A man in Madhya Pradesh’s capital Bhopal became a victim of cyber fraud while trying to book an online appointment with a doctor. The fraudsters first offered to arrange the doctor’s appointment and then sent a fake APK file to his WhatsApp account.
After the file was installed, ₹7.12 lakh was allegedly transferred from the victim’s bank accounts through 18 transactions without his consent and without any OTP. Police have registered a case and launched an investigation following his complaint.
How Did the Scam Begin?
The victim, a resident of the Hanumanganj police station area, told police that he had to consult a doctor on October 3, 2026. He searched for the doctor’s mobile number on Google. When he called the number displayed in the search results, the person on the other end allegedly told him that he needed to book an online appointment before visiting the doctor.
At around 9:02 am, the accused sent a file named Appointment.apk to the victim’s WhatsApp account from the mobile number +91 62919-05886. The caller allegedly instructed him to download and install the file to complete the appointment process and grant all the permissions requested by the application. Trusting the caller, the victim downloaded the APK file and installed it on his mobile phone.
After getting the file installed, the fraudster allegedly told the victim to make a small online payment of ₹5 in the name of generating an appointment token. The victim attempted to make the payment, but the transaction failed. The caller then asked him to come directly to the clinic at around 12:30 pm.
The victim subsequently deleted the APK file from his phone and went to the clinic himself for the consultation. He also paid the doctor’s consultation fee through Google Pay. He believed that the appointment process had ended and that there was no further issue.
However, according to the preliminary police investigation, the suspicious APK file installed on the phone had allegedly given the fraudsters access to the device. Although the victim deleted the file later, the alleged fraudulent activity surfaced a few days afterward.
Between around 11 am and 12:30 pm on October 6, 18 consecutive transactions were carried out from the victim’s bank accounts. Police said the transactions were made without the victim’s consent and without requiring any OTP. The fraudsters allegedly transferred the money to different accounts, siphoning off a total of ₹7,12,000.
The victim realised that he had been defrauded after receiving a series of transaction alerts from his bank. He immediately contacted the bank and got his accounts blocked. He then approached the Hanumanganj police station and submitted a written complaint.
What Are Police Investigating?
Police are now investigating the mobile number allegedly used in the fraud, the suspicious APK file and the bank transactions with the assistance of the cyber cell. Investigators are trying to determine which bank accounts received the money and whether their operators had any connection with the suspected fraud network.
The police are also examining the digital evidence and financial transaction trail to identify the people allegedly involved in the fraud. The case has highlighted the risk of downloading APK files sent by unknown callers, particularly when such files are presented as necessary for booking appointments or completing online services.
How Can a Doctor Appointment Turn Into a Scam?
The case also highlights a fraud route that can begin before a patient even reaches a hospital or clinic. A person searching online for a doctor, hospital or appointment number may contact a number believing it belongs to the genuine healthcare provider. The fraudster can then use the victim’s immediate need for an appointment to persuade them to follow instructions that appear to be part of the booking process.
In this case, the alleged fraud began after the victim searched Google for a doctor’s number and contacted the number displayed in the results. The subsequent request to install a file called “Appointment.apk” could appear connected to the appointment because of its name. The request for a small ₹5 token payment could further make the process appear like a routine booking procedure.
Why Are APK Files a Warning Sign?
Patients should be particularly cautious when someone claiming to arrange a medical appointment sends an APK file through WhatsApp or another messaging service and asks them to install it. An APK is an Android application installation file, and installing one received from an unknown source can expose the device to significant security risks, particularly if the application asks for extensive permissions.
The Bhopal case shows why the identity of a hospital, clinic or doctor should be independently verified before following payment or installation instructions received through a number found online. Patients should preferably use the healthcare provider’s verified official website, application or confirmed contact details for appointments rather than installing files sent by unknown callers.
The420 Takeaway: Verify Before Booking
A routine search for a doctor’s appointment can become an entry point for cyber fraud if the contact number or person handling the supposed booking is not genuine. Never install an APK sent over WhatsApp merely to book a medical appointment, and be cautious if a caller asks for unusual app permissions or a token payment. If money is fraudulently transferred, contact the bank immediately and report the incident through the cybercrime helpline 1930.
About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics