Faridabad Police have arrested a Gautam Budh Nagar resident in connection with a ₹97,000 cyber fraud in which a woman was allegedly tricked into installing a malicious APK file while trying to resolve an Airtel recharge problem.
The accused, identified as Manav Sharma, was arrested by the Cyber Police Station NIT team after investigators traced the fraud proceeds to his bank account. Police said the woman was targeted after searching online for a customer-care number.
The case adds to a series of recent APK-based frauds reported in Faridabad, where scammers have impersonated telecom companies, banks, gas providers and online businesses to persuade victims to install files outside official app stores.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Google search for customer care led victim to fraudster
According to police, the victim is a resident of Jawahar Colony in Faridabad.
On September 15, she recharged her Airtel SIM but did not receive the amount of mobile data she expected under the plan. She then searched Google for a customer-care number and called the number displayed in the results.
The person who answered allegedly introduced himself as an Airtel employee.
He told the woman that her Know Your Customer, or KYC, verification needed to be completed before the issue could be resolved.
The caller then sent an APK file to her WhatsApp number and asked her to open it for the supposed KYC process.
Phone screen went black after APK was opened
The woman told police that her mobile screen went black after she opened the file.
Soon afterwards, ₹97,000 was debited from her bank account.
Police registered a case at Cyber Police Station NIT and began tracing the financial trail.
Investigators subsequently found that the ₹97,000 allegedly reached a bank account belonging to Manav Sharma.
Police arrested Sharma and produced him before a court, which sent him to judicial custody. The report says he is educated up to Class 8 and unemployed.
At this stage, the available police account identifies him as the recipient account holder. It does not establish that he personally made the fraudulent call, created the APK or controlled the malware.
Those roles will have to be established through further investigation.
Why APK files are repeatedly appearing in Faridabad fraud cases
APK stands for Android Package Kit, the file format used to install applications on Android phones.
Legitimate Android apps also use APK files, but installing one received directly through WhatsApp, SMS or another unofficial source can be dangerous because it bypasses some of the safeguards provided by official app stores.
A malicious APK can potentially seek permissions that expose SMS messages, notifications, accessibility controls or other sensitive functions.
However, in this particular case, police have not publicly released a forensic analysis explaining exactly what the file did.
The victim’s account that the screen went black after installation suggests the phone may have been manipulated, but it would be premature to state precisely how the ₹97,000 transaction was authorised until investigators release technical findings.
Similar APK frauds have surfaced across Faridabad this month
The ₹97,000 case is not isolated.
On September 17, Hindustan reported that a Faridabad businessman and his wife lost about ₹2.28 lakh after an APK file was allegedly sent in connection with a Facebook advertisement for car mats.
Another Faridabad resident lost ₹6.35 lakh after scammers allegedly sent an APK while pretending to help with a pending gas bill.
A retired NTPC employee separately reported losing ₹4.33 lakh from two bank accounts after installing an APK received on WhatsApp.
On September 23, another Faridabad complainant said scammers posing as bank employees used a credit-card update pretext and an APK file in a fraud involving about ₹4.49 lakh.
These cases involve different victims and alleged methods, and there is currently no public evidence that they were operated by the same criminal group.
Fake customer-care numbers remain an important entry point
The new case also highlights a second recurring risk: fraudulent customer-care numbers appearing in search results or online advertisements.
Victims often believe they are calling a genuine bank, telecom company or e-commerce platform because they actively searched for help.
That gives the fraudster an immediate advantage.
The caller already knows that the victim has a real service problem and can tailor the conversation around it.
Faridabad Police dealt with a similar pattern earlier this month when two suspects were arrested in fraud cases involving fake customer-care numbers and losses totalling around ₹1.83 lakh.
The safest approach is to obtain support numbers from the service provider’s official website, verified app or billing documents rather than relying on advertisements or unfamiliar numbers appearing in general search results.
Arrest follows wider Faridabad cybercrime crackdown
The arrest comes during a broader enforcement drive by Faridabad Police.
Those cases involved different forms of cyber fraud, including malicious APK files, investment schemes and the use of bank accounts to move stolen funds.
The latest ₹97,000 case again shows why recipient accounts are central to cybercrime investigations.
Even where the person making the fraud call is located elsewhere, following the money can lead investigators to bank accounts used to receive or transfer the proceeds.
Whether an account holder knowingly participated in the fraud must still be established through evidence.
What this means for you: Never install an APK sent through WhatsApp or SMS for KYC, recharge, bill payment or customer support. If you need assistance from a telecom company or bank, use only the official app or contact details listed on its verified website.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics