ayub Khan Crossing after his child developed a health problem on August 24. He called a number shown in the search results and was told that the appointment process had changed.

The person on the other end allegedly sent Sharma an APK file through WhatsApp and asked him to install it to complete the booking.

The appointment was never confirmed. Sharma later visited the doctor directly and obtained treatment for his child.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

₹5.06 lakh found missing weeks later

The alleged fraud was discovered nearly three weeks later.

When Sharma visited his bank on September 12, he found that approximately ₹5.06 lakh had been withdrawn from his Punjab National Bank account without his authorisation, according to his complaint.

He subsequently approached the cybercrime authorities.

Bareilly Cyber Police registered a case against an unidentified person and began examining the mobile number, WhatsApp account, banking transactions and digital evidence connected with the APK file.

Inspector Siddharth Singh Tomar has been assigned the investigation, according to local reporting.

Police have not yet publicly established exactly how the money was removed from the account.

That distinction matters because while the APK is suspected to have played a role, forensic examination will be needed to determine what permissions it obtained and whether additional banking credentials, OTPs or other authentication information were compromised.

What an APK file can do

APK stands for Android Package Kit. It is the file format used to install applications on Android phones.

Legitimate Android apps also use APK files, but users normally receive them through trusted app stores.

Installing an APK sent directly through WhatsApp, SMS or another messaging service can bypass some of the safeguards provided by official app stores.

A malicious APK may ask for permissions to read messages, access contacts, display content over other apps or use accessibility features.

Depending on the malware involved and the permissions granted, attackers may be able to intercept sensitive information or manipulate what appears on the phone.

That is why the presence of an APK in a fraud case is significant, although investigators still need technical evidence before concluding exactly how the victim’s bank account was compromised.

Fake numbers in search results create another layer of risk

The Bareilly case also began with a problem that appears unrelated to banking: searching online for a doctor’s telephone number.

The victim believed he had found a legitimate contact linked to the clinic.

Police are now examining how the number allegedly associated with the fraudster appeared in online search results and who controlled it.

Cybercriminals have repeatedly exploited people searching for hospitals, customer-care services and other businesses by presenting unofficial contact numbers as genuine assistance lines.

A similar case was reported in Lucknow earlier this month, where a woman allegedly lost ₹2.53 lakh while trying to arrange a doctor’s appointment. She was reportedly asked to install a file named “hospital service.apk” before unauthorised transactions followed.

The two cases show a similar social-engineering pattern: the victim is already trying to complete a legitimate task, so the request to install an “appointment” application may appear less suspicious.

Appointment scams exploit trust, not just technology

The technical file is only one part of the fraud.

The first step is convincing the victim that the person answering the telephone genuinely represents the doctor or hospital.

In the Bareilly case, the caller allegedly claimed that the process for booking appointments had recently changed.

That explanation gave the subsequent APK download an apparently legitimate purpose.

Once a victim trusts the caller, requests for downloads, permissions, small payments or banking information can appear routine.

For this reason, deleting malware after installation may not be enough. Anyone who has installed an unknown APK should also contact their bank, review transactions, change important passwords from a clean device and report suspicious financial activity quickly.

India’s national cybercrime helpline is 1930, and complaints can also be submitted through the National Cyber Crime Reporting Portal.

The Bareilly police investigation will now focus on tracing the account transactions and determining whether the number and APK were used against other victims as well.

What this means for you: Never install an APK sent by someone claiming to book a doctor, hospital, courier or customer-care appointment. Verify telephone numbers from the organisation’s official website or established channels, and immediately contact your bank and 1930 if you installed an unknown file and notice suspicious activity.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected